Security News > 2025 > April

Threat actors are scanning your environment, even if you’re not
2025-04-28 05:30

In a world where organizations’ digital footprint is constantly changing and attackers regularly capitalize on security failings in exposed IT assets, making the effort to minimize your external...

GoSearch: Open-source OSINT tool for uncovering digital footprints
2025-04-28 05:00

GoSearch is an open-source OSINT tool built to uncover digital footprints linked to specific usernames. Designed for speed and accuracy, it lets users quickly track someone’s online presence...

Ransomware attacks are getting smarter, harder to stop
2025-04-28 04:30

Ransomware attacks are becoming more refined and pervasive, posing significant challenges to organizations globally. A Veeam report reveals that while the percentage of companies impacted by...

Most critical vulnerabilities aren’t worth your attention
2025-04-28 04:00

Web applications face a wide range of risks, including known-exploitable vulnerabilities, supply chain attacks, and insecure identity configurations in CI/CD, according to the Datadog State of...

Samsung admits Galaxy devices can leak passwords through clipboard wormhole
2025-04-28 02:59

PLUS: Microsoft fixes messes China used to attack it; Mitre adds ESXi advice; Employee-tracking screenshots leak; and more! Infosec in brief Samsung has warned that some of its Galaxy devices...

Coinbase fixes 2FA log error making people think they were hacked
2025-04-27 18:21

Coinbase has fixed a confusing bug in its account activity logs that caused users to think their credentials were compromised. [...]

Brave's Cookiecrumbler tool taps community to help block cookie notices
2025-04-27 14:12

Brave has open-sourceed a new tool called "Cookiecrumbler," which uses large language models (LLMs) to detect cookie consent notices and then community-driven reviews to block those that won't...

Week in review: MITRE ATT&CK v17.0 released, PoC for Erlang/OTP SSH bug is public
2025-04-27 08:00

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Released: MITRE ATT&CK v17.0, now with ESXi attack TTPs MITRE has released the latest version of...

Storm-1977 Hits Education Clouds with AzureChecker, Deploys 200+ Crypto Mining Containers
2025-04-27 05:02

Microsoft has revealed that a threat actor it tracks as Storm-1977 has conducted password spraying attacks against cloud tenants in the education sector over the past year. "The attack involves...

DragonForce expands ransomware model with white-label branding scheme
2025-04-26 15:23

The ransomware scene is re-organizing, with one gang known as DragonForce working to gather other operations under a cartel-like structure. [...]