Security News > 2025

Malicious npm packages target Ethereum developers' private keys
2025-01-03 15:53

Twenty malicious packages impersonating the Hardhat development environment used by Ethereum developers are targeting private keys and other sensitive data. [...]

ShredOS
2025-01-03 14:46

ShredOS is a stripped-down operating system designed to destroy data. GitHub page here.

Apple offers $95 million in Siri privacy violation settlement
2025-01-03 14:30

Apple has agreed to pay $95 million to settle a class action lawsuit in the U.S. alleging that its Siri assistant recorded private conversations and shared them with third parties. [...]

French govt contractor Atos denies Space Bears ransomware attack claims
2025-01-03 14:20

French tech giant Atos, which secures communications for the country's military and secret services, has denied claims made by the Space Bears ransomware gang that they compromised one of its...

CAPTCHAs now run Doom – on nightmare mode
2025-01-03 13:15

As if the bot defense measure wasn't obnoxious enough Though the same couldn't be said for most of us mere mortals, Vercel CEO Guillermo Rauch had a productive festive period, resulting in a...

Boffins carve up C so code can be converted to Rust
2025-01-03 12:33

Mini-C is a subset of C that can be automatically turned to Rust without much fuss Computer scientists affiliated with France's Inria and Microsoft have devised a way to automatically turn a...

New AI Jailbreak Method 'Bad Likert Judge' Boosts Attack Success Rates by Over 60%
2025-01-03 11:14

Cybersecurity researchers have shed light on a new jailbreak technique that could be used to get past a large language model's (LLM) safety guardrails and produce potentially harmful or malicious...

LDAPNightmare PoC Exploit Crashes LSASS and Reboots Windows Domain Controllers
2025-01-03 08:16

A proof-of-concept (PoC) exploit has been released for a now-patched security flaw impacting Windows Lightweight Directory Access Protocol (LDAP) that could trigger a denial-of-service (DoS)...

Critical Deadline: Update Old .NET Domains Before January 7, 2025 to Avoid Service Disruption
2025-01-03 06:49

Microsoft has announced that it's making an "unexpected change" to the way .NET installers and archives are distributed, requiring developers to update their production and DevOps infrastructure....

TotalAV VPN vs Surfshark: Which VPN Should You Choose?
2025-01-03 06:00

TotalAV combines a simple VPN with antivirus software, while Surfshark offers a standalone VPN with better features and faster speeds.