Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
Stealth Nginx Traffic Hijacking Campaign Exploits React2Shell and Baota Servers
Datadog Security Labs has reported a large-scale malicious campaign in which attackers gain access to Nginx servers and silently route ...
Substack Data Breach: Emails, Phone Numbers and Account Metadata Exposed
Substack has notified users of a data breach in which email addresses, phone numbers and internal account metadata were exposed ...
Open VSX Introduces Pre-Publication Security Scanning for VS Code Extensions
The Open VSX extension registry, maintained by the Eclipse Foundation, is introducing automated, pre-publication security scanning for Visual Studio Code ...
Metro4Shell (CVE-2025-11953): Critical React Native Metro Server Vulnerability Exploited in the Wild
The critical vulnerability CVE-2025-11953, informally dubbed Metro4Shell, is being actively abused to compromise React Native development environments. Attackers are exploiting ...
Nitrogen Ransomware Bug on VMware ESXi Makes Data Recovery Impossible
A critical implementation error in Nitrogen ransomware targeting VMware ESXi hosts effectively converts each attack into a data‑wiping event rather ...
Incognito Darknet Marketplace Admin Rui‑Siang Lin Sentenced to 30 Years: A Critical Case for Cybercrime and Dark Web Security
A U.S. federal court has handed down one of the harshest sentences to date for online drug trafficking: 24‑year‑old Taiwanese ...
Legion Winlocker: Fake Ransomware Linked to NyashTeam Targets Gamers and Home Users
At the end of 2025, analysts at F6 identified a malicious program that did not fit typical modern ransomware patterns. ...
OpenClaw AI Agents Targeted by Malicious Skills and Early Prompt Worms
The open‑source local AI assistant ecosystem OpenClaw (formerly Moltbot and ClawdBot) has rapidly evolved from a hobby project into a ...
APT28 Exploits Microsoft Office CVE-2026-21509 Zero-Day in Targeted European Attacks
Within days of Microsoft releasing an emergency security update for Microsoft Office, the Russian-linked threat group APT28 (also known as ...
France Targets X and Grok AI Over Illegal Content and Cybercrime Concerns
French law-enforcement authorities have searched the Paris office of social network X as part of a wide‑ranging criminal investigation into ...