Car Subscription Features Raise Your Risk of Government Surveillance, Police Records Show
28
Apr
2025

Car Subscription Features Raise Your Risk of Government Surveillance, Police Records Show

What is also clear from the documents is that US police are aware of the control corporations have over their…

New iOS Vulnerability Could Brick iPhones with Just One Line of Code
28
Apr
2025

New iOS Vulnerability Could Brick iPhones with Just One Line of Code

A security researcher has uncovered a critical vulnerability in iOS, Apple’s flagship mobile operating system. The flaw, CVE-2025-24091, which leverages…

PoC rootkit Curing evades traditional Linux detection systems
28
Apr
2025

PoC rootkit Curing evades traditional Linux detection systems

PoC rootkit Curing evades traditional Linux detection systems Pierluigi Paganini April 28, 2025 Researchers created a PoC rootkit called Curing…

CISA Alerts Users to Security Flaws in Planet Technology Network Products
28
Apr
2025

CISA Alerts Users to Security Flaws in Planet Technology Network Products

Why Application Security is Non-Negotiable The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application…

Critical SAP NetWeaver flaw exploited by suspected initial access broker (CVE-2025-31324)
28
Apr
2025

Critical SAP NetWeaver flaw exploited by suspected initial access broker (CVE-2025-31324)

CVE-2025-31324, a critical vulnerability in the SAP NetWeaver platform, is being actively exploited by attackers to upload malicious webshells to…

Rootkits and Cloud-Based Data T
28
Apr
2025

Earth Kurma Targets Southeast Asia With Rootkits and Cloud-Based Data Theft Tools

Government and telecommunications sectors in Southeast Asia have become the target of a “sophisticated” campaign undertaken by a new advanced…

Attackers chained Craft CMS zero-days attacks in the wild
28
Apr
2025

Attackers chained Craft CMS zero-days attacks in the wild

Attackers chained Craft CMS zero-days attacks in the wild Pierluigi Paganini April 28, 2025 Orange Cyberdefense’s CSIRT reported that threat…

Viasat Modems Zero-Day Vulnerabilities Let Attackers Execute Remote Code
28
Apr
2025

Viasat Modems Zero-Day Vulnerabilities Let Attackers Execute Remote Code

A severe zero-day vulnerability has been uncovered in multiple Viasat satellite modem models, including the RM4100, RM4200, EM4100, RM5110, RM5111,…

Critical FastCGI Library Flaw Exposes Embedded Devices to Code Execution
28
Apr
2025

Critical FastCGI Library Flaw Exposes Embedded Devices to Code Execution

A severe vulnerability (CVE-2025-23016) in the FastCGI library-a core component of lightweight web server communication been disclosed, threatening countless embedded…

WooCommerce Users Targeted by Fake Patch Phishing Campaign Deploying Site Backdoors
28
Apr
2025

WooCommerce Users Targeted by Fake Patch Phishing Campaign Deploying Site Backdoors

Apr 28, 2025Ravie LakshmananWebsite Security / Malware Cybersecurity researchers are warning about a large-scale phishing campaign targeting WooCommerce users with…

A Key Weapon in the Ongoing War Between Hackers and Defenders
28
Apr
2025

A Key Weapon in the Ongoing War Between Hackers and Defenders

Obfuscation stands as a powerful weapon for attackers seeking to shield their malicious code from defenders. This technique, which deliberately…

week in security
28
Apr
2025

A week in security (April 21 – April 27)

Last week on Malwarebytes Labs: Last week on ThreatDown: Stay safe! Our business solutions remove all remnants of ransomware and…