TechTrezor breach exposes 347,000 users to phishing risks
Latest

Cisco firewall flaws enable ransomware and state attacks
Two critical bugs in Cisco firewall management software are being actively exploited by state-sponsored hackers and ransomware groups to steal credentials and seize control of networks.

PaperCut Replaces Emergency Patches With Comprehensive Security Fixes
PaperCut has issued new maintenance releases that supersede previous emergency patches, addressing two flaws currently under active exploitation by state-linked actors.

Sogou Input Method Flaw Lets Hackers Install Backdoors
A China-linked group used a design flaw in a popular Chinese typing tool to seize control of Windows computers, according to new security research.

JFrog Artifactory Flaws Enable Rapid Admin Takeover
Attackers exploited a chain of two vulnerabilities in JFrog Artifactory to seize control of self-hosted servers and install persistent backdoors. The attacks targeted outdated systems, but a third flaw poses a broader risk to unpatched instances.

Conti ransomware member sentenced to four years in prison
A Ukrainian national has been sentenced to four years in prison for his role in the Conti ransomware operation, which extorted over $150 million from victims globally.

Android malware Mantax Otax combines ransomware and spying
A new malware strain called Mantax Otax targets Android users by encrypting files and stealing sensitive data, while also harassing victims to force payment.

LG disputes claims of passive audio surveillance in smart TVs
LG has firmly rejected allegations that its smart televisions secretly record ambient conversations. The company insists audio is only captured upon explicit user command, yet independent researchers argue the devices hold data far longer than expected.

IDScan offers free monitoring after data breach
A major identity protection firm is providing complimentary security services following a significant data leak involving sensitive government documents.

Gigabud Trojans Hide in Android Work Profiles
A new tactic used by the Gigabud banking trojan is evading security checks by isolating malware within Android's work profile feature.

AI Agents Drive Mass PaperCut Breaches
A suspected Russian-speaking threat actor used automated AI agents to exploit security flaws in PaperCut software, compromising over 440 instances across 48 countries in a matter of hours.

Check Point patches critical VPN certificate flaws
Check Point has released urgent fixes for two high-severity vulnerabilities in its firewall and management software that could allow remote attackers to execute code without authentication.

Wallet Makers Warn Users of Phishing Wave
Attackers exploited a shared email vendor to send fake security alerts to crypto users, prompting urgent warnings from major hardware wallet brands.
More

Illustration: Tradingbird Fake security alerts target hardware wallet users
Trezor and BitBox are warning users to disregard fraudulent security alerts, with Trezor now confirming the emails stem from a compromised third-party email service. The incident follows a recent data breach at logistics partner ShipMonk that exposed customer details and triggered extortion demands from the ShinyHunters group.

Illustration: Tradingbird US Freezes $52.8 Million in Crypto From Scam Marketplace
A coordinated federal effort has dismantled a major online hub for fraud services, seizing digital assets and targeting physical compounds in Madagascar.

Illustration: Tradingbird Smart home privacy risks and how to reduce them
Convenience in modern appliances often comes with hidden data collection practices that users rarely understand.

Illustration: Tradingbird LG Smart TV Privacy Investigation Reveals Network Scanning
New findings suggest LG televisions may monitor viewing habits and network activity without clear user consent, raising concerns about home surveillance.

Illustration: Tradingbird Stolen AI Tokens Bypass Security Checks
Cybercriminals are exploiting leaked AI service tokens to bypass multi-factor authentication, according to a new security report.

Illustration: Tradingbird Steam achievement leak exposes spoilers for unreleased titles
A data exposure on Steam has revealed achievement lists for dozens of upcoming games, creating a significant spoiler problem for players and publishers alike.

Illustration: Tradingbird Default credentials on self-hosted servers face rapid compromise
Keeping factory settings on home servers creates an immediate security risk. Automated scanners find and exploit these weak entry points within hours, turning a hobby into a liability.

Illustration: Tradingbird Exposed Bitcoin Wallets Face Critical Security Risk
A critical flaw in Alby Hub allowed attackers to steal funds from wallets exposed to the internet, affecting users who ran older versions.
