loader image
Fake Chrome Extensions Mimic Fortinet to Steal Data

A malicious campaign targeting Google Chrome users is leveraging more than 100 fake browser extensions to steal data and execute remote commands. The extensions, available through the Chrome Web Store, masquerade as legitimate services including Fortinet security tools, YouTube utilities, VPNs, AI assistants, and cryptocurrency platforms. Once installed, the extensions covertly exfiltrate browser cookies and […]

ChatGPT Flaw Exposes Users to Malicious Image Attacks

A newly disclosed vulnerability in OpenAI’s ChatGPT platform allows attackers to embed malicious SVG and image files into shared conversations, exposing users to cross-site scripting (XSS) attacks, phishing schemes and potentially harmful visual content. Tracked as CVE-2025-43714, the flaw affects the system through March 30, 2025. Security researchers found that ChatGPT improperly renders SVG files […]

Unimed Data Leak Exposes 14 Million Patient Chats

Unimed, the world’s largest healthcare cooperative based in Brazil, exposed at least 14 million patient-doctor communications due to a misconfiguration in its data infrastructure, Cybernews reported. The breach occurred through an unsecured deployment of Apache Kafka, an open-source platform used for real-time data transmission. The leaked data included conversations between patients and healthcare professionals, as […]

Mozilla Blocks Firefox Add-Ons That Steal Crypto

Mozilla has introduced a new security mechanism aimed at strengthening protections against malicious browser extensions in Firefox. The system is designed to detect and block add-ons that attempt to drain cryptocurrency wallets, a growing threat in the digital asset space. The feature has been integrated into Mozilla’s add-on portal, where users download and manage Firefox […]

Fake CAPTCHA Lures Users Into Running Malware Code

A new malware campaign is leveraging fake browser verification prompts to trick users into executing malicious code, cybersecurity researchers have found. The attack mimics Google’s “I’m not a robot” CAPTCHA system, but instead of clicking images, users are instructed to perform keyboard commands such as pressing Windows + R, Ctrl + V, and Enter. Unbeknownst […]

AT&T Data Breach Exposes 86 Million SSNs, Emails

Hackers have leaked a database containing personal records of 86 million AT&T customers, including decrypted Social Security Numbers, according to reports circulating online. The exposed data appears to include names, addresses, phone numbers, dates of birth and the decrypted SSNs of individuals tied to the U.S. telecom giant. The breach, believed to be one of […]

Windows Servers Exposed to Critical RDP Code Flaw

A critical vulnerability in Microsoft’s Remote Desktop Services, tracked as CVE-2025-32710, could allow unauthenticated attackers to execute arbitrary code remotely, the company disclosed on June 10. The flaw, rated 8.1 on the CVSS scale, affects a broad range of Windows Server versions from 2008 through 2025. The bug stems from a use-after-free condition combined with […]

INTERPOL Busts 20,000 Malicious IPs in Global Sweep

Interpol said it has dismantled more than 20,000 malicious internet addresses and domains tied to 69 strains of information-stealing malware, as part of a coordinated global crackdown on cybercrime. The operation, dubbed Operation Secure, ran from January through April 2025 and involved law enforcement agencies from 26 countries. Authorities worked together to identify the malicious […]

Mainline, Select Medical Breaches Hit 100,000 People

Mainline Health and Select Medical Holdings have reported separate data breaches that compromised the personal information of more than 100,000 individuals. The Mainline Select Medical breaches mark a growing trend of cybersecurity incidents targeting healthcare providers, raising concerns about data protection in the sector. Both organizations confirmed the incidents but have not disclosed the specific […]

EDRi Blasts EU Plan for Expanded Data Retention Rules

The European Digital Rights (EDRi) network voiced strong opposition last week to the European Commission’s proposed rules on data retention. In a joint response, EDRi blasts EU plans to expand the mandatory retention of user data by service providers, citing risks to privacy and civil liberties. The group raised concerns about the absence of proportional […]

Councils Face Tech Turmoil in Government Shake-Up

Councils undergoing structural reorganisation encounter a complex set of digital, data and technology hurdles. As administrative boundaries shift and service models evolve, councils face tech turmoil that threatens to derail integration efforts. These challenges include consolidating legacy systems, aligning data standards and managing cybersecurity risks. Despite the disruption, technology leaders see opportunities to modernize infrastructure […]

iHeartRadio Stations Breached, Data Exposed in Hack

Several radio stations operated by iHeartMedia suffered a data breach in December, exposing sensitive personal information including Social Security numbers and financial data. The breach affected multiple stations under the iHeartRadio brand, one of the largest radio networks in the United States. Details regarding the specific number of individuals impacted or the method by which […]