Security News > 2025

Product Walkthrough: How Reco Discovers Shadow AI in SaaS
2025-01-09 11:55

As SaaS providers race to integrate AI into their product offerings to stay competitive and relevant, a new challenge has emerged in the world of AI: shadow AI.  Shadow AI refers to the...

MirrorFace Leverages ANEL and NOOPDOOR in Multi-Year Cyberattacks on Japan
2025-01-09 10:44

Japan's National Police Agency (NPA) and National Center of Incident Readiness and Strategy for Cybersecurity (NCSC) accused a China-linked threat actor named MirrorFace of orchestrating a...

Webinar: Learn How to Stop Encrypted Attacks Before They Cost You Millions
2025-01-09 10:44

Ransomware isn’t slowing down—it’s getting smarter. Encryption, designed to keep our online lives secure, is now being weaponized by cybercriminals to hide malware, steal data, and avoid...

Critical RCE Flaw in GFI KerioControl Allows Remote Code Execution via CRLF Injection
2025-01-09 09:35

Threat actors are attempting to take advantage of a recently disclosed security flaw impacting GFI KerioControl firewalls that, if successfully exploited, could allow malicious actors to achieve...

Wireshark 4.4.3 released: Updated protocol support, bug fixes
2025-01-09 08:58

Wireshark, the popular network protocol analyzer, has reached version 4.4.3. Wireshark offers deep inspection across hundreds of protocols, live and offline analysis, and display filters. With...

The ongoing evolution of the CIS Critical Security Controls
2025-01-09 07:33

For decades, the CIS Critical Security Controls (CIS Controls) have simplified enterprises’ efforts to strengthen their cybersecurity posture by prescribing prioritized security measures for...

E.U. Commission Fined for Transferring User Data to Meta in Violation of Privacy Laws
2025-01-09 07:13

The European General Court on Wednesday fined the European Commission, the primary executive arm of the European Union responsible for proposing and enforcing laws for member states, for violating...

Ivanti Flaw CVE-2025-0282 Actively Exploited, Impacts Connect Secure and Policy Secure
2025-01-09 07:13

Ivanti is warning that a critical security flaw impacting Ivanti Connect Secure, Policy Secure, and ZTA Gateways has come under active exploitation in the wild beginning mid-December 2024. The...

GitLab CISO on proactive monitoring and metrics for DevSecOps success
2025-01-09 05:30

In this Help Net Security interview, Josh Lemos, CISO at GitLab, talks about the shift from DevOps to DevSecOps, focusing on the complexity of building systems and integrating security tools. He...

Sara: Open-source RouterOS security inspector
2025-01-09 05:00

Sara is an open-source tool designed to analyze RouterOS configurations and identify security vulnerabilities on MikroTik hardware. Sara’s main feature is using regular expressions as the primary...