Category: Cyber Security


  • Open VSX Token Leak Triggers Emergency Security Response

    The Open VSX token leak has triggered an urgent response from the Eclipse Foundation after attackers used exposed publisher tokens to upload malicious extensions. The supply-chain incident highlights ongoing risks in developer ecosystems, where compromised credentials can turn trusted tools into delivery channels for malware. How the Incident Happened Researchers identified hundreds of exposed tokens…

  • Lanscope Flaw Exploited as Zero-Day in Targeted Attacks

    Security researchers uncovered targeted attacks that exploited a Lanscope flaw as a zero-day, allowing China-linked hackers to breach networks and deploy custom backdoors. The campaign focused on organisations running Motex Lanscope Endpoint Manager and highlights the ongoing risk posed by unpatched enterprise software. The vulnerability provided administrative control without authentication, creating a direct path to…

  • Scareware Sensor in Microsoft Edge Speeds Up Scam Detection

    Microsoft is rolling out a new scareware sensor in Edge to block fake tech-support pages faster. The browser upgrade targets scareware tactics that lock screens, trigger loud alerts, and pressure users into calling fraudulent support numbers. With this change, Edge now reacts earlier and shares signals with Microsoft’s SmartScreen system to help stop scam domains…

  • BadCandy Infections Prompt Cisco Device Warning in Australia

    BadCandy infections continue to target unpatched Cisco IOS XE devices, prompting Australian cybersecurity authorities to issue an urgent advisory. The warning highlights renewed exploitation of an earlier Cisco vulnerability that attackers still use to gain administrative access and implant persistence mechanisms. Although Cisco released patches long ago, many devices remain exposed on the public internet,…

  • Fake Luxury Domains Target Major Fashion Houses

    Luxury shoppers face a growing digital scam wave as fake luxury domains multiply online at an aggressive pace. Cybercriminals are registering lookalike sites that mimic iconic designer brands in order to deceive consumers, harvest personal data, and intercept payments. This trend intensifies around major shopping periods, where demand for premium goods sharply increases. Analysts warn…

  • UPenn email fraud incident disrupts university community

    The UPenn email fraud incident alarmed students, alumni and staff at the University of Pennsylvania. A large batch of abusive emails appeared to come from accounts connected to the Graduate School of Education. The messages reached internal and external recipients and included threats, political language and claims about data exposure. University officials say the messages…

  • Microsoft Exchange Server best practices guide pushes urgent security upgrades

    The Microsoft Exchange Server best practices guide outlines urgent steps that organizations must take to secure on-premises email systems. The document, issued by CISA alongside international cybersecurity partners, highlights the rising threat to legacy Exchange deployments and calls for immediate hardening, patching and staged decommissioning of outdated servers. With aging email infrastructure becoming a prime…

  • EU energy-grid cybersecurity forum strengthens European power resilience

    The EU energy-grid cybersecurity forum brought policymakers, power-grid operators and security experts together to reinforce protections across Europe’s interconnected electricity infrastructure. The event highlighted the growing cyber risks facing modern energy networks and stressed the need for cooperation, regulation and operational readiness. As power systems become more digitised, the continent must adapt its defences to…

  • Chromium crash bug crashes browsers in seconds

    A newly discovered Chromium crash bug can force popular browsers to freeze and shut down within seconds. Security researchers demonstrated how a specially crafted URL triggers the flaw, causing immediate instability across Chromium-based browsers. This incident highlights how one weakness in a shared open-source engine can ripple across millions of users. How the Chromium Crash…

  • Backdoor in Robot Vacuum Raises Major Smart Home Privacy Concerns

    Smart home devices promise convenience, yet they often demand a deep level of trust. A recent discovery shows why that trust can fail. An engineer uncovered a backdoor in robot vacuum hardware after his device stopped working once he blocked its suspicious data traffic. The finding reveals serious privacy and security concerns in everyday connected…