Security

2025 was a breakout year for zero-day exploits

Zero-day exploits were once niche threats reserved for high-stakes espionage. However, that idea no longer holds true, and attackers are now increasingly able to weaponize them with relative ease to break into corporate networks.
Read more about 2025 was a breakout year for zero-day exploits

VPN downloads surge in 2025: US drives volume while Middle East leads in adoption

VPN application downloads are rising again after a post-pandemic slowdown, with growth concentrated in large markets such as the United...
Read more about VPN downloads surge in 2025: US drives volume while Middle East leads in adoption

Ka-ching! Legit browser extensions are now pilfering your private AI chats

Security researchers recently made a shocking discovery – malicious browser extensions are targeting users’ sensitive AI conversations. However, it turns out that the practice is widespread, and even legitimate extensions are pilfering users’ AI chats.
Read more about Ka-ching! Legit browser extensions are now pilfering your private AI chats

New Shai-Hulud 3.0 variant discovered, closing out 2025 with a malware bang

A new strain of the Shai-Hulud worm has been discovered by researchers, signaling that the self-propagating supply chain threat – responsible for a surge of attacks compromising NPM packages this fall – remains active and likely to continue impacting devs well into 2026.
Read more about New Shai-Hulud 3.0 variant discovered, closing out 2025 with a malware bang

Chrome extension malware steals ChatGPT and DeepSeek chats from 900k

Malicious Chrome extensions featured by Google have been stealing chat history from ChatGPT and DeepSeek.
Read more about Chrome extension malware steals ChatGPT and DeepSeek chats from 900k

MacOS developers targeted with crypto-stealing worms on Open VSX

Hackers have contaminated the Open VSX marketplace, which is used by millions of developers, with malware that steals cryptocurrency, credentials, and other sensitive data. The latest wave of malicious extensions is targeting macOS users exclusively.
Read more about MacOS developers targeted with crypto-stealing worms on Open VSX

Hackers rang in the New Year by looting French universities

Two French universities have been attacked during the festive season. The attackers allegedly walked away with thousands of students’ data.
Read more about Hackers rang in the New Year by looting French universities

As MongoBleed exploitation escalates, 95% of systems remain unpatched

Hackers are actively exploiting the MongoBleed vulnerability, dumping server memory and scouring for passwords, tokens, credentials, and other sensitive data, cyber authorities warn. Estimates suggest that 95% of exposed MongoDB systems remain unpatched.
Read more about As MongoBleed exploitation escalates, 95% of systems remain unpatched

French software company Nexpublica fined for failings leading to data breach

In Europe, a region where regulation matters, poor cybersecurity practices can result in significant fines. France’s data protection regulator has levied a fine of €1.7 million ($2 million) on the software company Nexpublica.
Read more about French software company Nexpublica fined for failings leading to data breach

The 2025 npm worm that shook the software supply chain

As a worm spread through hundreds of npm packages in 2025, it didn't exploit a vulnerability – it exploited the architecture. The systems that developers relied on had quietly become attack infrastructure.
Read more about The 2025 npm worm that shook the software supply chain

Got an AI agent on your computer? Assume a breach, security researcher warns

Instead of writing malware, hackers are already hijacking systems with words. When a computer has Claude Code, GitHub Copilot, Google Jules, or other similar systems, it instantly becomes vulnerable to zero-click attacks hidden in prompts on the web, documents, or repositories.
Read more about Got an AI agent on your computer? Assume a breach, security researcher warns

FBI launches training center to identify illegal drone activity

The FBI has launched its new National Counter-UAS Training Center, aimed at helping local law enforcement identify, track, and mitigate illegal drone activity across the US.
Read more about FBI launches training center to identify illegal drone activity

After robbing Amazon of Korea, the attacker threw his MacBook into the river

Following a former employee's theft of the company’s data, the “Amazon of Korea” is issuing $1.17 billion in vouchers to compensate its customers.
Read more about After robbing Amazon of Korea, the attacker threw his MacBook into the river

Data theft alert: insurer Aflac notifying millions of clients

Half a year after disclosing a cybersecurity incident, health and life insurer Aflac is now notifying roughly 22.6 million people that their personal data was stolen from the company's systems in June 2025.
Read more about Data theft alert: insurer Aflac notifying millions of clients

1.6M+ Salvation Army transactions exposed, hackers claim

Attackers have shared information on millions of donations to the Salvation Army, an international charitable organization run by Protestant Christians. Cybernews researchers believe that attackers could exploit data for financial crimes.
Read more about 1.6M+ Salvation Army transactions exposed, hackers claim

As tax filing approaches, hackers target US taxpayers

A Russia-linked ransomware gang claims to have stolen tax return data and Social Security numbers from a 75-year-old Massachusetts accounting firm, and now it’s waiting to be paid.
Read more about As tax filing approaches, hackers target US taxpayers

2.3M WIRED users exposed, hacker threatens release of 40M more records

Hackers have exposed 2.3 million WIRED subscribers to a heightened risk of phishing and other cyberattacks. The attackers are threatening to release 40 million more records allegedly stolen from Condé Nast, the publisher’s parent company.
Read more about 2.3M WIRED users exposed, hacker threatens release of 40M more records

The biggest corporate security blunders of 2025

2025 was defined not just by unprecedented attack techniques but by familiar corporate mistakes that attackers exploited on an unprecedented scale.
Read more about The biggest corporate security blunders of 2025

Christmas gift: method to exploit MongoBleed vulnerability leaking MongoDB secrets showcased on web

A researcher has decided to demonstrate how a high-severity MongoDB vulnerability, tracked as CVE-2025-14847 and dubbed MongoBleed, can be exploited and affect multiple supported and legacy MongoDB Server versions.
Read more about Christmas gift: method to exploit MongoBleed vulnerability leaking MongoDB secrets showcased on web

Accounting firm took over a year to inform users of data breach

Sax, a US-based accounting firm, suffered a data breach that exposed the personal information of nearly 250,000 individuals.
Read more about Accounting firm took over a year to inform users of data breach