Security

This open-source VPN manager is secretly owned by an attacker, researchers warn


Security hole in HP thin client disk encryption: key available with a single script

Tricking a TPM into handing over its sealed disk encryption key is alarmingly easy on HP thin client devices.
Read more about Security hole in HP thin client disk encryption: key available with a single script

Hackers hit Levi Strauss in cyberattack, corporate data stolen

The attackers used social engineering techniques on 3 employees to breach Levi Strauss.
Read more about Hackers hit Levi Strauss in cyberattack, corporate data stolen

Steam hardware purchasers in Europe exposed: data breach hits Valve’s logistics partner

Scammers are expected to use leaked details in attempts to extort money through fraudulent requests for delivery or customs fees.
Read more about Steam hardware purchasers in Europe exposed: data breach hits Valve’s logistics partner

Romance scams get a new twist: fake girls invading DMs to promote OnlyFans accounts

Phishers are finding OnlyFans subscription upsells profitable enough to fuel massive bot campaigns.
Read more about Romance scams get a new twist: fake girls invading DMs to promote OnlyFans accounts

Hackers phish their way into US defense manufacturer’s Microsoft 365 account

Exposed details may include highly sensitive export-controlled technical info.
Read more about Hackers phish their way into US defense manufacturer’s Microsoft 365 account

ING and Ace & Tate report security incident at logistics partner

De Bijenkorf, bol, and Ajax have fallen victim to a breach at a logistics partner. ING and Ace & Tate now join the list of victims.
Read more about ING and Ace & Tate report security incident at logistics partner

Ajax caught in CEVA hack fallout, fans left waiting

Ajax is the latest victim of the data breach at CEVA Logistics.
Read more about Ajax caught in CEVA hack fallout, fans left waiting

Out of control? Meta says its AI model hacked another organization

Could Meta just be trying to at least look like it’s keeping up with rival labs?
Read more about Out of control? Meta says its AI model hacked another organization

Logistics partner hack disrupts Dutch retailer’s business operations, customer information possibly exposed


Germany calls on administrators to implement security.txt on their websites

Security.txt would boost responsible vulnerability disclosure and improve Germany’s cyber resilience.
Read more about Germany calls on administrators to implement security.txt on their websites

Token theft now is an industry: platforms reselling access to LLM using stolen API keys

AI token chop shops pool stolen accounts, resell cut-rate access to Claude, GPT, and Gemini, and covertly harvest every prompt for more sensitive details.
Read more about Token theft now is an industry: platforms reselling access to LLM using stolen API keys

Tor, Private Relay, and other browser-level proxies don’t protect iOS and macOS users


4.5M Ryde accounts affected in latest data breach

All Ryde accounts in Norway and elsewhere have been affected.
Read more about 4.5M Ryde accounts affected in latest data breach

Dutch department store De Bijenkorf hit by hacker attack

No financial details or passwords have been stolen, but affected users should be vigilant for phishing attempts.
Read more about Dutch department store De Bijenkorf hit by hacker attack

Wall Street hackers launch AI voice cloning attacks targeting Citadel, Two Sigma, Point72

AI voice clones are turning trusted calls into traps for Wall Street employees.
Read more about Wall Street hackers launch AI voice cloning attacks targeting Citadel, Two Sigma, Point72

Tails Linux critical vulnerability allows websites to deanonymize users: emergency patch available

The exploit can be leveraged by state-sponsored attackers or hacking firms.
Read more about Tails Linux critical vulnerability allows websites to deanonymize users: emergency patch available

The bizarre Credit Agricole phishing campaign: how the scammers did it

Scammers competed to see who would earn more from their victims.
Read more about The bizarre Credit Agricole phishing campaign: how the scammers did it

Another massive NPM worm: 444 packages with 2 billion monthly downloads infected with malware


Iran-linked water cyberattacks spread to 12 US states: new report

State officials detected “hostile cyber activity” at multiple water facilities.
Read more about Iran-linked water cyberattacks spread to 12 US states: new report