Security News > 2025

Lotus Panda Hacks SE Asian Governments With Browser Stealers and Sideloaded Malware
2025-04-22 04:29

The China-linked cyber espionage group tracked as Lotus Panda has been attributed to a campaign that compromised multiple organizations in an unnamed Southeast Asian country between August 2024...

Compliance weighs heavily on security and GRC teams
2025-04-22 04:00

Only 29% of all organizations say their compliance programs consistently meet internal and external standards, according to Swimlane. Their report reveals that fragmented workflows, manual...

Bug hunter tricked SSL.com into issuing cert for Alibaba Cloud domain in 5 steps
2025-04-22 02:23

10 other certificates 'were mis-issued and have now been revoked' Certificate issuer SSL.com’s domain validation system had an unfortunate bug that was exploited by miscreants to obtain, without...

Today's LLMs craft exploits from patches at lightning speed
2025-04-21 20:31

Erlang? Er, man, no problem. ChatGPT, Claude to go from flaw disclosure to actual attack code in hours The time from vulnerability disclosure to proof-of-concept (PoC) exploit code can now be as...

Microsoft rated this bug as low exploitability. Miscreants weaponized it in just 8 days
2025-04-21 17:43

It's now hitting govt, enterprise targets On March 11 - Patch Tuesday - Microsoft rolled out its usual buffet of bug fixes. Just eight days later, miscreants had weaponized one of the...

Kimsuky Exploits BlueKeep RDP Vulnerability to Breach Systems in South Korea and Japan
2025-04-21 16:42

Cybersecurity researchers have flagged a new malicious campaign related to the North Korean state-sponsored threat actor known as Kimsuky that exploits a now-patched vulnerability impacting...

Microsoft Entra account lockouts caused by user token logging mishap
2025-04-21 16:26

Microsoft confirms that the weekend Entra account lockouts were caused by the invalidation of short-lived user refresh tokens that were mistakenly logged into internal systems. [...]

SuperCard X Android Malware Enables Contactless ATM and PoS Fraud via NFC Relay Attacks
2025-04-21 15:13

A new Android malware-as-a-service (MaaS) platform named SuperCard X can facilitate near-field communication (NFC) relay attacks, enabling cybercriminals to conduct fraudulent cashouts. The active...

WordPress ad-fraud plugins generated 1.4 billion ad requests per day
2025-04-21 13:00

A large-scale ad fraud operation called 'Scallywag' is monetizing pirating and URL shortening sites through specially crafted WordPress plugins that generate billions of daily fraudulent requests. [...]

Bitwarden vs LastPass 2025: Which Password Manager Is Better?
2025-04-21 12:00

In this comparison between Bitwarden and LastPass, we explore their features, security, ease of use and pricing. Find out which password manager is best for you.