Bluetooth flaw in Airoha chipsets allows eavesdropping via headphones, Scattered Spider hackers now targeting airlines, and Silver Fox group spreads malware via fake software sites. Horizon Healthcare hit by ransomware exposing patient data, Compumedics breach affects sleep study patients, and UK’s Richard Lander School shuts down after a cyberattack.
Security researchers discovered critical vulnerabilities in a widely used Airoha Bluetooth chipset affecting numerous popular audio devices. The flaws impact dozens of headphones and speakers from major brands including Sony, Bose, and Marshall. An attacker within Bluetooth range can potentially exploit the issues to eavesdrop through a microphone or steal a user’s contacts and call history. Although the chip manufacturer created a fix, device makers have not yet released the necessary firmware updates to the public.
The FBI has warned that the cybercrime group known as Scattered Spider is now actively targeting the airline industry. This group uses advanced social engineering techniques to impersonate employees, tricking IT help desks into granting them access to secure systems. The hackers often target high-value C-suite accounts to steal sensitive data, extort the company, and deploy ransomware. In response, security experts are urging aviation companies to immediately strengthen their internal identity verification processes to prevent these attacks.
A Chinese hacking group known as Silver Fox is distributing malware through fake websites that advertise popular software. The campaign delivers the Sainbox remote access trojan and the open-source Hidden rootkit to unsuspecting victims. These attacks primarily target Chinese-speaking users with malicious installers designed to look like legitimate software. This method provides the attackers with stealth and system control without requiring significant custom malware development.
Horizon Healthcare RCM, a revenue cycle management firm, suffered a ransomware attack and data breach in late December. The attack exposed a wide range of patient information, including health insurance data and, in some cases, Social Security numbers and financial details. The company’s public notice was transparent about the ransomware and strongly implied that it paid a demand to have the stolen data deleted. However, the total number of affected patients and which of its many healthcare partners were impacted remains unknown.
The sleep disorder diagnostic vendor Compumedics suffered a data breach that exposed patient data from Northern Light Health. The breach occurred between February and March 2025 and compromised files containing names, medical records, and sleep study results. While a subset of patients may have had Social Security numbers exposed, Northern Light Health believes its patients’ financial and insurance data were not involved. Compumedics has since enhanced its security, and all individuals who were affected by the incident have been notified by mail.
Richard Lander School in Cornwall, England, closed for two days due to a major cybersecurity incident affecting its IT systems. The school has very limited access to its data, which impacts its ability to function and properly safeguard its students. While an investigation into the incident is ongoing, officials have stated there is no evidence of a personal data compromise. The school administration will provide an update to parents on Tuesday regarding the operational plans for the rest of the week.
NATO allies have agreed to increase their defense spending to a new target of five percent of GDP within a decade. The goal includes 3.5 percent for core defense and 1.5 percent for indirect spending like cybersecurity capabilities. This increase is seen as a direct response to decades of U.S. criticism about burden-sharing, largely amplified by President Trump. Despite the new agreement, some allies have already expressed reluctance to meet the target, and the rules for spending remain vague.
A new report found that exploited vulnerabilities are the top cause of ransomware attacks for the third straight year. While the average recovery cost for victims is $1.53 million, the report notes that data encryption rates have actually dropped. Key operational factors enabling these attacks include a lack of internal cybersecurity expertise and insufficient staffing capacity. The findings highlight the critical need for organizations to prioritize proactive vulnerability management to combat these ongoing threats.
Microsoft has released a new open-source tool called RIFT to combat the growing threat of Rust-based malware. The Rust language is being used to create complex malware that is much larger and harder to reverse engineer than traditional programs. RIFT helps analysts by automatically identifying library code in Rust binaries, allowing them to focus on the malicious logic. By releasing the tool on GitHub, Microsoft aims to equip the cybersecurity community to better defend against these evolving threats.
Stay Alert as Bluetooth Flaw Lets Hackers Spy on Your Calls and Data
Security researchers have uncovered serious vulnerabilities in Airoha Bluetooth chipsets used in popular headphones and speakers from brands like Sony, Bose, and Marshall. These flaws allow attackers within Bluetooth range to bypass authentication, access device memory, steal contacts and call history, and even activate microphones to eavesdrop, all without user interaction. Although the chipmaker has issued a fix, many audio device manufacturers have not yet released firmware updates to users.
✅ What you should do:
Check your device manufacturer’s website for the latest firmware updates and apply them as soon as they’re available.
Avoid using Bluetooth audio devices in sensitive environments until updates are confirmed.
Unpair unused or unfamiliar Bluetooth devices from your phone or computer.
Keep your phone’s Bluetooth turned off when not in use to reduce exposure.
Use headphones with wired connections when privacy is a concern.
🔒 Why this matters:
These vulnerabilities turn everyday audio devices into potential surveillance tools. Even though attacks require close range and a high level of skill, the threat is real, especially for high-value targets. Staying updated and limiting Bluetooth exposure is essential for protecting your privacy.