Security News

Oracle Health reportedly warns of info leak from legacy server
2025-03-30 22:45

PLUS: OpenAI bumps bug bounties bigtime; INTERPOL arrests 300 alleged cyber-scammers; And more! Infosec in brief Oracle Health appears to have fallen victim to an info stealing attack that has led...

Hijacked Microsoft web domain injects spam into SharePoint servers
2025-03-27 23:11

The legacy domain for Microsoft Stream was hijacked to show a fake Amazon site promoting a Thailand casino, causing all SharePoint sites with old embedded videos to display it as spam. [...]

Recent Windows Server 2025 updates cause Remote Desktop freezes
2025-03-27 13:59

​Microsoft says a known issue is causing Remote Desktop freezes on Windows Server 2025 systems after installing security updates released since the February 2025 Patch Tuesday. [...]

RedCurl cyberspies create ransomware to encrypt Hyper-V servers
2025-03-26 14:06

A threat actor named 'RedCurl,' known for stealthy corporate espionage operations since 2018, is now using a ransomware encryptor designed to target Hyper-V virtual machines. [...]

Oracle Cloud says it's not true someone broke into its login servers and stole data
2025-03-23 21:09

Despite evidence to the contrary as alleged pilfered info goes on sale Oracle has straight up denied claims by a miscreant that its public cloud offering has been compromised and information stolen.…

Kaspersky Links Head Mare to Twelve, Targeting Russian Entities via Shared C2 Servers
2025-03-21 10:28

Two known threat activity clusters codenamed Head Mare and Twelve have likely joined forces to target Russian entities, new findings from Kaspersky reveal. "Head Mare relied heavily on tools...

Veeam RCE bug lets domain users hack backup servers, patch now
2025-03-20 23:30

Veeam has patched a critical remote code execution vulnerability tracked as CVE-2025-23120 in its Backup & Replication software that impacts domain-joined installations. [...]

Critical AMI MegaRAC bug can let attackers hijack, brick servers
2025-03-18 15:29

​A new critical severity vulnerability found in American Megatrends International's MegaRAC Baseboard Management Controller (BMC) software can let attackers hijack and potentially brick vulnerable...

New Critical AMI BMC Vulnerability Enables Remote Server Takeover and Bricking
2025-03-18 13:31

A critical security vulnerability has been disclosed in AMI's MegaRAC Baseboard Management Controller (BMC) software that could allow an attacker to bypass authentication and carry out...

Like whitebox servers, rent-a-crew crime 'affiliates' have commoditized ransomware
2025-03-07 11:31

Which is why taking down chiefs and infra behind big name brand operations isn't working Interview There's a handful of cybercriminal gangs that Jason Baker, a ransomware negotiator with...