Researchers Uncover 30+ Flaws in AI Coding Tools Enabling Data Theft & RCE Attacks

Over 30 security vulnerabilities have been disclosed in various artificial intelligence (AI)-powered Integrated Development Environments (IDEs) that combine prompt injection primitives with legitimate features to achieve data exfiltration and remote code execution. The security shortcomings have been collectively named IDEsaster by security researcher Ari Marzouk (MaccariTA). They affect popular IDEs and extensions such as Cursor, Windsurf, Kiro.dev, GitHub Copilot,…

Read More

Hyundai Motor launches 1st group-level dedicated cyberthreat team

Hyundai Motor Group has established a dedicated unit to respond to cyber threats and is sharply increasing its investment in information security as it accelerates efforts to strengthen protection across the group. The cyberthreat response team, led by Yang Ki-chang, head of the group’s Integrated Security Center, will oversee vulnerability assessments, threat monitoring and incident…

Read More

FCC says hackers hijack US radio gear to send for False Alerts

Hackers are hijacking U.S. radio transmission equipment to broadcast bogus emergency messages and obscene language, the Federal Communications Commission said on Wednesday. In a public notice, opens new tab, the FCC said a “recent string of cyber intrusions against various radio broadcasters” had occurred, resulting in the issuance of the U.S. Emergency Alert System’s “Attention Signal.”…

Read More

Deepwatch Expands its Footprint in India with a New GCC in Bengaluru to Advance AI-Driven Cybersecurity Innovation

Deepwatch, the leader in Precision MDR powered by AI + Humans, today announced the official opening of its new office in Bengaluru, India, marking a significant milestone in the company’s continued global expansion strategy. The state-of-the-art facility will serve as a key engineering and technology hub as the company continues to scale its research and…

Read More

OpenAI Confirms Mixpanel Breach Impacting API User Data

OpenAI has confirmed a security incident involving Mixpanel, a third-party analytics provider used for its API product frontend. The company clarified that the OpenAI Mixpanel security incident stemmed solely from a breach within Mixpanel’s systems and did not involve OpenAI’s infrastructure. According to the initial investigation, an attacker gained unauthorized access to a portion of Mixpanel’s environment…

Read More

Hackers Using New Matrix Push C2 to Deliver Malware & Phishing Attacks via Web Browser

Hackers are turning everyday web browsers into remote-control tools using a new command-and-control (C2) platform called Matrix Push C2, according to BlackFog research. The browser‑native, fileless framework abuses legitimate web push notification features to deliver malware, phishing pages, and data theft campaigns across Windows, macOS, Linux, and mobile platforms. Instead of dropping traditional malware binaries…

Read More

Phishing Trends Report, 2025, from Hoxhunt Data

The 2025 Phishing Trends Report provides the first reference point for the global incidence of real malicious clicks and the phishing attacks that bypass email filters. This information fills a critical gap in the cybersecurity literature. As phishing continuously reaches new levels, effective phishing protections and cyber security training models must do the same. The good…

Read More