Security

4B+ records, including numerous LinkedIn profiles, exposed in one of the largest lead-generation datasets ever found open

What appears to be 16TB of professional and corporate intelligence data includes LinkedIn URLs and profile handles, alongside other personal information.
Read more about 4B+ records, including numerous LinkedIn profiles, exposed in one of the largest lead-generation datasets ever found open

Notepad++ releases emergency patch as hackers exploit updater to deploy malware

Hackers are abusing Notepad++, a popular text and source code editor, to deliver malware. The app’s updater, WinGUp, can be tricked by an attacker-in-the-middle to pull compromised executables from malicious servers. Patches are now available.
Read more about Notepad++ releases emergency patch as hackers exploit updater to deploy malware

New malware on Microsoft Marketplace steals passwords and screenshots of desktops

Some developers thought they were installing a dark theme and an AI assistant on their VS Code. However, it turned out to be malware that stole their data.
Read more about New malware on Microsoft Marketplace steals passwords and screenshots of desktops

Cheap devices from China may come with hidden sensors and hacking tools

Cheap devices for remotely managing hardware can themselves pose a significant security risk. Dr. Matej Kovačič, a security researcher from Slovenia, found that a popular NanoKVM contained a hidden microphone, together with hacking tools and dangerous exploits that would make exploitation trivial.
Read more about Cheap devices from China may come with hidden sensors and hacking tools

Trump prioritizing trade with China over cyber war, Salt Typhoon goes unpunished

The US President wants the world’s fellow autocrats to like him so much that he seems unwilling to allow nuisances such as cyberattacks against America to get in the way. This means that Salt Typhoon, a complex Chinese cyberespionage group, is being given a pass.
Read more about Trump prioritizing trade with China over cyber war, Salt Typhoon goes unpunished

Cursor vulnerable to “catastrophic budget drain:” vibe coder finds a way to spend $1 million

Developers without admin privileges or attackers with limited access can bankrupt smaller companies simply by raising Cursor and AWS Bedrock spending limits, a report by OX Security has revealed.
Read more about Cursor vulnerable to “catastrophic budget drain:” vibe coder finds a way to spend $1 million

Hackers say Volkswagen dealership’s client list is now for sale

Hackers claim to have breached a Volkswagen dealership. The client's data is allegedly up for sale.
Read more about Hackers say Volkswagen dealership’s client list is now for sale

Check Point links US cyberattacks to global crises in new clash warning

Cyberattacks against the United States are no longer isolated events that cause only temporary technical inconvenience. According to Check Point, a cybersecurity company, they’re now mostly coordinated campaigns aimed at weakening Washington.
Read more about Check Point links US cyberattacks to global crises in new clash warning

Infostealers on the rise: time to take action, Australia recommends

The Australian Cyber Security Centre (ACSC) has been tracking and monitoring an increase in activity related to information-stealing malware, also known as infostealers.
Read more about Infostealers on the rise: time to take action, Australia recommends

Compromised Next.js devices weaponized by attackers: thousands remain vulnerable

Security researchers warn that hundreds of already compromised Next.js devices are hitting honeypots, while tens of thousands of servers remain vulnerable to the critical React vulnerability.
Read more about Compromised Next.js devices weaponized by attackers: thousands remain vulnerable

Russian hackers claim looting of secret big tech hardware designs

Everest Ransomware claims to have stolen over 100,000 sensitive engineering files from Benchmark Electronics, potentially exposing the inner workings of some of the world’s most advanced technology manufacturers.
Read more about Russian hackers claim looting of secret big tech hardware designs

US military contractor breach expose employee data

MAG Aerospace, military contractor for the US military in intelligence, surveillance and reconnaissance, suffered a breach exposing its employee data.
Read more about US military contractor breach expose employee data

Attack on the home of Spam exposes details of thousands

A ransomware attack on Minnesota’s Mower County exposed tens of thousands of its residents, the local government organization revealed in a recent breach notice.
Read more about Attack on the home of Spam exposes details of thousands

New ranking reveals 2 hottest cybersecurity skills

Some companies have been forced to hire underqualified and inexperienced people to fill cybersecurity roles. That’s just how bad the situation with cybersecurity industry skills shortages is.
Read more about New ranking reveals 2 hottest cybersecurity skills

View an ad an you’re cooked: Intellexa planted spyware with zero clicks

If you think an adblocker is optional, think again. Simply loading a single advertisement on any legitimate website or app was enough to secretly plant Intellexa’s Predator, one of the most advanced commercial spyware tools, linked to human rights abuses across many countries.
Read more about View an ad an you’re cooked: Intellexa planted spyware with zero clicks

Vibe coding disaster: Gemini 3 Pro “absolutely devastated” after it wipes entire drive

An app developer from Greece used an AI agent, powered by Google’s Gemini 3 Pro, to develop an image selector app. Instead, the bot wiped the entire D drive, making it unrepairable. “I lost a lot, a lot of things,” the developer warns.
Read more about Vibe coding disaster: Gemini 3 Pro “absolutely devastated” after it wipes entire drive

New “GhostFrame” kit fuels 1M+ ultra‑stealth phishing attacks

A new phishing framework called GhostFrame, built around an ultra-stealthy iframe architecture, has been linked to more than one million attacks. But it’s different from most other phishing kits.
Read more about New “GhostFrame” kit fuels 1M+ ultra‑stealth phishing attacks

CISA advisory on China's BRICKSTORM malware: “Treat this threat with the seriousness it demands”

A new BRICKSTORM malware advisory released by CISA on Thursday aims to help organizations defend their systems against the backdoor APT – a stealthy, evasive cyberespionage threat already in use by PRC-backed nation-state attackers.
Read more about CISA advisory on China's BRICKSTORM malware: “Treat this threat with the seriousness it demands”

Despite Microsoft’s secret patch, LNK loophole remains viable for hackers to deliver malware

Hackers have been stuffing seemingly innocuous LNK files with malware, invisible to users, and Microsoft has been reluctant to plug this hole. In November, the tech company released a silent patch that does almost nothing to stop the attackers. A third-party service offers an alternative unofficial update.
Read more about Despite Microsoft’s secret patch, LNK loophole remains viable for hackers to deliver malware

Tehran-linked hackers attack Israel using malware inspired by retro game

Iranian nation-state hackers have been inspired by a legendary mobile phone time-killing mainstay, say security researchers, who spotted them downloading malware masquerading as the Snake video game.
Read more about Tehran-linked hackers attack Israel using malware inspired by retro game