April 2025

SAP Confirms Critical NetWeaver Flaw Amid Suspected Zero-Day Exploitation by Hackers

SAP Confirms Critical NetWeaver Flaw Amid Suspected Zero-Day Exploitation by Hackers 2025-04-25 at 14:03 By Threat actors are likely exploiting a new vulnerability in SAP NetWeaver to upload JSP web shells with the goal of facilitating unauthorized file uploads and code execution.  “The exploitation is likely tied to either a previously disclosed vulnerability like CVE-2017-9844 […]

SAP Confirms Critical NetWeaver Flaw Amid Suspected Zero-Day Exploitation by Hackers Read More »

£13M government grant saves troubled Post Office from suboptimal IT

£13M government grant saves troubled Post Office from suboptimal IT 2025-04-25 at 13:47 By Lindsay Clark Taxpayers foot bill to get to new platform as Fujitsu package balloons to £2.44 billion The UK’s Post Office would have to cope with suboptimal IT, increased risks and costs, and reduced reporting accuracy if it didn’t receive £136

£13M government grant saves troubled Post Office from suboptimal IT Read More »

The sentiment engine of Bitcoin ETFs is rewiring market structure

The sentiment engine of Bitcoin ETFs is rewiring market structure 2025-04-25 at 13:03 By Cointelegraph by Michael Tabone The tide of capital once destined for raw spot Bitcoin has begun to flow through institutional canals, spot exchange-traded funds (ETFs), structured products and wrapped exposure, and while the water is rising fast, the waves aren’t quite

The sentiment engine of Bitcoin ETFs is rewiring market structure Read More »

Polygon CEO: DeFi must ditch hype for sustainable liquidity

Polygon CEO: DeFi must ditch hype for sustainable liquidity 2025-04-25 at 13:03 By Cointelegraph by Arijit Sarkar Polygon Labs CEO Marc Boiron called for a fundamental shift in how decentralized finance (DeFi) protocols manage liquidity, labeling the sector’s ongoing liquidity crisis as “self-inflicted.” In an exclusive interview, Boiron outlined Polygon’s vision for sustainable DeFi, emphasizing

Polygon CEO: DeFi must ditch hype for sustainable liquidity Read More »

Sam Bankman-Fried moved to a low-security prison — so what?

Sam Bankman-Fried moved to a low-security prison — so what? 2025-04-25 at 13:03 By Cointelegraph by Adrian Zmudzinski Sam “SBF” Bankman-Fried, the disgraced co-founder of collapsed cryptocurrency exchange FTX, to a low-security US federal correctional institution Bankman-Fried was moved to the low-security Terminal Island federal correctional institution. Previously, he was located at the Victorville medium-security

Sam Bankman-Fried moved to a low-security prison — so what? Read More »

Claims assistance firm fined for cold-calling people who put themselves on opt-out list

Claims assistance firm fined for cold-calling people who put themselves on opt-out list 2025-04-25 at 12:39 By Dan Robinson Third-party data supplier also in hot water with Brit regulator over consent issues Britain’s data privacy watchdog has slapped a fine of £90k ($120k) on a business that targeted people with intrusive marketing phone calls, despite

Claims assistance firm fined for cold-calling people who put themselves on opt-out list Read More »

Rack Ruby vulnerability could reveal secrets to attackers (CVE-2025-27610)

Rack Ruby vulnerability could reveal secrets to attackers (CVE-2025-27610) 2025-04-25 at 12:39 By Zeljka Zorz Researchers have uncovered three serious vulnerabilities in Rack, a server interface used by most Ruby web app frameworks (Ruby on Rails, Sinatra, Hanami, Roda, and others). Two of the flaws – CVE-2025-25184 and CVE-2025-27111 – could allow attackers to manipulate

Rack Ruby vulnerability could reveal secrets to attackers (CVE-2025-27610) Read More »

SAP Zero-Day Possibly Exploited by Initial Access Broker

SAP Zero-Day Possibly Exploited by Initial Access Broker 2025-04-25 at 12:38 By Ionut Arghire A zero-day vulnerability in SAP NetWeaver potentially affects more than 10,000 internet-facing applications. The post SAP Zero-Day Possibly Exploited by Initial Access Broker appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

SAP Zero-Day Possibly Exploited by Initial Access Broker Read More »

All Major Gen-AI Models Vulnerable to ‘Policy Puppetry’ Prompt Injection Attack

All Major Gen-AI Models Vulnerable to ‘Policy Puppetry’ Prompt Injection Attack 2025-04-25 at 12:38 By Ionut Arghire A new attack technique named Policy Puppetry can break the protections of major gen-AI models to produce harmful outputs. The post All Major Gen-AI Models Vulnerable to ‘Policy Puppetry’ Prompt Injection Attack appeared first on SecurityWeek. This article

All Major Gen-AI Models Vulnerable to ‘Policy Puppetry’ Prompt Injection Attack Read More »

Researchers Identify Rack::Static Vulnerability Enabling Data Breaches in Ruby Servers

