Menu

Monthly Archives: April 2025

Lizard Squad DDoS-for-hire service hacked – users’ details revealed

Lizard Squad failed to encrypt its database of LizardStresser’s registered users – storing details of their usernames and passwords in plaintext. A schoolboy error if ever I heard one.

Cybercrime deterrence: 6 important steps

Cybercrime: there’s too much of it, and we need to do more to deter it. With the President of the United States now making frequent references to “doing more about cybercrime” now is a good time to look at what steps must be taken.

1800 Minecraft logins leak online

More than 1,800 Minecraft login details have been leaked online, German news site Heise.de has revealed.

Facebook will highlight hoaxes in users’ newsfeeds

Facebook has announced plans to crack down on spam and hoaxes in the newsfeed, with a note highlighting ‘false information’ when enough people flag the link as a hoax.

How can businesses save money on internet security in 2015?

A recent report from Piper Jaffray found that 75% of companies expected to increase their IT security spending in 2015, following a year of high-profile hacks and data breaches in 2014.

Edward Snowden doesn’t use an iPhone for privacy reasons

NSA whistleblower Edward Snowden has claimed he doesn’t use an iPhone for fear of surveillance technology in the smartphone, reports The Independent.

Google reveals trio of security vulnerabilities in OS X

Google’s Project Zero has released information on three as yet unpatched vulnerabilities in Apple’s OS X operating system, reports Ars Technica.

Android Wi-Fi Direct bug means hackers can reboot your device

A vulnerability in Android’s Wi-Fi Direct functionality has been uncovered by security researchers.

MSIL/Agent.PYO: Have botnet, will travel

ESET’s researchers recently encountered a piece of malware targeting the filling of the forms belonging to the Consulate of Poland. To understand why it is first necessary to have a brief look at the application process for visas.

Taylor Swift hacked, but denies naked pictures will be leaked

Singer Taylor Swift has had her Twitter and Instagram accounts hacked, but laughed off claims that the hackers will release nude photographs of her.

Blackhat: Lessons from the Michael Mann, Chris Hemsworth movie?

Blackhat, the hacker movie directed by Michael Mann and starring Chris Hemsworth, could spread awareness of digital threats. If it is a learning opportunity, what are the lessons?

6 WhatsApp Security Tips

Even though WhatsApp now encrypts all of its messages and data, it pays to be secure with your chats. Here are our top WhatsApp security tips.

The New Hacker’s List and an Old Debate: Would you Hire a Hacker?

The recent opening of the Hacker List portal brings to mind the age-old question: Would you hire a hacker?

Facebook porn scam infects 110k users in 48 hours

A new porn scam is spreading startlingly quickly through Facebook – one that has managed to spread malware to over 110,000 users in 48 hours, reports The Guardian.

White House seeks 10% increase in cybersecurity spend

President Obama’s budget proposal for the 2016 fiscal year includes a projected 10 percent increase in cybersecurity spend, reports Reuters.

Internet Explorer exploit could let phishers steal logins

A vulnerability in the latest patched version of Microsoft Internet Explorer that could allow hackers to launch “highly credible phishing attacks” has been uncovered, according to PC World.

Facebook turns 11 – what you need to know, and what do your likes say about you?

Facebook updated its privacy settings at the end of January. As Facebook turns 11 today, here’s what you need to know about the new settings and how they could affect you.

The utterly crazy story of the death threat hacker (involves a cat)

A cat leads to a notorious death threat hacker finally being caught and jailed in Japan.

What are the alternatives to passwords?

Is it time for big companies – at the very least – to abandon weak password security? If so, what password alternatives are there?

Common eBay scams and how to avoid them

Buying and selling on eBay can be great, but it can also be fraught with risk. Here are some of the most common eBay scams and how they can be avoided.

It’s Safer Internet Day. So where is our Internet of Secure Things?

