Security News > 2025

Rethinking AppSec: How DevOps, containers, and serverless are changing the rules
2025-05-07 05:30

Application security is changing fast. In this Help Net Security interview, Loris Gutic, Global CISO at Bright, talks about what it takes to keep up. Gutic explains how DevOps, containers, and...

Autorize: Burp Suite extension for automatic authorization enforcement detection
2025-05-07 05:00

Autorize is an open-source Burp Suite extension that checks if users can access things they shouldn’t. It runs automatic tests to help security testers find authorization problems. Autorize...

1 in 3 workers keep AI use a secret
2025-05-07 04:30

Employees are feeling heightened concerns around the use of technology to enhance productivity, as well as job dissatisfaction and a lack of motivation at work. In fact, 30% of employees who use...

#AI
New Zealand kind-of moves to ban social media for under-16s, require age checks for new accounts
2025-05-07 04:05

Prime Minister bemoans bullying, addiction, and inappropriate content – but isn’t planning a rapid vote New Zealand’s government has signaled its support for a bill to ban social media for...

Personal data of top executives easily found online
2025-05-07 04:00

The personal information of 75% of corporate directors can be found on people search sites, according to Incogni. People search sites claim to reveal a variety of personal details, including...

Super spyware maker NSO must pay Meta $168M in WhatsApp court battle
2025-05-06 23:50

Don't f&#k with Zuck A California jury has awarded Meta more than $167 million in damages from Israeli surveillanceware slinger NSO Group, after the latter exploited a flaw in WhatsApp to allow...

Computacenter IT guy let girlfriend into Deutsche Bank server rooms, says fired whistleblower
2025-05-06 20:44

What was the plan, showing her his big iron? A now-former manager at Computacenter claims he was unfairly fired after alerting management that a colleague was repeatedly giving his girlfriend...

Pentagon declares war on 'outdated' software buying, opens fire on open source
2025-05-06 18:27

(If only that would keep folks off unsanctioned chat app side quests) The US Department of Defense (DoD) is overhauling its "outdated" software procurement systems, and insists it's putting...

Apache Parquet exploit tool detect servers vulnerable to critical flaw
2025-05-06 18:16

A proof-of-concept exploit tool has been publicly released for a maximum severity Apache Parquet vulnerability, tracked as CVE-2025-30065, making it easy to find vulnerable servers. [...]

Samsung MagicINFO 9 Server RCE flaw now exploited in attacks
2025-05-06 17:10

Hackers are exploiting an unauthenticated remote code execution (RCE) vulnerability in the Samsung MagicINFO 9 Server to hijack devices and deploy malware. [...]