Security

Hackers target Mac users with fake CleanMyMac, empty crypto wallets

Hackers are running a convincing malware campaign targeting Mac owners, stealing money and data. They are using a fraudulent CleanMyMac website and likely buying ads to reach users searching for the popular cleaner utility.
Read more about Hackers target Mac users with fake CleanMyMac, empty crypto wallets

“US power provider attacked,” claim Russian cyber gang

A Russia-linked ransomware gang has claimed it breached a US electric cooperative, raising fresh concerns that cybercriminals are once again circling critical power infrastructure.
Read more about “US power provider attacked,” claim Russian cyber gang

These Chrome AI assistants secretly harvested ChatGPT chats

Nearly 900,000 people installed AI browser assistants on Chrome and Edge that secretly harvested their chat conversations and browsing activity.
Read more about These Chrome AI assistants secretly harvested ChatGPT chats

Popular AI coding tool Blackbox AI, with 5M downloads, grants root access to hackers

Blackbox AI, one of the most popular AI coding and development assistants for VS Code, downloaded 5 million times, was hacked to give attackers remote access. The security researcher behind the attack asked the agent to apologize – it gave him root.
Read more about Popular AI coding tool Blackbox AI, with 5M downloads, grants root access to hackers

Cybercrooks using ICE as cover to steal information in phishing campaign

Companies hurrying to disable ICE-supporting messages might fall into a phishing trap.
Read more about Cybercrooks using ICE as cover to steal information in phishing campaign

Iran-linked Seedworm hackers found inside US bank, airline, tech networks

Iranian state-backed Seedworm hackers lurk inside US-Israeli critical networks – signaling a possible cyber campaign targeting US banking, aviation, and tech sectors.
Read more about Iran-linked Seedworm hackers found inside US bank, airline, tech networks

Windows user? Don’t get tricked by these GitHub tools spreading malware

Fake tools on GitHub are being used to raid Chrome, Microsoft Edge, and Brave browsers, to wipe your crypto wallets.
Read more about Windows user? Don’t get tricked by these GitHub tools spreading malware

Any browser extension can secretly install malware, researchers demonstrate

A handy price tracker, ad blocker, AI chatbot, or any other extension can turn malicious overnight and secretly install malware. Security researchers have demonstrated that extensions can modify every downloaded file without requiring permissions, and neither Google nor Mozilla sees a problem.
Read more about Any browser extension can secretly install malware, researchers demonstrate

Drone attacks expose vulnerability of cloud infrastructure in Gulf conflict

In the wake of Amazon's revelation that Iran struck three of its facilities in the UAE, and as Iran sees commercial cloud regions as high-leverage nodes for critical services, we might wonder what this all means going forward
Read more about Drone attacks expose vulnerability of cloud infrastructure in Gulf conflict

Developer finds his website banned by Google, spends weeks getting it delisted by security firms

One software engineer found that his side project website was mistakenly banned by Google – instantly, 10 other security firms flagged it, too. He spent weeks getting it delisted, raising concerns about one company’s control over the web.
Read more about Developer finds his website banned by Google, spends weeks getting it delisted by security firms

US and EU police seize LeakBase, a site where crooks share stolen passwords and hacking tools

European and US law enforcement have shut down LeakBase’s database, which prosecutors called “one of the world’s largest online forums for cybercriminals” for sharing stolen passwords and hacking tools.
Read more about US and EU police seize LeakBase, a site where crooks share stolen passwords and hacking tools

This paint company is dripping stolen information, hackers claim

The US branch of AkzoNobel, a multinational paint and coatings company from the Netherlands, has been attacked by hackers. They managed to steal approximately 170,000 files from the company.
Read more about This paint company is dripping stolen information, hackers claim

Claude AI shows just how fast technology is outpacing rules and ethics

The Claude saga that’s unfolding as we speak isn’t just about a popular AI chatbot going down. It’s about the awkward, unexpected place artificial intelligence has carved out for itself in the real world and the dramatic contrasts it highlights.
Read more about Claude AI shows just how fast technology is outpacing rules and ethics

China-linked hackers hide cyber spy operation inside Windows services and Google Drive

A cyber espionage campaign linked to the China-nexus hackers, tracked as Silver Dragon, has been uncovered, hiding inside legitimate Windows services and using Google Drive as a covert communications channel.
Read more about China-linked hackers hide cyber spy operation inside Windows services and Google Drive

AI agents are too easy to fool, with websites now littered with hidden “system override” commands

Don’t act surprised when your AI agent starts printing millions of pages of cabbages, deletes an entire system partition, or sends your life savings to fraudsters – they’re just being helpful. Security researchers have warned that many websites now sprinkle poison for AI, leaving malicious instructions for well-meaning agents to act upon. Here are 12 real-life examples.
Read more about AI agents are too easy to fool, with websites now littered with hidden “system override” commands

DoorDash, Walmart data manager breached, with millions of records exposed, attackers claim

Woflow, an AI-driven merchant data platform, has been claimed by ShinyHunters, the notorious data extortion group.
Read more about DoorDash, Walmart data manager breached, with millions of records exposed, attackers claim

Microsoft warning: attackers are abusing Google logins to spread malware

Hackers are hijacking trusted OAuth login flows to redirect victims to phishing traps, where they unknowingly download malware.
Read more about Microsoft warning: attackers are abusing Google logins to spread malware

Mass iPhone attack: government-grade iOS hacking tool falls into the hands of cybercriminals

iPhones are under mass attack, with Chinese scammers, Russian spies, and other cybercriminals using government-grade iOS exploit kits. Security experts suspect that the highly sophisticated spyware escaped the US government and are warning iOS users to update their devices to the latest version.
Read more about Mass iPhone attack: government-grade iOS hacking tool falls into the hands of cybercriminals

TikTok skips DM encryption, leaving privacy experts concerned

Unlike most of its rivals, TikTok is not planning to introduce end-to-end encryption on its direct messages. The platform says it wants to protect users, especially young people, from harm, but critics are already naming one caveat after another.
Read more about TikTok skips DM encryption, leaving privacy experts concerned

The Booking.com scam crisis – how a simple message revealed a sophisticated fraud

I was preparing for a long‑awaited weekend in Vilnius when my phone vibrated. The WhatsApp message came from someone calling...
Read more about The Booking.com scam crisis – how a simple message revealed a sophisticated fraud