Non-technical · Plain language · Daily

Security news that
anyone can understand.

Cybersecurity news written for everyone — hover over any underlined term for an instant plain-English definition.

Subscribe Free →
cybersecurityCyberBubbleFortinet

FortiBleed, Unpatchable iPhones, and a 15,000-Site Cleanup

Russian hackers compromised 86,644 Fortinet firewalls using default passwords — CISA says change them now. Plus: an unpatchable exploit hits iPhones XS through 11, and international police clean 15,000 infected sites.

· 7 min read
cybersecurityCyberBubblezero-day

Your Antivirus Has a Zero-Day

A zero-day in Windows Defender lets attackers seize full control of any Windows PC — with no patch yet available. Plus: 144 poisoned npm packages, a CVSS 10.0 Joomla flaw, and a hacker who stayed inside a network for 33 days after his server went offline.

· 7 min read
cybersecurityCyberBubbleClickFix

Fake Browser Updates Are Now a Professional Malware Delivery Business

The ClickFix technique has evolved into a sophisticated malware delivery industry — three new loader families this week alone. Plus: three critical Fortinet zero-days being actively exploited, Cisco SD-WAN compromised in the wild, and a cPanel plugin flaw added to CISA's 'must-patch' list.

· 7 min read
cybersecurityCyberBubbleChina APT

China Stole Medical Research Emails — Without Ever Breaking In

A China-linked group spent a year inside research networks by silently rewiring Google Workspace email forwarding. No password stolen, no malware dropped — just quiet redirection. Plus: a Palo Alto VPN bypass, 152 fake Chrome extensions, and backdoored WordPress plugins.

· 7 min read
cybersecurityCyberBubblephishing-as-a-service

INTERPOL Just Arrested 201 People Running a Phishing Store

Operation Ramz took down Sniper Dz — a platform that let anyone rent a complete phishing kit for a few dollars a month. 201 arrests across 13 countries. Plus: 400+ Arch Linux packages hijacked to steal credentials, and Europol dismantles a €336M crypto laundering service.

· 7 min read
cybersecurityCyberBubblezero-day

Hackers Attacked Universities for Two Weeks Before Oracle Knew

ShinyHunters exploited an Oracle PeopleSoft zero-day for 13 days before the company even knew it existed. Meanwhile: a ransomware group that spreads like a worm, GitHub's plan to fix npm's biggest security problem, and a flaw that bypasses Windows BitLocker.

· 7 min read
cybersecurityCyberBubblePatch Tuesday

Microsoft Just Patched 206 Flaws in One Day

It's a record-breaking Patch Tuesday — 206 vulnerabilities fixed, including three zero-days already being used in attacks. Plus: China's 1,500-device botnet and critical Ivanti, Fortinet, and SAP patches you shouldn't skip.

· 7 min read
cybersecurityCyberBubbleAI security

Your Coding Agent Can Be Hijacked Through a Bug Report

Researchers found that AI coding tools like Claude Code and Cursor can be tricked into running attacker code by poisoning a Sentry error report. Plus: a Chrome zero-day confirmed in the wild, and Vietnamese hackers with a supply chain twist.

· 7 min read
cybersecurityCyberBubbleAI security

The AI Worm That Doesn't Need the Internet

Researchers built a self-replicating worm that spreads between AI agents using only local models — no internet connection, no network traffic, nothing to detect. Plus: North Korea's fake job recruiter malware and a critical LiteLLM admin takeover bug.

· 7 min read
cybersecurityCyberBubblesupply chain attack

The Backdoor That Waited Nine Years

China-linked hackers replaced Linux login software with backdoored copies in 2016 — and nobody noticed until now. Plus: a Microsoft 365 AI flaw that stole emails via a real microsoft.com link, and a critical Splunk hole with no auth required.

· 7 min read