Security
Wavlink routers and other IoT devices hit by React2Shell attacks
Security researchers say a botnet called RondoDox has spent nine straight months targeting Internet of Things (IoT) devices and web servers, hitting popular platforms like WordPress, Drupal, and Struts2, alongside consumer-grade IoT devices such as Wavlink routers.
Read more about Wavlink routers and other IoT devices hit by React2Shell attacks
“Tinder for Nazis” hit by 100GB data leak, thousands of users exposed
An investigative journalist has infiltrated the white supremacist dating website WhiteDate and exfiltrated over 8,000 profiles and 100GB of data. Photos and other sensitive details have been made public, and the full “WhiteLeaks” data is available to journalists and researchers on DDoSecrets.
Read more about “Tinder for Nazis” hit by 100GB data leak, thousands of users exposed
European Space Agency confirms data breach impacted external servers
The Paris-headquartered space exploration agency has confirmed that attackers may have breached a “very small number” of its external servers.
Read more about European Space Agency confirms data breach impacted external servers
2.2M Chrome, Firefox, Edge users impacted by meeting-stealing malware
In a short period, researchers from Koi Security have uncovered three malicious browser extension campaigns that have impacted millions of browser users worldwide. The same Chinese threat actor is thought to be behind the campaigns.
Read more about 2.2M Chrome, Firefox, Edge users impacted by meeting-stealing malware
British hacker gets rare Australian visa after hacking the government website
Identifying a critical flaw in the Australian government system has earned a British ethical hacker one of the hardest-to-get types of visa.
Read more about British hacker gets rare Australian visa after hacking the government website
When customers take the stand: Cybersecurity faces a new kind of trial
Researchers estimate the cyber incident at Jaguar Land Rover could cost around £1.9 billion, making it the costliest cyberattack ever recorded in the UK. However, these costs may seem insignificant compared to those of future breaches.
Read more about When customers take the stand: Cybersecurity faces a new kind of trial
Chinese state hackers plant malware inside Windows
Chinese state hackers are infiltrating operating systems to bypass antivirus detection.
Read more about Chinese state hackers plant malware inside Windows
2025 was a breakout year for zero-day exploits
Zero-day exploits were once niche threats reserved for high-stakes espionage. However, that idea no longer holds true, and attackers are now increasingly able to weaponize them with relative ease to break into corporate networks.
Read more about 2025 was a breakout year for zero-day exploits
VPN downloads surge in 2025: US drives volume while Middle East leads in adoption
VPN application downloads are rising again after a post-pandemic slowdown, with growth concentrated in large markets such as the United...
Read more about VPN downloads surge in 2025: US drives volume while Middle East leads in adoption
Ka-ching! Legit browser extensions are now pilfering your private AI chats
Security researchers recently made a shocking discovery – malicious browser extensions are targeting users’ sensitive AI conversations. However, it turns out that the practice is widespread, and even legitimate extensions are pilfering users’ AI chats.
Read more about Ka-ching! Legit browser extensions are now pilfering your private AI chats
New Shai-Hulud 3.0 variant discovered, closing out 2025 with a malware bang
A new strain of the Shai-Hulud worm has been discovered by researchers, signaling that the self-propagating supply chain threat – responsible for a surge of attacks compromising NPM packages this fall – remains active and likely to continue impacting devs well into 2026.
Read more about New Shai-Hulud 3.0 variant discovered, closing out 2025 with a malware bang
Chrome extension malware steals ChatGPT and DeepSeek chats from 900k
Malicious Chrome extensions featured by Google have been stealing chat history from ChatGPT and DeepSeek.
Read more about Chrome extension malware steals ChatGPT and DeepSeek chats from 900k
MacOS developers targeted with crypto-stealing worms on Open VSX
Hackers have contaminated the Open VSX marketplace, which is used by millions of developers, with malware that steals cryptocurrency, credentials, and other sensitive data. The latest wave of malicious extensions is targeting macOS users exclusively.
Read more about MacOS developers targeted with crypto-stealing worms on Open VSX
Hackers rang in the New Year by looting French universities
Two French universities have been attacked during the festive season. The attackers allegedly walked away with thousands of students’ data.
Read more about Hackers rang in the New Year by looting French universities
As MongoBleed exploitation escalates, 95% of systems remain unpatched
Hackers are actively exploiting the MongoBleed vulnerability, dumping server memory and scouring for passwords, tokens, credentials, and other sensitive data, cyber authorities warn. Estimates suggest that 95% of exposed MongoDB systems remain unpatched.
Read more about As MongoBleed exploitation escalates, 95% of systems remain unpatched
French software company Nexpublica fined for failings leading to data breach
In Europe, a region where regulation matters, poor cybersecurity practices can result in significant fines. France’s data protection regulator has levied a fine of €1.7 million ($2 million) on the software company Nexpublica.
Read more about French software company Nexpublica fined for failings leading to data breach
The 2025 npm worm that shook the software supply chain
As a worm spread through hundreds of npm packages in 2025, it didn't exploit a vulnerability – it exploited the architecture. The systems that developers relied on had quietly become attack infrastructure.
Read more about The 2025 npm worm that shook the software supply chain
Got an AI agent on your computer? Assume a breach, security researcher warns
Instead of writing malware, hackers are already hijacking systems with words. When a computer has Claude Code, GitHub Copilot, Google Jules, or other similar systems, it instantly becomes vulnerable to zero-click attacks hidden in prompts on the web, documents, or repositories.
Read more about Got an AI agent on your computer? Assume a breach, security researcher warns
FBI launches training center to identify illegal drone activity
The FBI has launched its new National Counter-UAS Training Center, aimed at helping local law enforcement identify, track, and mitigate illegal drone activity across the US.
Read more about FBI launches training center to identify illegal drone activity
After robbing Amazon of Korea, the attacker threw his MacBook into the river
Following a former employee's theft of the company’s data, the “Amazon of Korea” is issuing $1.17 billion in vouchers to compensate its customers.
Read more about After robbing Amazon of Korea, the attacker threw his MacBook into the river