loader image
FBI Warns North Korean Hackers Using QR Codes

The FBI warns QR codes are being weaponized by North Korean hackers in a new wave of spear-phishing campaigns targeting U.S.-based organizations. In an advisory issued Thursday, federal investigators said state-sponsored actors tied to North Korea have begun embedding malicious QR codes into phishing emails aimed at compromising systems at think tanks, academic institutions, and […]

ICO Warns on Poor Agentic AI in Public Sector

The Information Commissioner’s Office (ICO) warns that poorly developed agentic AI applications in government could result in flawed decision-making and reduced public trust. The regulator raised concerns about the use of automated systems that act independently, especially without clear oversight or accountability in the public sector. In response, the ICO plans to open a consultation […]

UK Overhauls Cyber Plan, Creates Cyber Unit

The UK overhauls its cyber plan as part of a £210 million investment aimed at protecting public services from growing digital threats. As part of the initiative, authorities introduced a new Government Cyber Unit to improve coordination, bolster cyber resilience, and respond rapidly to incidents affecting critical infrastructure. The revamped Cyber Action Plan emphasizes enhanced […]

Asseco InfoMedica Plus Hit by Two Flaws

Poland’s national cybersecurity team, CERT Polska, has disclosed two newly identified vulnerabilities affecting the Asseco InfoMedica Plus software. The issues, tracked as CVE-2025-8306 and CVE-2025-8307, emerged following an external report that prompted further analysis by the agency. Both vulnerabilities could pose a risk to users of the healthcare-focused application, though details surrounding their technical implications […]

Fake ChatGPT Extensions Spied on 1M Chrome Users

Malicious actors have exploited fake ChatGPT extensions and counterfeit DeepSeek tools to spy on more than one million Google Chrome users, according to cybersecurity researchers. These extensions, disguised as legitimate AI-related tools, secretly collected user data once installed, compromising privacy under the guise of enhancing browser functionality. The deceptive add-ons appeared on the Chrome Web […]

NodeCordRAT Uses Discord to Steal Chrome Data

A malicious tool dubbed NodeCordRAT uses Discord as a command-and-control platform to exfiltrate sensitive browser data. According to cybersecurity researchers, the remote access trojan targets victims through compromised NPM packages, primarily aiming to extract information from Google Chrome, such as login credentials, browsing activity and authentication tokens. Distributed through seemingly legitimate JavaScript libraries, the malware […]

ChatGPT Health Prompts Privacy Alarm

OpenAI’s new health-focused feature has sparked a wave of concern among privacy advocates. The company encouraged users to link personal medical records and wellness app data through the latest ChatGPT health prompts, saying this would deliver more personalized support. In a recent blog post, OpenAI assured users that it added enhanced data privacy protections to […]

Logitech Gear Stops on Mac After Certificate Lapse

A growing number of Mac users report that their Logitech gear stops functioning properly due to an expired software certificate. Keyboards and mice suddenly lose compatibility, and users notice missing customizations and input interruptions. The issue affects devices connected via both USB receivers and Bluetooth. Logitech’s Options and Options+ software, which typically manages customization features, […]

CISA Flags HPE OneView Flaw as Actively Exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) flags a high-severity HPE OneView vulnerability as being actively exploited in the wild, raising concerns for organizations using the infrastructure management platform. The agency added the flaw to its Known Exploited Vulnerabilities catalog, a list that prioritizes weaknesses currently targeted by malicious actors. HPE OneView, used to […]

OpenAI Rolls Out GPT-5.2 Codex-Max

OpenAI rolls out GPT-5.2 “Codex-Max” to a select group of users as part of a testing phase, aiming to advance its capabilities in AI-assisted coding. The new model, described as potentially the company’s most robust coding tool to date, builds upon previous Codex versions while introducing performance enhancements that target software development tasks. The rollout […]

Chronomaly Zero-Day Lets Hackers Gain Root

A newly disclosed chronomaly zero-day lets hackers gain root access on Linux systems running certain vulnerable kernel versions, according to cybersecurity researcher farazsth98. The exploit leverages multiple security flaws that allow attackers to escalate privileges and take full control of a targeted system. Researchers linked the vulnerability to three tracked issues: CVE-2025-54322, CVE-2025-48543, and CVE-2025-38352. […]

Forcepoint Flaw Lets Attackers Escape Sandbox

A newly disclosed forcepoint flaw vulnerability in the Forcepoint One DLP Client allows attackers to escape a restricted Python environment and run arbitrary code. Identified as CVE-2025-14026, the high-severity bug undermines protections intended to sandbox user activity, raising concerns about broader data security risks. The flaw enables malicious actors to bypass constraints configured by the […]