loader image
Cyber Insurance Backstop Urged in Terror Law Renewals

A new report released Tuesday recommends that Congress tie the creation of a federal cyber insurance backstop to the renewal of an expiring terrorism insurance program. The Cyber Insurance Backstop Urged would aim to strengthen a lagging cyber insurance industry that experts say is not evolving quickly enough to meet growing threats. The report suggests […]

AI Arms Security Teams to Prevent, Not Just React

As the cybersecurity landscape evolves, experts urge security teams to shift their focus from crisis response to proactive prevention. In the AI era, where speed and scale define threats, AI arms security teams with tools to predict and neutralize attacks before they escalate. Traditional reactive strategies no longer suffice in a digital environment shaped by […]

NSA, CISA Urge Shift to Memory-Safe Coding Tools

The National Security Agency and the Cybersecurity and Infrastructure Security Agency released new guidance urging software developers to adopt memory safe programming languages. The NSA CISA urge shift aims to reduce vulnerabilities caused by memory-related coding errors, which often lead to exploitable security flaws in widely used software systems. The advisory emphasizes the critical role […]

ClickFunnels Probes Breach After Hackers Leak Data

ClickFunnels, a popular sales funnel builder platform, is investigating a reported data breach after hackers leaked what they claim is business-related information. The company has not yet confirmed the scope or origin of the incident but has acknowledged ongoing efforts to assess the situation. The leaked data reportedly includes internal business files, although the authenticity […]

Toronto Schools Say Hacker Kept Data After Ransom

A Toronto school district announced that sensitive data was not deleted by a hacker, despite a ransom payment and assurances that the breach had been contained. The district had previously relied on a video provided by the hacker, which appeared to show the deletion of stolen data following the payment. PowerSchool, the third-party vendor involved, […]

Google Ties LostKeys Spy Malware to Russia Hackers

Google has identified a new malware strain, dubbed LostKeys, being deployed by the Russian state-linked hacking group ColdRiver in a wave of cyberespionage attacks, according to a recent report. Since the start of the year, the group has used the malware to steal sensitive files from targets across Western governments, media organizations, think tanks, and […]

Fake AI Tools Spread Noodlophile Malware via Facebook

Cybercriminals are using fake artificial intelligence tools to distribute a new strain of malware known as Noodlophile, targeting more than 62,000 individuals through deceptive social media campaigns, according to cybersecurity researchers. Rather than using conventional phishing tactics or cracked software websites, attackers create highly convincing AI-themed platforms to lure victims. These fraudulent tools are promoted […]

Backdoored Magento Add-Ons Hit Online Retailers

A recent wave of malware infections has compromised numerous online stores using Magento, a popular e-commerce platform, following the discovery of backdoored extensions. According to researchers, the affected extensions were installed as part of a supply-chain attack that introduced malicious code into Magento-based systems. The incident highlights ongoing threats targeting third-party software components, which can […]

Chinese Hackers Hit Taiwan Drone, Military Supply Chains

A Chinese-speaking hacking group known as Earth Ammit has disrupted supply chains tied to Taiwan’s drone industry, cybersecurity researchers said. The group reportedly carried out two waves of cyber-espionage campaigns between 2023 and 2024, targeting a wide spectrum of sectors. The affected industries include military, satellite communications, heavy industry, media, technology, software services and healthcare. […]

Ukraine-Linked Hack Wipes Third of Russia Court Files

A cyberattack attributed to a pro-Ukrainian hacking group has reportedly wiped out approximately one-third of the archived case files from Pravosudiye, Russia’s national electronic court filing system, according to auditors. The breach, previously disclosed, targeted the digital infrastructure that supports the country’s judiciary, disrupting access to legal documents and court records. The attackers claimed responsibility […]

ChatGPT Leak Shows AI Tapping Outside Data via MCP

OpenAI’s ChatGPT is preparing to integrate support for the Model Context Protocol (MCP), according to a newly surfaced leak. The protocol will enable the AI chatbot to connect with third-party services, allowing it to draw on external data sources as contextual input during interactions. This capability marks a significant expansion in how ChatGPT can operate, […]

Hackers Use PWAs to Target Mobile Users in China Scam

A newly uncovered malware campaign is targeting mobile users through Progressive Web Applications (PWAs), exploiting browser protections and JavaScript to evade detection. Discovered by researchers at Cside.dev, the attack originates from China and leverages compromised Chinese-language novel websites to inject malicious code that activates only on mobile devices. The attack chain begins with users visiting […]