It’s Safer Internet Day. But millions of devices which have not been designed with security in mind are connecting to the internet. Shouldn’t we be able to tell the manufacturers that enough is enough?

WhatsApp privacy is ‘broken,’ reveals proof-of-concept hack

WhatsApp’s privacy settings are “broken” and can be bypassed by downloading a simple bit of software, claims the Dutch developer behind proof-of-concept tool WhatsSpy Public.

Facebook launches ThreatExchange for companies to share security threats

Facebook has officially launched ThreatExchange – a collaborative social network where companies can share information on cybersecurity threats, in an effort to neuter potential damage.

Facebook exploit allowed attackers to remotely delete photos

A Facebook hack that allowed attackers to remotely delete any photo they wanted to from the social network has been patched by the company.

Is your valentine for real? Six signs you might be falling for an online dating scam

With Valentine’s Day nearly upon us, millions will be looking for love online. Here’s six online dating scams to look out for.

Jamie Oliver website serves up a side of malware

Jamie Oliver’s website was affected by a malware issue, a spokesperson for the British celebrity chef has told the BBC.

Lenovo and Superfish? Don’t panic, you may not be affected

Lenovo’s installation of a security-breaking app called Superfish on some computers has customers justifiably angry, but some folks are now unnecessarily confused by false positive detection.

Top 10 breaches of 2014 attacked ‘old vulnerabilities’, says HP

A report by HP has found that 44 percent of all of the breaches in 2014 were caused by known vulnerabilities, between two and four years old.

Security terms explained: What does Zero Day mean?

One of the terms I’m most often asked to explain is what a “zero day” vulnerability or exploit is; let’s look at what that phrase entails.

Europol shuts down Ramnit botnet used to steal bank details

The Ramnit botnet that is said to have affected 3.2 million computers has been shut down by European police.

Electronic health records and data abuse: it’s about more than medical info

After the Anthem mega-breach, questions abound about possible abuses of medical data. Here is a breakdown that offers some context.

Blu-ray exploits could allow computer malware infection

A pair of possible exploits in hardware and software used for playing Blu-ray discs have come to light, reports PC World.

FREAK attack: security vulnerability breaks HTTPS protection

A widespread, long-standing security flaw that allows attackers to decrypt HTTPS-protected traffic between certain device and potentially millions of websites has been uncovered by security researchers, reports Ars Technica.

Casper Malware: After Babar and Bunny, Another Espionage Cartoon

In this post, we lift the veil on Casper – another piece of software that we believe to have been created by the same organization that is behind Babar and Bunny.

Lysa Myers: “There are still only a handful of women in the security field”

There are many female researchers and computer experts who contribute to the field, helping everyone enjoy safer technology. We spoke to one of the most prominent: Lysa Myers, a member of our research team in the US.

DDoS attack on feminist blog backfires on International Women’s Day

An attempt to silence feminism blog Femsplain backfires on DDoS attackers, as they only help to raise its profile.

FBI investigating apparent ISIS attacks on Western websites

A number of seemingly unconnected Western websites were hacked over the weekend, with messages claiming Islamic State as the perpetrator.

Operating System Vulnerabilities, Exploits and Insecurity

iOS and OS X the most vulnerable operating systems? Don’t confuse vulnerabilities with exploits, or patch frequency with insecurity.

CryptoFortress mimics TorrentLocker but is a different ransomware

ESET assess the differences between CryptoFortress and TorrentLocker: two very different strains of ransomware.

Will Windows 10 leave enterprises vulnerable to zero-days?

One thing Microsoft has been very public about is Windows 10’s new strategy of releasing patches to update the operating system at different times for consumer and enterprise versions.

Hackers phish for data with fake Apple Watch giveaway

Apple fans keen to get their hands on the Apple Watch are advised to think before they click, after hackers exploited a wave of enthusiasm around the launch with a phishing scam linked to a fake giveaway.

7 tasks that waste your IT team’s time

IT teams’ time is always limited, and it doesn’t help when other things get in the way. Here’s seven things that waste your IT team’s time.

