Security News > 2025

Fake Recruiter Emails Target CFOs Using Legit NetBird Tool Across 6 Global Regions
2025-06-02 05:51

Cybersecurity researchers have warned of a new spear-phishing campaign that uses a legitimate remote access tool called Netbird to target Chief Financial Officers (CFOs) and financial executives...

CISO 3.0: Leading AI governance and security in the boardroom
2025-06-02 05:30

In this Help Net Security interview, Aaron McCray, Field CISO at CDW, discusses how AI is transforming the CISO role from a tactical cybersecurity guardian into a strategic enterprise risk...

Review: Metasploit, 2nd Edition
2025-06-02 05:00

If you’ve spent any time in penetration testing, chances are you’ve crossed paths with Metasploit. The second edition of Metasploit tries to bring the book in line with how pentesters are using...

Security awareness training isn’t stopping breaches. Can AI help?
2025-06-02 04:30

In this Help Net Security video, Mick Leach, Field CISO at Abnormal AI, explores why security awareness training (SAT) is failing to reduce human error, the top cause of cybersecurity incidents....

48% of security pros are falling behind compliance requirements
2025-06-02 04:00

32% of security professionals think they can deliver zero-vulnerability software despite rising threats and compliance regulations, according to Lineaje. Meanwhile, 68% are more realistic, noting...

Lumma infostealer takedown may have inflicted only a flesh wound as crew keeps pinching and selling data
2025-06-02 01:16

PLUS: Ransomware gang using tech support scam; Czechia accuses China of infrastructure attack; And more! Infosec In Brief Despite last week’s FBI announcement that it helped to take down the crew...

Week in review: NIST proposes new vulnerabilities metric, flaws in NASA’s open source software
2025-06-01 08:00

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Vulnerabilities found in NASA’s open source software Vulnerabilities in open source software...

Exploit details for max severity Cisco IOS XE flaw now public
2025-05-31 14:09

Technical details about a maximum-severity Cisco IOS XE WLC arbitrary file upload flaw tracked as CVE-2025-20188 have been made publicly available, bringing us closer to a working exploit. [...]

Mysterious leaker GangExposed outs Conti kingpins in massive ransomware data dump
2025-05-31 10:23

'It's a high-stakes intelligence war' he told El Reg exclusive A mystery whistleblower calling himself GangExposed has exposed key figures behind the Conti and Trickbot ransomware crews,...

New Linux Flaws Allow Password Hash Theft via Core Dumps in Ubuntu, RHEL, Fedora
2025-05-31 10:19

Two information disclosure flaws have been identified in apport and systemd-coredump, the core dump handlers in Ubuntu, Red Hat Enterprise Linux, and Fedora, according to the Qualys Threat...