Security
ClickFix access broker campaign hits Windows with Python-driven backdoors
Businesses are being warned about a new cyber campaign targeting Windows environments where getting in is only the beginning – not the end – of the attack.
Read more about ClickFix access broker campaign hits Windows with Python-driven backdoors
Trial begins as mystery woman accuses Instagram and YouTube of addicting teens
A California state court case over whether Instagram and YouTube harmed a woman's mental health through addictive app design kicks off on Monday with opening statements, in a test of whether Big Tech platforms can be held liable for harming kids.
Read more about Trial begins as mystery woman accuses Instagram and YouTube of addicting teens
Hackers fuel panic with claims linking crypto data leak to recent kidnappings in France
France has seen a series of high‑profile crypto-related kidnappings and extortions in recent months, while the crypto tax platform Waltio recently confirmed a data breach. Hackers are now claiming a link between the two, sparking fear online.
Read more about Hackers fuel panic with claims linking crypto data leak to recent kidnappings in France
CoinbaseCartel hacker claims American audio behemoth Dolby
The company’s name was recently uploaded by cybercriminals who claim responsibility for a data breach. The alleged attackers are known for breaching SK Telecom, South Korea’s largest mobile carrier, last year.
Read more about CoinbaseCartel hacker claims American audio behemoth Dolby
Another active exploitation of SolarWinds Web Help Desk detected
Huntress researchers are seeing threat actors exploiting the SolarWinds Web Help Desk vulnerability across three customers. It’s stemming from the recently disclosed flaws affecting the tool.
Read more about Another active exploitation of SolarWinds Web Help Desk detected
Flickr issues warning over possible user data exposure
Photography platform Flickr has informed users of a security incident at one of the company’s third-party service providers, potentially involving users’ personal information.
Read more about Flickr issues warning over possible user data exposure
The end of owning your computer, and why so many are pushing back
Late last year, OpenAI reportedly secured roughly 40% of the world's RAM (DRAM) production. Predictably, shortages and price hikes followed. With AI's insatiable appetite, it's increasingly in the spotlight for the strain it's putting on the world's resources. So what's the answer?
Read more about The end of owning your computer, and why so many are pushing back
More hacking groups operate from China than from any other country, researchers say
Researchers found that hacking groups targeted 178 countries in 2025, with government, financial services, and telecommunications among the most affected sectors.
Read more about More hacking groups operate from China than from any other country, researchers say
Scam on steroids: fake PDFs now hide on decentralized web and mount as virtual drives
Security researchers warn about a new bizarrely complex phishing campaign. Hackers, to bypass security protections, send scam emails with fake PDFs hosted on decentralized networks – once downloaded, they mount entire virtual drives filled with malicious content.
Read more about Scam on steroids: fake PDFs now hide on decentralized web and mount as virtual drives
US surveillance, election cybersecurity — and why Tulsi Gabbard’s name just keeps on cropping up
A series of incidents involving federal surveillance practices, intelligence oversight, and election-security investigations are converging as early issues ahead of the United States’ 2026 midterm elections. And one name just keeps on being mentioned..
Read more about US surveillance, election cybersecurity — and why Tulsi Gabbard’s name just keeps on cropping up
Apple Pay phishing scam steals 2FA codes in real-time vishing attack
Security researchers on Friday are warning Apple users about a sophisticated phishing scam that tricks victims into believing their Apple Pay account has been hacked – then steals their login credentials and two-factor authentication (2FA) codes in real time.
Read more about Apple Pay phishing scam steals 2FA codes in real-time vishing attack
Cyber pros found a way to unredact some Epstein PDFs: emails contain raw code
The Department of Justice (DOJ) appears to have failed to redact all Epstein files completely: some blacked-out documents also contain raw email data that enables the complete reconstruction of email attachments. Computer forensic experts are already working to uncover hidden pieces.
Read more about Cyber pros found a way to unredact some Epstein PDFs: emails contain raw code
Winter Olympics face cyber risks, Russian cyberattacks already foiled
Experts say that the Milano-Cortina 2026 Winter Olympics, officially starting on Friday night, will be among the most digitally complex global events, making it a prime target for cyberattacks. Local authorities say cyber incidents have already begun.
Read more about Winter Olympics face cyber risks, Russian cyberattacks already foiled
Severe vulnerability affects NGINX: websites visitors in danger
NGINX, a widely deployed reverse proxy and load balancer, contains a high-severity vulnerability that enables attackers-in-the-middle to inject data into server responses, potentially altering them or causing redirects.
Read more about Severe vulnerability affects NGINX: websites visitors in danger
Attackers exploit Windows screensaver files to install remote access tools
A new spearphishing campaign is exploiting a little-used entry point into corporate networks: Windows screensaver files – a format many users and even security controls don’t typically treat as high risk.
Read more about Attackers exploit Windows screensaver files to install remote access tools
SolarWinds Web Help Desk users under threat as vulnerability actively exploited
CISA has warned SolarWinds Web Help Desk users that a remote code execution (RCE) vulnerability, patched by the vendor last week, is being actively exploited.
Read more about SolarWinds Web Help Desk users under threat as vulnerability actively exploited
FBI unable to access seized reporter’s iPhone: it’s protected by Apple’s Lockdown Mode
The move by the Federal Bureau of Investigation to execute a search warrant at a reporter’s home was scandalous. But at least the feds aren’t able to access her iPhone, thanks to Apple’s Lockdown Mode.
Read more about FBI unable to access seized reporter’s iPhone: it’s protected by Apple’s Lockdown Mode
Massive data leak hits Harvard and UPenn: ShinyHunters dump stolen records
Extortion group ShinyHunters has released datasets allegedly containing over 1 million records from Harvard University and 1.2 million records from the University of Pennsylvania, claiming they include personal and donor data. Security researchers warn about private lives and intimate institutional strategies exposed.
Read more about Massive data leak hits Harvard and UPenn: ShinyHunters dump stolen records
Bulletproof hosting reused Windows images, masking ransomware infrastructure
New Sophos research finds bulletproof hosting providers repeatedly deploy virtual machines from the same preconfigured Windows images, creating thousands of identically named servers that cybercriminal groups continue to exploit for cover.
Read more about Bulletproof hosting reused Windows images, masking ransomware infrastructure
The new SCAM Act: will it force social media to block ad fraudsters?
US Senators Ruben Gallego and Bernie Moreno have introduced anti-scam legislation requiring social media platforms to vet their advertisers.
Read more about The new SCAM Act: will it force social media to block ad fraudsters?