Security News > 2025 > April

Building a reasonable cyber defense program
2025-04-01 13:00

If you do business in the United States, especially across state lines, you probably know how difficult it is to comply with U.S. state data privacy laws. The federal government and many U.S....

Google makes end-to-end encrypted Gmail easy for all – even Outlook users
2025-04-01 13:00

The UK government must be thrilled Google will soon offer end-to-end encrypted (E2EE) email for all users, even those who do not use Google Workspace, and says it'll do so without imposing any...

Critical auth bypass bug in CrushFTP now exploited in attacks
2025-04-01 12:46

Attackers are now targeting a critical authentication bypass vulnerability in the CrushFTP file transfer software using exploits based on publicly available proof-of-concept code. [...]

UK threatens £100K-a-day fines under new cyber bill
2025-04-01 11:37

Tech secretary reveals landmark legislation's full details for first time The UK's technology secretary revealed the full breadth of the government's Cyber Security and Resilience (CSR) Bill for...

#UK
Apple Backports Critical Fixes for 3 Recent 0-Days Impacting Older iOS and macOS Devices
2025-04-01 11:28

Apple on Monday backported fixes for three vulnerabilities that have come under active exploitation in the wild to older models and previous versions of the operating systems. The vulnerabilities...

Attackers are probing Palo Alto Networks GlobalProtect portals
2025-04-01 11:19

Cybersecurity company GreyNoise is warning about a significant increase of scanning activity targeting internet-facing Palo Alto Networks GlobalProtect portals in the last 30 days, and has urged...

Nearly 24,000 IPs Target PAN-OS GlobalProtect in Coordinated Login Scan Campaign
2025-04-01 11:17

Cybersecurity researchers are warning of a spike in suspicious login scanning activity targeting Palo Alto Networks PAN-OS GlobalProtect gateways, with nearly 24,000 unique IP addresses attempting...

Case Study: Are CSRF Tokens Sufficient in Preventing CSRF Attacks?
2025-04-01 11:03

Explore how relying on CSRF tokens as a security measure against CSRF attacks is a recommended best practice, but in some cases, they are simply not enough. Introduction As per the Open Web...

China-Linked Earth Alux Uses VARGEIT and COBEACON in Multi-Stage Cyber Intrusions
2025-04-01 11:03

Cybersecurity researchers have shed light on a new China-linked threat actor called Earth Alux that has targeted various key sectors such as government, technology, logistics, manufacturing,...

Cell Phone OPSEC for Border Crossings
2025-04-01 11:01

I have heard stories of more aggressive interrogation of electronic devices at US border crossings. I know a lot about securing computers, but very little about securing phones. Are there easy...