Notepad++ updates were hijacked for months to deliver malware to chosen targets

Notepad++ updates were hijacked for months to deliver malware to chosen targets

techkahwa.net | 3 February 2026 The Notepad++ project has disclosed that attackers compromised the shared hosting server behind its website and used it to intercept and redirect update traffic from June to December 2025. The targeting was selective and not every user was hit, but the advice for everyone is the same: manually install Notepad++ … Read more

Microsoft rushes an emergency fix for an Office flaw already used in attacks

Microsoft rushes an emergency fix for an Office flaw already used in attacks

techkahwa.net | 27 January 2026 Microsoft has released an emergency fix for a Microsoft Office vulnerability, tracked as CVE-2026-21509, and the US cybersecurity agency CISA has already added it to its list of flaws being exploited in real attacks. For most people using Office 2021 or later, the fix is almost effortless: close every Office … Read more

Critical 10/10 flaw in React and Next.js lets attackers take over web servers

Critical 10/10 flaw in React and Next.js lets attackers take over web servers

techkahwa.net | 4 December 2025 The React team has disclosed a critical vulnerability in React Server Components that carries the maximum severity score of 10.0, and Next.js has confirmed that its apps are affected too. The short version for anyone running a modern React or Next.js site: upgrade to the latest patched release now, because … Read more

Europol takes down 1,025 servers behind the Rhadamanthys infostealer

Europol takes down 1,025 servers behind the Rhadamanthys infostealer

techkahwa.net | 14 November 2025 European police have knocked out a large chunk of the infrastructure behind three well-known malware families, including the Rhadamanthys infostealer. Europol says 1,025 servers were taken down in the latest phase of Operation Endgame, which wrapped up today. If you have ever installed a cracked app or a “free” copy … Read more

Google sues the gang behind fake parcel and toll text scams

Google sues the gang behind fake parcel and toll text scams

techkahwa.net | 12 November 2025 Google has filed a lawsuit against the people it says run Lighthouse, a service that sells ready-made kits for sending scam text messages about parcels, road tolls and unpaid fees. According to Google, the operation has reached over 1 million victims in more than 120 countries. The case matters well … Read more

Hackers stole F5 BIG-IP source code and bug details, and CISA orders emergency patching

Hackers stole F5 BIG-IP source code and bug details, and CISA orders emergency patching

techkahwa.net | 16 October 2025 F5, whose BIG-IP devices sit at the front door of many corporate and government networks, has disclosed that attackers broke into its systems and took parts of the BIG-IP source code along with information about vulnerabilities that had not yet been made public. The US cybersecurity agency CISA responded on … Read more

INTERPOL operation recovers 439 million dollars from cyber fraud, with the UAE and Qatar taking part

INTERPOL operation recovers 439 million dollars from cyber fraud, with the UAE and Qatar taking part

techkahwa.net | 25 September 2025 INTERPOL announced on 24 September that a months-long operation against online fraud recovered USD 439 million in cash and assets, and the UAE and Qatar were among the 40 participating countries and territories. One of the cases INTERPOL highlighted ended in Dubai, where money stolen through an email scam was … Read more

Ransomware at a check-in software supplier disrupts Heathrow, Brussels and Berlin airports

Ransomware at a check-in software supplier disrupts Heathrow, Brussels and Berlin airports

techkahwa.net | 22 September 2025 Since the night of Friday 19 September, passengers at several of Europe’s busiest airports have faced long queues and delays after the check-in system many airlines share there went down. The EU’s cybersecurity agency ENISA has now confirmed the cause: a ransomware incident at a third-party supplier, not at the … Read more