Red Dot Security Roundup: The April Vulnerability Update

by

Check out the highlights from Red Dot Security, which rounds up key cyberthreats and vulnerabilities that could affect your IT environment. 

In April 2025, Red Dot Security— authored by Jan Broucinek, an Integris security services operations manager— provided several updates on vulnerabilities. Here is a roundup of some vulnerability news happenings that may affect your IT environment:  

Apache Parquet suffered a critical defect that received the highest rating of 10.0 on the Common Vulnerability Scoring System (CVSS). 

An Apache Tomcat vulnerability was discovered under active exploitation and enables remote code execution (RCE). An RCE allows a malicious attacker to control a computer, server, or other device without physically accessing it. 

In the Q1 2025 Security Trends Report, Broucinek provides a series of links to trends seen, such as the following: 

State-sponsored breaches. Consider the recent Bybit hack, which enabled malicious actors from North Korea’s Lazarus Group to steal $1.48 billion from Bybit’s Ethereum cypto wallet. 

Quishing. Also known as QR code phishing, quishing is a cyberattack in which users scan QR codes to lure them into visiting fake websites for the purpose of stealing credentials or downloading malicious software. 

Smishing. A practice of sending text messages, purportedly from reputable organizations, to induce consumers to reveal personally identifiable information, infect their systems with malware, and steal credentials and valuable information, such as passwords or credit card numbers. 

For these threat updates and more, check out Red Dot Security. 

Lauren Horwitz is a 18-year veteran in the digital publishing industry, with skills in writing, editing, assigning and developing editorial strategy for print and the web. She is accustomed to interviewing sources for news stories and is familiar with digital trends such as search engine optimization and cloud-based tools for editorial collaboration and data analytics to understand readership trends. Currently, she is editor in director of content marketing at Integris. Previously, Horwitz was a director of content at HUMAN Security and editor in chief at Dynatrace as well as a senior editor at Informa Tech, managing editor of Cisco.com, and a senior executive editor in the Business Applications and Architecture group at TechTarget. She started in technology as a senior editor at Cutter Consortium, an IT research firm; and an editor at the American Prospect, a political journal.

Keep reading

Paid IT Assessments: Why They’re Worth It for Community Banks

Paid IT Assessments: Why They’re Worth It for Community Banks

If you're in IT leadership at a community bank or credit union, you know how hard it is to find the right managed IT service partner to augment your operations. Finding an IT partner that understands your regulatory and operational challenges is hard enough. Then,...