Security News > 2025

Microsoft: Exchange 2016 and 2019 reach end of support in six months
2025-04-15 15:07

​Microsoft warned that Exchange 2016 and Exchange 2019 will reach the end of support six months from now, on October 14. [...]

Hertz data breach: Customers in US, EU, UK, Australia and Canada affected
2025-04-15 14:21

American car rental company Hertz has suffered a data breach linked to last year’s exploitation of Cleo zero-day vulnerabilities by a ransomware gang. The breach resulted in information of an...

Chinese Hackers Target Linux Systems Using SNOWLIGHT Malware and VShell Tool
2025-04-15 14:06

The China-linked threat actor known as UNC5174 has been attributed to a new campaign that leverages a variant of a known malware dubbed SNOWLIGHT and a new open-source tool called VShell to infect...

Chinese snoops use stealth RAT to backdoor US orgs – still active last week
2025-04-15 14:00

Let the espionage and access resale campaigns begin (again) A cyberspy crew or individual with ties to China's Ministry of State Security has infected global organizations with a remote access...

Google adds Android auto-reboot to block forensic data extractions
2025-04-15 13:54

Google is rolling out a new security mechanism on Android devices that will automatically reboot locked, unused devices after three consecutive days of inactivity, restoring memory to an encrypted...

Critical Apache Roller Vulnerability (CVSS 10.0) Enables Unauthorized Session Persistence
2025-04-15 13:44

A critical security vulnerability has been disclosed in the Apache Roller open-source, Java-based blogging server software that could allow malicious actors to retain unauthorized access even...

Microsoft warns of CPU spikes when typing in classic Outlook
2025-04-15 13:41

Microsoft warned Windows users of increased CPU usage when typing while using recent versions of the classic Outlook email client. [...]

Majority of Browser Extensions Can Access Sensitive Enterprise Data, New Report Finds
2025-04-15 13:25

Everybody knows browser extensions are embedded into nearly every user’s daily workflow, from spell checkers to GenAI tools. What most IT and security people don’t know is that browser extensions’...

Malicious PyPI Package Targets MEXC Trading API to Steal Credentials and Redirect Orders
2025-04-15 13:20

Cybersecurity researchers have disclosed a malicious package uploaded to the Python Package Index (PyPI) repository that's designed to reroute trading orders placed on the MEXC cryptocurrency...

ActiveX blocked by default in Microsoft 365 because remote code execution is bad, OK?
2025-04-15 12:25

Stopping users shooting themselves in the foot with last century's tech Microsoft has twisted the knife into ActiveX once again, setting Microsoft 365 to disable all controls without so much as a prompt.…