cyber threats

Winsage
May 8, 2025
Several ransomware groups, including RansomEXX and Play, are exploiting a zero-day vulnerability in the Windows Common Log File System to elevate system privileges and deploy malware. This flaw was identified and patched during Microsoft's Patch Tuesday update in April 2024.
Winsage
May 6, 2025
Windows 10 will reach the end of support on October 14, 2025, leaving users vulnerable to cyber threats and software bugs. Microsoft has launched two new devices, the Surface Pro and Surface Laptop, to encourage users to upgrade. The Surface Pro features a 12-inch screen, a Snapdragon X Plus processor, and a 2-in-1 form factor, while the Surface Laptop has a 13-inch screen and offers a 23-hour battery life. Both devices include access to Copilot+ PC experiences and are available for purchase starting at £799.
AppWizard
May 6, 2025
Google will implement an update to its Play Integrity API in May 2025, affecting devices running Android 12 or earlier. This update coincides with the end of security updates for these older versions, potentially leading to app failures and increased vulnerability to cyber threats. Developers will need to revise their applications to comply with the new API standards, while users on outdated systems may face degraded performance or complete app failures. The urgency to upgrade to Android 13 or newer is emphasized for both users and developers.
Winsage
May 6, 2025
Microsoft is offering a 20% discount on all Windows 365 plans for new users to encourage Windows 10 users to transition before the operating system's end of life in October 2025. This discount applies for the duration of the Enterprise Agreement contract or the first year of the Windows 365 subscription, whichever is shorter. The end of life for Windows 10 is set for October 14, 2025, after which users will no longer receive free product or security updates. Approximately 20% of laptops running Windows 10 have hardware incompatible with Windows 11, which could lead to increased electronic waste if not addressed.
AppWizard
May 6, 2025
Google is set to introduce a security feature called "Intrusion Detection" in its upcoming Android 16, aimed at enhancing user security against threats. This feature, found in a beta version of the Google Play Services app, will log encrypted entries of essential device information to help users identify suspicious activity. "Intrusion Detection" is expected to be part of the Advanced Protection Program, which includes measures against malicious downloads and supports passkey sign-ins, moving away from traditional passwords. The feature's development has progressed, but it is unclear if it will launch with Android 16 or later. Android 16 Beta 4 was released to testers in mid-April, leading up to the anticipated full launch in May 2025.
Tech Optimizer
May 5, 2025
X Business, an e-commerce store specializing in handmade home décor, experienced a cybersecurity incident involving a malware strain called Chimera. The attack began during a routine update to their inventory management system and escalated within 12 hours, resulting in halted customer orders, locked employee accounts, and a crashed website. The attackers demanded a ransom of 0,000 in cryptocurrency, threatening to expose sensitive customer data. Chimera is an AI-driven malware that adapts its code to evade detection, targeting both Windows and macOS systems. It exploited a zero-day vulnerability in Windows' Print Spooler service and bypassed macOS security measures by forging code signatures. The malware used social engineering tactics to deceive employees into activating malicious payloads, leading to compromised systems and encrypted customer data. The recovery process took 48 hours, utilizing cybersecurity tools like CrowdStrike Falcon and SentinelOne Singularity to identify and isolate the malware. Data restoration was achieved through Acronis Cyber Protect and macOS Time Machine, while vulnerabilities were addressed with Qualys and emergency patch deployment via WSUS. The network security framework was improved using Cisco Umbrella and Zscaler Private Access to implement a Zero Trust architecture. The incident highlights the need for small enterprises to adopt proactive cybersecurity strategies, including a 3-2-1 backup approach, Zero Trust models, investment in AI-driven defense tools, and employee training to recognize social engineering attempts.
Tech Optimizer
May 5, 2025
VIPRE® Advanced Security received the Advanced+ award from AV-Comparatives in the March 2025 Malware Protection Test for its effectiveness against cyber threats. The test evaluated 19 security products using 10,030 malware samples on a Windows 11 system, focusing on both online and offline threats. VIPRE achieved a 98.7% detection rate in all scenarios, a 99.93% overall protection rate during execution testing, and had one of the lowest false positive counts among the products tested. VIPRE's security solutions are integrated into other Ziff Davis products, enhancing their protection capabilities. VIPRE is a subsidiary of Ziff Davis, Inc., specializing in cybersecurity solutions with over 25 years of experience.
Winsage
May 2, 2025
Microsoft is encouraging Windows 10 users to transition to Windows 11, promoting its Copilot+ PCs as a solution for those whose devices do not qualify for the upgrade. Copilot+ PCs feature AI tools like Recall, which captures and indexes screenshots for easy searching, and offer performance improvements, claiming to be up to five times faster than devices that are five years old. However, there are concerns about privacy and security related to Recall. Support for Windows 10 will end on October 14, 2025, after which it will no longer receive security updates. Options for Windows 10 users include upgrading to Windows 11 if eligible, purchasing a Copilot+ PC, paying for extended support, switching to Linux, or remaining on Windows 10 with associated risks.
Search