Security

Oscars 2026: attackers exploit Best Picture hype for One Battle After Another to spread malware via Google

Your obsession with the Academy Awards might drain your bank account. Cybernews researchers found that illegally downloading this years' Best Picture nominees may result in installing dangerous wallet-draining malware.
Read more about Oscars 2026: attackers exploit Best Picture hype for One Battle After Another to spread malware via Google

Russia military command tells troops to ditch unsafe MAX app and use Telegram again

The Kremlin recently moved to reduce usage of the popular messenger Telegram across the country and ordered the troops invading Ukraine to switch to MAX, a state-run service. Now, though, the military command seems to have realized that MAX is even less safe and is telling troops to reinstall Pavel Durov’s app on their devices.
Read more about Russia military command tells troops to ditch unsafe MAX app and use Telegram again

Weird friend requests on Facebook? Meta will warn users more often

Meta, the parent company of Facebook, Instagram, and WhatsApp, has introduced a new set of tools to help protect users against scams.
Read more about Weird friend requests on Facebook? Meta will warn users more often

Verifone and Stryker claims by Iran-linked hackers as cyber retaliation fears grow

In less than a day, the Iran-linked hacktivist group Handala claims attacks on two multinational US companies – the electronic payments giant Verifone and the major medical technology company Stryker, both of which have strong ties to Israel. Verifone on Thursday denied the breach claims.
Read more about Verifone and Stryker claims by Iran-linked hackers as cyber retaliation fears grow

Hackers hijack Wordpress sites and deploy CAPTCHA ClickFix in global infostealer campaign

Cybercriminals have compromised hundreds of websites – including regional news outlets and the website of a US Senate candidate – in a global malware operation new research has uncovered.
Read more about Hackers hijack Wordpress sites and deploy CAPTCHA ClickFix in global infostealer campaign

HR departments are being targeted with fake resumes that disable security protection

A threat campaign against human resource (HR) departments has recently been launched. What seems like a decent resume actually is malicious software that kills security defenses, including antivirus programs and Endpoint Detection and Response (EDR) tools.
Read more about HR departments are being targeted with fake resumes that disable security protection

Who owns your Chrome extension? Researchers warn side projects are being turned into malware

Many Chrome extensions start as small developer projects, and once they gain users, are sold on. But what if the new owner turns out to be a bad actor who gains the ability to update software running inside thousands of browsers?
Read more about Who owns your Chrome extension? Researchers warn side projects are being turned into malware

Red-teamers unleash AI agent on McKinsey’s chatbot, gain full access in two hours

An offensive AI agent, created by red-team security startup CodeWall, autonomously chose McKinsey’s AI chatbot as a target and then hacked it in just two hours, gaining full read and write access to the system. This was just an experiment, but clearly, malicious machine-speed intrusions are possible.
Read more about Red-teamers unleash AI agent on McKinsey’s chatbot, gain full access in two hours

Beware: researchers uncover hundreds of malvertising campaigns on Meta platforms

A disinformation-for-profit network uses trusted news brands, real personalities, fabricated media narratives, emotional hooks, and advanced evasion techniques to drive victims – all users of Meta platforms – into investment fraud funnels, researchers say.
Read more about Beware: researchers uncover hundreds of malvertising campaigns on Meta platforms

China fuels OpenClaw adoption despite mounting security concerns

Local governments in China are offering subsidies to drive adoption of the OpenClaw AI agent, even as security experts in China and abroad warn that improper configuration of the software could carry serious cybersecurity risks.
Read more about China fuels OpenClaw adoption despite mounting security concerns

Man who accidentally discovered DJI robot vacuum backdoor awarded $30K

All that software engineer Sammy Azdoufal ever wanted was to connect his DJI robot vacuum cleaner to a PlayStation 5 controller. What actually happened was that he discovered a way to access a network of 7,000 remote-control DJI robots, enabling him to peek into other people’s homes. For this, he was rewarded $30,000 by DJI.
Read more about Man who accidentally discovered DJI robot vacuum backdoor awarded $30K

Scammers impersonate local zoning officials in latest phishing scheme, FBI warns

A new email phishing scam impersonating US city and county officials is tricking homeowners and businesses into forking over fraudulent fees for nonexistent planning and zoning permits, the FBI warns.
Read more about Scammers impersonate local zoning officials in latest phishing scheme, FBI warns

Viral GitHub project claims WiFi can "see through walls" – developers aren’t convinced

Wifi-DensePose claims to track human movement behind walls using ordinary wireless signals – triggering privacy concerns. Yet developers say at best it’s a proof of concept, at worst, “AI slop”.
Read more about Viral GitHub project claims WiFi can "see through walls" – developers aren’t convinced

Hackers claim leak of 141,000 Success Magazine users

A 100-year-old business magazine read by millions may have just had 141,000 subscriber records dumped onto a hacker forum.
Read more about Hackers claim leak of 141,000 Success Magazine users

Hackers claim breach of hat brand worn by Nicole Kidman and Hillary Clinton

A luxury fashion label worn by Hollywood stars has landed on a ransomware gang’s hit list.
Read more about Hackers claim breach of hat brand worn by Nicole Kidman and Hillary Clinton

Roblox users warned: 50 million login records are up for sale on the dark web

A threat actor claims to be selling a trove of Roblox credentials, likely harvested by infostealer malware from users directly. The database, which allegedly contains 50 million records, is listed for $777, according to Brinztech, a cybersecurity firm.
Read more about Roblox users warned: 50 million login records are up for sale on the dark web

MrBeast-advertised calorie app Cal AI allegedly hacked: 3 million subscribers exposed

Cal AI, the viral calorie-tracking app endorsed by many celebrities, has allegedly suffered a massive data breach. A threat actor dumped nearly 15GB of data, including 3 million emails, personal and subscription details, and even “times of day users eat.” The incident has not yet been officially confirmed.
Read more about MrBeast-advertised calorie app Cal AI allegedly hacked: 3 million subscribers exposed

Russia-backed hackers breach Signal, WhatsApp accounts

Russian-backed hackers have launched a global cyber campaign to gain access to Signal and WhatsApp accounts used by officials, military personnel and journalists, two intelligence agencies in the Netherlands warned on Monday.
Read more about Russia-backed hackers breach Signal, WhatsApp accounts

Campaign tricks Israelis into downloading a malicious version of a popular emergency app

The Acronis Threat Research Unit (TRU) has identified a campaign targeting Israelis. It tricks them into downloading a trojanized version of the RedAlert rocket app for Android.
Read more about Campaign tricks Israelis into downloading a malicious version of a popular emergency app

NGINX UI critical vulnerability enables hackers to download full system backups

A critical vulnerability is affecting the NGINX UI, a widely used third-party web management tool for NGINX, the most popular web server. Unauthenticated attackers can download a full system backup with user credentials, session tokens, SSL private keys, configurations, and other sensitive data.
Read more about NGINX UI critical vulnerability enables hackers to download full system backups