information security news

Critical Apache Roller flaw allows to retain unauthorized access even after a password changeCritical Apache Roller flaw allows to retain unauthorized access even after a password change

Critical Apache Roller flaw allows to retain unauthorized access even after a password change

A critical flaw (CVE-2025-24859, CVSS 10) in Apache Roller lets attackers keep access even after password changes. All versions ≤6.1.4…

1 month ago
Meta will use public EU user data to train its AI modelsMeta will use public EU user data to train its AI models

Meta will use public EU user data to train its AI models

Meta announced that it will use public EU user data to train AI, resuming plans paused last year over Irish…

1 month ago
Hertz disclosed a data breach following 2024 Cleo zero-day attackHertz disclosed a data breach following 2024 Cleo zero-day attack

Hertz disclosed a data breach following 2024 Cleo zero-day attack

Hertz Corporation disclosed a data breach after customer data was stolen via Cleo zero-day exploits in late 2024, affecting Hertz,…

1 month ago
Gladinet flaw CVE-2025-30406 actively exploited in the wildGladinet flaw CVE-2025-30406 actively exploited in the wild

Gladinet flaw CVE-2025-30406 actively exploited in the wild

Huntress reports active exploitation of Gladinet CVE-2025-30406 in the wild, affecting seven organizations and 120 endpoints. Security researchers at Huntress…

1 month ago
New malware ‘ResolverRAT’ targets healthcare, pharmaceutical firmsNew malware ‘ResolverRAT’ targets healthcare, pharmaceutical firms

New malware ‘ResolverRAT’ targets healthcare, pharmaceutical firms

New malware ‘ResolverRAT’ is targeting healthcare and pharmaceutical firms, using advanced capabilities to steal sensitive data. Morphisec researchers discovered a…

1 month ago
Malicious NPM packages target PayPal usersMalicious NPM packages target PayPal users

Malicious NPM packages target PayPal users

Threat actors deploy malicious NPM packages to steal PayPal credentials and hijack cryptocurrency transfers. Fortinet researchers discovered multiple malicious NPM packages that…

1 month ago
Tycoon2FA phishing kit rolled out significant updatesTycoon2FA phishing kit rolled out significant updates

Tycoon2FA phishing kit rolled out significant updates

The operators of the Phishing-as-a-Service (PhaaS) platform Tycoon2FA have rolled out significant updates to enhance its evasion capabilities. Tycoon2FA, a…

1 month ago
South African telecom provider Cell C disclosed a data breach following a cyberattackSouth African telecom provider Cell C disclosed a data breach following a cyberattack

South African telecom provider Cell C disclosed a data breach following a cyberattack

Cell C, one of the biggest telecom providers in South Africa confirms a data breach following a 2024 cyberattack. Cell…

1 month ago
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 41SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 41

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 41

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Lazarus…

1 month ago
Security Affairs newsletter Round 519 by Pierluigi Paganini – INTERNATIONAL EDITIONSecurity Affairs newsletter Round 519 by Pierluigi Paganini – INTERNATIONAL EDITION

Security Affairs newsletter Round 519 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free…

1 month ago