<img src="https://secure.ruth8badb.com/159098.png" alt="" style="display:none;">

IT Security Newsletter - 6-4-2025

SHARE

Breaches

Victoria's Secret Says It Will Postpone Earnings Report After Recent Security Breach

Victoria's Secret is postponing the release of its quarterly earnings following a security breach that disrupted the popular lingerie brand's corporate operations and led it to take down its U.S. shopping site for several days last week. In a Tuesday update, Victoria's Secret said it first detected a "security incident involving its information technology systems" on May 24 - and immediately turned to response protocols in effects "to contain and eradicate unauthorized network access." READ MORE...

Trends

"Godfather" of AI calls out latest models for lying to users

One of the "godfathers" of artificial intelligence has attacked a multibillion-dollar race to develop the cutting-edge technology, saying the latest models are displaying dangerous characteristics such as lying to users. Yoshua Bengio, a Canadian academic whose work has informed techniques used by top AI groups such as OpenAI and Google, issued his warning in an interview with the Financial Times. READ MORE...

Software Updates

Google quietly pushes emergency fix for Chrome 0-day as exploit runs wild

Google revealed Monday that it had quietly deployed a configuration change last week to block active exploitation of a Chrome zero-day. Google Threat Analysis Group (TAG) team members Clement Lecigne and Benoît Sevens spotted the high-severity bug, tracked as CVE-2025-5419, on May 27. It's an out-of-bounds read and write vulnerability in Chrome's V8 JavaScript engine that could allow a remote attacker to corrupt memory and potentially hijack execution via a booby-trapped HTML page. READ MORE...

Information Security

35,000 Solar Power Systems Exposed to Internet

An analysis conducted recently by researchers at cybersecurity firm Forescout showed that roughly 35,000 solar power systems are exposed to the internet and potentially vulnerable to remote attacks. Forescout has found more than 90 vulnerabilities in solar power products over the past years, including 46 flaws in Sungrow, Growatt and SMA Solar Technology products that were disclosed earlier this year as part of a project dubbed 'SUN:DOWN'. READ MORE...


You say Cozy Bear, I say Midnight Blizzard, Voodoo Bear, APT29 …

Microsoft and CrowdStrike made a lot of noise on Monday about teaming up with other threat-intel outfits to "bring clarity to threat-actor naming." It's a great idea that would benefit network defenders tasked with keeping track of the 200-plus nation-state, financially motivated, and hacktivist crews that all the major security vendors and government agencies call by different names. Take Cozy Bear, also dubbed Midnight Blizzard, APT29, or UNC2452, depending on who you ask. READ MORE...

Exploits/Vulnerabilities

CISA warns of ConnectWise ScreenConnect bug exploited in attacks

CISA is alerting federal agencies in the U.S. of hackers exploiting a recently patched ScreenConnect vulnerability that could lead to executing remote code on the server. The agency is warning that four other security problems affecting ASUS routers and the Craft content management system (CMS) are also actively exploited. On April 24, ConnectWise addressed the security issue, tracked as CVE-2025-3935, stating that the vulnerability could be exploited for a ViewState code injection attack. READ MORE...


Hewlett Packard Enterprise warns of critical StoreOnce auth bypass

Hewlett Packard Enterprise (HPE) has issued a security bulletin to warn about eight vulnerabilities impacting StoreOnce, its disk-based backup and deduplication solution. Among the flaws fixed this time is a critical severity (CVSS v3.1 score: 9.8) authentication bypass vulnerability tracked under CVE-2025-37093, three remote code execution bugs, two directory traversal problems, and a server-side request forgery issue. READ MORE...

On This Date

  • ...in 1783, the Montgolfier brothers demonstrate their first hot-air balloon at the palace in Versailles, France.
  • ...in 1896, Henry Ford completes the Ford Quadricycle, the very first internal-combustion powered automobile.
  • ...in 1919, the 19th Amendment is passed by Congress, guaranteeing women's right to vote.
  • ...in 1942, the Battle of Midway begins.