Wed.May 14, 2025

article thumbnail

Patch Tuesday, May 2025 Edition

Krebs on Security

Microsoft on Tuesday released software updates to fix at least 70 vulnerabilities in Windows and related products, including five zero-day flaws that are already seeing active exploitation. Adding to the sense of urgency with this month’s patch batch from Redmond are fixes for two other weaknesses that now have public proof-of-concept exploits available.

article thumbnail

Upcoming Speaking Engagements

Schneier on Security

This is a current list of where and when I am scheduled to speak: I’m speaking (remotely) at the Sektor 3.0 Festival in Warsaw, Poland, May 21-22, 2025. The list is maintained on this page.

206
206
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

CFPB Quietly Kills Rule to Shield Americans From Data Brokers

WIRED Threat Level

Russell Vought, acting director of the Consumer Financial Protection Bureau, has canceled plans to more tightly regulate the sale of Americans sensitive personal data.

145
145
article thumbnail

Google’s Advanced Protection Now on Android

Schneier on Security

Google has extended its Advanced Protection features to Android devices. It’s not for everybody, but something to be considered by high-risk users. Wired article , behind a paywall.

Risk 155
article thumbnail

How to Avoid Pitfalls In Automation: Keep Humans In the Loop

Speaker: Erroll Amacker

Automation is transforming finance but without strong financial oversight it can introduce more risk than reward. From missed discrepancies to strained vendor relationships, accounts payable automation needs a human touch to deliver lasting value. This session is your playbook to get automation right. We’ll explore how to balance speed with control, boost decision-making through human-machine collaboration, and unlock ROI with fewer errors, stronger fraud prevention, and smoother operations.

article thumbnail

Microsoft Fixes 78 Flaws, 5 Zero-Days Exploited; CVSS 10 Bug Impacts Azure DevOps Server

The Hacker News

Microsoft on Tuesday shipped fixes to address a total of 78 security flaws across its software lineup, including a set of five zero-days that have come under active exploitation in the wild. Of the 78 flaws resolved by the tech giant, 11 are rated Critical, 66 are rated Important, and one is rated Low in severity.

Software 118
article thumbnail

News alert: INE Security highlights monthly CVE Labs aimed at sharpening real-world defense

The Last Watchdog

Cary, NC, May 14, 2025, CyberNewswire — INE Security , a global leader in hands-on cybersecurity training and certifications, today highlighted how ongoing real-world practice with the latest CVEs (Common Vulnerabilities and Exposures) is essential for transforming security teams from reactive to proactive defenders. With over 26,000 new CVEs documented in the past year, security teams are drowning in vulnerability alerts while facing exploit windows that have compressed to hours in many c

LifeWorks

More Trending

article thumbnail

North Korean IT Workers Are Being Exposed on a Massive Scale

WIRED Threat Level

Security researchers are publishing 1,000 email addresses they claim are linked to North Korean IT worker scams that infiltrated Western companiesalong with photos of men allegedly involved in the schemes.

Scams 118
article thumbnail

Samsung Patches CVE-2025-4632 Used to Deploy Mirai Botnet via MagicINFO 9 Exploit

The Hacker News

Samsung has released software updates to address a critical security flaw in MagicINFO 9 Server that has been actively exploited in the wild. The vulnerability, tracked as CVE-2025-4632 (CVSS score: 9.8), has been described as a path traversal flaw. "Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.

Software 108
article thumbnail

Fortinet fixed actively exploited FortiVoice zero-day

Security Affairs

Fortinet fixed a critical remote code execution zero-day vulnerability actively exploited in attacks targeting FortiVoice enterprise phone systems. Fortinet released security updates to address a critical remote code execution zero-day, tracked as CVE-2025-32756 , that was exploited in attacks targeting FortiVoice enterprise phone systems. The vulnerability is a stack-based overflow issue that impacts in FortiVoice, FortiMail, FortiNDR, FortiRecorder and FortiCamera.

Malware 107
article thumbnail

New Chrome Vulnerability Enables Cross-Origin Data Leak via Loader Referrer Policy

The Hacker News

Google on Wednesday released updates to address four security issues in its Chrome web browser, including one for which it said there exists an exploit in the wild. The high-severity vulnerability, tracked as CVE-2025-4664 (CVSS score: 4.3), has been characterized as a case of insufficient policy enforcement in a component called Loader.

