News
October 8, 2025 • 1 min read • Hackernews
Hackers Exploit WordPress Sites to Power Next-Gen ClickFix Phishing Attacks
Cybersecurity researchers are calling attention to a nefarious campaign targeting WordPress sites to make malicious JavaScript injections that are designed to redirect users to sketchy sites. Site visitors get injected content that was drive-by malware like fake Cloudflare verification, Sucuri researcher Puja Srivastava said in an analysis published last week. The website
October 8, 2025 • 1 min read • theVerge
The problems with AI in the smart home
October 8, 2025 • 1 min read • theVerge
Microsoft is moving GitHub over to Azure servers
October 8, 2025 • 1 min read • theVerge
Google8217s AI try-on imagines your feet in new shoes
October 8, 2025 • 1 min read • Hackernews
Chinese Hackers Weaponize Open-Source Nezha Tool in New Attack Wave
Threat actors with suspected ties to China have turned a legitimate open-source monitoring tool called Nezha into an attack weapon, using it to deliver a known malware called Gh0st RAT to targets. The activity, observed by cybersecurity company Huntress in August 2025, is characterized by the use of an unusual technique
October 8, 2025 • 1 min read • Hackernews
Step Into the Password Graveyard If You Dare and Join the Live Session
Every year, weak passwords lead to millions in losses — and many of those breaches could have been stopped. Attackers don’t need advanced tools; they just need one careless login. For IT teams, that means endless resets, compliance struggles, and sleepless nights worrying about the next credential leak. This Halloween, The Hacker News
October 8, 2025 • 1 min read • Hackernews
LockBit Qilin and DragonForce Join Forces to Dominate the Ransomware Ecosystem
Three prominent ransomware groups DragonForce, LockBit, and Qilin have announced a new strategic ransomware alliance, once underscoring continued shifts in the cyber threat landscape. The coalition is seen as an attempt on the part of the financially motivated threat actors to conduct more effective ransomware attacks, ReliaQuest said in a report
October 8, 2025 • 1 min read • Hackernews
Severe Framelink Figma MCP Vulnerability Lets Hackers Execute Code Remotely
Cybersecurity researchers have disclosed details of a now-patched vulnerability in the popular figma-developer-mcp Model Context Protocol (MCP) server that could allow attackers to achieve code execution. The vulnerability, tracked as CVE-2025-53967 (CVSS score 7.5), is a command injection bug stemming from the unsanitized use of user input, opening the door to
October 8, 2025 • 1 min read • Hackernews
No Time to Waste Embedding AI to Cut Noise and Reduce Risk
Artificial intelligence is reshaping cybersecurity on both sides of the battlefield. Cybercriminals are using AI-powered tools to accelerate and automate attacks at a scale defenders have never faced before. Security teams are overwhelmed by an explosion of vulnerability data, tool outputs, and alerts, all while operating with finite human resources.
October 8, 2025 • 1 min read • Hackernews
OpenAI Disrupts Russian North Korean and Chinese Hackers Misusing ChatGPT for Cyberattacks
OpenAI on Tuesday said it disrupted three activity clusters for misusing its ChatGPT artificial intelligence (AI) tool to facilitate malware development. This includes a Russian‑language threat actor, who is said to have used the chatbot to help develop and refine a remote access trojan (RAT), a credential stealer with an aim