Security

Russian actors suspected of AI deepfakes impersonating US State Secretary Marco Rubio

Russian threat actors are suspected of creating AI deepfakes of US Secretary of State Marco Rubio and then using the AI-generated content to contact at least five foreign ministers and US officials, the State Department warned on Tuesday.
Read more about Russian actors suspected of AI deepfakes impersonating US State Secretary Marco Rubio

Hackers can target Teslas and other EVs through public chargers

Plugging an electric car into a charger creates a data link that can be abused for many attacks, a researcher warns. Hackers can attempt to steal money, data, or electricity, gain unauthorized control, or even shut down entire systems.
Read more about Hackers can target Teslas and other EVs through public chargers

iPhone wingman app leaks 160K chat screenshots

The publicly accessible bucket contained data from the iOS app FlirtAI - Get Rizz & Dates. It mainly included private chats that users wanted the AI wingman to help them reply to.
Read more about iPhone wingman app leaks 160K chat screenshots

Over 26,000 Bitcoin Depot customers learn of data breach one year later

Bitcoin Depot, a publicly traded bitcoin ATM company, has informed thousands of individuals that their sensitive data, including driver’s license numbers, may have been stolen. The breach happened a year ago, but victims are only now receiving notification letters.
Read more about Over 26,000 Bitcoin Depot customers learn of data breach one year later

SatanLock ransomware gang shuts down operation, files will be leaked

The ransomware group called SatanLock is ending its operation. All the data that it has stolen from victims will be leaked online.
Read more about SatanLock ransomware gang shuts down operation, files will be leaked

Ingram Micro struck by ransomware attack, causing ongoing system outage

Ingram Micro Holding Corporation has acknowledged that it fell victim to a ransomware attack, but refuses to share details about the incident.
Read more about Ingram Micro struck by ransomware attack, causing ongoing system outage

Linux contains dangerous secure boot flaw: hackers can bypass it with a USB stick

Physically present hackers can effectively bypass secure boot protections on modern Linux Systems and inject persistent malware. The quick fix is to modify the kernel and prevent the system from dropping into a debug shell during boot failures.
Read more about Linux contains dangerous secure boot flaw: hackers can bypass it with a USB stick

Teléfonica victim of a new data breach, hacker claims

A hacker going by the name “Rey” claims to have stolen 106GB of data from Teléfonica. The Spanish telecommunications company says it's nothing more than an extortion attempt.
Read more about Teléfonica victim of a new data breach, hacker claims

The rising threat of mobile malware: How to protect your device in 2025

The number of mobile users is increasing every year – and so do the instances of mobile malware.
Read more about The rising threat of mobile malware: How to protect your device in 2025

Hackers target vibe coders with malicious extensions for their code editors

Hackers are exploiting a dangerous loophole to target vibe coders. Cursor, Windsurf, and other AI-powered code editors can’t access the VS Code Marketplace and instead rely on riskier third-party platforms, where malicious extensions and critical flaws thrive.
Read more about Hackers target vibe coders with malicious extensions for their code editors

Phishers exploit PDFs impersonating PayPal, DocuSign, and Microsoft

Everyone trusts PDFs – and that’s exactly why cybercriminals are so obsessed with them.
Read more about Phishers exploit PDFs impersonating PayPal, DocuSign, and Microsoft

Prime Day is here — and so are fake Amazon sites, experts warn

As Amazon Prime Day approaches with promises of deals and dopamine, cybercrooks are already circling like vultures.
Read more about Prime Day is here — and so are fake Amazon sites, experts warn

BMW Financial Services entangled in cyber incident

BMW Financial Services has been caught up in a third-party breach that affected a small pool of people, but details are still vague.
Read more about BMW Financial Services entangled in cyber incident

FBI issues warning as pump-and-dump clubs on social media surge

Exclusive “investment clubs” on social media or messaging apps often are outright scams designed to lure investors into pump-and-dump stock manipulation, the Federal Bureau of Investigation (FBI) has warned. The FBI is urging victims to provide more details about any incidents.
Read more about FBI issues warning as pump-and-dump clubs on social media surge

Interview with Surfshark: why VPNs are essential to modern digital life

Learn why people like you invest in VPNs, and what one of the top VPN providers is doing to protect...
Read more about Interview with Surfshark: why VPNs are essential to modern digital life

Major cybergang says it’s done, offers “goodwill” gesture

Hunters International, the ransomware gang behind the Benetton Group and Circle K hacks, claims it’s retiring, adding the “decision was not made lightly.”
Read more about Major cybergang says it’s done, offers “goodwill” gesture

Hacker analyzes “deleted” data on GitHub, scores $25K in bug bounties

GitHub commits are never truly deleted, and some developers are discovering this the hard way. White-hat hacker Sharon Brizinov scanned “deleted” GitHub dangling commits and found thousands of secrets granting even admin access to all developers’ repositories, earning $25,000 in bounties in the process.
Read more about Hacker analyzes “deleted” data on GitHub, scores $25K in bug bounties

Recruiting software maker exposes nearly 26M resumes

TalentHook, a cloud-based applicant tracking system, left a misconfigured instance open. It spilled tens of millions of job seekers’ CVs, full of personal details ranging from full names to home addresses.
Read more about Recruiting software maker exposes nearly 26M resumes

Critical Linux “sudo” flaw allows any user to take over the system

Millions of Linux systems worldwide, including those running critical services, are potentially vulnerable to a new, easy-to-exploit sudo flaw that allows unauthorized users to run commands as root on Ubuntu, Fedora, and other servers.
Read more about Critical Linux “sudo” flaw allows any user to take over the system

67% of EU governmental institutions score D or F for cybersecurity efforts

85% of employees reuse breached passwords in EU institutions rated lowest for cybersecurity.
Read more about 67% of EU governmental institutions score D or F for cybersecurity efforts