New VMScape attack breaks guest-host isolation on AMD, Intel CPUs
A new Spectre-like attack dubbed VMScape allows a malicious virtual machine (VM) to leak cryptographic keys from an unmodified QEMU hypervisor process running on modern AMD or Intel CPUs. The attack breaks the isolation between VMs and the cloud hypervisor, bypassing existing Spectre mitigations and threatening to leak sensitive data by leveraging speculative execution. The […]
DDoS defender targeted in 1.5 Bpps denial-of-service attack
A DDoS mitigation service provider in Europe was targeted in a massive distributed denial-of-service attack that reached 1.5 billion packets per second. The attack originated from thousands of IoTs and MikroTik routers, and it was mitigated by FastNetMon, a company that offers protection against service disruptions. āThe attack reached 1.5 billion packets per second (1.5 Gpps) ā one […]
Microsoft waives fees for Windows devs publishing to Microsoft Store
Microsoft announced that, starting today, individual Windows developers will no longer have to pay for publishing their applications on the Microsoft Store. The company said that developers can now submit Win32 (including .NET WPF and WinForms), UWP, PWA, .NET MAUI, or Electron apps to the Microsoft Store without paying any registration fees. Redmond will also […]
Hackers left empty-handed after massive NPM supply-chain attack
The largest supply-chain compromise in the history of the NPM ecosystem has impacted roughly 10% of all cloud environments, but theĀ attackerĀ made little profit off it. The attackĀ occurredĀ earlier this weekĀ after maintainer Josh Junon (qix) fell for a password reset phishing lureĀ and compromised multiple highly popular NPM packages, among themĀ chalkĀ andĀ degub-js,Ā that cumulatively have more thanĀ 2.6 billion weekly downloads. […]
Pixel 10 fights AI fakes with new Android photo verification tech
Google is integrating C2PA Content Credentials into the Pixel 10 camera and Google Photos, to help users distinguish between authentic, unaltered images and those generated or edited with artificial intelligence technology. The American company notes that the problem of labeling synthetic media has become bigger in recent years as traditional approaches are no longer suitable […]
Cursor AI editor lets repos āautorunā malicious code on devices
A weakness in the Cursor code editor exposes developers to the risk of automatically executing tasks in a malicious repository as soon as itās opened. Threat actors can exploit the flaw to drop malware, hijack developer environments, or steal credentials and API tokens, without developers having to execute any commands. CursorĀ is an AI-poweredĀ Integrated Development Environment (IDE) built […]
Jaguar Land Rover confirms data theft after recent cyberattack
Jaguar Land Rover (JLR) confirmed today that attackers also stole “some data” during a recent cyberattack that forced it to shut down systems and instruct staff not to report to work. JRL functions as a standalone entity under Tata Motors India after its purchase from Ford in 2008. With an annual revenue of over $38 billion (Ā£29 […]
Microsoft fixes streaming issues triggered by Windows updates
Microsoft has resolved severe lag and stuttering issues with NDI streaming software affecting Windows 10 and Windows 11 systems after installing the August 2025 security updates. The company confirmed these problems after receiving widespread reports from users who experienced a range of performance issues while using various streaming apps, including OBS (Open Broadcast Software) and NDI Tools. “Severe stuttering, lag, and choppy audio/video might […]
Microsoft fixes app install issues caused by August Windows updates
Microsoft has fixed a known issue caused by the August 2025 security updates, which triggers unexpected User Account Control (UAC) prompts and app installation problems for non-admin users on all Windows versions. This issue is caused by a security patch that mitigates a Windows Installer privilege escalation vulnerability (CVE-2025-50173), which can enable authenticated attackers to […]
U.S. sanctions cyber scammers who stole billions from Americans
The U.S. Department of the Treasury has sanctioned several large networks of cyber scam operations in Southeast Asia, which stole over $10 billion from Americans last year. These operations, mainly those in Burma and Cambodia,Ā are notoriousĀ for using forced labor, human trafficking, and physical violence, essentially operating as modern slavery farms that conduct online fraud. The […]