111
111
article thumbnail

Why Giant Content Libraries Do Nothing for Your Employees’ Cyber Resilience

Many cybersecurity awareness platforms offer massive content libraries, yet they fail to enhance employees’ cyber resilience. Without structured, engaging, and personalized training, employees struggle to retain and apply key cybersecurity principles. Phished.io explains why organizations should focus on interactive, scenario-based learning rather than overwhelming employees with excessive content.

article thumbnail

URGENT Chrome Update: High-Risk CVE-2025-4664 Flaw Actively Exploited In The Wild – Patch Immediately!

Penetration Testing

Google has released a critical Stable Channel Update for Chrome Desktop, bumping the version to 136.0.7103.113/.114 for Windows The post URGENT Chrome Update: High-Risk CVE-2025-4664 Flaw Actively Exploited In The Wild Patch Immediately! appeared first on Daily CyberSecurity.

Risk 116
article thumbnail

Microsoft Patch Tuesday security updates for May 2025 fixed 5 actively exploited zero-days

Security Affairs

Microsoft Patch Tuesday security updates for May 2025 addressed 75 security flawsacross multiple products, including five zero-day flaws. Microsoft Patch Tuesday security updates addressed 75 security vulnerabilities in Windows and Windows Components, Office and Office Components,NET and Visual Studio, Azure, Nuance PowerScribe, Remote Desktop Gateway Service, and Microsoft Defender.

article thumbnail

DarkCloud Stealer Returns: AutoIt-Powered Malware Strikes with New Stealth Tactics

Penetration Testing

First spotted in 2022 and actively developed ever since, DarkCloud Stealer has reemerged with a sophisticated new variant The post DarkCloud Stealer Returns: AutoIt-Powered Malware Strikes with New Stealth Tactics appeared first on Daily CyberSecurity.

Malware 112
article thumbnail

Believe it or not, Microsoft just announced a Linux distribution service - here's why

Zero Day

Microsoft is open-sourcing its Linux Integration Services Automation image-testing service for everyone.

107
107
article thumbnail

Zero Trust Mandate: The Realities, Requirements and Roadmap

The DHS compliance audit clock is ticking on Zero Trust. Government agencies can no longer ignore or delay their Zero Trust initiatives. During this virtual panel discussion—featuring Kelly Fuller Gordon, Founder and CEO of RisX, Chris Wild, Zero Trust subject matter expert at Zermount, Inc., and Principal of Cybersecurity Practice at Eliassen Group, Trey Gannon—you’ll gain a detailed understanding of the Federal Zero Trust mandate, its requirements, milestones, and deadlines.

article thumbnail

Xerox Patches Dozens of Vulnerabilities in FreeFlow Print Server with April 2025 Security Update

Penetration Testing

On May 12, 2025, Xerox published Security Bulletin XRX25-009, announcing the release of its April 2025 Security Patch The post Xerox Patches Dozens of Vulnerabilities in FreeFlow Print Server with April 2025 Security Update appeared first on Daily CyberSecurity.

article thumbnail

The Internet's Biggest-Ever Black Market Just Shut Down Amid a Telegram Purge

WIRED Threat Level

Following a WIRED inquiry, Telegram banned thousands of accounts used for crypto scam money laundering, including those of Haowang Guarantee, a black market that enabled over $27 billion in transactions.

article thumbnail

Microsoft Restructures: 6,000 Jobs Cut Amid AI Focus

Penetration Testing

Microsoft recently announced a strategic organizational restructuring, which will result in a workforce reduction of approximately 3%, affecting The post Microsoft Restructures: 6,000 Jobs Cut Amid AI Focus appeared first on Daily CyberSecurity.

article thumbnail

Rebooting your phone daily is your best defense against zero-click attacks - here's why

Zero Day

Phone hacking technologies are getting stealthier. It's time to treat your phone like a computer, says this cybersecurity expert.

article thumbnail

Next-Level Fraud Prevention: Strategies for Today’s Threat Landscape

Speaker: Sierre Lindgren

Fraud is a battle that every organization must face – it’s no longer a question of “if” but “when.” Every organization is a potential target for fraud, and the finance department is often the bullseye. From cleverly disguised emails to fraudulent payment requests, the tactics of cybercriminals are advancing rapidly. Drawing insights from real-world cases and industry expertise, we’ll explore the vulnerabilities in your processes and how to fortify them effectively.

article thumbnail

Obfuscated Malware Delivered via Google Calendar Invites and Unicode PUAs

Penetration Testing

Malware authors have begun exploiting Google Calendar invites and Unicode Private Use Area (PUA) characters to deliver obfuscated The post Obfuscated Malware Delivered via Google Calendar Invites and Unicode PUAs appeared first on Daily CyberSecurity.

