07 Nov, 2025

Open VSX rotates access tokens used in supply-chain malware attack

The Open VSX registry rotated access tokens after they were accidentally leaked by developers in public repositories and allowed threat actors to publish malicious extensions in a supply chain attack. The leak was discovered by Wiz researchers two weeks ago, when they reported an exposure of over 550 secrets across Microsoft VSCode and Open VSX marketplaces. Some […]

3 mins read

Microsoft: Windows Task Manager won’t quit after KB5067036 update

Microsoft has confirmed a known issue that is preventing users from quitting the Windows 11 Task Manager after installing the October 2025 optional update. This comes after widespread user reports that the Task Manager continues to run in the background even after quitting the app using the “Close” button, resulting in various performance issues, including stuttering and CPU hangs. […]

3 mins read

Penn hacker claims to have stolen 1.2 million donor records in data breach

A hacker has taken responsibility for last week’s University of Pennsylvania “We got hacked” email incident, saying it was a far more extensive breach that exposed data on 1.2 million donors and internal documents. On Friday, University of Pennsylvania alumni and students began receiving multiple offensive emails from Penn.edu addresses claiming the university had been hacked and […]

3 mins read

OpenAI is going Meta route, as it considers memory-based ads on ChatGPT

OpenAI is planning to introduce ads on ChatGPT, as it continues to struggle with revenue from paid users. OpenAI, valued at about $500 billion, plans to spend billions in the coming year, but it does not have a reliable revenue source. As per the Financial Times, ChatGPT has about 800 million users, but only 5% percent […]

2 mins read

Google confirms AI search will have ads, but they may look different

Google Ads are not going anywhere. Eventually, AI Search results on Google and likely other properties will have ads. Google recently reported $56.57 billion in revenue from ads on Search and YouTube. You obviously can’t expect ads to disappear from its search business. Right now, Google has two AI features. The first is AI Overviews, which appears at […]

2 mins read

Windows 11 Build 26220.7051 released with “Ask Copilot” feature

Windows 11 Build 26220.7051 is now rolling out to testers in the Insider Program, and there are at least three new features, including Ask Copilot on the taskbar. Up until now, you could access Copilot on Windows 11 via the app or browser, but now you can use a new taskbar-based ‘Ask Copilot’ to interact with […]

2 mins read

China-linked hackers exploited Lanscope flaw as a zero-day in attacks

China-linked cyber-espionage actors tracked as ‘Bronze Butler’ (Tick) exploited a Motex Lanscope Endpoint Manager vulnerability as a zero-day to deploy an updated version of their Gokcpdoor malware. The discovery of this activity comes from Sophos researchers, who observed the threat actors exploiting the vulnerability in mid-2025 before it was patched to steal confidential information. The flaw […]

2 mins read

Windows 11 tests shared Bluetooth audio support, but only for AI PCs

If you have two headphones, speakers, or any other Bluetooth hardware, you can now share audio between the two devices simultaneously on a Copilot+ PC. Microsoft is testing a new feature called “shared audio,” which is built on top of Bluetooth LE Audio broadcast technology. With Bluetooth LE Audio broadcast technology, Windows can now transmit an audio stream to […]

2 mins read

‘We got hacked’ emails threaten to leak University of Pennsylvania data

The University of Pennsylvania suffered a cybersecurity incident on Friday, where students and alumni received a series of offensive emails from various University email addresses, claiming that data was stolen in a breach. The emails have a subject line of “We got hacked  (Action Required)” and claim that data was stolen during an alleged breach, also […]

2 mins read

Australia warns of BadCandy infections on unpatched Cisco devices

The Australian government is warning about ongoing cyberattacks against unpatched Cisco IOS XE devices in the country to infect routers with the BadCandy webshell. The vulnerability exploited in these attacks is CVE-2023-20198, a max-severity flaw that allows remote unauthenticated threat actors to create a local admin user via the web user interface and take over […]

2 mins read