Millions of (very) private chats exposed by two AI companion apps | Malware

Cybernews discovered how two AI companion apps, Chattee Chat and GiMe Chat, exposed millions of intimate conversations from over 400,000 users. This is not the first time we have to…

Read more

What Sets Top-Tier Platforms Apart? | Cybersecurity

The SOC of 2026 will no longer be a human-only battlefield. As organizations scale and threats evolve in sophistication and velocity, a new generation of AI-powered agents is reshaping how…

Read more

CL0P-Linked Hackers Breach Dozens of Organizations Through Oracle Software Flaw | Cybersecurity

Oct 10, 2025Ravie LakshmananVulnerability / Threat Intelligence Dozens of organizations may have been impacted following the zero-day exploitation of a security flaw in Oracle’s E-Business Suite (EBS) software since August…

Read more

Your passwords don’t need so many fiddly characters, NIST says | Malware

It’s once again time to change your passwords, but if one government agency has its way, this might be the very last time you do it. After nearly four years…

Read more

One stolen iPhone uncovered a network smuggling thousands of devices to China | Malware

If you think Apple’s ‘Find My’ feature was just there to help you locate your phone when it slipped down the side of the couch, think again. It turns out…

Read more

Fake VPN and streaming app drops malware that drains your bank account | Malware

Security researchers are warning Android users to delete a fake VPN and streaming app that can let criminals take over their phones and drain their bank accounts. The app, Mobdro…

Read more

The Evolution of UTA0388’s Espionage Malware | Cybersecurity

Oct 09, 2025Ravie LakshmananCyber Espionage / Artificial Intelligence A China-aligned threat actor codenamed UTA0388 has been attributed to a series of spear-phishing campaigns targeting North America, Asia, and Europe that…

Read more

New ClayRat Spyware Targets Android Users via Fake WhatsApp and TikTok Apps | Cybersecurity

Oct 09, 2025Ravie LakshmananMobile Security / Malware A rapidly evolving Android spyware campaign called ClayRat has targeted users in Russia using a mix of Telegram channels and lookalike phishing websites…

Read more

California just put people back in control of their data | Malware

California’s 2025 legislative session closed with 14 new privacy and AI-related bills. We’d like to highlight a few of the most relevant signed bills and encourage other states and countries…

Read more

AI Becomes Russia’s New Cyber Weapon in War on Ukraine | Cybersecurity

Oct 09, 2025Ravie LakshmananArtificial Intelligence / Malware Russian hackers’ adoption of artificial intelligence (AI) in cyber attacks against Ukraine has reached a new level in the first half of 2025…

Read more

Is your computer mouse eavesdropping on you? | Malware

The short answer is: probably not, but theoretically it’s possible. Researchers at the University of California found a method they called Mic-E-Mouse, which turns your computer mouse into a spy…

Read more

Hackers Exploit WordPress Sites to Power Next-Gen ClickFix Phishing Attacks | Cybersecurity

Cybersecurity researchers are calling attention to a nefarious campaign targeting WordPress sites to make malicious JavaScript injections that are designed to redirect users to sketchy sites. “Site visitors get injected…

Read more

Modeling scams see mature models as attractive new prospects | Malware

The BBC reported on modeling scams targeting older models. Modeling scams aren’t new, but it’s worth looking at how they spread today, how to spot them, and—most importantly—how to avoid…

Read more

Step Into the Password Graveyard… If You Dare (and Join the Live Session) | Cybersecurity

Oct 08, 2025The Hacker NewsPassword Security / Cyber Attacks Every year, weak passwords lead to millions in losses — and many of those breaches could have been stopped. Attackers don’t…

Read more

“Can you test my game?” Fake itch.io pages spread hidden malware to gamers | Malware

You get a message from a Discord friend. Or maybe an unknown indie developer reaches out to you. “Can you test my game?” they ask.  The webpage they send over…

Read more

Embedding AI to Cut Noise and Reduce Risk | Cybersecurity

Artificial intelligence is reshaping cybersecurity on both sides of the battlefield. Cybercriminals are using AI-powered tools to accelerate and automate attacks at a scale defenders have never faced before. Security…

