Security
UK networks hit by 67 million attacks targeting Hikvision cameras
A decade-old bug in Hikvision’s internet-connected cameras generated more than 67 million attack attempts against UK companies last year, proving that old exploits are still a gift to hackers if they remain unpatched and network-connected.
Read more about UK networks hit by 67 million attacks targeting Hikvision cameras
40K+ exposed as California weed delivery service leaks customer photo IDs, selfies, other details
Three Trees, a California-based marijuana products delivery service, has spilled the personal details of thousands of people. Customers and delivery drivers had their personal info, as well as selfies and IDs, left publicly accessible.
Read more about 40K+ exposed as California weed delivery service leaks customer photo IDs, selfies, other details
CISA, America’s top cyber defense agency, has no access to Anthropic’s Mythos
Anthropic is marketing its new cybersecurity-focused AI model Mythos as too dangerous for public release, but hasn’t even provided the US Cybersecurity and Infrastructure Agency with access to it. This seems bizarre.
Read more about CISA, America’s top cyber defense agency, has no access to Anthropic’s Mythos
750,000 DNN websites in danger: a simple SVG upload can lead to complete compromise
DNN, the leading open-source content management platform (CMS) in the Microsoft ecosystem, has patched a stored cross-site scripting (XSS) vulnerability. It enables hackers to upload malicious SVG files and achieve remote code execution.
Read more about 750,000 DNN websites in danger: a simple SVG upload can lead to complete compromise
Two major US banks targeted — Citizens Bank and Frost Bank confirms breach
Two major US banks have appeared on a ransomware leak site, with hackers dangling sensitive financial data. The attackers released samples of sensitive financial data, setting a six-day ultimatum before public release.
Read more about Two major US banks targeted — Citizens Bank and Frost Bank confirms breach
Agoda denies breach, as 82M records allegedly hit hacker forum
The data allegedly belonging to Agoda has hit underground hacker forums, with 82 million records for sale. Agoda dismisses the claims, stating that the data does not belong to the company.
Read more about Agoda denies breach, as 82M records allegedly hit hacker forum
Anthropic investigates unauthorized Mythos access by Discord group
Anthropic has opened an investigation after discovering that a small group of Discord users gained unauthorized access to the AI company’s powerful new Mythos model, Bloomberg reported on Tuesday.
Read more about Anthropic investigates unauthorized Mythos access by Discord group
“Free and open-source” Bloomberg Terminal alternative tops GitHub Trending chart: bring your own data
A “Free and open-source” alternative to Bloomberg Terminal has AI agents bolted on and is topping GitHub trending charts on Tuesday. However, full features sit behind a paywall, and free users are required to use their own data.
Read more about “Free and open-source” Bloomberg Terminal alternative tops GitHub Trending chart: bring your own data
Healthcare orgs in Illinois and Texas potentially leak data of 600,000 individuals
Threat actors continue to target the American healthcare industry. Three US organizations – one in Texas and two in Illinois – have disclosed significant data breaches affecting nearly 600,000 individuals in total.
Read more about Healthcare orgs in Illinois and Texas potentially leak data of 600,000 individuals
ANTS Hack: 19 million records exposed in French ID agency breach
The French government has confirmed that its database used to secure identity documents has been breached, exposing around 19 million records containing passport, national ID card, and driver’s license data.
Read more about ANTS Hack: 19 million records exposed in French ID agency breach
“The browser is the new cyberbattleground”: NordLayer’s Andrius Buinovskis on the browser security gap most companies leave wide open in 2026
TLDR In an exclusive interview with Cybernews, NordLayer’s Head of Product Andrius Buinovskis makes the case for why businesses can...
Read more about “The browser is the new cyberbattleground”: NordLayer’s Andrius Buinovskis on the browser security gap most companies leave wide open in 2026
Lovable goes on ego trip denying vulnerability, then blames others for said vulnerability
Vibecoding platform Lovable has admitted a serious flaw in its service after, bizarrely, first denying the vulnerability and blaming the alleged misunderstanding on unclear documentation and design. Then it threw HackerOne, the bug-bounty service, under the bus.
Read more about Lovable goes on ego trip denying vulnerability, then blames others for said vulnerability
Dutch warship compromised with $5 tracker and a postcard
Cheap tech just keeps on exposing NATO warships. In the latest example, a journalist was able to send a Bluetooth tracker to a Dutch frigate.
Read more about Dutch warship compromised with $5 tracker and a postcard
TikTok video downloader extensions infect over 130K users with covert spyware
Featured Chrome and Edge browser extensions for downloading TikTok videos are secretly spying on users and profiling them. They have remote-control backdoors that could be abused for data exfiltration or worse. Twelve extensions infected over 130,000 users.
Read more about TikTok video downloader extensions infect over 130K users with covert spyware
Banks raise alarm over Anthropic's Mythos AI: Could it exploit financial system weaknesses?
Regulators from Australia and South Korea have raised concerns regarding Anthropic’s AI model Mythos, arguing that it has the potential to destabilize entire banking systems.
Read more about Banks raise alarm over Anthropic's Mythos AI: Could it exploit financial system weaknesses?
Dutch consumers launch mass lawsuit against Odido over data breach affecting 6.2 million customers
Consumers United in Court (CUIC) is launching a class-action lawsuit against telecom provider Odido regarding the massive data leak in February.
Read more about Dutch consumers launch mass lawsuit against Odido over data breach affecting 6.2 million customers
OpenAI’s coding agent fails incident response, obscures active threats, complicates investigation
With AI’s capabilities growing every day, it’s not a bad idea to turn to the technology in response to a cyberattack. But a human has to be kept in a loop – otherwise, all kinds of problems are almost guaranteed. One Linux user just learned this the hard way.
Read more about OpenAI’s coding agent fails incident response, obscures active threats, complicates investigation
Vercel hacked after fatal OAuth misstep: granting “Allow All” permissions
Vercel, a cloud platform and maintainer of Next.js, a major web development framework, has been hacked, and hackers are selling access to credentials that could help pull off “the largest supply chain attack ever if done right.” An OAuth token, granting too many permissions, became a single point of failure.
Read more about Vercel hacked after fatal OAuth misstep: granting “Allow All” permissions
Hacker “Jeffrey Epstein” leaks 400K records from Netherlands' largest webshop
A hacker claims to have stolen personally identifiable information from over 400,000 Belgian customers of bol, the largest and most successful webshop in the Netherlands and Belgium. However, the company is unaware of any data breach.
Read more about Hacker “Jeffrey Epstein” leaks 400K records from Netherlands' largest webshop
Zara, Carnival, 7-Eleven hit by ShinyHunters, 9M+ records at risk in “pay or leak” warning
Zara, Carnival, and 7-Eleven are the latest brands named by ShinyHunters on Friday, with the ransomware gang threatening to dump troves of data unless the companies pay up by an April 21st deadline.
Read more about Zara, Carnival, 7-Eleven hit by ShinyHunters, 9M+ records at risk in “pay or leak” warning