Security

After robbing Amazon of Korea, the attacker threw his MacBook into the river

Following a former employee's theft of the company’s data, the “Amazon of Korea” is issuing $1.17 billion in vouchers to compensate its customers.
Read more about After robbing Amazon of Korea, the attacker threw his MacBook into the river

Data theft alert: insurer Aflac notifying millions of clients

Half a year after disclosing a cybersecurity incident, health and life insurer Aflac is now notifying roughly 22.6 million people that their personal data was stolen from the company's systems in June 2025.
Read more about Data theft alert: insurer Aflac notifying millions of clients

1.6M+ Salvation Army transactions exposed, hackers claim

Attackers have shared information on millions of donations to the Salvation Army, an international charitable organization run by Protestant Christians. Cybernews researchers believe that attackers could exploit data for financial crimes.
Read more about 1.6M+ Salvation Army transactions exposed, hackers claim

As tax filing approaches, hackers target US taxpayers

A Russia-linked ransomware gang claims to have stolen tax return data and Social Security numbers from a 75-year-old Massachusetts accounting firm, and now it’s waiting to be paid.
Read more about As tax filing approaches, hackers target US taxpayers

2.3M WIRED users exposed, hacker threatens release of 40M more records

Hackers have exposed 2.3 million WIRED subscribers to a heightened risk of phishing and other cyberattacks. The attackers are threatening to release 40 million more records allegedly stolen from Condé Nast, the publisher’s parent company.
Read more about 2.3M WIRED users exposed, hacker threatens release of 40M more records

The biggest corporate security blunders of 2025

2025 was defined not just by unprecedented attack techniques but by familiar corporate mistakes that attackers exploited on an unprecedented scale.
Read more about The biggest corporate security blunders of 2025

Christmas gift: method to exploit MongoBleed vulnerability leaking MongoDB secrets showcased on web

A researcher has decided to demonstrate how a high-severity MongoDB vulnerability, tracked as CVE-2025-14847 and dubbed MongoBleed, can be exploited and affect multiple supported and legacy MongoDB Server versions.
Read more about Christmas gift: method to exploit MongoBleed vulnerability leaking MongoDB secrets showcased on web

Accounting firm took over a year to inform users of data breach

Sax, a US-based accounting firm, suffered a data breach that exposed the personal information of nearly 250,000 individuals.
Read more about Accounting firm took over a year to inform users of data breach

IBM sees seven major cybersecurity dangers next year: AI, AI, AI, AI, AI, not AI, likely AI

Artificial intelligence (AI) will be at the forefront of nearly all major cybersecurity threats next year. It poses a danger to organizations both from within and outside, empowering cybercriminals, causing incidents, and enabling attacker bots to act independently.
Read more about IBM sees seven major cybersecurity dangers next year: AI, AI, AI, AI, AI, not AI, likely AI

They are offering up to $15k reward for betraying your boss

A new type of side hustle has recently gained popularity among those willing to steal data from their current employers.
Read more about They are offering up to $15k reward for betraying your boss

Can we trust Chinese tech? The US government doesn’t think so

An American tech company is being sued after allegedly deceiving customers about “serious security risks” associated with its video surveillance cameras, raising concerns about the use of Chinese-made technology.
Read more about Can we trust Chinese tech? The US government doesn’t think so

Nissan leak affects 21,000 customers

Hackers have managed to exfiltrate personal information of approximately 21,000 Nissan customers by accessing a third-party’s digital environment.
Read more about Nissan leak affects 21,000 customers

OpenAI says prompt injection attacks “long-term security challenge”

Artificial intelligence (AI) prompt injection attacks will remain one of the most challenging security threats, with no guaranteed complete fix. The best way to protect ourselves is to continuously strengthen our defenses against it, according to OpenAI.
Read more about OpenAI says prompt injection attacks “long-term security challenge”

Vincent AI phishing vulnerability found, 200K+ law firms at risk of credential and data theft

Vincent, the vLex AI assistant used by tens of thousands of legal teams and law firms worldwide, contains an AI-phishing vulnerability that attackers could exploit via hidden HTML code – all to steal users’ login credentials and potentially expose sensitive client files.
Read more about Vincent AI phishing vulnerability found, 200K+ law firms at risk of credential and data theft

France’s postal and banking systems attacked as Christmas rush peaks

France’s postal service was knocked down after a suspected cyberattack, with frustrated clients lining up to deliver Christmas parcels.
Read more about France’s postal and banking systems attacked as Christmas rush peaks

Code that works can also be malware: this WhatsApp API is stealing messages

A popular WhatsApp library trusted by tens of thousands of developers was quietly spying on messages, contacts, and credentials, maintaining access even after being uninstalled.
Read more about Code that works can also be malware: this WhatsApp API is stealing messages

Hospitals exposed as medical devices create massive cyber risks

Even a doctor’s Bluetooth music speaker can compromise a hospital’s cybersecurity network, and chief information security officers won't be among the first to know.
Read more about Hospitals exposed as medical devices create massive cyber risks

Scammers exploit official Google domain to send phishing emails undetected

Scammers have found a way to send fraudulent emails using Google’s official @google.com domain by abusing Google Cloud automation tools. Thousands of organizations received phishing emails that evaded security detection.
Read more about Scammers exploit official Google domain to send phishing emails undetected

Hackers attack WatchGuard Firebox firewalls: 120K IPs exposed and vulnerable

With hackers already knocking at the gates, around 120,000 WatchGuard Firebox firewalls, which protect thousands of companies, remain unpatched and vulnerable to a critical flaw, according to the latest research by the ShadowServer Foundation.
Read more about Hackers attack WatchGuard Firebox firewalls: 120K IPs exposed and vulnerable

Prince of Persia ran a covert Iranian spy campaign for over a decade

For nearly two decades, an Iran-backed hacking group, once thought to have faded away, has quietly evolved, research reveals.
Read more about Prince of Persia ran a covert Iranian spy campaign for over a decade