Normal view
Malicious MoltBot skills used to push password-stealing malware
CTM360 Report Warns of Global Surge in Fake High-Yield Investment Scams
Notepad++ update feature hijacked by Chinese state hackers for months
Open VSX Publisher Account Hijacked in Fresh GlassWorm Attack
A hacker published malicious versions of four established VS Code extensions to distribute a GlassWorm malware loader.
The post Open VSX Publisher Account Hijacked in Fresh GlassWorm Attack appeared first on SecurityWeek.
Panera Bread breach impacts 5.1 million accounts, not 14 million customers
NationStates confirms data breach, shuts down game site
Notepad++ Supply Chain Hack Conducted by China via Hosting Provider
The likely state-sponsored threat actor had access to the hosting provider for months and targeted only certain Notepad++ customers.
The post Notepad++ Supply Chain Hack Conducted by China via Hosting Provider appeared first on SecurityWeek.
-
Data and computer security | The Guardian

- Why should renters like me have to trade away our privacy just to get a roof over our heads? | Samantha Floreani
Why should renters like me have to trade away our privacy just to get a roof over our heads? | Samantha Floreani
The rise in real estate tech means renters often hand over huge amounts of revealing information to digital third parties β at great risk
Get our breaking news email, free app or daily news podcast
Would you trade your data privacy and security for housing? Thanks to the rise in real estate technologies, renters often have no choice but to hand over huge amounts of revealing information to digital third parties just to have somewhere to live. All the while we are told: trust us, we take your privacy seriously.
But recent Guardian reporting has revealed that seven popular βrent-techβ platforms have serious security vulnerabilities, leaving millions of documents containing personal information of renters exposed on the open web for years. When they were alerted to the risk, only two of the seven companies responded to say they would put additional security measures in place. Is this what taking renter privacy seriously looks like?
Continue reading...
Β© Photograph: Jacob Wackerhausen/Getty Images

Β© Photograph: Jacob Wackerhausen/Getty Images

Β© Photograph: Jacob Wackerhausen/Getty Images
Exposed MongoDB instances still targeted in data extortion attacks
New Apple privacy feature limits location tracking on iPhones, iPads
CrowdStrike to Acquire Seraphic to Secure Work in Any Browser
-
Data and computer security | The Guardian

- Real estate agents in Australia using apps that leave millions of lease documents at risk, digital researcher says
Real estate agents in Australia using apps that leave millions of lease documents at risk, digital researcher says
Exclusive: βThis is a blatant and disturbing disregard for the law and for peopleβs security,β digital rights advocate says
Get our breaking news email, free app or daily news podcast
Australian platforms used by real estate agents to upload documentation for renters and landlords are leaving peopleβs personal information exposed in hyperlinks accessible online.
An analysis of seven rent platforms provided to Guardian Australia by a researcher, who wished to remain anonymous, revealed millions of leasing documents could be accessed by threat actors.
Continue reading...
Β© Photograph: Carly Earl/The Guardian

Β© Photograph: Carly Earl/The Guardian

Β© Photograph: Carly Earl/The Guardian
CrowdStrike to Acquire Seraphic to Secure Work in Any Browser
Vulnerability & Patch Roundup β January 2026
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises.
To help educate website owners about potential threats to their environments, weβve compiled a list of important security updates and vulnerability patches for the WordPress ecosystem this past month.
The vulnerabilities listed below are virtually patched by the Sucuri Firewall and existing clients are protected.
Continue reading Vulnerability & Patch Roundup β January 2026 at Sucuri Blog.
U.S. convicts ex-Google engineer for sending AI tech data to China
Cloud storage payment scam floods inboxes with fake renewals
Mandiant details how ShinyHunters abuse SSO to steal cloud data
eScan Antivirus Delivers Malware in Supply Chain Attack
Hackers compromised a MicroWorld Technologies update server and fed a malicious file to eScan customers.
The post eScan Antivirus Delivers Malware in Supply Chain Attack appeared first on SecurityWeek.
