loader image
VSCode Marketplace Hit as Malicious Plugins Found

A recent investigation by cybersecurity firm HelixGuard uncovered a dozen malicious plugins infiltrating the VSCode Marketplace, highlighting growing concerns over supply chain risks in integrated development environments. Attackers used these extensions to target software developers directly, embedding harmful code into seemingly legitimate tools. The plugins, once installed, could grant unauthorized access or leak sensitive development […]

Sweden Grid Operator Probes Ransomware Data Leak

Sweden’s national grid operator has launched an investigation into a potential cybersecurity breach after a ransomware group claimed to possess hundreds of gigabytes of confidential data. The Sweden Grid Operator probes ransomware threats linked to this incident, which could impact critical infrastructure systems across the country. The ransomware gang alleges it stole extensive internal documents […]

U.S. Rejects Landmark UN Cybercrime Treaty in Hanoi

More than 70 countries signed a landmark United Nations treaty aimed at combating cybercrime this weekend in Hanoi. While hailed as a major step toward global digital security, the U.S. rejects landmark UN cybercrime convention by choosing not to sign the agreement alongside the other nations. The new treaty seeks to establish a unified international […]

Microsoft Patches 172 Bugs in Year’s Biggest Update

Microsoft patched 172 security vulnerabilities in its October 2025 Patch Tuesday release, the highest monthly total so far this year. The update includes fixes for three zero-day flaws, two publicly disclosed issues, and eight vulnerabilities rated as critical. Microsoft Patches 172 Bugs across a broad range of products, underscoring the continued need for rapid response […]

Gerar Hack Exposes 546GB of Youth Employment Data

Hackers breached Gerar, a Brazilian non-profit dedicated to youth employment, and claimed to have stolen 546 gigabytes of sensitive data. The Gerar hack exposes 546GB of personal and official records, according to a report published by Cybernews. The compromised information reportedly includes documents tied to the organization’s programs that serve young people across Brazil. Cybernews […]

Iran’s Ravin Academy Breached in MOIS-Linked Attack

Iran’s Ravin Academy, a cybersecurity training facility linked to the country’s Ministry of Intelligence and Security (MOIS), confirmed it suffered a data breach. The organization disclosed the incident through its official Telegram channel and stated that an investigation is underway. Iran’s Ravin Academy breached systems appear to have exposed sensitive internal data, although the full […]

Italian Spyware Firm Tied to Chrome Zero-Day Attacks

A recent wave of cyberattacks exploiting a zero-day vulnerability in Google Chrome has been linked to an Italian spyware firm tied to Memento Labs. The attacks, part of a campaign dubbed Operation ForumTroll, delivered malware to targeted systems earlier this year, leveraging flaws now tracked as CVE-2025-2857 and CVE-2025-2783. Researchers identified the malware as a […]

Hacking Team Successor Tied to New Spyware Campaign

Kaspersky researchers on Monday revealed a malware campaign they have attributed to the Hacking Team successor tied to an infamous Italian surveillance technology firm. The investigation also uncovered a new strain of commercial spyware, dubbed “Dante,” linked to the same entity. Analysts say the malware appears to target systems in a manner consistent with previous […]

QNAP Warns of Critical Flaw in Windows Backup Tool

QNAP has issued an urgent security alert, urging users to patch a critical ASP.NET Core vulnerability that affects its NetBak PC Agent software. The flaw, tracked as CVE-2025-55315, exposes systems running the Windows-based backup utility to potential exploitation. This vulnerability originates from ASP.NET Core, a web framework developed by Microsoft, and could allow attackers to […]

Microsoft to Prompt Memory Scans After BSOD Crashes

Microsoft is testing a new Windows 11 feature that alerts users to scan system memory following a blue screen of death (BSOD) crash. The prompt appears upon the next login, aiming to help users detect potential hardware or software issues that may have triggered the system failure. The initiative signals Microsoft to prompt memory diagnostics […]

ChatGPT Atlas Tool Exposes Users to Prompt Injection Risks

Security researchers have identified a new method for prompt injection attacks using the address bar in OpenAI’s ChatGPT Atlas Tool Exposes. According to findings, a prompt concealed as a URL can deceive users into unknowingly copying and pasting malicious instructions into the AI interface. This tactic creates a potential entry point for attackers to manipulate […]

Microsoft WSUS Exploits Hit Multiple Firms, Google Says

Google has issued a warning that attackers are actively exploiting Microsoft WSUS vulnerabilities to compromise multiple organizations. The tech giant’s threat intelligence team observed a wave of intrusions targeting Windows Server Update Services, a tool used to manage and distribute Microsoft software updates across enterprise environments. Threat actors appear to be leveraging flaws in the […]