Security

NordVPN data breach scammer claims chip parts maker ASML, gets caught lying again

The same pseudo-hacker who recently took credit for a fake NordVPN data breach now claims to have penetrated the Dutch chip component behemoth ASML. However, the Cybernews research team believes the attacker is once again full of hot air.
Read more about NordVPN data breach scammer claims chip parts maker ASML, gets caught lying again

British school closes doors after cyberattack

A school in Nuneaton has temporarily closed its doors due to a cyberattack. As a precautionary measure to prevent further damage, the school's IT systems have been taken completely offline.
Read more about British school closes doors after cyberattack

Attackers could cash out your gift card after popular platform left them passwordless

A secondhand electronics marketplace has accidentally streamed its users’ login codes and gift card credits to the open internet.
Read more about Attackers could cash out your gift card after popular platform left them passwordless

When workflows go rogue: critical n8n vulnerability opens door to system commands

A critical vulnerability has been discovered in n8n, a popular open-source workflow automation platform, enabling authenticated attackers to execute arbitrary commands on host systems.
Read more about When workflows go rogue: critical n8n vulnerability opens door to system commands

Used Booking.com lately? You might have accidentally installed malware

Russian hackers have crafted a new “ClickFix” social engineering campaign targeting Booking.com users, tricking victims into installing malware using fake CAPTCHAs and a simulated Blue Screen of Death.
Read more about Used Booking.com lately? You might have accidentally installed malware

If Meta earns billions from scammy ads, maybe it’s time to mandate adblockers?

Malvertising has become such a prevalent threat that hackers are now suggesting cyber insurance companies should mandate adblockers. The provocative idea was raised at the 39th Chaos Communication Congress in Germany. However, not everyone agrees.
Read more about If Meta earns billions from scammy ads, maybe it’s time to mandate adblockers?

Stolen passwords and no MFA led to 50 major recent breaches

A single password stolen from an employee after an infostealer infection led to 50 recent breaches in major global companies. One threat actor has built a reputation for breaking into cloud storage platforms that lack multi-factor authentication (MFA), exploiting even years-old passwords.
Read more about Stolen passwords and no MFA led to 50 major recent breaches

Python-based VVS Stealer sneaks off with your Discord data

A new Python-based information stealer called VVS Stealer is capable of harvesting Discord credentials and tokens, cybersecurity researchers say. In fact, the stealer seems to have been specifically designed to steal a victim’s Discord data.
Read more about Python-based VVS Stealer sneaks off with your Discord data

Attackers claim 1M+ customer records stolen from top US internet provider

The Brightspeed data breach involves personal customer data, including full names, home addresses, and limited payment card details, according to claims by the cybercriminals behind the alleged attack.
Read more about Attackers claim 1M+ customer records stolen from top US internet provider

Your Hinge app could be running a malware campaign: here’s how

A security researcher has demonstrated how a mainstream dating app can covertly serve as malware infrastructure, concealing commands within profile photos and prompts.
Read more about Your Hinge app could be running a malware campaign: here’s how

Hacking trio reemerges as a threat, but suffers setback over a honeypot

Scattered Lapsus$ Hunters (SLH) hacking collective, known for including minors and targeting major corporations, has reemerged with expanded recruitment and activity, security researchers warn. However, the New Year began with a stumble: the gang fell for a honeypot.
Read more about Hacking trio reemerges as a threat, but suffers setback over a honeypot

Nord Security confirms systems are secure after fake breach allegations

NordVPN has released a statement confirming that all systems and data remain secure, following fake claims by a threat actor of an alleged breach.
Read more about Nord Security confirms systems are secure after fake breach allegations

Russia-linked hackers nab highly sensitive Bolttech data, demand ransom

Everest Ransomware claims to have intercepted around 186GB of data from Bolttech, a global insurance infrastructure platform. The threat actor is demanding a ransom payment from the company.
Read more about Russia-linked hackers nab highly sensitive Bolttech data, demand ransom

China averaged 2.6 million cyberattacks on Taiwan daily

Chinese cyberattacks on Taiwan's key infrastructure from hospitals to banks rose 6% in 2025 from the previous year to an average of 2.63 million attacks a day, the island's National Security Bureau said, adding some were synchronised with military drills in "hybrid threats" to paralyse the island.
Read more about China averaged 2.6 million cyberattacks on Taiwan daily

France wants to ban social media for children under 15

The French government has introduced a bill aimed at banning children under the age of 15 from using social media.
Read more about France wants to ban social media for children under 15

Knownsec leak unmasks secret cyberweapons and role in China’s state-linked spying

A leak from Knownsec, a major Chinese cybersecurity firm, exposes how the firm operated far beyond the role of a conventional defense vendor. It combined the development of cyberweapons with large-scale intelligence collection to support state-linked cyber operations.
Read more about Knownsec leak unmasks secret cyberweapons and role in China’s state-linked spying

US lifts sanctions on three linked to Predator spyware

The US has lifted sanctions on three people who have previously been accused of being involved in developing and distributing Predator, a powerful spyware tool alleged to have been used against journalists, politicians, dissidents, and US officials.
Read more about US lifts sanctions on three linked to Predator spyware

New York-based fashion maker claimed by Russia-linked hackers

Esquire Brands, a maker of kids' footwear operating several popular brands, has been targeted by a prominent ransomware gang, which claims to have stolen confidential data.
Read more about New York-based fashion maker claimed by Russia-linked hackers

Wavlink routers and other IoT devices hit by React2Shell attacks

Security researchers say a botnet called RondoDox has spent nine straight months targeting Internet of Things (IoT) devices and web servers, hitting popular platforms like WordPress, Drupal, and Struts2, alongside consumer-grade IoT devices such as Wavlink routers.
Read more about Wavlink routers and other IoT devices hit by React2Shell attacks

“Tinder for Nazis” hit by 100GB data leak, thousands of users exposed

An investigative journalist has infiltrated the white supremacist dating website WhiteDate and exfiltrated over 8,000 profiles and 100GB of data. Photos and other sensitive details have been made public, and the full “WhiteLeaks” data is available to journalists and researchers on DDoSecrets.
Read more about “Tinder for Nazis” hit by 100GB data leak, thousands of users exposed