glassworm malware is back in circulation after security researchers discovered three new malicious VSCode extensions on the OpenVSX marketplace. These uploads revived the same threat operators that earlier distributed harmful extensions before their takedown. The new campaign uses updated techniques, stronger persistence, and stealthier exfiltration methods, raising concerns about the safety of open development ecosystems.…
Malicious NuGet packages have raised fresh alarm across the developer ecosystem after security researchers revealed that several uploads contained disruptive time-bomb scripts. These packages executed destructive commands after a delay, causing corruption, system instability, and workflow interruptions. The incident highlights an urgent need for stronger supply-chain security in software development environments that rely on open…
Electric bus security now sits at the center of a national review in Denmark after regulators flagged potential risks in Chinese-made public transport vehicles. Authorities want to determine how remote-management functions, software access routes, and connected subsystems may expose the country’s bus network to cyber-physical threats. This examination reflects a growing global concern about modern…
The RTV Noord hack has disrupted operations at the Dutch regional broadcaster and prompted an investigation into possible involvement by the Rhysida ransomware gang. The newsroom experienced technical outages that affected digital systems, internal workflows, and production tools. While the broadcaster continues to restore services, investigators evaluate evidence that suggests a targeted cyberattack against the…
The Rockstar layoffs leaks controversy has escalated after the studio removed more than 30 employees and claimed they shared confidential information in public forums. The company states that the dismissals followed an internal review that confirmed multiple policy violations involving sensitive material. However, labour representatives argue the firings align with union-organising efforts, creating a clash…
The Oracle EBS breach has emerged as a critical factor in a recent cyberattack that targeted internal systems at The Washington Post. New research links the intrusion to a zero-day vulnerability in Oracle’s widely used enterprise suite. The Clop ransomware group exploited this flaw during an operation that affected multiple organizations. The findings highlight the…
The Rhysida data leak reveals significant operational and financial exposure inside Gemini Group, a major supplier operating across several industries. The ransomware gang published large volumes of internal records after the company refused to meet payment demands. The leaked data includes sensitive documents, financial reports, internal communications, and technical materials. The incident highlights ongoing risks…
The Gootloader malware returned after a seven-month hiatus and began a new campaign with enhanced tactics. Security teams observed attacker-controlled sites ranking high in search engines to deliver malicious files. These sites mimic legitimate document templates and drive victims toward downloads that initiate the attack chain. The malware’s comeback signals a renewed risk for both…
A critical CentOS Web Panel bug is now under active exploitation, prompting a new alert from the U.S. Cybersecurity and Infrastructure Security Agency. Attackers target exposed servers running outdated versions of the control panel, which powers thousands of Linux-based web hosting environments. CISA added the flaw to its Known Exploited Vulnerabilities catalog and urged administrators…