Security

Your questions, answered by Cybernews: Signal uses Google servers, but is your data safe?

Signal is using Google infrastructure. Does this mean that people searching for privacy are unwittingly falling back into the trap? Our team has selected one pressing and common reader issue and deconstructed it to help you stay safe online.
Read more about Your questions, answered by Cybernews: Signal uses Google servers, but is your data safe?

Half a terabyte of personal records exposed from youth non-profit

Attackers claim to have infiltrated Gerar, a Brazilian non-profit that provides training opportunities to youth. The breach allegedly involved sensitive details ranging from names to military service documents.
Read more about Half a terabyte of personal records exposed from youth non-profit

Toys ‘R’ Us data breach: What customer data was exposed?

Toys ‘R’ Us Canada has disclosed a data breach, which it learned about after attackers posted stolen customer information on the “unindexed internet.”
Read more about Toys ‘R’ Us data breach: What customer data was exposed?

Moroccan hackers caught using nation-state-levels of deception just to steal gift cards

Security researchers are warning about a group of Moroccan hackers who invest heavily in reconnaissance, launch convincing social engineering attacks that evade security tools, infiltrate cloud environments, and maintain persistence to ultimately steal gift cards.
Read more about Moroccan hackers caught using nation-state-levels of deception just to steal gift cards

F5 breach exposes powerful backdoor exploited by China-linked hackers

Researchers investigating artifacts from the recent F5 BIG-IP breach are warning about a stealthy and powerful backdoor used by China-linked threat actors. Known as Brickstorm, the malware leaves minimal traces, enabling attackers to gain long-term access.
Read more about F5 breach exposes powerful backdoor exploited by China-linked hackers

Lazarus Group now using fake job ads to target European drone manufacturers

A fresh wave of Operation DreamJob, a long-term campaign linked to North Korea’s Lazarus Group, is targeting European defense contractors – mostly firms involved in drone and UAV development, researchers say.
Read more about Lazarus Group now using fake job ads to target European drone manufacturers

German state minister accuses AfD of spying for the Kremlin

Georg Maier, the Minister of the Interior of the state of Thuringia, has accused the far-right wing political party Alternative für Deutschland (AfD) of espionage for Russia. Maier says he has evidence to support his claim.
Read more about German state minister accuses AfD of spying for the Kremlin

Millions relying on just one password for everything: does it still matter?

Using a single password across all accounts remains a widespread problem, leaving millions of people potentially exposed. Traditionally, users would be advised to change their passwords regularly, but with the evolution of cybercrime techniques, this may no longer always work.
Read more about Millions relying on just one password for everything: does it still matter?

Lithuanian police bust major bot farm, 75K SIM cards seized

Authorities in the Lithuanian capital, Vilnius, have dismantled a major SIM box operation, uncovering a trove of equipment suspected of being used in various fraud and cybercrime schemes on PayPal, Facebook, Google, and other platforms.
Read more about Lithuanian police bust major bot farm, 75K SIM cards seized

TikTok could quietly give ICE and DHS your IP address

TikTok has quietly altered its law enforcement guidelines to seemingly fit President Donald Trump’s vision of a country free from “illegal aliens.”
Read more about TikTok could quietly give ICE and DHS your IP address

More than half of Americans have had their personal data leaked online, study shows

More than half of Americans say they’ve been the victim of a data leak, while another 46% say they’ve never checked to find out, meaning their personal data may be at risk.
Read more about More than half of Americans have had their personal data leaked online, study shows

Attackers abusing OAuth to maintain access long after passwords are reset

Hackers are exploiting a loophole to retain access to hijacked user accounts, even after password resets and multi-factor authentication are enforced. They do this by creating internal malicious web apps and issuing OAuth tokens to maintain persistent access.
Read more about Attackers abusing OAuth to maintain access long after passwords are reset

This million-dollar leak from a Shopify rival went unnoticed for 2 years

Indian Shopify competitor Dukaan leaked sensitive credentials that could have resulted in hundreds of millions dollars drained from merchants’ accounts.
Read more about This million-dollar leak from a Shopify rival went unnoticed for 2 years

Hackers threaten to drop 47GB of top golf brand’s secrets

A Russian-linked ransomware gang claims to have stolen 47GB of data from a major golf apparel company, and the countdown to public release has begun.
Read more about Hackers threaten to drop 47GB of top golf brand’s secrets

Hackers actively exploiting Windows SMB flaw, gaining SYSTEM privileges over networks

Hackers are actively exploiting Windows SMB component vulnerability, which enables them to gain SYSTEM privileges over a network. The flaw affects all unpatched Windows systems. Microsoft released an update in June, 2025.
Read more about Hackers actively exploiting Windows SMB flaw, gaining SYSTEM privileges over networks

Be prepared: AWS outage likely to trigger surge in phishing attacks

Over six million individuals are reported to have been impacted by Monday’s AWS outage, leaving affected users ripe for scam attacks. Here’s what to look out for.
Read more about Be prepared: AWS outage likely to trigger surge in phishing attacks

Hackers doxx hundreds of ICE agents, raising risk of targeted attacks

Hackers have exposed the personal data of hundreds of Homeland Security and Justice Department employees, just as tensions between US agents and the public reach a breaking point.
Read more about Hackers doxx hundreds of ICE agents, raising risk of targeted attacks

Grocery delivery platform data leaked, hackers claim

Getir, a major grocery delivery platform, has allegedly had its data leaked. Attackers claim to have accessed the company’s intranet, but Cybernews researchers are skeptical.
Read more about Grocery delivery platform data leaked, hackers claim

Windows 10 users reluctant to update: main Windows 11 issues

Broken localhost and unresponsive accessories are a few of the issues that the company has already addressed.
Read more about Windows 10 users reluctant to update: main Windows 11 issues

Users beware: Xubuntu website serving malware instead of OS downloads

Users attempting to download Xubuntu, a lightweight Linux distribution derived from Ubuntu, are reporting getting malware instead. The project’s maintainers have temporarily disabled dowloads.
Read more about Users beware: Xubuntu website serving malware instead of OS downloads