News

Threat Intelligence News from LevelBlue SpiderLabs December 2025

Threat Intelligence News from LevelBlue SpiderLabs December 2025 2025-12-15 at 13:48 By LevelBlue SpiderLabs is the threat intelligence unit of LevelBlue and includes a global team of threat researchers and data scientists who, combined with proprietary technology in data analytics and machine learning (ML), analyze one of the largest and most diverse collections of threat […]

Threat Intelligence News from LevelBlue SpiderLabs December 2025 Read More »

Kali Linux 2025.4: New tools and “quality-of-life” improvements

Kali Linux 2025.4: New tools and “quality-of-life” improvements 2025-12-15 at 13:48 By Zeljka Zorz OffSec has released Kali Linux 2025.4, a new version of its widely used penetration testing and digital forensics platform. Most of the changes are related to appearance and usability: Kali’s GNOME desktop environment now organizes Kali tools into folders via the

Kali Linux 2025.4: New tools and “quality-of-life” improvements Read More »

Update your Apple devices to fix actively exploited vulnerabilities! (CVE-2025-14174, CVE-2025-43529)

Update your Apple devices to fix actively exploited vulnerabilities! (CVE-2025-14174, CVE-2025-43529) 2025-12-15 at 12:58 By Zeljka Zorz Apple has issued security updates with fixes for two WebKit vulnerabilities (CVE-2025-14174, CVE-2025-43529) that have been exploited as zero-days. Several days before the release of these updates, Google fixed CVE-2025-14174 in the desktop version of Chrome, though at

Update your Apple devices to fix actively exploited vulnerabilities! (CVE-2025-14174, CVE-2025-43529) Read More »

How researchers are teaching AI agents to ask for permission the right way

How researchers are teaching AI agents to ask for permission the right way 2025-12-15 at 09:06 By Mirko Zorz People are starting to hand more decisions to AI agents, from booking trips to sorting digital files. The idea sounds simple. Tell the agent what you want, then let it work through the steps. The hard

How researchers are teaching AI agents to ask for permission the right way Read More »

Europe’s DMA raises new security worries for mobile ecosystems

Europe’s DMA raises new security worries for mobile ecosystems 2025-12-15 at 08:43 By Anamarija Pogorelec Mobile security has long depended on tight control over how apps and services interact with a device. A new paper from the Center for Cybersecurity Policy and Law warns that this control may weaken as the European Union’s Digital Markets

Europe’s DMA raises new security worries for mobile ecosystems Read More »

Prometheus: Open-source metrics and monitoring systems and services

Prometheus: Open-source metrics and monitoring systems and services 2025-12-15 at 08:43 By Anamarija Pogorelec Prometheus is an open-source monitoring and alerting system built for environments where services change often and failures can spread fast. For security teams and DevOps engineers, it has become a common way to track system behavior, spot early warning signs, and

Prometheus: Open-source metrics and monitoring systems and services Read More »

What types of compliance should your password manager support?

What types of compliance should your password manager support? 2025-12-15 at 07:49 By Sinisa Markovic Lost credentials and weak authentication controls still sit at the center of many security incidents. IT leaders and CISOs know this problem well. They also know that regulators watch how organizations protect passwords, track access, and document security decisions. That

What types of compliance should your password manager support? Read More »

Manufacturing is becoming a test bed for ransomware shifts

Manufacturing is becoming a test bed for ransomware shifts 2025-12-15 at 07:12 By Anamarija Pogorelec Manufacturing leaders may feel that ransomware risk has settled, but new data shows the threat is shifting in ways that require attention, according to a Sophos report. A global survey of 332 IT and security leaders outlines how attackers are

Manufacturing is becoming a test bed for ransomware shifts Read More »

Week in review: 40 open-source tools securing the stack, invisible IT to be the next workplace priority

Week in review: 40 open-source tools securing the stack, invisible IT to be the next workplace priority 2025-12-14 at 11:04 By Help Net Security Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: 40 open-source tools redefining how security teams secure the stack Open source security software has become

Week in review: 40 open-source tools securing the stack, invisible IT to be the next workplace priority Read More »

What 35 years of privacy law say about the state of data protection

What 35 years of privacy law say about the state of data protection 2025-12-12 at 09:52 By Anamarija Pogorelec Privacy laws have expanded around the world, and security leaders now work within a crowded field of requirements. New research shows that these laws provide stronger rights and duties, but the protections do not always translate

