Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
Open VSX Introduces Pre-Publication Security Scanning for VS Code Extensions
The Open VSX extension registry, maintained by the Eclipse Foundation, is introducing automated, pre-publication security scanning for Visual Studio Code ...
Metro4Shell (CVE-2025-11953): Critical React Native Metro Server Vulnerability Exploited in the Wild
The critical vulnerability CVE-2025-11953, informally dubbed Metro4Shell, is being actively abused to compromise React Native development environments. Attackers are exploiting ...
Nitrogen Ransomware Bug on VMware ESXi Makes Data Recovery Impossible
A critical implementation error in Nitrogen ransomware targeting VMware ESXi hosts effectively converts each attack into a data‑wiping event rather ...
Incognito Darknet Marketplace Admin Rui‑Siang Lin Sentenced to 30 Years: A Critical Case for Cybercrime and Dark Web Security
A U.S. federal court has handed down one of the harshest sentences to date for online drug trafficking: 24‑year‑old Taiwanese ...
Legion Winlocker: Fake Ransomware Linked to NyashTeam Targets Gamers and Home Users
At the end of 2025, analysts at F6 identified a malicious program that did not fit typical modern ransomware patterns. ...
OpenClaw AI Agents Targeted by Malicious Skills and Early Prompt Worms
The open‑source local AI assistant ecosystem OpenClaw (formerly Moltbot and ClawdBot) has rapidly evolved from a hobby project into a ...
APT28 Exploits Microsoft Office CVE-2026-21509 Zero-Day in Targeted European Attacks
Within days of Microsoft releasing an emergency security update for Microsoft Office, the Russian-linked threat group APT28 (also known as ...
France Targets X and Grok AI Over Illegal Content and Cybercrime Concerns
French law-enforcement authorities have searched the Paris office of social network X as part of a wide‑ranging criminal investigation into ...
Notepad++ Supply Chain Attack: Lotus Blossom APT Deploys Chrysalis Backdoor
Recent investigations by Rapid7 have revealed a significant supply chain attack against the Notepad++ update infrastructure, attributed to the Chinese‑speaking ...
GlassWorm Malware Hidden in Open VSX Extensions: Supply Chain Attack Targets VS Code Developers
On 30 January 2026, the Open VSX marketplace faced a notable software supply chain attack: four Visual Studio Code extensions ...