Wed.Jun 04, 2025

article thumbnail

The Ramifications of Ukraine’s Drone Attack

Schneier on Security

You can read the details of Operation Spiderweb elsewhere. What interests me are the implications for future warfare: If the Ukrainians could sneak drones so close to major air bases in a police state such as Russia, what is to prevent the Chinese from doing the same with U.S. air bases? Or the Pakistanis with Indian air bases? Or the North Koreans with South Korean air bases?

article thumbnail

Roundcube Webmail under fire: critical exploit found after a decade

Security Affairs

A critical flaw in Roundcube webmail, undetected for 10 years, allows attackers to take over systems and execute arbitrary code. A critical flaw, tracked as CVE-2025-49113 (CVSS score of 9.9) has been discovered in the Roundcube webmail software. The vulnerability went unnoticed for over a decade, an attacker can exploit the flaw to take control of affected systems and run malicious code, putting users and organizations at significant risk.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Malicious PyPI, npm, and Ruby Packages Exposed in Ongoing Open-Source Supply Chain Attacks

The Hacker News

Several malicious packages have been uncovered across the npm, Python, and Ruby package repositories that drain funds from cryptocurrency wallets, erase entire codebases after installation, and exfiltrate Telegram API tokens, once again demonstrating the variety of supply chain threats lurking in open-source ecosystems.

article thumbnail

Qualcomm patches three exploited security flaws, but you could still be vulnerable

Zero Day

Device manufacturers must still apply the critical updates to their individual products, but we're not out of the woods yet.

article thumbnail

How to Avoid Pitfalls In Automation: Keep Humans In the Loop

Speaker: Erroll Amacker

Automation is transforming finance but without strong financial oversight it can introduce more risk than reward. From missed discrepancies to strained vendor relationships, accounts payable automation needs a human touch to deliver lasting value. This session is your playbook to get automation right. We’ll explore how to balance speed with control, boost decision-making through human-machine collaboration, and unlock ROI with fewer errors, stronger fraud prevention, and smoother operations.

article thumbnail

A GPS Blackout Would Shut Down the World

WIRED Threat Level

GPS jamming and spoofing attacks are on the rise. If the global navigation system the US relies on were to go down entirely, it would send the world into unprecedented chaos.

110
110
article thumbnail

News alert: $198K in Grants Awarded to Boost Cybersecurity Workforce in Massachusetts

The Last Watchdog

Boston, MA, Jun. 4, 2025, The Healey-Driscoll administration and Massachusetts Technology Collaboratives (MassTech) MassCyberCenter awarded $198,542 to four Massachusetts-based programs focused on preparing professionals for the cybersecurity workforce.MassTech provided the funds through the Alternative Cyber Career Education (ACE) Grant Program , a statewide effort to support young adults and retrain existing professionals with alternative options to traditional cybersecurity degree programs.

LifeWorks

More Trending

article thumbnail

Chaos RAT Malware Targets Windows and Linux via Fake Network Tool Downloads

The Hacker News

Threat hunters are calling attention to a new variant of a remote access trojan (RAT) called Chaos RAT that has been used in recent attacks targeting Windows and Linux systems. According to findings from Acronis, the malware artifact may have been distributed by tricking victims into downloading a network troubleshooting utility for Linux environments.

Malware 98
article thumbnail

Cartier disclosed a data breach following a cyber attack

Security Affairs

Luxury-goods conglomerate Cartier disclosed a data breach that exposed customer information after a cyberattack. Cartier has disclosed a data breach following a cyberattack that compromised its systems, exposing customers’ personal information. The incident comes amid a wave of cyberattacks targeting luxury fashion brands. The luxury firm states that the threat actors gained access to “limited client information.” Compromised data includes customers’ names, e-mail address

article thumbnail

Google Exposes Vishing Group UNC6040 Targeting Salesforce with Fake Data Loader App

The Hacker News

Google has disclosed details of a financially motivated threat cluster that it said "specialises" in voice phishing (aka vishing) campaigns designed to breach organizations' Salesforce instances for large-scale data theft and subsequent extortion.

article thumbnail

Tech prophet Mary Meeker just dropped a massive report on AI trends - here's your TL;DR

Zero Day

She said 'unprecedented' so many times I almost lost count.

