Security

Most wanted hackers hide in plain sight – and there's nothing police can do

When we think of hackers, we usually picture shadowy figures operating beyond the reach of law enforcement agencies. The moment agencies get a whiff of who and where they are, they vanish into the shadows again.
Read more about Most wanted hackers hide in plain sight – and there's nothing police can do

BuddyBoss platform compromised, hundreds of websites already hacked

Cybernews has discovered an ongoing attack against live servers running BuddyBoss, a premium WordPress platform for e-learning and online communities. Hundreds of websites have been compromised, and thousands remain in danger. Admins are advised to take immediate action: disable updates, revert any recent changes, and assume compromise.
Read more about BuddyBoss platform compromised, hundreds of websites already hacked

Wrong kind of spark: Innova Energie ex-employee steals customer IBANs in insider breach

Dutch energy company Innova Energie has sent an email to affected customers to inform them of a recent data breach carried out by a former employee.
Read more about Wrong kind of spark: Innova Energie ex-employee steals customer IBANs in insider breach

CISA issues urgent Microsoft Intune security warning

The Cybersecurity and Infrastructure Security Agency (CISA) is strongly encouraging businesses and organizations to improve the security of their Microsoft environment, starting with Microsoft Intune.
Read more about CISA issues urgent Microsoft Intune security warning

Scam protection company Aura just got scammed: 900,000 records stolen

A company promising to protect you from scams just got scammed itself. Over 900,000 records are now floating on the dark web after attackers dropped an entire dataset.
Read more about Scam protection company Aura just got scammed: 900,000 records stolen

Companies now required to reveal AI use to get cyber insurance

Insurers in India are pressing companies to reveal how they use AI as part of stricter cyber insurance assessments. The move reflects growing concern that opaque AI deployments could introduce new security gaps and complicate risk modelling.
Read more about Companies now required to reveal AI use to get cyber insurance

China working on encryption that can't be cracked by tomorrow's computers

China will likely develop national standards for post-quantum cryptography in the next three years as it pours funds into research, according to a leading expert in the field.
Read more about China working on encryption that can't be cracked by tomorrow's computers

Telegram executes record number of takedowns, but cyber crooks still stand tall

Telegram bans and takedowns are now extremely massive and frequent. Pavel Durov, the CEO, is apparently trying to clean up his act, but cybercriminal ecosystems aren’t shrinking – they’re adapting. And quickly.
Read more about Telegram executes record number of takedowns, but cyber crooks still stand tall

Ubiquiti rushes out emergency fix for critical bug in UniFi Network Application

Ubiquiti has disclosed a maximum severity vulnerability in its UniFi Network Application, the software for managing WiFi access points, switches, and gateways. Hackers can break in without any credentials.
Read more about Ubiquiti rushes out emergency fix for critical bug in UniFi Network Application

Ten major tech companies ordered to hand over all communications with EU regulators

The US Committee on the Judiciary is demanding all communications from ten major American tech companies with so-called “foreign censors,” including the European Commission and EU Member States.
Read more about Ten major tech companies ordered to hand over all communications with EU regulators

Stryker cyberattack delays surgeries as CISA warns to harden Microsoft systems

Stryker said Wednesday that last week’s cyberattack has now delayed some surgeries, as CISA warns attackers are targeting Microsoft endpoint management systems used by US organizations.
Read more about Stryker cyberattack delays surgeries as CISA warns to harden Microsoft systems

Millions of Crime Stoppers tips exposed, challenging the anonymity promise

Hacktivists have leaked millions of anonymous tips submitted by Crime Stoppers informants. A massive 91.53GB dataset, dubbed BlueLeaks 2.0, has been made available to journalists and researchers by transparency collective DDoSecrets, which says tipsters were never anonymous.
Read more about Millions of Crime Stoppers tips exposed, challenging the anonymity promise

Hackers are doing their homework – and your VPN is first on the list, report warns

New findings from Hewlett Packard Enterprise (HPE) show that cybergangs like Akira are diligently doing their market research on VPN technologies to identify weak entry points before launching attacks.
Read more about Hackers are doing their homework – and your VPN is first on the list, report warns

Hackers turn GitHub’s favourite OpenWebUI AI servers into crypto mining zombie army

Popular open-source AI servers were secretly hijacked for more than a year and turned into a silent army of crypto mining machines.
Read more about Hackers turn GitHub’s favourite OpenWebUI AI servers into crypto mining zombie army

Japan to launch “hack back” powers this October

During a press briefing on Tuesday, Chief Cabinet Secretary Minoru Kihara said that the time was right to allow offensive cyber operations as the country faced its “most complicated national security environment” since the Second World War.
Read more about Japan to launch “hack back” powers this October

Hundreds of code repos falling like dominoes, infected by new wave of self-replicating malware

Hundreds of GitHub and npm repositories, and dozens of extensions for VS Code and other code editors, have been compromised in a new massive wave of the GlassWorm supply chain attack. Thousands of developers are at risk, with the latest victims being popular React Native packages with over 130,000 monthly downloads.
Read more about Hundreds of code repos falling like dominoes, infected by new wave of self-replicating malware

CISA flags actively exploited vulnerability of file transfer software used by US Air Force and Sony

The US Cybersecurity and Infrastructure Security Agency (CISA) has officially urged US federal agencies to secure their Wing FTP Server instances against an actively exploited vulnerability that could be chained in remote code execution (RCE) attacks.
Read more about CISA flags actively exploited vulnerability of file transfer software used by US Air Force and Sony

Chinese chatbots fooled into recommending nonexistent health gadget

A fake fitness tracker in China has revealed how easily chatbots can be misled by poisoned data. The incident raises fresh concerns about the reliability of chatbot outputs.
Read more about Chinese chatbots fooled into recommending nonexistent health gadget

Dutch telecom's bid to keep Chinese kit fails as court backs spy agency fears

Telecom provider Odido has lost an appeal regarding the replacement of network components from Huawei and ZTE in critical parts of its mobile network.
Read more about Dutch telecom's bid to keep Chinese kit fails as court backs spy agency fears

Russia found sharing drone technology, battlefield tactics with Iran to boost strike capabilities

Russia is now sharing satellite imagery, upgraded drone technology, and tactical guidance with Iran – likely improving Tehran’s ability to strike US and allied targets in the Middle East.
Read more about Russia found sharing drone technology, battlefield tactics with Iran to boost strike capabilities