Security

Thousands of Firefox users compromised: 17 extensions hide malware in icons

At least 17 Firefox extensions slipped past detection by hiding malware in an unlikely place – their icons. Thousands of users have been infected, and the malicious add-ons are still available on the Firefox platform.
Read more about Thousands of Firefox users compromised: 17 extensions hide malware in icons

Users alarmed after Pornhub was linked to data breach that affected OpenAI

A cyberattack that impacted the ChatGPT maker OpenAI has also impacted adult content behemoth Pornhub. The hackers claiming responsibility say they have the browsing histories of Premium Pornhub users.
Read more about Users alarmed after Pornhub was linked to data breach that affected OpenAI

Google will shut down “unhelpful” dark web monitoring tool

Google has announced that it’s about to discontinue its dark web monitoring tool in February, less than two years after it was launched to help users determine if their personal data is available anywhere on the dark web.
Read more about Google will shut down “unhelpful” dark web monitoring tool

SoundCloud discloses breach affecting millions, warns users about phishing attempts

SoundCloud, an online audio streaming platform popular among artists sharing and promoting music, has disclosed a data breach affecting millions of users. Attackers have exfiltrated email addresses, along with other publicly available data.
Read more about SoundCloud discloses breach affecting millions, warns users about phishing attempts

Payroll data stolen in Jaguar Land Rover cyberattack

The personal information of thousands of Jaguar Land Rover staff members has been harvested by attackers, putting them at risk of potential fraud.
Read more about Payroll data stolen in Jaguar Land Rover cyberattack

Apple and Google fail to bar US-sanctioned companies from their app stores

The Apple App Store and Google Play Store are hosting dozens of apps with direct connections to US-sanctioned Russian, Chinese, and other companies, according to a report by the Tech Transparency Project.
Read more about Apple and Google fail to bar US-sanctioned companies from their app stores

Researchers see global surge in attacks by new ransomware group “Gentlemen”

Not exactly chivalrous, a newly identified ransomware group called Gentlemen has been gaining prominence since August. Researchers say the gang’s technical sophistication suggests a coordinated team with extensive experience in enterprise-focused attacks.
Read more about Researchers see global surge in attacks by new ransomware group “Gentlemen”

Apple urges updates as hackers target iPhones

Apple is urging billions of iPhone users to update immediately after confirming that hackers are already exploiting newly patched flaws in iOS 26.2.
Read more about Apple urges updates as hackers target iPhones

Hackers turn ChatGPT, Grok chat links into malware traps on search engines

Cybercriminals are flooding search results with manipulated ChatGPT or Grok answers. Users trying to clean their Macs or free up space end up installing powerful infostealer malware.
Read more about Hackers turn ChatGPT, Grok chat links into malware traps on search engines

LastPass fined £1.2M by ICO for comprehensive data breach

The Information Commissioner’s Office (ICO) has imposed a fine of £1.2 million on LastPass UK following a data breach that affected 1.6 million people.
Read more about LastPass fined £1.2M by ICO for comprehensive data breach

Your questions, answered by Cybernews: Can your vape be hacked?

Screening Windows, playing Doom, hosting a website, or orchestrating a cyberattack. What else can be done with your vape? Each week, our team selects one pressing and common reader issue and deconstructs it to help you stay safe online.
Read more about Your questions, answered by Cybernews: Can your vape be hacked?

Stanford University pits cybersecurity researchers versus AI: should humans worry?

Ten cyber pros were given $2,000 to beat the autonomous AI agents in hacking a live enterprise environment. One of them actually succeeded, but the victory comes at a steeper cost.
Read more about Stanford University pits cybersecurity researchers versus AI: should humans worry?

EU can’t attract and retain cyber talent: why?

Both public and private organizations in critical sectors across the European Union are finding it difficult to attract and retain cybersecurity professionals, ENISA (the European Union Agency for Cybersecurity) says.
Read more about EU can’t attract and retain cyber talent: why?

Chinese state hackers attended Cisco cybersec training, researcher claims

Two Chinese hackers accused of running one of Beijing’s biggest cyber-espionage campaigns may have first learned their craft in a beginner-level Cisco training program.
Read more about Chinese state hackers attended Cisco cybersec training, researcher claims

Feds charge former Accenture employee for misleading them on cloud security

A former product manager at Accenture repeatedly lied to the company’s government customers about the compliance of its cloud product with security regulations. Now, she’s been charged by the Justice Department.
Read more about Feds charge former Accenture employee for misleading them on cloud security

React, Next.js disclose follow-up vulnerabilities, again urge users to patch immediately

Web server admins must scramble to update their backend servers again after React and Next.js disclosed two additional follow-up vulnerabilities related to last week’s discovery of a critical bug.
Read more about React, Next.js disclose follow-up vulnerabilities, again urge users to patch immediately

Google rushes Chrome updates after new vulnerability found exploited in wild

Chrome users are racing against active attackers after Google confirmed a newly patched vulnerability is already being exploited in the wild. Clues lead to Google’s WebGL engine.
Read more about Google rushes Chrome updates after new vulnerability found exploited in wild

Microsoft urges users to change passwords, as the Dune-inspired worm hits again

A resurrected and more vicious Shai-Hulud worm is silently tearing through the software supply chain, compromising developers and cloud pipelines at scale.
Read more about Microsoft urges users to change passwords, as the Dune-inspired worm hits again

Google launches Android emergency live video to stream 911 calls in real time

Google’s Android Emergency Live Video lets users stream live footage to 911 dispatchers, giving first responders vital real-time context to save lives faster.
Read more about Google launches Android emergency live video to stream 911 calls in real time

Newly identified ransomware can execute total takeover of compromised devices

Droidlock, a new type of malware more accurately classified as ransomware, has the ability to lock device screens with a ransomware-like overlay and illegally acquire app lock credentials. This then leads to a total takeover of the compromised device.
Read more about Newly identified ransomware can execute total takeover of compromised devices