Cybersecurity
Latest news, analysis, and updates in cybersecurity.

USB Crypto Malware Weaponizes Windows Shortcut Files
A USB worm turns Windows shortcuts into crypto theft traps, swapping wallet addresses and hunting seed phrases before funds move.

Texas Data Breach Hands Hackers 3 Million ID Records
Hackers accessed IDs and passport numbers for over 3 million Texas license customers, turning a state vendor into a fraud risk.

Popa Botnet Pulls Alarum Into Android TV Proxy Scandal
Researchers say Popa turned cheap Android TV boxes into proxy relays linked to Alarum's NetNut, putting consent and investor risk in focus.

17M Attacks Hammer Gravity SMTP Vulnerability on WordPress
More than 17M attacks are exploiting Gravity SMTP on WordPress, exposing secrets through an unauthenticated REST API endpoint.

Beats Studio Buds Flaw Let Nearby Hackers Tap Mics
A Beats mic flaw puts accessory security in the spotlight as cloud, airline and Android TV risks pile up.

Dormant Key Turns Klue Breach Into Salesforce Theft
A dormant Klue API credential let attackers steal OAuth tokens and Salesforce data, exposing a dangerous SaaS trust chain.

Dream's $260M Raise Crowns Sovereign AI's New Power Broker
Dream's $260M raise values it at $3B and frames sovereign AI defense as the next venture battleground.

CryptoBandits Malware Hijacks Wallets Through USB Sticks
CryptoBandits turns USB drives into wallet traps, swapping copied addresses and stealing crypto data before users notice.

74,000 Fortinet Logins Spill in FortiBleed Data Leak
FortiBleed exposed nearly 74,000 Fortinet device credentials, pushing CISA to demand resets, MFA and public-access lockdowns.

Spies Could Listen Through Patched Beats Studio Buds Flaw
Apple patched a high-severity Beats bug that could let nearby attackers listen through earbuds before pairing.

Paid ShapedPlugin Updates Smuggle Malware Into WordPress
ShapedPlugin's trusted Pro update channel shipped malware to paying WordPress users, stealing credentials and enabling remote file writes.

Klue OAuth Breach Lets Icarus Raid Salesforce Data
Attackers abused Klue OAuth tokens to raid Salesforce data at speed, turning trusted SaaS access into an extortion path.