Security News > 2025

US govt says North Korea stole over $659 million in crypto last year
2025-01-14 20:01

​North Korean state-backed hacking groups have stolen over $659 million worth of cryptocurrency in multiple crypto-heists, according to a joint statement issued by the United States, South Korea,...

FBI wipes Chinese PlugX malware from thousands of Windows PCs in America
2025-01-14 19:40

Hey, Xi: Zài jiàn! The FBI, working with French cops, obtained nine warrants to remotely wipe PlugX malware from thousands of Windows-based computers that had been infected by Chinese...

Windows 10 KB5049981 update released with new BYOVD blocklist
2025-01-14 19:28

Microsoft has released the KB5049981 cumulative update for Windows 10 22H2 and Windows 10 21H2, which contains an updated Kernel driver blocklist to prevent Bring Your Own Vulnerable Driver...

Microsoft January 2025 Patch Tuesday fixes 8 zero-days, 159 flaws
2025-01-14 19:01

Today is Microsoft's January 2025 Patch Tuesday, which includes security updates for 159 flaws, including eight zero-day vulnerabilities, with three actively exploited in attacks. [...]

Windows 11 KB5050009 & KB5050021  cumulative updates released
2025-01-14 18:48

Microsoft has released the Windows 11 KB5050009 and KB5050021 cumulative updates for versions 24H2 and 23H2 to fix security vulnerabilities and issues. [...]

Google OAuth flaw lets attackers gain access to abandoned accounts
2025-01-14 17:28

A weakness in Google's OAuth "Sign in with Google" feature could enable attackers that register domains of defunct startups to access sensitive data of former employee accounts linked to various...

Fortinet fixes FortiOS zero-day exploited by attackers for months (CVE-2024-55591)
2025-01-14 17:15

Fortinet has patched an authentication bypass vulnerability (CVE-2024-55591) affecting its FortiOS firewalls and FortiProxy web gateways that has been exploited as a zero-day by attackers to...

Upcoming Speaking Engagements
2025-01-14 17:05

This is a current list of where and when I am scheduled to speak: I’m speaking on “AI: Trust & Power” at Capricon 45 in Chicago, Illinois, USA, at 11:30 AM on February 7, 2025. I’m also signing...

Microsoft Uncovers macOS Vulnerability CVE-2024-44243 Allowing Rootkit Installation
2025-01-14 16:53

Microsoft has shed light on a now-patched security flaw impacting Apple macOS that, if successfully exploited, could have allowed an attacker running as "root" to bypass the operating system's...

Google OAuth Vulnerability Exposes Millions via Failed Startup Domains
2025-01-14 16:38

New research has pulled back the curtain on a "deficiency" in Google's "Sign in with Google" authentication flow that exploits a quirk in domain ownership to gain access to sensitive data....