Read more

Discord warns users after data stolen in third-party breach | Malware

Popular social platform Discord has suffered a data breach—though technically, it wasn’t Discord itself that was hacked. A third-party customer support provider was compromised, allowing attackers to access Discord’s user…

Read more

Don’t connect your wallet: Best Wallet cryptocurrency scam is making the rounds | Malware

Phishers and scammers can’t get enough of sending their feeble attempts to Malwarebytes’ employees. For which we can’t thank them enough because it means we can warn you, our readers….

Read more

BatShadow Group Uses New Go-Based ‘Vampire Bot’ Malware to Hunt Job Seekers | Cybersecurity

Oct 07, 2025Ravie LakshmananMalware / Threat Intelligence A Vietnamese threat actor named BatShadow has been attributed to a new campaign that leverages social engineering tactics to deceive job seekers and…

Read more

Troops and veterans’ personal information leaked in CPAP Medical data breach | Malware

In December 2024, CPAP Medical Supplies and Services Inc. (CPAP), a Jacksonville—a Florida-based provider of sleep therapy services and CPAP machines—experienced a cybersecurity incident that compromised the personal data of…

Read more

AI Is Already the #1 Data Exfiltration Channel in the Enterprise | Cybersecurity

For years, security leaders have treated artificial intelligence as an “emerging” technology, something to keep an eye on but not yet mission-critical. A new Enterprise AI and SaaS Data Security…

Read more

Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks | Cybersecurity

Oct 07, 2025Ravie LakshmananCyber Attack / Ransomware CrowdStrike on Monday said it’s attributing the exploitation of a recently disclosed security flaw in Oracle E-Business Suite with moderate confidence to a…

Read more

How to set up two-factor authentication (2FA) on your Facebook account | Malware

While two-factor authentication (2FA) is not completely fool-proof, it is one of the best ways to protect your accounts from hackers. It adds an extra step when logging in, which…

Read more

Phishers target 1Password users with convincing fake breach alert | Malware

In a very recent and well-targeted phishing attempt, scammers tried to get hold of the 1Password credentials belonging to a Malwarebytes’ employee. Stealing someone’s 1Password login would be like hitting…

Read more

New Report Links Research Firms BIETA and CIII to China’s MSS Cyber Operations | Cybersecurity

Oct 06, 2025Ravie LakshmananNetwork Security / Cyber Espionage A Chinese company named the Beijing Institute of Electronics Technology and Application (BIETA) has been assessed to be likely led by the…

Read more

What’s there to save about social media? (Lock and Code S06E20) | Malware

This week on the Lock and Code podcast… “Connection” was the promise—and goal—of much of the early internet. No longer would people be separated from vital resources and news that…

Read more

5 Critical Questions For Adopting an AI Security Solution | Cybersecurity

In the era of rapidly advancing artificial intelligence (AI) and cloud technologies, organizations are increasingly implementing security measures to protect sensitive data and ensure regulatory compliance. Among these measures, AI-SPM…

Read more

A week in security (September 29 – October 5) | Malware

October 3, 2025 – After posting children’s photos online and issuing ransom demands, cybercriminals targeting Kido nurseries say they’ve erased the stolen data. October 2, 2025 – Meta has announced…

Read more

Zimbra Zero-Day Exploited to Target Brazilian Military via Malicious ICS Files | Cybersecurity

Oct 06, 2025Ravie LakshmananEmail Security / Zero-Day A now patched security vulnerability in Zimbra Collaboration was exploited as a zero-day earlier this year in cyber attacks targeting the Brazilian military….

Read more

One Click Can Turn Perplexity’s Comet AI Browser Into a Data Thief | Cybersecurity

Oct 04, 2025Ravie LakshmananAgentic AI / Enterprise Security Cybersecurity researchers have disclosed details of a new attack called CometJacking targeting Perplexity’s agentic AI browser Comet by embedding malicious prompts within…

Read more