Security
Oscars 2026: attackers exploit Best Picture hype for One Battle After Another to spread malware via Google
Your obsession with the Academy Awards might drain your bank account. Cybernews researchers found that illegally downloading this years' Best Picture nominees may result in installing dangerous wallet-draining malware.
Read more about Oscars 2026: attackers exploit Best Picture hype for One Battle After Another to spread malware via Google
Russia military command tells troops to ditch unsafe MAX app and use Telegram again
The Kremlin recently moved to reduce usage of the popular messenger Telegram across the country and ordered the troops invading Ukraine to switch to MAX, a state-run service. Now, though, the military command seems to have realized that MAX is even less safe and is telling troops to reinstall Pavel Durov’s app on their devices.
Read more about Russia military command tells troops to ditch unsafe MAX app and use Telegram again
Weird friend requests on Facebook? Meta will warn users more often
Meta, the parent company of Facebook, Instagram, and WhatsApp, has introduced a new set of tools to help protect users against scams.
Read more about Weird friend requests on Facebook? Meta will warn users more often
Verifone and Stryker claims by Iran-linked hackers as cyber retaliation fears grow
In less than a day, the Iran-linked hacktivist group Handala claims attacks on two multinational US companies – the electronic payments giant Verifone and the major medical technology company Stryker, both of which have strong ties to Israel. Verifone on Thursday denied the breach claims.
Read more about Verifone and Stryker claims by Iran-linked hackers as cyber retaliation fears grow
Hackers hijack Wordpress sites and deploy CAPTCHA ClickFix in global infostealer campaign
Cybercriminals have compromised hundreds of websites – including regional news outlets and the website of a US Senate candidate – in a global malware operation new research has uncovered.
Read more about Hackers hijack Wordpress sites and deploy CAPTCHA ClickFix in global infostealer campaign
HR departments are being targeted with fake resumes that disable security protection
A threat campaign against human resource (HR) departments has recently been launched. What seems like a decent resume actually is malicious software that kills security defenses, including antivirus programs and Endpoint Detection and Response (EDR) tools.
Read more about HR departments are being targeted with fake resumes that disable security protection
Who owns your Chrome extension? Researchers warn side projects are being turned into malware
Many Chrome extensions start as small developer projects, and once they gain users, are sold on. But what if the new owner turns out to be a bad actor who gains the ability to update software running inside thousands of browsers?
Read more about Who owns your Chrome extension? Researchers warn side projects are being turned into malware
Red-teamers unleash AI agent on McKinsey’s chatbot, gain full access in two hours
An offensive AI agent, created by red-team security startup CodeWall, autonomously chose McKinsey’s AI chatbot as a target and then hacked it in just two hours, gaining full read and write access to the system. This was just an experiment, but clearly, malicious machine-speed intrusions are possible.
Read more about Red-teamers unleash AI agent on McKinsey’s chatbot, gain full access in two hours
Beware: researchers uncover hundreds of malvertising campaigns on Meta platforms
A disinformation-for-profit network uses trusted news brands, real personalities, fabricated media narratives, emotional hooks, and advanced evasion techniques to drive victims – all users of Meta platforms – into investment fraud funnels, researchers say.
Read more about Beware: researchers uncover hundreds of malvertising campaigns on Meta platforms
China fuels OpenClaw adoption despite mounting security concerns
Local governments in China are offering subsidies to drive adoption of the OpenClaw AI agent, even as security experts in China and abroad warn that improper configuration of the software could carry serious cybersecurity risks.
Read more about China fuels OpenClaw adoption despite mounting security concerns
Man who accidentally discovered DJI robot vacuum backdoor awarded $30K
All that software engineer Sammy Azdoufal ever wanted was to connect his DJI robot vacuum cleaner to a PlayStation 5 controller. What actually happened was that he discovered a way to access a network of 7,000 remote-control DJI robots, enabling him to peek into other people’s homes. For this, he was rewarded $30,000 by DJI.
Read more about Man who accidentally discovered DJI robot vacuum backdoor awarded $30K
Scammers impersonate local zoning officials in latest phishing scheme, FBI warns
A new email phishing scam impersonating US city and county officials is tricking homeowners and businesses into forking over fraudulent fees for nonexistent planning and zoning permits, the FBI warns.
Read more about Scammers impersonate local zoning officials in latest phishing scheme, FBI warns
Viral GitHub project claims WiFi can "see through walls" – developers aren’t convinced
Wifi-DensePose claims to track human movement behind walls using ordinary wireless signals – triggering privacy concerns. Yet developers say at best it’s a proof of concept, at worst, “AI slop”.
Read more about Viral GitHub project claims WiFi can "see through walls" – developers aren’t convinced
Hackers claim leak of 141,000 Success Magazine users
A 100-year-old business magazine read by millions may have just had 141,000 subscriber records dumped onto a hacker forum.
Read more about Hackers claim leak of 141,000 Success Magazine users
Hackers claim breach of hat brand worn by Nicole Kidman and Hillary Clinton
A luxury fashion label worn by Hollywood stars has landed on a ransomware gang’s hit list.
Read more about Hackers claim breach of hat brand worn by Nicole Kidman and Hillary Clinton
Roblox users warned: 50 million login records are up for sale on the dark web
A threat actor claims to be selling a trove of Roblox credentials, likely harvested by infostealer malware from users directly. The database, which allegedly contains 50 million records, is listed for $777, according to Brinztech, a cybersecurity firm.
Read more about Roblox users warned: 50 million login records are up for sale on the dark web
MrBeast-advertised calorie app Cal AI allegedly hacked: 3 million subscribers exposed
Cal AI, the viral calorie-tracking app endorsed by many celebrities, has allegedly suffered a massive data breach. A threat actor dumped nearly 15GB of data, including 3 million emails, personal and subscription details, and even “times of day users eat.” The incident has not yet been officially confirmed.
Read more about MrBeast-advertised calorie app Cal AI allegedly hacked: 3 million subscribers exposed
Russia-backed hackers breach Signal, WhatsApp accounts
Russian-backed hackers have launched a global cyber campaign to gain access to Signal and WhatsApp accounts used by officials, military personnel and journalists, two intelligence agencies in the Netherlands warned on Monday.
Read more about Russia-backed hackers breach Signal, WhatsApp accounts
Campaign tricks Israelis into downloading a malicious version of a popular emergency app
The Acronis Threat Research Unit (TRU) has identified a campaign targeting Israelis. It tricks them into downloading a trojanized version of the RedAlert rocket app for Android.
Read more about Campaign tricks Israelis into downloading a malicious version of a popular emergency app
NGINX UI critical vulnerability enables hackers to download full system backups
A critical vulnerability is affecting the NGINX UI, a widely used third-party web management tool for NGINX, the most popular web server. Unauthenticated attackers can download a full system backup with user credentials, session tokens, SSL private keys, configurations, and other sensitive data.
Read more about NGINX UI critical vulnerability enables hackers to download full system backups