February’s Patch Tuesday assumes battle stations
Just 58 CVEs to spar with in February, but plenty are already under attack
Categories: Threat Research, X-ops
Tags: Patch Tuesday, Microsoft, Windows
Cybersecurity researchers have flagged a “coordinated malware campaign” on the JetBrains Marketplace that has published no less than 15 malicious plugins capable of exfiltrating artificial intelligence (AI) provider keys. “Every plugin poses as an AI coding assistant built on DeepSeek and other large language models, offering chat, commit messages, code review, bug finding, and unit…
On February 17, DataBreaches reported that the RansomHub ransomware group claimed responsibility for an attack on the Sault Ste. Marie Tribe of Chippewa Indians. RansomHub claimed to have “temporarily locked” the tribe’s infrastructure and to have acquired 119 GB of files (501, 211 files). The post included statements by RansomHub as seen on their dark…
Redazione reports: A 44-year-old man, a Romanian citizen, was arrested in Milan on charges of being the main director behind a series of cyber attacks orchestrated by the ‘Diskstation’ gang. This is a criminal organisation specialised in ransomware, active mainly against companies, professionals and technical studies. The arrest, carried out by the Italian Postal Police, is the…
The PA News Agency reports: A medical professional who used a patient’s personal data to visit her home with a gift while working as a vaccinator has been struck off the register. Josep Bofill Blanch, who was a registered physiotherapist employed by NHS Grampian in north-east Scotland, met the woman and gave her an injection when…
Broadcom has released security updates to address three actively exploited security flaws in VMware ESXi, Workstation, and Fusion products that could lead to code execution and information disclosure. The list of vulnerabilities is as follows – CVE-2025-22224 (CVSS score: 9.3) – A Time-of-Check Time-of-Use (TOCTOU) vulnerability that leads to an out-of-bounds write, which a malicious…
Malicious actors are exploiting Cascading Style Sheets (CSS), which are used to style and format the layout of web pages, to bypass spam filters and track users’ actions. That’s according to new findings from Cisco Talos, which said such malicious activities can compromise a victim’s security and privacy. “The features available in CSS allow attackers…