Security News

Devs sent into security panic by 'feature that was helpful … until it wasn't'
2025-01-10 08:30

Screenshot showed it wasn't a possible attack – unless you qualify everything Google does as a threat On Call Velkomin, Vælkomin, Hoş geldin, and welcome to Friday, and therefore to another...

What’s Next for Open Source Software Security in 2025?
2025-01-09 19:53

Hidden dependencies, social engineering attacks, and the complexity of foundation models can all contribute tothe insecure use of open-source software in 2025.

Security pros baited with fake Windows LDAP exploit traps
2025-01-09 13:16

Tricky attackers trying yet again to deceive the good guys on home territory Security researchers are once again being lured into traps by attackers, this time with fake exploits of serious...

The ongoing evolution of the CIS Critical Security Controls
2025-01-09 07:33

For decades, the CIS Critical Security Controls (CIS Controls) have simplified enterprises’ efforts to strengthen their cybersecurity posture by prescribing prioritized security measures for...

Sara: Open-source RouterOS security inspector
2025-01-09 05:00

Sara is an open-source tool designed to analyze RouterOS configurations and identify security vulnerabilities on MikroTik hardware. Sara’s main feature is using regular expressions as the primary...

Neglected Domains Used in Malspam to Evade SPF and DMARC Security Protections
2025-01-08 18:09

Cybersecurity researchers have found that bad actors are continuing to have success by spoofing sender email addresses as part of various malspam campaigns. Faking the sender address of an email...

UN aviation agency confirms recruitment database security breach
2025-01-08 13:30

​The United Nations' International Civil Aviation Organization (ICAO) has confirmed that a threat actor has stolen approximately 42,000 records after hacking into its recruitment database. [...]

FCC Launches 'Cyber Trust Mark' for IoT Devices to Certify Security Compliance
2025-01-08 09:56

The U.S. government on Tuesday announced the launch of the U.S. Cyber Trust Mark, a new cybersecurity safety label for Internet-of-Things (IoT) consumer devices. "IoT products can be susceptible...

Washington state sues T-Mobile over 2021 data breach security failures
2025-01-07 18:08

Washington state has sued T-Mobile over failing to secure the sensitive personal information of over 2 million Washington residents in a 2021 data breach. [...]

UN aviation agency investigating 'potential' security breach
2025-01-07 15:59

​On Monday, the United Nations' International Civil Aviation Organization (ICAO) announced it was investigating what it described as a "reported security incident." [...]