Security News

New TCESB Malware Found in Active Attacks Exploiting ESET Security Scanner
2025-04-09 11:38

A Chinese-affiliated threat actor known for its cyber-attacks in Asia has been observed exploiting a security flaw in security software from ESET to deliver a previously undocumented malware...

How to Leak to a Journalist
2025-04-09 11:02

Neiman Lab has some good advice on how to leak a story to a journalist.

RCE flaw in MSP-friendly file sharing platform exploited by attackers (CVE-2025-30406)
2025-04-09 10:37

A critical RCE vulnerability (CVE-2025-30406) affecting the Gladinet CentreStack file-sharing/remote access platform has been added to CISA’s Known Exploited Vulnerabilities catalog on Tuesday....

Explosive Growth of Non-Human Identities Creating Massive Security Blind Spots
2025-04-09 10:30

GitGuardian's State of Secrets Sprawl report for 2025 reveals the alarming scale of secrets exposure in modern software environments. Driving this is the rapid growth of non-human identities...

PipeMagic Trojan Exploits Windows Zero-Day Vulnerability to Deploy Ransomware
2025-04-09 08:04

Microsoft has revealed that a now-patched security flaw impacting the Windows Common Log File System (CLFS) was exploited as a zero-day in ransomware attacks aimed at a small number of targets....

OpenSSL prepares for a quantum future with 3.5.0 release
2025-04-09 08:01

The OpenSSL Project has released version 3.5.0 of its widely used open-source cryptographic library, introducing new features and notable changes that signal its evolution toward future-ready...

CISA Warns of CentreStack's Hard-Coded MachineKey Vulnerability Enabling RCE Attacks
2025-04-09 08:00

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a critical security flaw impacting Gladinet CentreStack to its Known Exploited Vulnerabilities (KEV) catalog,...

Microsoft Patches 125 Flaws Including Actively Exploited Windows CLFS Vulnerability
2025-04-09 07:06

Microsoft has released security fixes to address a massive set of 125 flaws affecting its software products, including one vulnerability that it said has been actively exploited in the wild. Of...

Master IT Fundamentals with This CompTIA Certification Prep Bundle
2025-04-09 07:00

Prepare for a successful IT career with lifetime access to expert-led courses covering CompTIA A+, Network+, Security+, and Cloud+ certification prep.

Why CISOs are doubling down on cyber crisis simulations
2025-04-09 05:30

Cyber threats aren’t going away, and CISOs know prevention isn’t enough. Being ready to respond is just as important. Cyber crisis simulations offer a way to test that readiness. They let teams...