VS Code forks recommend missing extensions and pose supply chain risks with Open VSX

January 6, 2026Ravi LakshmananThreat Intelligence/Cloud Security Popular artificial intelligence (AI)-powered Microsoft Visual Studio Code (VS Code) forks such as Cursor, Windsurf, Google Antigravity, and Trae have been found to promote extensions that are not present in the Open VSX registry, potentially opening the door to supply chain risk if bad actors publish malicious packages with […]

New n8n vulnerability (9.9 CVSS) allows authenticated users to execute system commands

January 6, 2026Ravi LakshmananVulnerabilities / DevOps A critical new security vulnerability has been disclosed in n8n, an open source workflow automation platform, that could allow an authenticated attacker to execute arbitrary system commands on the underlying host. This vulnerability is tracked as CVE-2025-68668 and is rated 9.9 on the CVSS scoring system. This is described […]

Critical flaw in AdonisJS Bodyparser (CVSS 9.2) allows arbitrary file writing on the server

January 6, 2026Ravi LakshmananVulnerabilities / Web Security Users of the ‘@adonisjs/bodyparser’ npm package are advised to update to the latest version following disclosure of a critical security vulnerability that, if successfully exploited, could allow a remote attacker to write arbitrary files on the server. This flaw is tracked as CVE-2026-21440 (CVSS score: 9.2) and is […]

Russian-aligned hackers exploit Viber to target Ukraine’s military and government

January 5, 2026Ravi LakshmananCyber ​​Spy / Windows Security A Russian-aligned attacker known as UAC-0184 has been observed leveraging the Viber messaging platform to distribute malicious ZIP archives and target military and government agencies in Ukraine. “The organization will continue its high-intensity intelligence-gathering operations against the Ukrainian military and government sectors in 2025,” the 360 ​​Threat […]

Kimwolf Android botnet infects over 2 million devices via exposed ADB and proxy networks

January 5, 2026Ravi LakshmananIoT security/mobile security According to Synthient’s findings, the botnet known as Kimwolf infected more than 2 million Android devices by tunneling through residential proxy networks. “The primary actors involved in the Kimwolf botnet have been observed monetizing the botnet through app installations, selling residential proxy bandwidth, and selling DDoS capabilities,” the company […]

IoT Exploits, Wallet Breaches, Rogue Extensions, AI Abuse & More

Jan 05, 2026Ravie LakshmananHacking News / Cybersecurity The year opened without a reset. The same pressure carried over, and in some places it tightened. Systems people assume are boring or stable are showing up in the wrong places. Attacks moved quietly, reused familiar paths, and kept working longer than anyone wants to admit. This week’s […]

The State of Cybersecurity in 2025: Key Segments, Insights, and Innovations

January 5, 2026hacker newsData protection/artificial intelligence Features: Cybersecurity is being reshaped by forces that go beyond individual threats and tools. As organizations operate across cloud infrastructure, distributed endpoints, and complex supply chains, security has moved from a collection of point solutions to a matter of architecture, reliability, and speed of execution. This report examines how […]

New VVS Stealer malware targets Discord accounts via obfuscated Python code

January 5, 2026Ravi LakshmananThreat Intelligence / Windows Security Cybersecurity researchers have revealed details of a new Python-based information stealer called VVS Stealer (also known as VVS $tealer) that can collect Discord credentials and tokens. Palo Alto Networks Unit 42 reports that the thief was allegedly sold on Telegram in April 2025. “The VVS stealer code […]

Transparent Tribe launches new RAT attack against Indian government and academia

Threat actors known as Transparent Tribe are believed to have launched new attacks targeting government, academic, and strategic organizations in India using remote access Trojans (RATs) that allow them to take permanent control over compromised hosts. “The campaign uses deceptive delivery techniques, including weaponized Windows shortcut (LNK) files that disguise as legitimate PDF documents and […]