Millions of (very) private chats exposed by two AI companion apps | Malware
Cybernews discovered how two AI companion apps, Chattee Chat and GiMe Chat, exposed millions of intimate conversations from over 400,000 users. This is not the first time we have to…
Read moreWhat Sets Top-Tier Platforms Apart? | Cybersecurity
The SOC of 2026 will no longer be a human-only battlefield. As organizations scale and threats evolve in sophistication and velocity, a new generation of AI-powered agents is reshaping how…
Read moreCL0P-Linked Hackers Breach Dozens of Organizations Through Oracle Software Flaw | Cybersecurity
Oct 10, 2025Ravie LakshmananVulnerability / Threat Intelligence Dozens of organizations may have been impacted following the zero-day exploitation of a security flaw in Oracle’s E-Business Suite (EBS) software since August…
Read moreYour passwords don’t need so many fiddly characters, NIST says | Malware
It’s once again time to change your passwords, but if one government agency has its way, this might be the very last time you do it. After nearly four years…
Read moreOne stolen iPhone uncovered a network smuggling thousands of devices to China | Malware
If you think Apple’s ‘Find My’ feature was just there to help you locate your phone when it slipped down the side of the couch, think again. It turns out…
Read moreFake VPN and streaming app drops malware that drains your bank account | Malware
Security researchers are warning Android users to delete a fake VPN and streaming app that can let criminals take over their phones and drain their bank accounts. The app, Mobdro…
Read moreThe Evolution of UTA0388’s Espionage Malware | Cybersecurity
Oct 09, 2025Ravie LakshmananCyber Espionage / Artificial Intelligence A China-aligned threat actor codenamed UTA0388 has been attributed to a series of spear-phishing campaigns targeting North America, Asia, and Europe that…
Read moreNew ClayRat Spyware Targets Android Users via Fake WhatsApp and TikTok Apps | Cybersecurity
Oct 09, 2025Ravie LakshmananMobile Security / Malware A rapidly evolving Android spyware campaign called ClayRat has targeted users in Russia using a mix of Telegram channels and lookalike phishing websites…
Read moreCalifornia just put people back in control of their data | Malware
California’s 2025 legislative session closed with 14 new privacy and AI-related bills. We’d like to highlight a few of the most relevant signed bills and encourage other states and countries…
Read moreAI Becomes Russia’s New Cyber Weapon in War on Ukraine | Cybersecurity
Oct 09, 2025Ravie LakshmananArtificial Intelligence / Malware Russian hackers’ adoption of artificial intelligence (AI) in cyber attacks against Ukraine has reached a new level in the first half of 2025…
Read moreIs your computer mouse eavesdropping on you? | Malware
The short answer is: probably not, but theoretically it’s possible. Researchers at the University of California found a method they called Mic-E-Mouse, which turns your computer mouse into a spy…
Read moreHackers Exploit WordPress Sites to Power Next-Gen ClickFix Phishing Attacks | Cybersecurity
Cybersecurity researchers are calling attention to a nefarious campaign targeting WordPress sites to make malicious JavaScript injections that are designed to redirect users to sketchy sites. “Site visitors get injected…
Read moreModeling scams see mature models as attractive new prospects | Malware
The BBC reported on modeling scams targeting older models. Modeling scams aren’t new, but it’s worth looking at how they spread today, how to spot them, and—most importantly—how to avoid…
Read moreStep Into the Password Graveyard… If You Dare (and Join the Live Session) | Cybersecurity
Oct 08, 2025The Hacker NewsPassword Security / Cyber Attacks Every year, weak passwords lead to millions in losses — and many of those breaches could have been stopped. Attackers don’t…
Read more“Can you test my game?” Fake itch.io pages spread hidden malware to gamers | Malware
You get a message from a Discord friend. Or maybe an unknown indie developer reaches out to you. “Can you test my game?” they ask. The webpage they send over…
Read moreEmbedding AI to Cut Noise and Reduce Risk | Cybersecurity
Artificial intelligence is reshaping cybersecurity on both sides of the battlefield. Cybercriminals are using AI-powered tools to accelerate and automate attacks at a scale defenders have never faced before. Security…
Read moreDiscord warns users after data stolen in third-party breach | Malware
Popular social platform Discord has suffered a data breach—though technically, it wasn’t Discord itself that was hacked. A third-party customer support provider was compromised, allowing attackers to access Discord’s user…
Read moreDon’t connect your wallet: Best Wallet cryptocurrency scam is making the rounds | Malware
Phishers and scammers can’t get enough of sending their feeble attempts to Malwarebytes’ employees. For which we can’t thank them enough because it means we can warn you, our readers….
