Security News > 2025 > February

Bybit declares war on North Korea's Lazarus crime-ring to regain $1.5B stolen from wallet
2025-02-26 23:08

Up to $140M in bounty rewards for return of Ethereum allegedly pilfered by hermit nation Cryptocurrency exchange Bybit, just days after suspected North Korean operatives stole $1.5 billion in...

SonicWall Report: “Threat Actors are Moving at Unprecedented Speeds”
2025-02-26 19:36

SonicWall’s 2025 Annual Threat Report noted the U.S. healthcare sector and Latin America were targeted by cybercriminals.

VSCode extensions with 9 million installs pulled over security risks
2025-02-26 19:10

Microsoft has removed two popular VSCode extensions, 'Material Theme - Free' and 'Material Theme Icons - Free,' from the Visual Studio Marketplace for allegedly containing malicious code. [...]

Qualcomm pledges 8 years of security updates for Android kit using its chips (YMMV)
2025-02-26 18:57

Starting with Snapdragon 8 Elite and 'droid 15 It seems manufacturers are finally getting the message that people want to use their kit for longer without security issues, as Qualcomm has said...

Hackers Exploited Krpano Framework Flaw to Inject Spam Ads on 350+ Websites
2025-02-26 17:19

A cross-site scripting (XSS) vulnerability in a virtual tour framework has been weaponized by malicious actors to inject malicious scripts across hundreds of websites with the goal of manipulating...

PyPi package with 100K installs pirated music from Deezer for years
2025-02-26 16:59

A malicious PyPi package named 'automslc' has been downloaded over 100,000 times from the Python Package Index since 2019, abusing hard-coded credentials to pirate music from the Deezer streaming...

Lazarus hacked Bybit via breached Safe{Wallet} developer machine
2025-02-26 16:58

​Forensic investigators have found that North Korean Lazarus hackers stole $1.5 billion from Bybit after hacking a developer's device at the multisig wallet platform Safe{Wallet}. [...]

Pump.fun X account hacked to promote scam governance token
2025-02-26 16:07

The immensely popular memecoin generator Pump.fun had its X account hacked to promote a fake "PUMP" token cryptocurrency scam. [...]

What cybersecurity pros read for fun
2025-02-26 16:00

While cybersecurity pros spend much of their time immersed in technical reports, risk assessments, and policy documents, fiction offers a refreshing perspective on security and hacking. Great...

EncryptHub breaches 618 orgs to deploy infostealers, ransomware
2025-02-26 15:31

A threat actor tracked as 'EncryptHub,' aka Larva-208, has been targeting organizations worldwide with spear-phishing and social engineering attacks to gain access to corporate networks. [...]