Security News

Week in review: Chrome sandbox escape 0-day fixed, Microsoft adds new AI agents to Security Copilot
2025-03-30 08:00

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Microsoft’s new AI agents take on phishing, patching, alert fatigue Microsoft is rolling out a new...

New Ubuntu Linux security bypasses require manual mitigations
2025-03-28 15:14

Three security bypasses have been discovered in Ubuntu Linux's unprivileged user namespace restrictions, which could be enable a local attacker to exploit vulnerabilities in kernel components. [...]

Android Malware Exploits a Microsoft-Related Security Blind Spot to Avoid Detection
2025-03-27 20:05

Microsoft’s .NET MAUI lets developers build cross-platform apps in C#, but its use of binary blob files poses new risks by bypassing Android’s DEX-based security checks.

Security shop pwns ransomware gang, passes insider info to authorities
2025-03-27 16:32

Researchers say 'proactive' approach is needed to combat global cybercrime Here's one you don't see every day: A cybersecurity vendor is admitting to breaking into a notorious ransomware crew's...

UK NCSC offers security guidance for domain and DNS registrars
2025-03-27 14:47

The UK National Cyber Security Centre (NCSC) has released security guidance for domain registrars and operators of Domain Name System (DNS) services. “DNS registrars have an important role to help...

The hidden costs of security tool bloat and how to fix it
2025-03-27 06:00

In this Help Net Security interview, Shane Buckley, President and CEO at Gigamon, discusses why combating tool bloat is a top priority for CISOs as they face tighter budgets and expanding security...

ETSI releases security standard for the quantum future
2025-03-27 04:30

ETSI launched post-quantum security standard to guarantee the protection of critical data and communications in the future. The specification “Efficient Quantum-Safe Hybrid Key Exchanges with...

US defense contractor cops to sloppy security, settles after infosec lead blows whistle
2025-03-26 20:07

MORSE to pay -- .. .-.. .-.. .. --- -. ... for failing to meet cyber-grade A US defense contractor will cough up $4.6 million to settle complaints it failed to meet cybersecurity requirements on...

Whitepaper: Voice of Security 2025
2025-03-26 14:00

Discover insights from 900 security leaders across the globe in IDC’s Voice of Security 2025 survey, sponsored by Tines in partnership with AWS. Understand the biggest challenges facing security...

New Security Flaws Found in VMware Tools and CrushFTP — High Risk, PoC Released
2025-03-26 04:20

Broadcom has issued security patches to address a high-severity security flaw in VMware Tools for Windows that could lead to an authentication bypass. Tracked as CVE-2025-22230, the vulnerability...