Security

New ranking reveals 2 hottest cybersecurity skills

Some companies have been forced to hire underqualified and inexperienced people to fill cybersecurity roles. That’s just how bad the situation with cybersecurity industry skills shortages is.
Read more about New ranking reveals 2 hottest cybersecurity skills

View an ad an you’re cooked: Intellexa planted spyware with zero clicks

If you think an adblocker is optional, think again. Simply loading a single advertisement on any legitimate website or app was enough to secretly plant Intellexa’s Predator, one of the most advanced commercial spyware tools, linked to human rights abuses across many countries.
Read more about View an ad an you’re cooked: Intellexa planted spyware with zero clicks

Vibe coding disaster: Gemini 3 Pro “absolutely devastated” after it wipes entire drive

An app developer from Greece used an AI agent, powered by Google’s Gemini 3 Pro, to develop an image selector app. Instead, the bot wiped the entire D drive, making it unrepairable. “I lost a lot, a lot of things,” the developer warns.
Read more about Vibe coding disaster: Gemini 3 Pro “absolutely devastated” after it wipes entire drive

New “GhostFrame” kit fuels 1M+ ultra‑stealth phishing attacks

A new phishing framework called GhostFrame, built around an ultra-stealthy iframe architecture, has been linked to more than one million attacks. But it’s different from most other phishing kits.
Read more about New “GhostFrame” kit fuels 1M+ ultra‑stealth phishing attacks

CISA advisory on China's BRICKSTORM malware: “Treat this threat with the seriousness it demands”

A new BRICKSTORM malware advisory released by CISA on Thursday aims to help organizations defend their systems against the backdoor APT – a stealthy, evasive cyberespionage threat already in use by PRC-backed nation-state attackers.
Read more about CISA advisory on China's BRICKSTORM malware: “Treat this threat with the seriousness it demands”

Despite Microsoft’s secret patch, LNK loophole remains viable for hackers to deliver malware

Hackers have been stuffing seemingly innocuous LNK files with malware, invisible to users, and Microsoft has been reluctant to plug this hole. In November, the tech company released a silent patch that does almost nothing to stop the attackers. A third-party service offers an alternative unofficial update.
Read more about Despite Microsoft’s secret patch, LNK loophole remains viable for hackers to deliver malware

Tehran-linked hackers attack Israel using malware inspired by retro game

Iranian nation-state hackers have been inspired by a legendary mobile phone time-killing mainstay, say security researchers, who spotted them downloading malware masquerading as the Snake video game.
Read more about Tehran-linked hackers attack Israel using malware inspired by retro game

“Worst case scenario” vulnerability found in React, Next.js

A critical security flaw has been discovered in React, one of the most widely used JavaScript libraries for building websites. The bug enables external attackers to run privileged, arbitrary code on servers without any authorization.
Read more about “Worst case scenario” vulnerability found in React, Next.js

CISA issues new guidance for secure AI deployment in critical operational technology (OT) systems

Critical infrastructure operators across the West were issued new guidance on Wednesday on how to securely integrate artificial intelligence into operational technology (OT) – all to help reduce the risk of targeted attacks.
Read more about CISA issues new guidance for secure AI deployment in critical operational technology (OT) systems

UK’s cyber tool blocks a billion clicks from landing on malicious sites

The UK online crime disruption tool prevented a billion visits to known malicious websites – a figure that’s 14 times larger than the country’s total population.
Read more about UK’s cyber tool blocks a billion clicks from landing on malicious sites

US AI giants face trillion-dollar dilemma as cheaper Chinese models take two of top five positions

DeepSeek is now more than twice as intelligent as it was when it was first released a year ago. While the new model is still slightly behind the best from Google, Anthropic, or OpenAI, it will complete the same job at least 22 times cheaper.
Read more about US AI giants face trillion-dollar dilemma as cheaper Chinese models take two of top five positions

Insuretech firm leaks millions of personal records, future travel data

Companjon, an insurance technology company, exposed an unprotected Kafka stream, leaking millions of logs, including travel itineraries, full names, emails, and other personally identifiable information.
Read more about Insuretech firm leaks millions of personal records, future travel data

Russia-linked hackers threaten Asus with 1TB leak after dark-web countdown appears

The multinational electronics giant’s name has appeared on a dark web forum, with attackers claiming to have obtained a treasure trove of Asus information.
Read more about Russia-linked hackers threaten Asus with 1TB leak after dark-web countdown appears

Phishing Alert: LVMH, Disney, Uber, Mastercard used in fake Calendly recruitment scam

Attackers impersonating 75 major brands, such as LVMH, Unilever, Lego, and dozens more, are using fake Calendly invites to steal Google Workspace and Facebook Business ad credentials – all part of a recently discovered phishing campaign, researchers said on Tuesday.
Read more about Phishing Alert: LVMH, Disney, Uber, Mastercard used in fake Calendly recruitment scam

Three Ivy League data breaches in under 3 months: UPenn is the latest to admit a leak

The University of Pennsylvania (UPenn) has confirmed that it suffered a data breach last month, making it the second Ivy League school to face an intrusion in just a few weeks. Princeton and Columbia were also breached earlier this year.
Read more about Three Ivy League data breaches in under 3 months: UPenn is the latest to admit a leak

I created a blank website and got 30K clicks immediately: here’s why this is a problem

I created a new .com website, and it became an instant hit. After a week, Cloudflare sent me a greeting for surpassing the first 1,000 page views. In fact, the website had already received over 4,000 page views. In less than a month, the site had already garnered over 30,000 page views. Except none of these views were actual people.
Read more about I created a blank website and got 30K clicks immediately: here’s why this is a problem

One billion PCs run end-of-life Windows 10, despite half of them supporting Windows 11 upgrade

One billion PCs are still running the Windows 10 operating system, which reached end-of-life in October, despite half of them being completely capable of running Windows 11, according to Dell. Unwillingness to switch leaves many systems vulnerable to security exploits, and it appears that upgrading is not that straightforward.
Read more about One billion PCs run end-of-life Windows 10, despite half of them supporting Windows 11 upgrade

Most young cybercriminals hang up their keyboards in their twenties, study finds

Most youth cybercriminal careers are short-lived, typically peaking around age twenty, before declining sharply, a Dutch study suggests. This trajectory is not unique and mirrors traditional youth offenses.
Read more about Most young cybercriminals hang up their keyboards in their twenties, study finds

Apple defies India’s demands over undeletable state app, ignites surveillance firestorm

Apple does not plan to comply with a mandate to preload its smartphones with a state-owned cyber safety app and will convey its concerns to New Delhi, three sources said, after the government's move sparked surveillance concerns and a political uproar.
Read more about Apple defies India’s demands over undeletable state app, ignites surveillance firestorm

Man sentenced to 7 years in prison for using “evil twin” WiFi network during flight

A 44-year-old man from Australia faces lengthy jail time for creating a so-called evil twin WiFi network during a domestic flight.
Read more about Man sentenced to 7 years in prison for using “evil twin” WiFi network during flight