deepseek Fake DeepSeek AI Packages on PyPI Steal Developer Credentials Threat actors exploit the popularity of DeepSeek by publishing infostealing malware disguised as developer tools on the Python Package Index. The malicious packages steal API keys and credentials before exfiltrating the data to an attacker-controlled server.
microsoft Microsoft Recall Delay Exposes Deep Windows User Privacy Fears Microsoft delays its AI-powered Recall feature after security researchers reveal critical vulnerabilities that expose user screenshots. The controversy highlights growing tension between rapid AI integration and user privacy in Windows 11.
microsoft Microsoft Delays Controversial AI Recall Feature After Security Backlash Microsoft postpones its Windows Recall feature to the Windows Insider Program following severe privacy and security criticism from experts. The company decides to gather feedback and improve safeguards before a broader public release.
cybersecurity Why Cyberattacks Play a Minor Role in the Russia-Ukraine Conflict Despite high expectations, the Russia-Ukraine war features surprisingly few major cyber operations as kinetic strikes prove more effective. Ukraine responds by mobilizing a global cyber army to target Russian infrastructure.
viasat Viasat Hack Shows Cyber Attacks Enable Physical Warfare in Ukraine A Russian-linked cyberattack on Viasat's satellite network disrupted Ukrainian communications just hours before the physical invasion began. This software supply chain attack demonstrates how adversaries use malicious code to directly support military operations.
hermeticwiper New HermeticWiper Malware Destroys Data Across Ukraine Networks A destructive data-wiping malware called HermeticWiper is currently compromising hundreds of computers in Ukraine. The attackers use ransomware as a decoy to distract victims while the malware permanently destroys their data.
hermeticwiper HermeticWiper Malware Devastates Ukrainian Systems Through Boot Records A newly discovered destructive malware known as HermeticWiper targets Ukrainian organizations by corrupting master boot records to cause complete system failure. The attackers use a fraudulently signed driver to execute the damage while deploying a fake ransomware decoy.
cisa US Agencies Update Shields Up Guidance Amid Russian Malware Threats CISA and the FBI update their Shields Up webpage with new defensive recommendations as Russian state-sponsored wiper malware targets Ukrainian organizations. Officials urge all US businesses to immediately assess and bolster their cybersecurity postures.
deepseek Attackers Target Developers With Fake DeepSeek Packages on PyPI Threat actors are exploiting the recent hype around DeepSeek by distributing malicious Python packages designed to steal sensitive data. The packages are quickly removed, but developers still face significant risks from trendy, unverified code.
cyberhaven Cyberhaven Chrome Extension Hacked in Christmas Day Supply Chain Attack Hackers compromise a Cyberhaven developer account to push a malicious Chrome extension update that steals session tokens and passwords. The company quickly removes the compromised version and urges all affected users to rotate their credentials immediately.
cybersecurity Russian Hackers Exploit Firefox and Windows Zero-Days in Broad Campaign A Russian-linked hacking group uses two new zero-day vulnerabilities to silently install malware on Firefox and Windows devices across Europe and North America. Both Mozilla and Microsoft have now released patches for the exploited flaws.
ransomware Trump Faces Record Ransomwave Threat as Cybersecurity Policy Shifts President-elect Donald Trump inherits a record-breaking ransomware crisis despite recent U.S. government disruptions against major cybercriminal networks. Industry leaders expect significant changes in cybersecurity policy as attacks continue to rise regardless of political leadership.
fbi FBI Seizes 260,000-Device Botnet Operated by Chinese State Hackers U.S. authorities take control of a massive botnet run by the Chinese hacking group Flax Typhoon to target critical infrastructure. The FBI successfully removes the malware despite attempted counterattacks from the hackers.
microsoft Microsoft Delays AI Recall Feature Amid Heavy Privacy Backlash Microsoft postpones the public preview of its Recall screenshot feature for Copilot+ PCs after facing severe criticism from security researchers and privacy advocates. The tool will now only be available to Windows Insider Program users as the company addresses significant security concerns.
mars stealer Security Startup Finds Flaw to Lock Out Mars Stealer Malware Operators Researchers discover a vulnerability that lets them remotely disable Mars Stealer servers, delete stolen data, and cut ties with infected victims. The unorthodox countermeasure permanently locks cybercriminals out of their own malicious dashboards.