North Korea’s Lazarus Group, a hacking group, has created fake US companies and job adverts to target crypto developers with malware with the aim to steal crypto funds for state operations, according to a report from Reuters. The hackers used LinkedIn and Upwork to appear legitimate, luring applicants to download malware-infected attachments.

Spring Security Vulnerability Let Attackers Determine Which Usernames are Valid
A vulnerability (CVE-2025-22234) in various Spring Security versions allows attackers to exploit timing attacks to determine valid usernames, jeopardizing user enumeration defenses. Affected versions include