* bsc#1239460 Cross-References: * CVE-2025-24049

Google’s got a hot cloud infosec startup, a new unified platform — and its eye on Microsoft’s $20B+ security biz
Securing Kubernetes and Cloud-Native Environments through DevSecOps

An update that fixes one vulnerability is now available.

This update includes an upstream patch to accept “0” as a valid epoch in Debian packages processed by BSSolv. This fixes a bug that prevents the Open Build Service backend from working

* bsc#1207948 * bsc#1215199 * bsc#1215211 * bsc#1218470 * bsc#1221651

Pharmacist accused of using webcams to spy on women in intimate moments at work, home

Update to 128.9.0 https://www.thunderbird.net/en-US/thunderbird/128.9.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2025-24/

Bad luck, Windows 10 users. No fix yet for ransomware-exploited bug
The AI Fix #45: The Turing test falls to GPT-4.5
Don’t open that JPG sent via WhatsApp for Windows. It might be an .EXE
Beware these 10 malicious VS Code extensions
Scattered Spider stops the Rickrolls, starts the RAT race

Expat could be made to crash if it received specially crafted input.

Mastering SSH for Secure Linux Remote Server Management
Meta launches AI family Llama 4 — but the EU doesn’t get everything
Why is cloud-based AI so hard?

* bsc#1240416 Cross-References: * CVE-2025-31344

* bsc#1240416 Cross-References: * CVE-2025-31344

Net::EasyTCP Perl module includes encryption functionality that requires a secure random number generator. Until and including the version 0.26, this module used a random number generator without any such guarantees. The reason for this was that it relied on Crypt::Random, a Perl module

Russian bots hard at work spreading political unrest on Romania’s internet
Visual Studio Code stabilizes agent mode

Prior to version 0.008, the Perl module Data::Entropy relied on Perl’s builtin rand function to choose an entropy source. Version 0.008 does away with this need.

As CISA braces for more cuts, threat intel sharing takes a hit
Warning to developers: Stay away from these 10 VSCode extensions
Oracle says its cloud was in fact compromised

https://security-tracker.debian.org/tracker/DSA-5897-1

Cloudflare unveils agentic AI development tools
Kotlin, Swift, and Ruby losing popularity – Tiobe index
That massive GitHub supply chain attack? It all started with a stolen SpotBugs token
Alleged Scattered Spider SIM-swapper must pay back $13.2M to 59 victims
Chrome to patch decades-old flaw that let sites peek at your history
UK’s attempt to keep details of Apple ‘backdoor’ case secret… denied
King Bob pleads guilty to Scattered Spider-linked cryptocurrency thefts from investors

* bsc#1236217 * bsc#1239182 * bsc#1240550 Cross-References:

* jsc#PED-11136 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6

* bsc#1240083 Cross-References: * CVE-2025-3028 * CVE-2025-3029

10 Java-based tools and frameworks for generative AI
Language models in generative AI – does size matter?
AI demands more software developers, not less
What native cloud security tools won’t catch
Asian tech players react to US tariffs with delays, doubts, deal-making
Signalgate solved? Report claims journalist’s phone number accidentally saved under name of Trump official

Update to 0.4.8; Fixes: RHBZ#2237964, RHBZ#2282129

5.0.0

Fix CVE-2024-12905.

Address CVE-2025-30093 – rhbz#2355671

5.0.0

Fix CVE-2024-12905.

Red Hat OpenShift and zero trust: Securing workloads with cert-manager and OpenShift Service Mesh

Update to 135.0.7049.52 High CVE-2025-3066: Use after free in Navigations Medium CVE-2025-3067: Inappropriate implementation in Custom Tabs Medium CVE-2025-3068: Inappropriate implementation in Intents Medium CVE-2025-3069: Inappropriate implementation in Extensions

Backport fixes from v1.127.1

This is an update fixing CVE 2025-30232.