Risk
-
CISA Identifies Exploited Windows Vulnerability: Urgent Fixes Required
CISA has identified a medium-severity vulnerability in Microsoft Windows, designated CVE-2025-24054, which has come under active exploitation. The vulnerability, tied to the deprecated NTLM authentication protocol, allows unauthorized access to sensitive data. Urgent measures are required to secure systems against ongoing attacks targeting both governmental and private institutions.
-
Tech Giants Lead Push for Shorter Digital Certificate Lifespans
Tech giants Apple and Google are leading a significant initiative to reduce the maximum lifespans of digital certificates, aiming to strengthen cybersecurity and mitigate risks associated with long-term certificates. The proposal suggests a maximum validity of 90 days from Google and 47 days from Apple, potentially revolutionizing internet safety standards.
-
New ResolverRAT Malware Targets Global Healthcare and Pharmaceutical Sectors
ResolverRAT, a new remote access trojan, poses a significant threat to healthcare and pharmaceutical organizations globally through sophisticated phishing tactics and stealthy operations, according to security researchers.
-
Human Element Critical in Combating Rising Cyber Threats, Experts Warn
As cyber threats evolve, experts stress the critical role of human intervention in enhancing cybersecurity resilience. Over half of UK businesses face projected cyber breaches in 2024, emphasizing the need for employee training and awareness within organizations.
-
Cybersecurity Risks with Third-Party Identity Providers Prompt New Solutions
As businesses increasingly rely on third-party identity providers for cybersecurity, experts warn about the risks, suggesting innovative solutions like extra-factor authentication to enhance security without ceding control.
-
IKEA Operator Reports €20 Million Loss from Ransomware Attack
Fourlis Group, operator of IKEA stores in several Eastern European countries, reported a €20 million loss due to a ransomware attack that occurred in late November 2024. The incident primarily impacted IKEA’s sales and e-commerce operations, with the company stating that it did not pay the ransom demanded by attackers.
-
China’s Smishing Triad Expands Phishing Tactics, Directly Targeting Banks
The Smishing Triad, a group of cybercriminals based in China, has expanded its phishing operations from impersonating toll road operators to directly targeting international banks and financial institutions, raising significant cybersecurity concerns.
-
Cybersecurity Firm Reports on Exploitation of Serious CrushFTP Vulnerability
Huntress has detailed alarming activities following exploitation of the CrushFTP vulnerability, demonstrating ongoing risks to critical sectors like marketing and retail. CISA has added the flaw to its KEV catalog, prompting renewed urgency for organizations to secure their systems.
-
NIST Places Pre-2018 Vulnerabilities on Deferred Status Amid Resource Reallocation
NIST has announced that all CVEs published before 2018 will be marked as ‘Deferred’ in the National Vulnerability Database, reallocating resources towards emerging threats while placing the responsibility for legacy vulnerabilities on individual organizations.
-
New Cyber Threat Emerges as PoisonSeed Targets CRM Accounts
The PoisonSeed campaign is exploiting compromised credentials from CRM tools and email services to send spam containing cryptocurrency seed phrases, endangering businesses and individuals alike.









