Browsing: Threats & Incidents

Stay updated on the latest cyberattacks, breaches, vulnerabilities, and digital threats impacting users, companies, and everyday technology.

Cybersecurity researchers found multiple vulnerabilities in four Microsoft Visual Studio Code extensions, including Live Server and Code Runner, which have over 125 million installs. These flaws could allow attackers to steal local files and execute code remotely. The vulnerabilities, such as CVE-2025-65717 and CVE-2025-65716, remain unpatched, posing significant risks to developers and organizations relying on these tools.

Notepad++ has enhanced its update process with version 8.9.2, which now verifies signed XML and installers, making it ‘effectively unexploitable.’ This follows a cyberattack attributed to the Chinese government-linked group Lotus Blossom that compromised the update service. The recent updates include the removal of risky dependencies and improved auto-updater security, highlighting the importance of maintaining software integrity for users and organizations.

As of February 2026, OpenClaw, a platform for autonomous AI agents, faces significant vulnerabilities due to its architecture, which was exploited in the ClawHavoc supply-chain attack. This attack revealed that about 12% of ClawHub skills were malicious, posing risks to thousands of deployments. The vulnerabilities stem from system-level access, untrusted ingestion of content, and autonomous communication, leading to potential data theft and compromise of digital identities.

Gijs Tuinman, the Netherlands’ defense secretary, stated that Lockheed Martin’s F-35 fighter jet can be jailbroken similarly to an iPhone. His comments suggest that European forces could modify the aircraft’s software without US permission if needed. This raises concerns about the dependency on US technology and the implications of potential remote control over European fleets, as previously highlighted by German defense contractor Hensoldt’s Joachim Schranzhofer.

On January 27, 2026, OpenSSL announced twelve new zero-day vulnerabilities discovered by an AI system. These vulnerabilities, found during fall and winter 2025, include CVE-2025-15467, a high-severity stack buffer overflow. AISLE is credited with identifying 13 of 14 OpenSSL CVEs assigned in 2025, highlighting the significant impact of AI in cybersecurity.

The rise of shadow technology, particularly shadow AI, poses significant risks as organizations rapidly scale microservices and AI systems without adequate governance. Shadow APIs have previously led to security breaches due to undocumented endpoints, and now AI introduces even greater unpredictability and risk. The Wallarm API ThreatStats™ Report Q3 2025 noted a 57% increase in AI-related API vulnerabilities, highlighting the urgent need for improved monitoring and security measures.

Notepad++ has implemented security enhancements to its update mechanism following a supply chain compromise that occurred in June 2025. The attackers exploited vulnerabilities in the update process, allowing them to deliver malicious updates. With the release of Notepad++ v8.9.2, the software now verifies signed XML files and installer signatures, making the update process significantly more secure.

The 2026 API ThreatStats Report by Wallarm highlights that APIs are the most exploited attack surface, with 11,053 API-related vulnerabilities identified in 2025. This represents 17% of all published vulnerabilities, with 43% of CISA KEV additions also being API-related. The report emphasizes that improving API security is crucial for organizations, especially as AI applications increasingly rely on APIs, making the consequences of vulnerabilities more significant.

The article discusses critical security metrics that can predict breaches, emphasizing the importance of credential reuse, stale access paths, alert fatigue, and change velocity. It highlights that breaches often stem from identity issues, such as reused credentials across systems, which create vulnerabilities. Understanding these metrics is essential for organizations to improve their security posture and prevent incidents.

Securin’s 2025 Ransomware Report reveals that generative AI is enhancing ransomware operations by lowering entry barriers for attackers. The report analyzed 7,061 confirmed ransomware victims across 117 threat groups, identifying that three groups—Qilin, Akira, and CL0P—accounted for nearly 30% of all incidents. Commercial facilities emerged as the most targeted sector, indicating a shift in attack strategies that prioritize environments with significant operational consequences.