Security News > 2025 > April

SAP fixes suspected Netweaver zero-day exploited in attacks
2025-04-25 13:01

SAP has released out-of-band emergency NetWeaver updates to fix a suspected remote code execution (RCE) zero-day flaw actively exploited to hijack servers. [...]

SAP fixes critical Netweaver flaw exploited in attacks
2025-04-25 13:01

SAP has released out-of-band emergency updates for NetWeaver to fix an actively exploited remote code execution (RCE) vulnerability used to hijack servers. [...]

Cryptocurrency Thefts Get Physical
2025-04-25 11:07

Long story of a $250 million cryptocurrency theft that, in a complicated chain events, resulted in a pretty brutal kidnapping.

New Critical SAP NetWeaver Flaw Exploited to Drop Web Shell, Brute Ratel Framework
2025-04-25 10:41

Threat actors are likely exploiting a new vulnerability in SAP NetWeaver to upload JSP web shells with the goal of facilitating unauthorized file uploads and code execution.  "The exploitation is...

Why NHIs Are Security's Most Dangerous Blind Spot
2025-04-25 10:30

When we talk about identity in cybersecurity, most people think of usernames, passwords, and the occasional MFA prompt. But lurking beneath the surface is a growing threat that does not involve...

FBI seeks help to unmask Salt Typhoon hackers behind telecom breaches
2025-04-25 09:34

The FBI has asked the public for information on Chinese Salt Typhoon hackers behind widespread breaches of telecommunications providers in the United States and worldwide. [...]

Claims assistance firm fined for cold-calling people who put themselves on opt-out list
2025-04-25 09:29

Third-party data supplier also in hot water with Brit regulator over consent issues Britain's data privacy watchdog has slapped a fine of £90k ($120k) on a business that targeted people with...

Rack Ruby vulnerability could reveal secrets to attackers (CVE-2025-27610)
2025-04-25 09:26

Researchers have uncovered three serious vulnerabilities in Rack, a server interface used by most Ruby web app frameworks (Ruby on Rails, Sinatra, Hanami, Roda, and others). Two of the flaws –...

Researchers Identify Rack::Static Vulnerability Enabling Data Breaches in Ruby Servers
2025-04-25 08:57

Cybersecurity researchers have disclosed three security flaws in the Rack Ruby web server interface that, if successfully exploited, could enable attackers to gain unauthorized access to files,...

DslogdRAT Malware Deployed via Ivanti ICS Zero-Day CVE-2025-0282 in Japan Attacks
2025-04-25 08:43

Cybersecurity researchers are warning about a new malware called DslogdRAT that's installed following the exploitation of a now-patched security flaw in Ivanti Connect Secure (ICS). The malware,...