Malware 104
article thumbnail

Xinbi Telegram Market Tied to $8.4B in Crypto Crime, Romance Scams, North Korea Laundering

The Hacker News

A Chinese-language, Telegram-based marketplace called Xinbi Guarantee has facilitated no less than $8.4 billion in transactions since 2022, making it the second major black market to be exposed after HuiOne Guarantee.

article thumbnail

Gen AI use at work saps our motivation even as it boosts productivity, new research shows

Zero Day

Harvard studies find that the output from AI-assisted human workers is generally of a higher quality, but the psychological costs are significant.

96
article thumbnail

PyPI Malware Alert: Malicious ‘solana-token’ Package Targets Solana Developers

Penetration Testing

The ReversingLabs research team has uncovered yet another software supply chain attack targeting the cryptocurrency ecosystem, this time The post PyPI Malware Alert: Malicious ‘solana-token’ Package Targets Solana Developers appeared first on Daily CyberSecurity.

Malware 95
article thumbnail

Prevent Data Breaches With Zero-Trust Enterprise Password Management

Keeper Security is transforming cybersecurity for people and organizations around the world. Keeper’s affordable and easy-to-use solutions are built on a foundation of zero-trust and zero-knowledge security to protect every user on every device. Our next-generation privileged access management solution deploys in minutes and seamlessly integrates with any tech stack to prevent breaches, reduce help desk costs and ensure compliance.

article thumbnail

Not sold on screenless drawing tablets? This new Wacom won me over

Zero Day

Wacom's new Intuos Pro is a creator's dream come true with lots of customization options and a fantastic drawing experience.

104
104
article thumbnail

Earth Ammit Breached Drone Supply Chains via ERP in VENOM, TIDRONE Campaigns

The Hacker News

A cyber espionage group known as Earth Ammit has been linked to two related but distinct campaigns from 2023 to 2024 targeting various entities in Taiwan and South Korea, including military, satellite, heavy industry, media, technology, software services, and healthcare sectors.

article thumbnail

I test a lot of AI coding tools, and this stunning new OpenAI release just saved me days of work

Zero Day

It took ChatGPT Deep Research minutes to reverse-engineer my full GitHub repo, when I'd need days. Here's why this is a big deal.

article thumbnail

European Vulnerability Database is Live: What This ‘Essential Tool’ Offers Security Experts

Tech Republic Security

The announcement comes after concerns that the US government would stop funding the operations of MITRE, the nonprofit behind the CVE database.

article thumbnail

Optimizing The Modern Developer Experience with Coder

Many software teams have migrated their testing and production workloads to the cloud, yet development environments often remain tied to outdated local setups, limiting efficiency and growth. This is where Coder comes in. In our 101 Coder webinar, you’ll explore how cloud-based development environments can unlock new levels of productivity. Discover how to transition from local setups to a secure, cloud-powered ecosystem with ease.

article thumbnail

Tech leaders are rushing to deploy agentic AI, study shows

Zero Day

With growing investor pressure, tech companies are pushing AI agents as a more practical and dynamic alternative to traditional chatbots. It seems to be working.

101
101
article thumbnail

U.S. CISA adds Microsoft Windows flaws to its Known Exploited Vulnerabilities catalog

Security Affairs

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Windows flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Microsoft Windows flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the descriptions for these flaws: CVE-2025-30397 (CVSS score: 7.5) Scripting Engine Memory Corruption Vulnerability CVE-2025-30400 (CVSS score: 7.8) Microsoft Desktop Window Manager (DWM) Core Library

article thumbnail

How to use your Android phone as a webcam when your laptop's default won't cut it

Zero Day

Does your PC have a mediocre webcam or none at all? Just use your Android phone instead. Here's how.

95
article thumbnail

Learning How to Hack: Why Offensive Security Training Benefits Your Entire Security Team

The Hacker News

Organizations across industries are experiencing significant escalations in cyberattacks, particularly targeting critical infrastructure providers and cloud-based enterprises. Verizons recently released 2025 Data Breach Investigations Report found an 18% YoY increase in confirmed breaches, with the exploitation of vulnerabilities as an initial access step growing by 34%.

article thumbnail

The Tumultuous IT Landscape Is Making Hiring More Difficult

After a year of sporadic hiring and uncertain investment areas, tech leaders are scrambling to figure out what’s next. This whitepaper reveals how tech leaders are hiring and investing for the future. Download today to learn more!