Researchers Identify Rack::Static Vulnerability Enabling Data Breaches in Ruby Servers 2025-04-25 at 12:17 By Cybersecurity researchers have disclosed three security flaws in the Rack Ruby web server interface that, if successfully exploited, could enable attackers to gain unauthorized access to files, inject malicious data, and tamper with logs under certain conditions. The vulnerabilities, flagged by

Researchers Identify Rack::Static Vulnerability Enabling Data Breaches in Ruby Servers Read More »

DslogdRAT Malware Deployed via Ivanti ICS Zero-Day CVE-2025-0282 in Japan Attacks

DslogdRAT Malware Deployed via Ivanti ICS Zero-Day CVE-2025-0282 in Japan Attacks 2025-04-25 at 12:17 By Cybersecurity researchers are warning about a new malware called DslogdRAT that’s installed following the exploitation of a now-patched security flaw in Ivanti Connect Secure (ICS). The malware, along with a web shell, were “installed by exploiting a zero-day vulnerability at

DslogdRAT Malware Deployed via Ivanti ICS Zero-Day CVE-2025-0282 in Japan Attacks Read More »

‘Vitalik: An Ethereum Story’ is less about crypto and more about being human

‘Vitalik: An Ethereum Story’ is less about crypto and more about being human 2025-04-25 at 12:03 By Cointelegraph by Stephen Laddin When Zach Ingrasci and Chris Temple had the idea to make the documentary film Vitalik: An Ethereum Story, they were actually filming another documentary, and over the course of their filmmaking journey, they ended

‘Vitalik: An Ethereum Story’ is less about crypto and more about being human Read More »

Arkansas city rejects crypto mining proposal after community pushback

Arkansas city rejects crypto mining proposal after community pushback 2025-04-25 at 12:03 By Cointelegraph by Amin Haqshanas The planning commission of Vilonia, Arkansas, unanimously rejected a proposal to establish a cryptocurrency mining facility within the city limits, following strong opposition from residents. According to local reports, the decision came after weeks of community pushback, where

Arkansas city rejects crypto mining proposal after community pushback Read More »

RTFKT’s CloneX avatars reappear after issue blacks out NFTs

RTFKT’s CloneX avatars reappear after issue blacks out NFTs 2025-04-25 at 11:22 By Cointelegraph by Brayden Lindrea More than 19,800 CloneX digital avatars developed by non-fungible token firm RTFKT Studios have reappeared after Cloudflare blacked out the NFTs for apparently violating its terms of service. “This content has been restricted. Using Cloudflare’s basic service in

RTFKT’s CloneX avatars reappear after issue blacks out NFTs Read More »

Earth Kurma APT Campaign Targets Southeast Asian Government, Telecom Sectors

Earth Kurma APT Campaign Targets Southeast Asian Government, Telecom Sectors 2025-04-25 at 11:22 By An APT group dubbed Earth Kurma is actively targeting government and telecommunications organizations in Southeast Asia using advanced malware, rootkits, and trusted cloud services to conduct cyberespionage. This article is an excerpt from Trend Micro Research, News and Perspectives View Original

Earth Kurma APT Campaign Targets Southeast Asian Government, Telecom Sectors Read More »

Detectify Asset Classification and Scan Recommendations improves vulnerability testing

Detectify Asset Classification and Scan Recommendations improves vulnerability testing 2025-04-25 at 11:22 By Industry News Detectify announced new Asset Classification and Scan Recommendations capabilities. This innovation directly addresses a critical challenge for security teams: knowing what else, beyond their core applications, requires in-depth testing. The new features automatically classify discovered web assets based on attacker

Detectify Asset Classification and Scan Recommendations improves vulnerability testing Read More »

Rubrik Identity Resilience protects vulnerable authentication infrastructure

Rubrik Identity Resilience protects vulnerable authentication infrastructure 2025-04-25 at 11:22 By Industry News Rubrik announced its upcoming solution, Identity Resilience, designed to secure the entire identity landscape alongside data. Identity Resilience aims to protect the most common entry points for attackers – human and non-human identities (NHIs) – to help organizations maintain operations with minimal

Rubrik Identity Resilience protects vulnerable authentication infrastructure Read More »

BreachLock AEV simulates Real attacks to validate and prioritize exposures

BreachLock AEV simulates Real attacks to validate and prioritize exposures 2025-04-25 at 11:22 By Industry News BreachLock AEV automates multistep, threat-intelligence-led attack scenarios—helping security teams uncover real exposures and prioritize what matters most. Going beyond just showing security teams their risk, BreachLock Adversarial Exposure Validation simulates how real-world adversaries would exploit it by mirroring their

BreachLock AEV simulates Real attacks to validate and prioritize exposures Read More »

Dashlane introduces Omnix for AI-powered credential protection

Dashlane introduces Omnix for AI-powered credential protection 2025-04-25 at 10:53 By Industry News Dashlane unveiled a new approach to addressing human risk in response to the rise of AI-driven phishing attacks and shadow IT in corporate environments. Built on innovation that pushes beyond vault-based password management, Dashlane Omnix is the AI-accelerated credential security platform that unifies

Dashlane introduces Omnix for AI-powered credential protection Read More »

Scroll to Top