❌

Normal view

Critical React Native Metro dev server bug under attack as researchers scream into the void

3 February 2026 at 20:01

Too slow react-ion time

Baddies are exploiting a critical bug in React Native's Metro development server to deliver malware to both Windows and Linux machines, and yet the in-the-wild attacks still haven't received the "broad public acknowledgement" that they should, according to security researchers.…

Notepad++ hijacking blamed on Chinese Lotus Blossom crew behind Chrysalis backdoor

3 February 2026 at 00:23

The group targets telecoms, critical infrastructure - all the usual high-value orgs

Security researchers have attributed the Notepad++ update hijacking to a Chinese government-linked espionage crew called Lotus Blossom (aka Lotus Panda, Billbug), which abused weaknesses in the update infrastructure to gain a foothold in high-value targets by delivering a newly identified backdoor dubbed Chrysalis.…

StopICE hacked to send alarming text messages, admins accuse border patrol agent of sabotage

2 February 2026 at 20:16

The ICE-tracking service says it doesn't store usernames or addresses

ICE-reporting service StopICE has blamed a US Customs and Border Protection (CBP) agent for attacking its app and website and sending users text messages warning them that their information had been "sent to the authorities."…

Thousands more Oregon residents learn their health data was stolen in TriZetto breach

30 January 2026 at 19:32

Parent company Cognizant hit with multiple lawsuits

Thousands more Oregonians will soon receive data breach letters in the continued fallout from the TriZetto data breach, in which someone hacked the insurance verification provider and gained access to its healthcare provider customers across multiple US states.…

Let them eat sourdough: ShinyHunters claims Panera Bread as stolen credentials victim

27 January 2026 at 20:49

Plus, the gang says it got in via Microsoft Entra SSO

ShinyHunters says it stole several slices of data from Panera Bread, but that's just the yeast of everyone's problems. The extortionist gang also claims to have stolen data from CarMax and Edmunds, in addition to three other organizations it posted to its blog last week.…

Feds totally skipping infosec industry's biggest conference this year

24 January 2026 at 01:22

But ex-CISA boss and new RSAC CEO Jen Easterly will be there

updatedΒ  The US Cybersecurity and Infrastructure Security Agency won't attend the annual RSA Conference in March, an agency spokesperson confirmed to The Register. Sessions involving speakers from the FBI and National Security Agency (NSA) have also disappeared from the agenda.…

Crims compromised energy firms' Microsoft accounts, sent 600 phishing emails

22 January 2026 at 20:18

Logging in, not breaking in

Unknown attackers are abusing Microsoft SharePoint file-sharing services to target multiple energy-sector organizations, harvest user credentials, take over corporate inboxes, and then send hundreds of phishing emails from compromised accounts to contacts inside and outside those organizations.…

Don't click on the LastPass 'create backup' link - it's a scam

21 January 2026 at 19:10

Phishing campaign tries to reel in master passwords

updatedΒ  Password managers make great targets for attackers because they can hold many of the keys to your kingdom. Now, LastPass has warned customers about phishing emails claiming that action is required ahead of scheduled maintenance and told them not to fall for the scam. …

Remember VoidLink, the cloud-targeting Linux malware? An AI agent wrote it

20 January 2026 at 19:48

AI + skilled malware developers = security threat

VoidLink, the newly spotted Linux malware that targets victims' clouds with 37 evil plugins, was generated "almost entirely by artificial intelligence" and likely developed by just one person, according to the research team that discovered the do-it-all implant.…

❌