What 35 years of privacy law say about the state of data protection Read More »

LLM privacy policies keep getting longer, denser, and nearly impossible to decode

LLM privacy policies keep getting longer, denser, and nearly impossible to decode 2025-12-12 at 08:30 By Sinisa Markovic People expect privacy policies to explain what happens to their data. What users get instead is a growing wall of text that feels harder to read each year. In a new study, researchers reviewed privacy policies for

LLM privacy policies keep getting longer, denser, and nearly impossible to decode Read More »

Ransomware keeps widening its reach

Ransomware keeps widening its reach 2025-12-12 at 08:21 By Anamarija Pogorelec Ransomware keeps shifting into new territory, pulling in victims from sectors and regions that once saw fewer attacks. The latest Global Threat Briefing for H2 2025 from CyberCube shows incidents spreading in ways that make it harder for security leaders to predict where threats

Ransomware keeps widening its reach Read More »

Uneven regulatory demands expose gaps in mobile security

Uneven regulatory demands expose gaps in mobile security 2025-12-12 at 07:36 By Anamarija Pogorelec Mobile networks carry a great deal of the world’s digital activity, which makes operators a frequent target for attacks. A study released by the GSMA shows that operators spend between $15 and $19 billion a year on core cybersecurity functions. Spending

Uneven regulatory demands expose gaps in mobile security Read More »

New infosec products of the week: December 12, 2025

New infosec products of the week: December 12, 2025 2025-12-12 at 07:06 By Anamarija Pogorelec Here’s a look at the most interesting products from the past week, featuring releases from Apptega, Backslash Security, BigID, Black Kite, Bugcrowd, NinjaOne, Nudge Security, and Veza. Apptega Policy Manager streamlines policy creation and compliance oversight Apptega revealed its Policy

New infosec products of the week: December 12, 2025 Read More »

40 open-source tools redefining how security teams secure the stack

40 open-source tools redefining how security teams secure the stack 2025-12-11 at 09:07 By Anamarija Pogorelec Open source security software has become a key way for teams to get flexibility, transparency, and capability without licensing costs. The free tools in this roundup address problems security teams deal with, from managing large environments to catching misconfigurations

40 open-source tools redefining how security teams secure the stack Read More »

LLM vulnerability patching skills remain limited

LLM vulnerability patching skills remain limited 2025-12-11 at 08:47 By Sinisa Markovic Security teams are wondering whether LLMs can help speed up patching. A new study tests that idea and shows where the tools hold up and where they fall short. The researchers tested LLMs from OpenAI, Meta, DeepSeek, and Mistral to see how well

LLM vulnerability patching skills remain limited Read More »

Password habits are changing, and the data shows how far we’ve come

Password habits are changing, and the data shows how far we’ve come 2025-12-11 at 08:13 By Help Net Security In this Help Net Security video, Andréanne Bergeron, Security Researcher at Flare, explains how changes in user habits, policy shifts, and new tools have shaped password security over nearly twenty years. She walks through research based

Password habits are changing, and the data shows how far we’ve come Read More »

Product showcase: Tuta – secure, encrypted, private email

Product showcase: Tuta – secure, encrypted, private email 2025-12-11 at 08:13 By Help Net Security Tuta, formerly known as Tutanota, is built for anyone who wants email that stays private. Instead of treating encryption like a bonus feature, the service encrypts almost everything by default. That means your messages are locked down from the moment

Product showcase: Tuta – secure, encrypted, private email Read More »

Teamwork is failing in slow motion and security feels it

Teamwork is failing in slow motion and security feels it 2025-12-11 at 07:07 By Anamarija Pogorelec Security leaders often track threats in code, networks, and policies. But a quieter risk is taking shape in the everyday work of teams. Collaboration is getting harder even as AI use spreads across the enterprise. That tension creates openings

Teamwork is failing in slow motion and security feels it Read More »

Henkel CISO on the messy truth of monitoring factories built across decades

Henkel CISO on the messy truth of monitoring factories built across decades 2025-12-10 at 09:08 By Mirko Zorz In this Help Net Security interview, Stefan Braun, CISO at Henkel, discusses how smart manufacturing environments introduce new cybersecurity risks. He explains where single points of failure hide, how attackers exploit legacy systems, and why monitoring must

Henkel CISO on the messy truth of monitoring factories built across decades Read More »

Scroll to Top