{"id":19065,"date":"2025-04-14T06:39:46","date_gmt":"2025-04-14T04:39:46","guid":{"rendered":"https:\/\/kordon.app\/?p=19065"},"modified":"2025-04-15T08:57:38","modified_gmt":"2025-04-15T06:57:38","slug":"security-news-roundup-from-last-week-that-we-found-interesting-14-04-2025","status":"publish","type":"post","link":"https:\/\/kordon.app\/et\/security-news-roundup-from-last-week-that-we-found-interesting-14-04-2025\/","title":{"rendered":"Security News Roundup From Last Week That We Found Interesting &#8211; 14.04.2025"},"content":{"rendered":"<p>Here are a few news stories from last week we found interesting and think are worth your attention.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Serious Security Issues Found in Perplexity AI&#8217;s Chatbot Android App (11.04.2025)<\/strong><\/h4>\n\n\n\n<p>Security researchers have uncovered serious vulnerabilities in Perplexity AI&#8217;s Android app. Notably, API keys were easily accessible, potentially allowing attackers to impersonate users and access their conversations. Oh, 2 months ago same issues were discovered in Deepseeks Android app.&nbsp;<\/p>\n\n\n\n<p><em>This is really bad, you should not use it on Android.&nbsp;<\/em><\/p>\n\n\n\n<p><strong>Read more: <\/strong><a href=\"https:\/\/www.darkreading.com\/application-security\/11-bugs-found-perplexity-chatbots-android-app\">https:\/\/www.darkreading.com\/application-security\/11-bugs-found-perplexity-chatbots-android-app<\/a><\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Attackers Are Now Into \u2018Spam bombing\u2019 as Part of Their Social Engineering Campaign (10.04.2025)<\/strong><\/h4>\n\n\n\n<p>Essentially, the target gets an insane amount of harmless looking e-mails (like hundreds within 5 minutes) sent from a reputable marketing source like Mailchimp. Imagine real looking newsletters, signups, promotions etc. everything that the automatic checks would let through. And then \u201ca helpful IT person\u201d steps in to help the target resolve the issue and steal some credentials and breach along the way.<\/p>\n\n\n\n<p><em>Something to include as an example in your next security training.&nbsp;<\/em><\/p>\n\n\n\n<p><strong>Read more: <\/strong><a href=\"https:\/\/www.darktrace.com\/blog\/email-bombing-exposed-darktraces-email-defense-in-action\">https:\/\/www.darktrace.com\/blog\/email-bombing-exposed-darktraces-email-defense-in-action<\/a> or here.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Ransomware attack cost IKEA operator in Eastern Europe $23 million and they didn\u2019t even pay (11.04.2025)<\/strong><\/h4>\n\n\n\n<p>Initial incident happened in December 2024, it has taken months to recover, repell new attacks and coordinating with external cyber security service firm.&nbsp;<\/p>\n\n\n\n<p><em>$23 million is bad but can you imagine coordinating with data protection authorities in 4 countries.&nbsp;<\/em><\/p>\n\n\n\n<p><strong>Read more: <\/strong><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/ransomware-attack-cost-ikea-operator-in-eastern-europe-23-million\">https:\/\/www.bleepingcomputer.com\/news\/security\/ransomware-attack-cost-ikea-operator-in-eastern-europe-23-million<\/a><\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Google announces Sec-Gemini v1, a new experimental cybersecurity model (04.04.2025)<\/strong><\/h4>\n\n\n\n<p>Sec-Gemini v1 is an AI model that uses real-time threat intel to boost cybersecurity workflows and shift the balance towards defenders. It\u2019s supposedly much better than the other models but you can\u2019t use it yet, only available for research partners for now.<\/p>\n\n\n\n<p><strong>Read more: <\/strong><a href=\"https:\/\/security.googleblog.com\/2025\/04\/google-launches-sec-gemini-v1-new.html\">https:\/\/security.googleblog.com\/2025\/04\/google-launches-sec-gemini-v1-new.html<\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>Here are a few news stories from first week of April we found interesting and think are worth your attention.<\/p>","protected":false},"author":1,"featured_media":19067,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[32,26],"tags":[],"class_list":["post-19065","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","category-blog"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/kordon.app\/et\/wp-json\/wp\/v2\/posts\/19065","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/kordon.app\/et\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/kordon.app\/et\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/kordon.app\/et\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/kordon.app\/et\/wp-json\/wp\/v2\/comments?post=19065"}],"version-history":[{"count":8,"href":"https:\/\/kordon.app\/et\/wp-json\/wp\/v2\/posts\/19065\/revisions"}],"predecessor-version":[{"id":19090,"href":"https:\/\/kordon.app\/et\/wp-json\/wp\/v2\/posts\/19065\/revisions\/19090"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/kordon.app\/et\/wp-json\/wp\/v2\/media\/19067"}],"wp:attachment":[{"href":"https:\/\/kordon.app\/et\/wp-json\/wp\/v2\/media?parent=19065"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/kordon.app\/et\/wp-json\/wp\/v2\/categories?post=19065"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/kordon.app\/et\/wp-json\/wp\/v2\/tags?post=19065"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}