Security

“We backed up Spotify:” pirates claim to have scraped 300TB of music

Spotify’s entire music catalog has allegedly been scraped by Anna’s Archive, a major shadow digital library best known for its collection of books and academic papers. It plans to release 300TB of music torrents, described as the “world’s first preservation archive,” containing 86 million of the most popular tracks.
Read more about “We backed up Spotify:” pirates claim to have scraped 300TB of music

Acting CISA boss fails polygraph test organized by career staff, seeks revenge

At least six career staffers and the US Cybersecurity and Infrastructure Security Agency (CISA) allegedly organized a polygraph test for the agency’s acting director, Madhu Gottumukkala, this summer. He failed and then began suspending employees left and right.
Read more about Acting CISA boss fails polygraph test organized by career staff, seeks revenge

Cybercriminals flock to a new unrestricted AI tool: 10,000 prompts on the first day

Cybercriminals are using a new and highly capable uncensored AI tool called DIG AI, which appeared on the Darknet. The “not good” AI is actively misused for fraud, malware creation, terrorism, child sexual abuse material (CSAM), and other criminal activities, security firm Resecurity warns.
Read more about Cybercriminals flock to a new unrestricted AI tool: 10,000 prompts on the first day

Adblockers save an average user 2 days of loading time per year, AdGuard claims

Adblockers reduce network requests by more than half, save a third of bandwidth usage, and spare every user two days of loading time per year, according to a new report by AdGuard. These benefits come in addition to adblockers’ primary purpose: defeating intrusive ads, malvertising, tracking, and other annoyances.
Read more about Adblockers save an average user 2 days of loading time per year, AdGuard claims

Denmark fingers Russia as culprit in two “destructive” cyberattacks

The Danish government has formally accused Russia of carrying out two “destructive and disruptive” cyberattacks and described them as “very clear evidence” of a hybrid warfare, whatever it actually is.
Read more about Denmark fingers Russia as culprit in two “destructive” cyberattacks

Hackers find a simple trick to access WhatsApp accounts: linking a new device

WhatsApp users are sharing their accounts with hackers, who trick them into completing what appears to be a routine verification process. Victims silently approve attacker-controlled devices, granting nearly full access, Gen Digital researchers warn.
Read more about Hackers find a simple trick to access WhatsApp accounts: linking a new device

Hacker arrested over ties to France Interior Ministry data breach

French authorities have apprehended a 22-year-old hacker, allegedly linked to the recent data breach of the France’s Ministry of the Interior (Beauvau).
Read more about Hacker arrested over ties to France Interior Ministry data breach

A critical Cisco vulnerability is letting China spy on email systems

A critical Cisco vulnerability with no patch is being actively exploited by suspected China-aligned hackers to quietly seize control of exposed email security appliances.
Read more about A critical Cisco vulnerability is letting China spy on email systems

Google sues another Chinese scam group over large phishing scheme

Google has sued a Chinese cybercriminal group, which the tech giant claims is responsible for millions of scam text messages sent to Americans this year. This is the company’s second similar complaint in a month.
Read more about Google sues another Chinese scam group over large phishing scheme

GhostPoster malware campaign exploits live Firefox extensions

A live malware campaign called GhostPoster is hiding malicious JavaScript inside Firefox extension logo files, resulting in over 50,000 unsuspecting users to download more than a dozen compromised add-ons so far.
Read more about GhostPoster malware campaign exploits live Firefox extensions

8M VPN users just got their AI chats wiped and sold

Widely used Chrome browser extensions have been quietly wiping users’ conversations with AI chatbots and selling the sensitive data to third parties.
Read more about 8M VPN users just got their AI chats wiped and sold

Massive new botnet hijacks almost 2 million Android devices and briefly surpasses Google

A massive new botnet, Kimwolf, briefly surpassed Google on the top websites chart. With 1.8 million Android devices and counting, a botnet of such scale is capable of launching unseen cyberattacks, researchers warn.
Read more about Massive new botnet hijacks almost 2 million Android devices and briefly surpasses Google

Most smart devices run outdated web browsers, expose owners to attacks

Most smart devices on today’s market come with an embedded web browser that runs extremely out-of-date versions, a new study has found. This exposes device buyers to cyberattacks as soon as they turn on their new gadgets.
Read more about Most smart devices run outdated web browsers, expose owners to attacks

US childcare platform exposes 140K records, including minors' data

A misconfigured database left the personal details of parents and children from thousands of childcare centers exposed to anyone on the internet.
Read more about US childcare platform exposes 140K records, including minors' data

France confirms cyberattack on Ministry of Interior, hackers claim 16M individuals exposed

The ministry has confirmed that it suffered a cyberattack, but has not shared how many individuals may have been exposed.
Read more about France confirms cyberattack on Ministry of Interior, hackers claim 16M individuals exposed

Too many hacks lead to Telegram: security researchers recommend blocking it

Multiple recent cyberattacks have relied on Telegram infrastructure as a central tool for tracking victims, controlling malware, and moving stolen data, prompting security researchers to recommend blocking Telegram traffic where it is not essential.
Read more about Too many hacks lead to Telegram: security researchers recommend blocking it

Fortinet firewalls under active attack, users urged to update now

Threat actors have begun actively exploiting two critical vulnerabilities in a popular firewall device, Fortinet FortiGate, just days after they were publicly disclosed.
Read more about Fortinet firewalls under active attack, users urged to update now

Amazon exposes Russian cyber saboteurs targeting Western critical infrastructure

Amazon’s threat intelligence team has revealed a years-long Russian state-sponsored campaign that targeted Western critical infrastructure between 2021 and 2025.
Read more about Amazon exposes Russian cyber saboteurs targeting Western critical infrastructure

Suspect pleads guilty to credential stuffing attack on DraftKings

A 21-year-old man from Farmington, Minnesota, has pleaded guilty to orchestrating a credential stuffing attack on the sports and betting website DraftKings. He now risks a prison sentence of up to five years.
Read more about Suspect pleads guilty to credential stuffing attack on DraftKings

Thousands of Firefox users compromised: 17 extensions hide malware in icons

At least 17 Firefox extensions slipped past detection by hiding malware in an unlikely place – their icons. Thousands of users have been infected, and the malicious add-ons are still available on the Firefox platform.
Read more about Thousands of Firefox users compromised: 17 extensions hide malware in icons