Security

Wavlink routers and other IoT devices hit by React2Shell attacks

Security researchers say a botnet called RondoDox has spent nine straight months targeting Internet of Things (IoT) devices and web servers, hitting popular platforms like WordPress, Drupal, and Struts2, alongside consumer-grade IoT devices such as Wavlink routers.
Read more about Wavlink routers and other IoT devices hit by React2Shell attacks

“Tinder for Nazis” hit by 100GB data leak, thousands of users exposed

An investigative journalist has infiltrated the white supremacist dating website WhiteDate and exfiltrated over 8,000 profiles and 100GB of data. Photos and other sensitive details have been made public, and the full “WhiteLeaks” data is available to journalists and researchers on DDoSecrets.
Read more about “Tinder for Nazis” hit by 100GB data leak, thousands of users exposed

European Space Agency confirms data breach impacted external servers

The Paris-headquartered space exploration agency has confirmed that attackers may have breached a “very small number” of its external servers.
Read more about European Space Agency confirms data breach impacted external servers

2.2M Chrome, Firefox, Edge users impacted by meeting-stealing malware

In a short period, researchers from Koi Security have uncovered three malicious browser extension campaigns that have impacted millions of browser users worldwide. The same Chinese threat actor is thought to be behind the campaigns.
Read more about 2.2M Chrome, Firefox, Edge users impacted by meeting-stealing malware

British hacker gets rare Australian visa after hacking the government website

Identifying a critical flaw in the Australian government system has earned a British ethical hacker one of the hardest-to-get types of visa.
Read more about British hacker gets rare Australian visa after hacking the government website

When customers take the stand: Cybersecurity faces a new kind of trial

Researchers estimate the cyber incident at Jaguar Land Rover could cost around £1.9 billion, making it the costliest cyberattack ever recorded in the UK. However, these costs may seem insignificant compared to those of future breaches.
Read more about When customers take the stand: Cybersecurity faces a new kind of trial

Chinese state hackers plant malware inside Windows

Chinese state hackers are infiltrating operating systems to bypass antivirus detection.
Read more about Chinese state hackers plant malware inside Windows

2025 was a breakout year for zero-day exploits

Zero-day exploits were once niche threats reserved for high-stakes espionage. However, that idea no longer holds true, and attackers are now increasingly able to weaponize them with relative ease to break into corporate networks.
Read more about 2025 was a breakout year for zero-day exploits

VPN downloads surge in 2025: US drives volume while Middle East leads in adoption

VPN application downloads are rising again after a post-pandemic slowdown, with growth concentrated in large markets such as the United...
Read more about VPN downloads surge in 2025: US drives volume while Middle East leads in adoption

Ka-ching! Legit browser extensions are now pilfering your private AI chats

Security researchers recently made a shocking discovery – malicious browser extensions are targeting users’ sensitive AI conversations. However, it turns out that the practice is widespread, and even legitimate extensions are pilfering users’ AI chats.
Read more about Ka-ching! Legit browser extensions are now pilfering your private AI chats

New Shai-Hulud 3.0 variant discovered, closing out 2025 with a malware bang

A new strain of the Shai-Hulud worm has been discovered by researchers, signaling that the self-propagating supply chain threat – responsible for a surge of attacks compromising NPM packages this fall – remains active and likely to continue impacting devs well into 2026.
Read more about New Shai-Hulud 3.0 variant discovered, closing out 2025 with a malware bang

Chrome extension malware steals ChatGPT and DeepSeek chats from 900k

Malicious Chrome extensions featured by Google have been stealing chat history from ChatGPT and DeepSeek.
Read more about Chrome extension malware steals ChatGPT and DeepSeek chats from 900k

MacOS developers targeted with crypto-stealing worms on Open VSX

Hackers have contaminated the Open VSX marketplace, which is used by millions of developers, with malware that steals cryptocurrency, credentials, and other sensitive data. The latest wave of malicious extensions is targeting macOS users exclusively.
Read more about MacOS developers targeted with crypto-stealing worms on Open VSX

Hackers rang in the New Year by looting French universities

Two French universities have been attacked during the festive season. The attackers allegedly walked away with thousands of students’ data.
Read more about Hackers rang in the New Year by looting French universities

As MongoBleed exploitation escalates, 95% of systems remain unpatched

Hackers are actively exploiting the MongoBleed vulnerability, dumping server memory and scouring for passwords, tokens, credentials, and other sensitive data, cyber authorities warn. Estimates suggest that 95% of exposed MongoDB systems remain unpatched.
Read more about As MongoBleed exploitation escalates, 95% of systems remain unpatched

French software company Nexpublica fined for failings leading to data breach

In Europe, a region where regulation matters, poor cybersecurity practices can result in significant fines. France’s data protection regulator has levied a fine of €1.7 million ($2 million) on the software company Nexpublica.
Read more about French software company Nexpublica fined for failings leading to data breach

The 2025 npm worm that shook the software supply chain

As a worm spread through hundreds of npm packages in 2025, it didn't exploit a vulnerability – it exploited the architecture. The systems that developers relied on had quietly become attack infrastructure.
Read more about The 2025 npm worm that shook the software supply chain

Got an AI agent on your computer? Assume a breach, security researcher warns

Instead of writing malware, hackers are already hijacking systems with words. When a computer has Claude Code, GitHub Copilot, Google Jules, or other similar systems, it instantly becomes vulnerable to zero-click attacks hidden in prompts on the web, documents, or repositories.
Read more about Got an AI agent on your computer? Assume a breach, security researcher warns

FBI launches training center to identify illegal drone activity

The FBI has launched its new National Counter-UAS Training Center, aimed at helping local law enforcement identify, track, and mitigate illegal drone activity across the US.
Read more about FBI launches training center to identify illegal drone activity

After robbing Amazon of Korea, the attacker threw his MacBook into the river

Following a former employee's theft of the company’s data, the “Amazon of Korea” is issuing $1.17 billion in vouchers to compensate its customers.
Read more about After robbing Amazon of Korea, the attacker threw his MacBook into the river