Read moreBatShadow Group Uses New Go-Based ‘Vampire Bot’ Malware to Hunt Job Seekers | Cybersecurity
Oct 07, 2025Ravie LakshmananMalware / Threat Intelligence A Vietnamese threat actor named BatShadow has been attributed to a new campaign that leverages social engineering tactics to deceive job seekers and…
Read moreTroops and veterans’ personal information leaked in CPAP Medical data breach | Malware
In December 2024, CPAP Medical Supplies and Services Inc. (CPAP), a Jacksonville—a Florida-based provider of sleep therapy services and CPAP machines—experienced a cybersecurity incident that compromised the personal data of…
Read moreAI Is Already the #1 Data Exfiltration Channel in the Enterprise | Cybersecurity
For years, security leaders have treated artificial intelligence as an “emerging” technology, something to keep an eye on but not yet mission-critical. A new Enterprise AI and SaaS Data Security…
Read moreOracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks | Cybersecurity
Oct 07, 2025Ravie LakshmananCyber Attack / Ransomware CrowdStrike on Monday said it’s attributing the exploitation of a recently disclosed security flaw in Oracle E-Business Suite with moderate confidence to a…
Read moreHow to set up two-factor authentication (2FA) on your Facebook account | Malware
While two-factor authentication (2FA) is not completely fool-proof, it is one of the best ways to protect your accounts from hackers. It adds an extra step when logging in, which…
Read morePhishers target 1Password users with convincing fake breach alert | Malware
In a very recent and well-targeted phishing attempt, scammers tried to get hold of the 1Password credentials belonging to a Malwarebytes’ employee. Stealing someone’s 1Password login would be like hitting…
Read moreNew Report Links Research Firms BIETA and CIII to China’s MSS Cyber Operations | Cybersecurity
Oct 06, 2025Ravie LakshmananNetwork Security / Cyber Espionage A Chinese company named the Beijing Institute of Electronics Technology and Application (BIETA) has been assessed to be likely led by the…
Read moreWhat’s there to save about social media? (Lock and Code S06E20) | Malware
This week on the Lock and Code podcast… “Connection” was the promise—and goal—of much of the early internet. No longer would people be separated from vital resources and news that…
Read more5 Critical Questions For Adopting an AI Security Solution | Cybersecurity
In the era of rapidly advancing artificial intelligence (AI) and cloud technologies, organizations are increasingly implementing security measures to protect sensitive data and ensure regulatory compliance. Among these measures, AI-SPM…
Read moreA week in security (September 29 – October 5) | Malware
October 3, 2025 – After posting children’s photos online and issuing ransom demands, cybercriminals targeting Kido nurseries say they’ve erased the stolen data. October 2, 2025 – Meta has announced…
Read moreZimbra Zero-Day Exploited to Target Brazilian Military via Malicious ICS Files | Cybersecurity
Oct 06, 2025Ravie LakshmananEmail Security / Zero-Day A now patched security vulnerability in Zimbra Collaboration was exploited as a zero-day earlier this year in cyber attacks targeting the Brazilian military….
Read moreOne Click Can Turn Perplexity’s Comet AI Browser Into a Data Thief | Cybersecurity
Oct 04, 2025Ravie LakshmananAgentic AI / Enterprise Security Cybersecurity researchers have disclosed details of a new attack called CometJacking targeting Perplexity’s agentic AI browser Comet by embedding malicious prompts within…
Read more