Security News > 2025 > April

Samsung admits Galaxy devices can leak passwords through clipboard wormhole
2025-04-28 02:59

PLUS: Microsoft fixes messes China used to attack it; Mitre adds ESXi advice; Employee-tracking screenshots leak; and more! Infosec in brief Samsung has warned that some of its Galaxy devices...

Coinbase fixes 2FA log error making people think they were hacked
2025-04-27 18:21

Coinbase has fixed a confusing bug in its account activity logs that caused users to think their credentials were compromised. [...]

Brave's Cookiecrumbler tool taps community to help block cookie notices
2025-04-27 14:12

Brave has open-sourceed a new tool called "Cookiecrumbler," which uses large language models (LLMs) to detect cookie consent notices and then community-driven reviews to block those that won't...

Week in review: MITRE ATT&CK v17.0 released, PoC for Erlang/OTP SSH bug is public
2025-04-27 08:00

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Released: MITRE ATT&CK v17.0, now with ESXi attack TTPs MITRE has released the latest version of...

Storm-1977 Hits Education Clouds with AzureChecker, Deploys 200+ Crypto Mining Containers
2025-04-27 05:02

Microsoft has revealed that a threat actor it tracks as Storm-1977 has conducted password spraying attacks against cloud tenants in the education sector over the past year. "The attack involves...

DragonForce expands ransomware model with white-label branding scheme
2025-04-26 15:23

The ransomware scene is re-organizing, with one gang known as DragonForce working to gather other operations under a cartel-like structure. [...]

WooCommerce admins targeted by fake security patches that hijack sites
2025-04-26 14:09

A large-scale phishing campaign targets WooCommerce users with a fake security alert urging them to download a "critical patch" that adds a Wordpress backdoor to the site. [...]

ToyMaker Uses LAGTOY to Sell Access to CACTUS Ransomware Gangs for Double Extortion
2025-04-26 10:38

Cybersecurity researchers have detailed the activities of an initial access broker (IAB) dubbed ToyMaker that has been observed handing over access to double extortion ransomware gangs like...

Signalgate lessons learned: If creating a culture of security is the goal, America is screwed
2025-04-25 23:58

Infosec is a team sport … unless you're in the White House Opinion Just when it seems they couldn't be that careless, US officials tasked with defending the nation go and do something else that...

Amid CVE funding fumble, 'we were mushrooms, kept in the dark,' says board member
2025-04-25 22:19

What next for US-bankrolled vulnerability tracker? It's edging closer to a more independent, global future Kent Landfield, a founding member of the Common Vulnerabilities and Exposures (CVE)...