Security News > 2025 > April

Week in review: Probing activity on Palo Alto Networks GlobalProtect portals, Patch Tuesday forecast
2025-04-06 08:00

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Attackers are probing Palo Alto Networks GlobalProtect portals Cybersecurity company GreyNoise is...

Microsoft Credits EncryptHub, Hacker Behind 618+ Breaches, for Disclosing Windows Flaws
2025-04-05 15:50

A likely lone wolf actor behind the EncryptHub persona was acknowledged by Microsoft for discovering and reporting two security flaws in Windows last month, painting a picture of a "conflicted"...

Coinbase to fix 2FA account activity entry freaking out users
2025-04-05 15:36

Coinbase is fixing an incorrect account activity message that freaks out customers and makes them think their credentials were compromised. [...]

North Korean Hackers Deploy BeaverTail Malware via 11 Malicious npm Packages
2025-04-05 14:23

The North Korean threat actors behind the ongoing Contagious Interview campaign are spreading their tentacles on the npm ecosystem by publishing more malicious packages that deliver the BeaverTail...

WinRAR flaw bypasses Windows Mark of the Web security alerts
2025-04-05 14:14

A vulnerability in the WinRAR file archiver solution could be exploited to bypass the Mark of the Web (MotW) security warning and execute arbitrary code on a Windows machine. [...]

Malicious Python Packages on PyPI Downloaded 39,000+ Times, Steal Sensitive Data
2025-04-05 08:38

Cybersecurity researchers have uncovered malicious libraries in the Python Package Index (PyPI) repository that are designed to steal sensitive information. Two of the packages, bitcoinlibdbfix...

Friday Squid Blogging: Two-Man Giant Squid
2025-04-04 21:03

The Brooklyn indie art-punk group, Two-Man Giant Squid, just released a new album. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Trump fires NSA boss, deputy
2025-04-04 19:26

Intelligence chief booted after less than two years on the job President Trump today fired the head of the NSA and US Cyber Command and his deputy.…

Port of Seattle says ransomware breach impacts 90,000 people
2025-04-04 17:26

​Port of Seattle, the U.S. government agency overseeing Seattle's seaport and airport, is notifying roughly 90,000 individuals of a data breach after their personal information was stolen in an...

PoisonSeed phishing campaign behind emails with wallet seed phrases
2025-04-04 16:49

A large-scale phishing campaign dubbed 'PoisonSeed' compromises corporate email marketing accounts to distribute emails containing crypto seed phrases used to drain cryptocurrency wallets. [...]