04/03

Hotpatch for Windows client now available - Windows IT Pro Blog

https://techcommunity.microsoft.com/blog/windows-itpro-blog/hotpatch-for-windows-client-now-available/4399808
Hotpatch for Windows client now available - Windows IT Pro Blog

Suspected China-Nexus Threat Actor Actively Exploiting Critical Ivanti Connect Secure Vulnerability (CVE-2025-22457) | Google Cloud Blog

https://cloud.google.com/blog/topics/threat-intelligence/china-nexus-exploiting-critical-ivanti-vulnerability
Suspected China-Nexus Threat Actor Actively Exploiting Critical Ivanti Connect Secure Vulnerability (CVE-2025-22457) | Google Cloud Blog

Tracking Adversaries: EvilCorp, the RansomHub affiliate

https://blog.bushidotoken.net/2025/04/tracking-adversaries-evilcorp-ransomhub.html
Tracking Adversaries: EvilCorp, the RansomHub affiliate

Recent GitHub supply chain attack traced to leaked SpotBugs token

https://www.bleepingcomputer.com/news/security/recent-github-supply-chain-attack-traced-to-leaked-spotbugs-token/
Recent GitHub supply chain attack traced to leaked SpotBugs token

BH2025_ReverseEngineeringHexagonISDB.pdf

https://zerodayengineering.com/research/slides/BH2025_ReverseEngineeringHexagonISDB.pdf
BH2025_ReverseEngineeringHexagonISDB.pdf

Legacy Stripe API Exploited to Validate Stolen Payment Cards in Web Skimmer Campaign

https://thehackernews.com/2025/04/legacy-stripe-api-exploited-to-validate.html
Legacy Stripe API Exploited to Validate Stolen Payment Cards in Web Skimmer Campaign

Ivanti patches Connect Secure zero-day exploited since mid-March

https://www.bleepingcomputer.com/news/security/ivanti-patches-connect-secure-zero-day-exploited-since-mid-march/
Ivanti patches Connect Secure zero-day exploited since mid-March

Oracle privately confirms Cloud breach to customers

https://www.bleepingcomputer.com/news/security/oracle-reportedly-confirms-oracle-cloud-breach-to-customers/
Oracle privately confirms Cloud breach to customers

Triada Malware Preloaded on Counterfeit Android Phones Infects 2,600+ Devices

https://thehackernews.com/2025/04/triada-malware-preloaded-on-counterfeit.html
Triada Malware Preloaded on Counterfeit Android Phones Infects 2,600+ Devices

Texas State Bar warns of data breach after INC ransomware claims attack

https://www.bleepingcomputer.com/news/security/texas-state-bar-warns-of-data-breach-after-inc-ransomware-claims-attack/
Texas State Bar warns of data breach after INC ransomware claims attack

CVE-2025-31334: WinRAR Flaw Enables Mark-of-the-Web Bypass and Arbitrary Code Execution

https://securityonline.info/cve-2025-31334-winrar-flaw-enables-mark-of-the-web-bypass-and-arbitrary-code-execution/
CVE-2025-31334: WinRAR Flaw Enables Mark-of-the-Web Bypass and Arbitrary Code Execution

Verizon Call Filter API flaw exposed customers' incoming call history

https://www.bleepingcomputer.com/news/security/verizon-call-filter-api-flaw-exposed-customers-incoming-call-history/
Verizon Call Filter API flaw exposed customers' incoming call history

Fast Flux: A National Security Threat | CISA

https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-093a
Fast Flux: A National Security Threat | CISA