• Telegram bans channels for extortion and doxxing

    Telegram bans channels for extortion and doxxing after receiving hundreds of detailed abuse reports from users. The decision follows the discovery of networks publishing personal data and demanding payment for its removal. What triggered the action According to the platform, administrators of several channels published damaging personal information about individuals, including private communications, addresses, and…

  • Dam cyberattack hits Norway’s Bremanger

    Pro-Russian hackers carried out a dam cyberattack in Bremanger, Norway. The incident opened floodgates for hours, alarming residents and raising concerns about the security of critical infrastructure. What happened at the dam On April 7, attackers accessed the dam’s control systems remotely. They opened a gate, releasing 500 litres of water per second for four…

  • GitHub Abuse Engine detects malicious activity

    Check Point’s GitHub Abuse Engine detects and stops malicious activity on GitHub. It uses AI to block credential theft, drive-by payloads, and other threats before they can harm users. Why GitHub abuse is dangerous Cybercriminals abuse GitHub’s trusted infrastructure to spread malware or harvest sensitive credentials. Because GitHub’s domains are widely trusted, traditional detection tools…

  • Messaging call restrictions hit Russian users

    Russia has restricted voice and video calls on WhatsApp and Telegram. This move affects millions and strengthens the state’s control over online communication. Reasons for the restrictions Roskomnadzor, Russia’s communications regulator, claims criminals use these apps for fraud, extortion, and sabotage coordination. Officials say both platforms failed to comply with legal demands for user data…

  • XZ Utils backdoor found in DockerHub images

    Researchers discovered a hidden XZ Utils backdoor in multiple DockerHub images, posing a serious risk to developers and organizations. The malicious code could allow attackers to gain control over affected systems and compromise sensitive data. How the threat emerged Security researchers found that several Docker images contained a version of XZ Utils with a backdoor.…

  • AI web browser assistant risks data exposure

    An AI web browser assistant could put your private information at risk, according to new cybersecurity research. Unsafe extension behavior may allow sensitive data, including browsing activity and personal credentials, to be accessed or shared without consent. How the risk occurs AI-powered browser assistants operate through extensions that integrate with web pages, read content, and…

  • HTTP/1.1 flaw leaves 24M sites exposed

    A critical HTTP/1.1 flaw threatens over 24 million websites, enabling attackers to hijack accounts, steal sensitive data, and plant malicious code. The vulnerability hides in backend systems still using HTTP/1.1, even when front-end services appear modern and secure. How the flaw works HTTP/1.1 contains ambiguous request boundaries, which attackers exploit in request smuggling or “desync”…

  • FDA AI Hallucinations Expose Healthcare Risks

    FDA AI hallucinations created a serious safety risk. Experts flagged Elsa’s fabricated medical studies right after its release. Leaders emphasize human oversight and robust safeguards to avoid endangering patients. Elsa’s Hallucination Problem Brooke Hartley Moy, co‑founder and CEO of Infactory, says she wasn’t surprised when Elsa started inventing fake research data in its drug‑approval recommendations.…

  • Reddit Blocks Archive to Halt Unauthorized AI Scraping

    Reddit blocks archive access to most of its content after detecting unauthorized AI scraping. The platform tightly controls its data and prioritizes user privacy and licensing revenue. What Changed for the Internet Archive Reddit now limits the Internet Archive’s Wayback Machine to indexing only the platform’s homepage. It prevents access to post pages, user profiles,…

  • Passkey Attacks Expose Authentication Weaknesses

    Passkey attacks expose serious authentication weaknesses. Attackers use downgrade tricks to bypass FIDO2 passkeys and force weaker sign-in methods. Users are at risk unless they remove backup options and enforce strong access policies. How Downgrade Attacks Work Proofpoint researchers show that phishing kits can prompt users to sign in using passwords instead of passkeys—especially when…