Security
2025 was a breakout year for zero-day exploits
Zero-day exploits were once niche threats reserved for high-stakes espionage. However, that idea no longer holds true, and attackers are now increasingly able to weaponize them with relative ease to break into corporate networks.
Read more about 2025 was a breakout year for zero-day exploits
VPN downloads surge in 2025: US drives volume while Middle East leads in adoption
VPN application downloads are rising again after a post-pandemic slowdown, with growth concentrated in large markets such as the United...
Read more about VPN downloads surge in 2025: US drives volume while Middle East leads in adoption
Ka-ching! Legit browser extensions are now pilfering your private AI chats
Security researchers recently made a shocking discovery – malicious browser extensions are targeting users’ sensitive AI conversations. However, it turns out that the practice is widespread, and even legitimate extensions are pilfering users’ AI chats.
Read more about Ka-ching! Legit browser extensions are now pilfering your private AI chats
New Shai-Hulud 3.0 variant discovered, closing out 2025 with a malware bang
A new strain of the Shai-Hulud worm has been discovered by researchers, signaling that the self-propagating supply chain threat – responsible for a surge of attacks compromising NPM packages this fall – remains active and likely to continue impacting devs well into 2026.
Read more about New Shai-Hulud 3.0 variant discovered, closing out 2025 with a malware bang
Chrome extension malware steals ChatGPT and DeepSeek chats from 900k
Malicious Chrome extensions featured by Google have been stealing chat history from ChatGPT and DeepSeek.
Read more about Chrome extension malware steals ChatGPT and DeepSeek chats from 900k
MacOS developers targeted with crypto-stealing worms on Open VSX
Hackers have contaminated the Open VSX marketplace, which is used by millions of developers, with malware that steals cryptocurrency, credentials, and other sensitive data. The latest wave of malicious extensions is targeting macOS users exclusively.
Read more about MacOS developers targeted with crypto-stealing worms on Open VSX
Hackers rang in the New Year by looting French universities
Two French universities have been attacked during the festive season. The attackers allegedly walked away with thousands of students’ data.
Read more about Hackers rang in the New Year by looting French universities
As MongoBleed exploitation escalates, 95% of systems remain unpatched
Hackers are actively exploiting the MongoBleed vulnerability, dumping server memory and scouring for passwords, tokens, credentials, and other sensitive data, cyber authorities warn. Estimates suggest that 95% of exposed MongoDB systems remain unpatched.
Read more about As MongoBleed exploitation escalates, 95% of systems remain unpatched
French software company Nexpublica fined for failings leading to data breach
In Europe, a region where regulation matters, poor cybersecurity practices can result in significant fines. France’s data protection regulator has levied a fine of €1.7 million ($2 million) on the software company Nexpublica.
Read more about French software company Nexpublica fined for failings leading to data breach
The 2025 npm worm that shook the software supply chain
As a worm spread through hundreds of npm packages in 2025, it didn't exploit a vulnerability – it exploited the architecture. The systems that developers relied on had quietly become attack infrastructure.
Read more about The 2025 npm worm that shook the software supply chain
Got an AI agent on your computer? Assume a breach, security researcher warns
Instead of writing malware, hackers are already hijacking systems with words. When a computer has Claude Code, GitHub Copilot, Google Jules, or other similar systems, it instantly becomes vulnerable to zero-click attacks hidden in prompts on the web, documents, or repositories.
Read more about Got an AI agent on your computer? Assume a breach, security researcher warns
FBI launches training center to identify illegal drone activity
The FBI has launched its new National Counter-UAS Training Center, aimed at helping local law enforcement identify, track, and mitigate illegal drone activity across the US.
Read more about FBI launches training center to identify illegal drone activity
After robbing Amazon of Korea, the attacker threw his MacBook into the river
Following a former employee's theft of the company’s data, the “Amazon of Korea” is issuing $1.17 billion in vouchers to compensate its customers.
Read more about After robbing Amazon of Korea, the attacker threw his MacBook into the river
Data theft alert: insurer Aflac notifying millions of clients
Half a year after disclosing a cybersecurity incident, health and life insurer Aflac is now notifying roughly 22.6 million people that their personal data was stolen from the company's systems in June 2025.
Read more about Data theft alert: insurer Aflac notifying millions of clients
1.6M+ Salvation Army transactions exposed, hackers claim
Attackers have shared information on millions of donations to the Salvation Army, an international charitable organization run by Protestant Christians. Cybernews researchers believe that attackers could exploit data for financial crimes.
Read more about 1.6M+ Salvation Army transactions exposed, hackers claim
As tax filing approaches, hackers target US taxpayers
A Russia-linked ransomware gang claims to have stolen tax return data and Social Security numbers from a 75-year-old Massachusetts accounting firm, and now it’s waiting to be paid.
Read more about As tax filing approaches, hackers target US taxpayers
2.3M WIRED users exposed, hacker threatens release of 40M more records
Hackers have exposed 2.3 million WIRED subscribers to a heightened risk of phishing and other cyberattacks. The attackers are threatening to release 40 million more records allegedly stolen from Condé Nast, the publisher’s parent company.
Read more about 2.3M WIRED users exposed, hacker threatens release of 40M more records
The biggest corporate security blunders of 2025
2025 was defined not just by unprecedented attack techniques but by familiar corporate mistakes that attackers exploited on an unprecedented scale.
Read more about The biggest corporate security blunders of 2025
Christmas gift: method to exploit MongoBleed vulnerability leaking MongoDB secrets showcased on web
A researcher has decided to demonstrate how a high-severity MongoDB vulnerability, tracked as CVE-2025-14847 and dubbed MongoBleed, can be exploited and affect multiple supported and legacy MongoDB Server versions.
Read more about Christmas gift: method to exploit MongoBleed vulnerability leaking MongoDB secrets showcased on web
Accounting firm took over a year to inform users of data breach
Sax, a US-based accounting firm, suffered a data breach that exposed the personal information of nearly 250,000 individuals.
Read more about Accounting firm took over a year to inform users of data breach