Microsoft Patch Tuesday, July 2025 Edition

Editor note: Auto-formatted for readability. Microsoft today released updates to fix at least 137 security vulnerabilities in its Windows operating systems and supported software. None of the weaknesses addressed this month are known to be actively exploited, but 14 of the flaws earned Microsoft’s most-dire “critical” rating, meaning they could be exploited to seize control … Read more

UK Arrests Four in ‘Scattered Spider’ Ransom Group

Editor note: Auto-formatted for readability. Authorities in the United Kingdom this week arrested four people aged 17 to 20 in connection with recent data theft and extortion attacks against the retailers Marks & Spencer and Harrods, and the British food retailer Co-op Group. The breaches have been linked to a prolific but loosely-affiliated cybercrime group … Read more

Phishers Target Aviation Execs to Scam Customers

Editor note: Auto-formatted for readability. KrebsOnSecurity recently heard from a reader whose boss’s email account got phished and was used to trick one of the company’s customers into sending a large payment to scammers. An investigation into the attacker’s infrastructure points to a long-running Nigerian cybercrime ring that is actively targeting established companies in the … Read more

UK Age Verification Law: Online Safety Act Privacy Guide 2025

Editor note: Auto-formatted for readability. The UK's new age verification requirements take effect July 25th, 2025, fundamentally changing how you access online content. Under the Online Safety Act, platforms must verify users' ages before allowing access to adult content and other potentially harmful material. This affects everything from social media and gaming sites to adult … Read more

Microsoft Fix Targets Attacks on SharePoint Zero-Day

Editor note: Auto-formatted for readability. On Sunday, July 20, Microsoft Corp. issued an emergency security update for a vulnerability in SharePoint Server that is actively being exploited to compromise vulnerable organizations. The patch comes amid reports that malicious hackers have used the SharePoint flaw to breach U.S. federal and state agencies, universities, and energy companies. … Read more

Poor Passwords Tattle on AI Hiring Bot Maker Paradox.ai

Editor note: Auto-formatted for readability. Security researchers recently revealed that the personal information of millions of people who applied for jobs at McDonald’s was exposed after they guessed the password (“123456”) for the fast food chain’s account at Paradox.ai, a company that makes artificial intelligence based hiring chatbots used by many Fortune 500 firms. Paradox.ai … Read more

DOGE Denizen Marko Elez Leaked API Key for xAI

Editor note: Auto-formatted for readability. Marko Elez, a 25-year-old employee at Elon Musk’s Department of Government Efficiency (DOGE), has been granted access to sensitive databases at the U.S. Social Security Administration, the Treasury and Justice departments, and the Department of Homeland Security. So it should fill all Americans with a deep sense of confidence to … Read more

Wave of 150 crypto-draining extensions hits Firefox add-on store

Editor note: Auto-formatted for readability. A malicious campaign dubbed 'GreedyBear' has snuck onto the Mozilla add-ons store, targeting Firefox users with 150 malicious extensions and stealing an estimated $1,000,000 from unsuspecting victims. […] Our Top VPN Picks for 2025 ExpressVPN Best Overall Get Deal NordVPN Best Value Get Deal Surfshark Best for Families Get Deal … Read more

Massive IPTV piracy service with 28,000 channels taken offline

Editor note: Auto-formatted for readability. The Alliance for Creativity and Entertainment (ACE) announced the shutdown of Rare Breed TV, a major illegal IPTV service provider, after reaching a financial settlement with its operators. […] Our Top VPN Picks for 2025 ExpressVPN Best Overall Get Deal NordVPN Best Value Get Deal Surfshark Best for Families Get … Read more