Security

Dutch watchdog accuses Meta of turning a blind eye as scam ads keep circulating

According to the Consumentenbond, the consumer interest group in the Netherlands, Meta barely monitors advertisers and takes no action against unreliable online stores.
Read more about Dutch watchdog accuses Meta of turning a blind eye as scam ads keep circulating

Ivanti Connect Secure devices may carry dormant RESURGE malware

The Cybersecurity and Infrastructure Security Agency (CISA) is warning that RESURGE malware may still be silently embedded in Ivanti Connect Secure VPN appliances. It remains dormant until attackers attempt to regain access.
Read more about Ivanti Connect Secure devices may carry dormant RESURGE malware

Hackers claim LexisNexis cloud breach exposing 400K users and .gov emails

Hackers claim to have breached LexisNexis by accessing its AWS infrastructure, publishing a trove of internal records allegedly tied to 400K users – including .gov accounts from courts and federal agencies.
Read more about Hackers claim LexisNexis cloud breach exposing 400K users and .gov emails

Attackers could hijack Perplexity’s Comet browser to take over your 1Password vault

Researchers have identified a new family of vulnerabilities affecting the Perplexity Comet agentic browser. Two distinct exploit paths enable zero-click agent compromise and credential theft or full account takeover via authorized workflows, including interactions with 1Password.
Read more about Attackers could hijack Perplexity’s Comet browser to take over your 1Password vault

“We go bankrupt:” stolen Gemini API key turns $180 monthly bill into $82K catastrophe, developer says

Just as researchers are ringing the alarm bells about thousands of exposed Google API keys, one small dev team is facing the worst-case scenario – an $82,000 bill.
Read more about “We go bankrupt:” stolen Gemini API key turns $180 monthly bill into $82K catastrophe, developer says

How do 100 lava lamps help Cloudflare with data encryption?

There’s a security reason behind why Cloudflare’s office has a wall with 100 lava lamps.
Read more about How do 100 lava lamps help Cloudflare with data encryption?

Check if your Chrome is up to date: Google’s Gemini might still be spying on you

This is why you need to update your Chrome. A patched Chrome vulnerability could have turned Google’s Gemini AI into a built-in surveillance tool.
Read more about Check if your Chrome is up to date: Google’s Gemini might still be spying on you

“Star Citizen” maker says that an undisclosed month-old data breach isn’t a big deal

Cloud Imperium Games (CIG), a British gaming company, knew for over a month that its customers' personal information had been accessed by hackers. It seems the company doesn’t see this data breach as that much of a big deal.
Read more about “Star Citizen” maker says that an undisclosed month-old data breach isn’t a big deal

Next.js turf war heating up: Cloudflare’s vibe-coded gambit humbled by critical security bugs

Cloudflare boasted about a single engineer with just $1,100 in AI tokens building “a drop-in replacement for Next.js” in a week. This kicked off a beef with Vercel, which maintains Next.js, a popular web development tool. The ambitious project arrived riddled with security holes, but with enough punch to rattle the industry.
Read more about Next.js turf war heating up: Cloudflare’s vibe-coded gambit humbled by critical security bugs

Wild pack without a leader: pro-Iranian hackers already active in wake of US-Israeli strikes

With the conflict in the Middle East entering a phase of total infrastructure and economic warfare, threat analysts are urging organizations across the US and its allies to beware of potential retaliatory cyberattacks. In fact, they’ve already begun.
Read more about Wild pack without a leader: pro-Iranian hackers already active in wake of US-Israeli strikes

US agencies dump Anthropic as Altman revises Defense Department agreement

The US Treasury Department, State Department, and the federal housing agency announced they are terminating all use of Anthropic products, in a shift to OpenAI, the ChatGPT maker led by Sam Altman, who on Monday said changes were being made to the it US Defense Department agreement.
Read more about US agencies dump Anthropic as Altman revises Defense Department agreement

Motorola joins forces with GrapheneOS to boost smartphone security

Smartphone manufacturer Motorola has announced a partnership with GrapheneOS Foundation, touting it as “a new chapter in smartphone security.” The non-profit explains that the Lenovo-owned company is working on “a subset of their next generation” devices to meet GrapheneOS requirements.
Read more about Motorola joins forces with GrapheneOS to boost smartphone security

French Airbus and Boeing parts supplier confirms data breach

A Russia-linked ransomware gang claims it has breached a key French supplier to Airbus and Boeing – LISI Group and stolen financial and corporate data. The company has confirmed the “cyber incident.”
Read more about French Airbus and Boeing parts supplier confirms data breach

This purchase order PDF is fake, malicious, and after your password

Another day, another scam on Telegram. Researchers have found an attachment posing as a purchase order in PDF form that’s actually a credential-harvesting web page quietly sending passwords and other sensitive data straight to a Telegram bot controlled by an attacker.
Read more about This purchase order PDF is fake, malicious, and after your password

Unprecedented GitHub hacking spree: “security research” AI bot compromises major repos from Microsoft, Datadog, and others

The AI bot, still active on GitHub, is hacking one repo after another, curating its own brag page, and claiming to have scanned over 47,000 repositories. In just one week, it targeted at least six popular open-source projects, including those from Microsoft and DataDog. Trivy, a popular vulnerability scanner repo, was fully compromised.
Read more about Unprecedented GitHub hacking spree: “security research” AI bot compromises major repos from Microsoft, Datadog, and others

After the hack: why Odido’s crisis is only getting bigger

A massive data breach, private information published on the dark web, millions of victims, a fake class-action lawsuit, and a criminal investigation launched by the Public Prosecution Service. For some, this may sound like a script for a Hollywood blockbuster.
Read more about After the hack: why Odido’s crisis is only getting bigger

AI assistant runs hacker’s commands just from opening a project: critical vulnerability found in Claude Code

Claude Code, one of the most popular command-line AI coding assistants, contained critical vulnerabilities that enabled remote code execution and the theft of sensitive data, bypassing user consent. Attackers could hide malicious instructions in repository-level configuration files.
Read more about AI assistant runs hacker’s commands just from opening a project: critical vulnerability found in Claude Code

Hackers give Wall Street billionaires 5 days to panic: here's what they're demanding

A dark web countdown is ticking for Pathstone Family Office after ShinyHunters claimed it stole 641,000 sensitive records from the elite wealth manager.
Read more about Hackers give Wall Street billionaires 5 days to panic: here's what they're demanding

Odido hackers talk big game, leak emails and phone numbers

ShinyHunters, a prominent extortion group, has started leaking information allegedly stolen from Odido, the largest Dutch telecom. The agitated attackers are threatening to leak two million records every day.
Read more about Odido hackers talk big game, leak emails and phone numbers

Scattered Lapsus$ Hunters looking to hire: Who is its target employee, and how much does it pay?

The attacker collective is looking for female voices to be used in its new vishing campaign.
Read more about Scattered Lapsus$ Hunters looking to hire: Who is its target employee, and how much does it pay?