World Password Day, observed on the first Thursday of May, is a global reminder of just how critical strong password habits are in today’s digital world. With cyber threats continuing to evolve, this day encourages everyone, from individuals to large organizations, to take a closer look at how they protect their online identities. To mark the occasion, several cybersecurity experts shared their insights on the current state of password security, the challenges we face, and what steps we can all take to stay safer online. Tony Ball, President, Payment & Identity, at Entrust For decades, passwords have been the weak…
Kirsten Doyle
Aqua Security’s Team Nautilus has discovered a critical vulnerability in six popular AWS services that could allow bad actors to gain control over cloud environments. The flaw, rooted in how AWS automatically creates default IAM roles in new regions, could be exploited without user interaction. It could endanger organizations using Glue, SageMaker, EMR, CloudFormation, Redshift, and CodeBuild. The attack vector, termed “Shadow Role”, takes advantage of AWS’s behavior of silently creating IAM roles with predefined trust policies when specific services are used in a new region. These roles are designed to allow specific AWS services to assume them on behalf…
Seventy-five zero-day vulnerabilities were actively exploited in 2024 — down from 98 in 2023, but still higher than the 63 reported in 2022. These vulnerabilities were split between consumer-facing platforms like browsers and mobile devices, and enterprise-level technologies such as security software and networking appliances. This was one of the findings of Google Threat Intelligence Group’s (GTIG’s) annual report on zero-day vulnerabilities exploited in the wild. It revealed an interesting shift in attacker priorities despite a drop in total cases. “While individual year counts have fluctuated, the average trendline indicates that the rate of zero-day exploitation continues to grow at…
A trusted Uyghur-language text editor has been weaponized to target exiled Uyghur activists, says a new investigation by Citizen Lab. In this campaign, threat actors are exploiting culturally significant software to conduct digital surveillance against the Uyghur diaspora, a community already under intense pressure from the Chinese government. This incident is the latest in a series of digital attacks against Uyghur, Tibetan, and other diaspora communities. For years, Chinese state-aligned actors have used malware, phishing, and spyware, often hidden in culturally relevant apps, to monitor, intimidate, and silence critics abroad. Spearphishing Attack Targets World Uyghur Congress The attack began with…
An advanced persistent threat (APT) group dubbed Earth Kurma is behind a stealthy, multi-year cyber-espionage campaign targeting government and telecommunications organizations across Southeast Asia. According to Trend Micro researchers Nick Dai and Sunny Lu, the campaign has been active since at least 2020. Sophisticated Toolsets and Cloud Abuse Earth Kurma has shown a high level of operational maturity, blending advanced malware with living-off-the-land binaries and trusted infrastructure. It uses a custom suite of malware, including TESDAT, DMLOADER, SIMPOBOXSPY, and KRNRAT, which facilitate stealthy data collection, persistence, and communication with command-and-control (C&C) servers. The malicious actors leverage public cloud platforms to…
Verizon has unveiled its 2025 Data Breach Investigations Report (DBIR), which revealed a dramatic increase in cyberattacks. The report showed that third-party breaches have doubled to 30%. Also, exploitation of vulnerabilities has increased by 34%. This creates a serious threat for businesses worldwide. The latest report shows a steep rise in zero-day exploits and ransomware—bad news for the cybersecurity landscape. Human error, weak credentials, and the abuse of GenAI continues to be major vulnerabilities. Unfortunately, bad actors only grow more cunning. The report analyzed over 22,000 security incidents, including 12,195 confirmed data breaches. It discovered that credential abuse (22%) and the exploitation of vulnerabilities (20%) remain the leading initial attack vectors,…
A new Android spyware campaign is targeting Russian military personnel by hiding malicious code inside a popular mapping app, says cybersecurity firm Doctor Web. The spyware, identified as Android.Spy.1292.origin, is embedded in a modified version of the Alpine Quest mapping application. It is being distributed through unofficial app sources, including a Russian Android app catalog and a fake Telegram channel posing as the app’s developer. Alpine Quest is widely used for topographic mapping in both online and offline modes. While it’s popular among outdoor enthusiasts, it’s often used by Russian soldiers in active combat zones, too. The attackers appear to…
Proving there are no depths they won’t plum, cybercriminals have begun exploiting the news of Pope Francis’s passing in a range of malicious campaigns. This tactic has been popular for some time. Bad actors are the first to jump on the bandwagon during major world events—from global disasters to the deaths of famous people. From disinformation and scams, to malware, there is no tragedy they won’t take advantage of. According to Check Point Research, “They typically begin with disinformation campaigns on social media platforms like Instagram, TikTok, or Facebook, uploading fake images generated by AI.” These campaigns aim to grab…
A critical security vulnerability has been discovered in the Commvault Command Center, that could enable malicious actors to remotely to execute arbitrary code without authentication,” Commvault said in an advisory. “This vulnerability could lead to a complete compromise of the Command Center environment. Fortunately, other installations within the same system are not affected by this vulnerability,” the advisory added. The vulnerability, tracked as CVE-2025-34028, carries a CVSS score of 10.0 – the highest possible. A researcher from watchTowr Labs, Sonny Macdonald, is credited with discovering and reporting the flaw on 7 April. He said it could be exploited to achieve…
At this year’s RSA Conference, the theme “Many Voices. One Community” is a reminder that cybersecurity isn’t just about technology—it’s about people. In a field driven by constant innovation and rapid response, the strength of our defenses often depends on the breadth of perspectives behind them. We asked our panel of cybersecurity experts two key questions: Is the community doing enough to elevate individual voices and welcome diverse perspectives? And how can we create more space for those who aren’t always heard? Their candid responses highlight both the progress we’ve made—and the opportunities still ahead. Identifying Gaps in Security Cybersecurity…
