Security
New naming convention for threat actors unveiled: they're sh*ts
The cybersecurity community wants to radically overhaul how the malicious threat actors are named. Calling them various types of “shits” is supposed to strip away the perceived glamour of cybercriminal life and deter youth crime.
Read more about New naming convention for threat actors unveiled: they're sh*ts
Microsoft prompts AI to look for flaws in bootloaders, finds twenty
Widely used open-source bootloaders, including GRUB2 for Linux, U-boot, and Barebox, are affected by dangerous flaws that enable attackers to run arbitrary code and take over systems. Microsoft said it used AI to unveil the flaws, saving a week’s worth of time.
Read more about Microsoft prompts AI to look for flaws in bootloaders, finds twenty
Gig platform app Yoojo leaks millions of user files
The service marketplace platform Yoojo has exposed over 14 million files, including passports and communication screenshots.
Read more about Gig platform app Yoojo leaks millions of user files
Royal Mail customer data stolen in massive attack, hackers claim
Attackers say they breached the British postal service last month, scooping a whopping 144 gigabytes of data, including confidential documents and customer names and addresses.
Read more about Royal Mail customer data stolen in massive attack, hackers claim
Moscow Metro targeted in likely retaliatory cyberattack
The Moscow subway’s website and mobile app experienced disruptions on Monday, with many users saying that they couldn’t access their personal accounts a day later. A likely retaliatory cyberattack is suspected after Russian-aligned threat actors hacked Ukrainian Railways.
Read more about Moscow Metro targeted in likely retaliatory cyberattack
Researchers are warning Android users about Crocodilus banking Trojan
New Android malware uses advanced techniques for device takeover and data theft.
Read more about Researchers are warning Android users about Crocodilus banking Trojan
Hackers broke Google’s AI. Here’s how they did it
Hackers cracked Google’s AI and got rewarded.
Read more about Hackers broke Google’s AI. Here’s how they did it
65% of the 100 largest US hospitals and health systems have had a recent data breach
Cybernews research team analyzed the 100 largest US hospitals and health systems websites and evaluated their cybersecurity posture.
Read more about 65% of the 100 largest US hospitals and health systems have had a recent data breach
A fake Zoom app is spreading – and it’s harvesting your data
A fake Zoom installer is making the rounds, luring unsuspecting users into downloading malware which quietly takes over their systems.
Read more about A fake Zoom app is spreading – and it’s harvesting your data
Was Check Point hacked? Security firm calls ransom demands old news
Hackers claim they’ve obtained a “sensitive dataset” from the Tel Aviv-based cybersecurity company Check Point Software. They want over $400,000 for what the firm calls an “old, known, and very pinpointed event.”
Read more about Was Check Point hacked? Security firm calls ransom demands old news
FBI investigates cyberattack at Oracle, patient records breached
The Federal Bureau of Investigation (FBI) is probing the cyberattack at Oracle as the hackers broke into the cloud computing company's computer systems and stole patient data, Bloomberg News reported on Friday, citing a person familiar with the matter.
Read more about FBI investigates cyberattack at Oracle, patient records breached
Thousands of Australians just got their IDs and bank details exposed
Australia’s largest online marketplace for car loans has exposed thousands of driver's licenses and partial credit card details.
Read more about Thousands of Australians just got their IDs and bank details exposed
Browser-native ransomware may be the next billion-dollar threat
We might soon see a large-scale ransomware campaign without hackers even touching a device, a report warns.
Read more about Browser-native ransomware may be the next billion-dollar threat
If someone who sounds like Cristiano Ronaldo calls you, hang up
Cybercriminals are using artificial intelligence (AI) to clone the voices of these famous basketball players, football players, and other sportspeople.
Read more about If someone who sounds like Cristiano Ronaldo calls you, hang up
Hackers are after your router and other network devices, Eclypsium warns
Eclypsium, a supply chain security firm, has seen a sharp spike in attacks against network infrastructure. Juniper routers are at the center of the two major campaigns in 2025.
Read more about Hackers are after your router and other network devices, Eclypsium warns
Critical sandbox escape flaw affects Firefox, Tor on Windows
Following reports on hackers exploiting a dangerous zero-day on Chrome, Mozilla has released a similar fix for its browser. Tor urges users to update "immediately."
Read more about Critical sandbox escape flaw affects Firefox, Tor on Windows
T-Mobile takes a $33 million hit
T-Mobile has to pay $33 million in a case filed in the United States over crypto theft via SIM swapping.
Read more about T-Mobile takes a $33 million hit
French Department of Education sends phishing mail to 2.5 million students
Both schools and students in France are regularly targeted by hackers via their digital workspaces.
Read more about French Department of Education sends phishing mail to 2.5 million students
More "unclassified" data spills under Waltz watch: US officials who use Venmo exposed
Mike Waltz, the United States national security adviser, left his Venmo friend list public, leaving sensitive information open for bad actors to exploit.
Read more about More "unclassified" data spills under Waltz watch: US officials who use Venmo exposed
Privacy disaster as LGBTQ+ and BDSM dating apps leak private photos
BDSM, LGBTQ+, and sugar dating apps have been found exposing users' private images, with some of them even leaking photos shared in private messages.
Read more about Privacy disaster as LGBTQ+ and BDSM dating apps leak private photos