Latest Cybersecurity News and Articles


DNS: The Secret Weapon CISOs May Be Overlooking In the Fight Against Cyberattacks

08 April 2025
While often relegated to a purely functional role, DNS offers unparalleled opportunities for preemptive defense against cyberattacks. The post DNS: The Secret Weapon CISOs May Be Overlooking In the Fight Against Cyberattacks appeared first on SecurityWeek.

Anecdotes Raises $30 Million for Enterprise GRC Platform

08 April 2025
Anecdotes has raised $55 million in an extended Series B funding round that brings the total raised by the company to $85 million.  The post Anecdotes Raises $30 Million for Enterprise GRC Platform appeared first on SecurityWeek.

SAP Patches Critical Code Injection Vulnerabilities

08 April 2025
SAP released 20 security notes on April 2025 patch day, including three addressing critical code injection and authentication bypass flaws. The post SAP Patches Critical Code Injection Vulnerabilities appeared first on SecurityWeek.

Aurascape Banks Hefty $50 Million to Mitigate ‘Shadow AI’ Risks

08 April 2025
Silicon Valley startup secures big investment from Menlo Ventures and Mayfield Fund to solve the “shadow AI” security problem. The post Aurascape Banks Hefty $50 Million to Mitigate ‘Shadow AI’ Risks appeared first on SecurityWeek.

WhatsApp Vulnerability Could Facilitate Remote Code Execution

08 April 2025
An update for the WhatsApp desktop app for Windows patches CVE-2025-30401, a spoofing vulnerability that could be used to trick users. The post WhatsApp Vulnerability Could Facilitate Remote Code Execution appeared first on SecurityWeek.

ESET Vulnerability Exploited for Stealthy Malware Execution

08 April 2025
A sophisticated APT tracked as ToddyCat has exploited an ESET DLL search order hijacking vulnerability for malware delivery. The post ESET Vulnerability Exploited for Stealthy Malware Execution appeared first on SecurityWeek.

Corsha Raises $18 Million to Enhance and Extend Machine-to-Machine Security

08 April 2025
The new funds will be used to extend Corsha’s reach into critical infrastructure and further improve its own use of AI. The post Corsha Raises $18 Million to Enhance and Extend Machine-to-Machine Security appeared first on SecurityWeek.

Troy Rydman hired as CIO and CISO at Packsize

08 April 2025
Troy Rydman has been hired as the chief information officer (CIO) and chief information security officer (CISO) at Packsize. 

Tailscale Raises $160 Million for Secure Networking Platform 

08 April 2025
Tailscale’s new Series C funding round brings the total raised by the company for its secure networking platform to $275 million. The post Tailscale Raises $160 Million for Secure Networking Platform  appeared first on SecurityWeek.

Agentic AI in the SOC - Dawn of Autonomous Alert Triage

08 April 2025
Security Operations Centers (SOCs) today face unprecedented alert volumes and increasingly sophisticated threats. Triaging and investigating these alerts are costly, cumbersome, and increases analyst fatigue, burnout, and attrition. While artificial intelligence has emerged as a go-to solution, the term “AI” often blurs crucial distinctions. Not all AI is built equal, especially in the SOC. Many

Exploited Vulnerability Puts 5,000 Ivanti VPN Appliances at Risk

08 April 2025
More than 5,000 Ivanti Connect Secure appliances are vulnerable to attacks exploiting CVE-2025-22457, which has been used by Chinese hackers. The post Exploited Vulnerability Puts 5,000 Ivanti VPN Appliances at Risk appeared first on SecurityWeek.

UAC-0226 Deploys GIFTEDCROOK Stealer via Malicious Excel Files Targeting Ukraine

08 April 2025
The Computer Emergency Response Team of Ukraine (CERT-UA) has revealed a new set of cyber attacks targeting Ukrainian institutions with information-stealing malware. The activity is aimed at military formations, law enforcement agencies, and local self-government bodies, particularly those located near Ukraine's eastern border, the agency said. The attacks involve distributing phishing emails

Android Update Patches Two Exploited Vulnerabilities

08 April 2025
Android’s latest security update resolves two exploited Kernel vulnerabilities, as well as critical-severity bugs. The post Android Update Patches Two Exploited Vulnerabilities appeared first on SecurityWeek.

Threat Actors Setting Up Persistent Access to Hosts Hacked in CrushFTP Attacks

08 April 2025
Huntress has shared details on the post-exploitation activities of threat actors targeting the recent CrushFTP vulnerability. The post Threat Actors Setting Up Persistent Access to Hosts Hacked in CrushFTP Attacks appeared first on SecurityWeek.

CISA Adds CrushFTP Vulnerability to KEV Catalog Following Confirmed Active Exploitation

08 April 2025
A recently disclosed critical security flaw impacting CrushFTP has been added by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to its Known Exploited Vulnerabilities (KEV) catalog after reports emerged of active exploitation in the wild. The vulnerability is a case of authentication bypass that could permit an unauthenticated attacker to take over susceptible instances. It has

Google Releases Android Update to Patch Two Actively Exploited Vulnerabilities

08 April 2025
Google has shipped patches for 62 vulnerabilities, two of which it said have been exploited in the wild. The two high-severity vulnerabilities are listed below - CVE-2024-53150 (CVSS score: 7.8) - An out-of-bounds flaw in the USB sub-component of Kernel that could result in information disclosure CVE-2024-53197 (CVSS score: 7.8) - A privilege escalation flaw in the USB sub-component of Kernel

PCI DSS 4.0.1: A Cybersecurity Blueprint by the Industry, for the Industry

07 April 2025
As PCI DSS 4.0.1 comes into force, it shows the power of industry collaboration in cybersecurity. The post PCI DSS 4.0.1: A Cybersecurity Blueprint by the Industry, for the Industry appeared first on SecurityWeek.

Google Pushing ‘Sec-Gemini’ AI Model for Threat-Intel Workflows

07 April 2025
Experimental Sec-Gemini v1 touts a combination of Google’s Gemini LLM capabilities with real-time security data and tooling from Mandiant. The post Google Pushing ‘Sec-Gemini’ AI Model for Threat-Intel Workflows appeared first on SecurityWeek.

CISA and FBI Warn Fast Flux is Powering Resilient Malware, C2, and Phishing Networks

07 April 2025
Cybersecurity agencies from Australia, Canada, New Zealand, and the United States have published a joint advisory about the risks associated with a technique called fast flux that has been adopted by threat actors to obscure a command-and-control (C2) channel. "'Fast flux' is a technique used to obfuscate the locations of malicious servers through rapidly changing Domain Name System (DNS)

CRM, Bulk Email Providers Targeted in Crypto Phishing Campaign

07 April 2025
‘PoisonSeed’ phishing campaign targets CRM and bulk email providers to distribute “crypto seed phrase” messages. The post CRM, Bulk Email Providers Targeted in Crypto Phishing Campaign appeared first on SecurityWeek.