Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
Notepad++ Supply Chain Attack: Lotus Blossom APT Deploys Chrysalis Backdoor
Recent investigations by Rapid7 have revealed a significant supply chain attack against the Notepad++ update infrastructure, attributed to the Chinese‑speaking ...
GlassWorm Malware Hidden in Open VSX Extensions: Supply Chain Attack Targets VS Code Developers
On 30 January 2026, the Open VSX marketplace faced a notable software supply chain attack: four Visual Studio Code extensions ...
MongoDB Ransomware Attacks: Exposed Databases Wiped and Held for Bitcoin
MongoDB instances exposed directly to the internet are once again being hit by automated ransomware campaigns. Attackers are systematically scanning ...
MongoDB Ransomware Attacks: Exposed Databases Wiped and Held for Bitcoin
MongoDB instances exposed directly to the internet are once again being hit by automated ransomware campaigns. Attackers are systematically scanning ...
Chat & Ask AI Data Breach: Firebase Misconfiguration Exposes Millions of Private AI Chats
A large-scale data exposure incident has hit Chat & Ask AI, a popular generative AI application with around 50 million ...
Critical OpenClaw RCE Vulnerability and Moltbook Data Exposure Expose AI Agent Security Risks
Two recent security incidents involving the OpenClaw AI agent platform (previously known as ClawdBot and Moltbot) and its companion service ...
Microsoft to Disable NTLM by Default in Windows: Enterprise Authentication Enters a New Era
Microsoft has announced a fundamental change in Windows authentication: in upcoming client and server releases, the NTLM (New Technology LAN ...
Notepad++ Supply Chain Attack: What Happened and How to Protect Software Updates
In 2025, the popular text editor Notepad++ became the target of a sophisticated software supply chain attack. Attackers did not ...
New ClickFix Campaign Uses Fake CAPTCHA, App‑V and PNG Steganography to Deploy Amatera Infostealer
Researchers at BlackPoint Cyber have documented a technically sophisticated malware campaign that combines ClickFix social engineering, a fake CAPTCHA page ...
Ex-Google Engineer Convicted for Stealing AI Infrastructure Trade Secrets for China
A US federal jury has convicted former Google engineer Linwei (Leon) Ding of stealing confidential information about Google’s artificial intelligence ...