105
105
article thumbnail

Why Giant Content Libraries Do Nothing for Your Employees’ Cyber Resilience

Many cybersecurity awareness platforms offer massive content libraries, yet they fail to enhance employees’ cyber resilience. Without structured, engaging, and personalized training, employees struggle to retain and apply key cybersecurity principles. Phished.io explains why organizations should focus on interactive, scenario-based learning rather than overwhelming employees with excessive content.

article thumbnail

Your SaaS Data Isn't Safe: Why Traditional DLP Solutions Fail in the Browser Era

The Hacker News

Traditional data leakage prevention (DLP) tools aren't keeping pace with the realities of how modern businesses use SaaS applications. Companies today rely heavily on SaaS platforms like Google Workspace, Salesforce, Slack, and generative AI tools, significantly altering the way sensitive information is handled.

92
article thumbnail

I replaced my 4K TV with a UST projector - and the visual upgrade was worth it

Zero Day

The Formovie Cinema Edge ultra-short-throw projector commands a premium price, but its performance makes it well worth the investment.

91
article thumbnail

The US Grid Attack Looming on the Horizon

WIRED Threat Level

A major cyberattack on the US electrical grid has long worried security experts. Such an attack wouldnt be easy. But if an adversary pulled it off, itd be lights out in more ways than one.

89
article thumbnail

Are wind power generators actually viable at home? My buying advice after months of testing

Zero Day

Solar generators are all the rage, but what do you do when the clouds roll in? This gadget will keep the power coming.

89
article thumbnail

Zero Trust Mandate: The Realities, Requirements and Roadmap

The DHS compliance audit clock is ticking on Zero Trust. Government agencies can no longer ignore or delay their Zero Trust initiatives. During this virtual panel discussion—featuring Kelly Fuller Gordon, Founder and CEO of RisX, Chris Wild, Zero Trust subject matter expert at Zermount, Inc., and Principal of Cybersecurity Practice at Eliassen Group, Trey Gannon—you’ll gain a detailed understanding of the Federal Zero Trust mandate, its requirements, milestones, and deadlines.

article thumbnail

The Texting Network for the End of the World

WIRED Threat Level

Everyone knows what its like to lose cell service. A burgeoning open source project called Meshtastic is filling the gap for when youre in the middle of nowhereor when disaster strikes.

Hacking 85
article thumbnail

Your Asus router may be part of a botnet - here's how to tell and what to do

Zero Day

Cybercriminals have hacked into thousands of Asus routers, possibly as a prelude to a botnet attack, says a security firm.

Hacking 75
article thumbnail

You're Not Ready

WIRED Threat Level

Seems bad out there. Unfortunately, it can always get worse. From evil hacker AI to world-changing cyberattacks, WIRED envisions the future you haven't prepared for.

84
article thumbnail

Is ChatGPT Plus still worth $20 when the free version packs so many premium features?

Zero Day

ChatGPT Pro is 10 times the price of ChatGPT Plus. Is either plan worth the money, or should you stick with free? Here's how to decide.

91
article thumbnail

Next-Level Fraud Prevention: Strategies for Today’s Threat Landscape

Speaker: Sierre Lindgren

Fraud is a battle that every organization must face – it’s no longer a question of “if” but “when.” Every organization is a potential target for fraud, and the finance department is often the bullseye. From cleverly disguised emails to fraudulent payment requests, the tactics of cybercriminals are advancing rapidly. Drawing insights from real-world cases and industry expertise, we’ll explore the vulnerabilities in your processes and how to fortify them effectively.

article thumbnail

Deepfake Scams Are Distorting Reality Itself

WIRED Threat Level

The easy access that scammers have to sophisticated AI tools means everything from emails to video calls cant be trusted.

Scams 80
article thumbnail

Will Massive Security Glossary From Microsoft, Google, CrowdStrike, Palo Alto Improve Collaboration?

Tech Republic Security

This effort is not about creating a single naming standard, said Vasu Jakkal, corporate vice president of Microsoft Security.

90
article thumbnail

The Rise of ‘Vibe Hacking’ Is the Next AI Nightmare

WIRED Threat Level

In the very near future, victory will belong to the savvy blackhat hacker who uses AI to generate code at scale.

Hacking 79
article thumbnail

10 personal safety features every Pixel user should know about - and use

Zero Day

Keep your data and physical safety protected with just a few taps on your Pixel phone. Here's how.

78
article thumbnail

Prevent Data Breaches With Zero-Trust Enterprise Password Management

Keeper Security is transforming cybersecurity for people and organizations around the world. Keeper’s affordable and easy-to-use solutions are built on a foundation of zero-trust and zero-knowledge security to protect every user on every device. Our next-generation privileged access management solution deploys in minutes and seamlessly integrates with any tech stack to prevent breaches, reduce help desk costs and ensure compliance.

article thumbnail

Google fixes another actively exploited vulnerability in Chrome, so update now!

Malwarebytes

Google has released an update for the Chrome browser to patch an actively exploited flaw. The update brings the Stable channel to versions 137.0.7151.68/.69 for Windows and Mac and 137.0.7151.68 for Linux. The easiest way to update Chrome is to allow it to update automatically, but you can end up lagging behind if you never close your browser or if something goes wrongsuch as an extension stopping you from updating the browser.

Spyware 73
article thumbnail

The $700 Android phone that made me forget about my Pixel 9 Pro

Zero Day

The latest Redmagic 10 Air could easily replace your current device with its performant, well-built design. But it has its some caveats.

76
article thumbnail

See How Much Faster a Quantum Computer Will Crack Encryption

WIRED Threat Level

A quantum computer will likely one day be able to break the encryption protecting the world's secrets. See how much faster such a machine could decrypt a password compared to a present-day supercomputer.

article thumbnail

What AI pioneer Yoshua Bengio is doing next to make AI safer

Zero Day

Yoshua Bengio's new nonprofit, LawZero, is pushing AI for public good - de-emphasizing profits, AGI, and autonomous capability.

80
article thumbnail

Optimizing The Modern Developer Experience with Coder

Many software teams have migrated their testing and production workloads to the cloud, yet development environments often remain tied to outdated local setups, limiting efficiency and growth. This is where Coder comes in. In our 101 Coder webinar, you’ll explore how cloud-based development environments can unlock new levels of productivity. Discover how to transition from local setups to a secure, cloud-powered ecosystem with ease.

article thumbnail

Meta, Yandex Covertly Tracked Billions of Android Users, According to Researcher

Tech Republic Security

A report highlights how Meta and Yandex bypassed privacy and security controls to implement web-to-app tracking on Android users.

118
118
article thumbnail

AT&T has a new cheaper wireless plan for seniors - how to tell if you qualify

Zero Day

AT&T's senior plan offers unlimited talk, text, and data at a discount. Just make sure you read the fine print.

article thumbnail

Luxury, Loyalty and Lateral Movement: Retail and Banking Attacks Surge

SecureWorld News

In a matter of days, three major cybersecurity incidents have hit the retail and financial services sectors, drawing renewed attention to supply chain vulnerabilities, credential-based attacks, and the increasing value of non-financial customer data. These breachesaffecting Cartier, Main Street Bank, and The North Faceunderscore the rising threat landscape facing luxury and everyday consumer brands.

Retail 65
article thumbnail

I changed 5 settings on my TV to significantly improve the performance

Zero Day

With a bit of tweaking of your TV's basic settings, you can experience crisper images and a better viewing experience overall.

70
article thumbnail

The Tumultuous IT Landscape Is Making Hiring More Difficult

After a year of sporadic hiring and uncertain investment areas, tech leaders are scrambling to figure out what’s next. This whitepaper reveals how tech leaders are hiring and investing for the future. Download today to learn more!