Plug and Pwn attack uses fake USB devices for Windows SYSTEM access

Windows users are at risk of being exploited through a new class of attacks dubbed “Plug and Pwn,” where fake USB devices can be used to gain SYSTEM privileges on compromised machines. This disturbing trend highlights how even seemingly innocuous features in operating systems can be abused by malicious actors. Security researchers Alejandro Hernando and … Read more

Hundreds of fake Chrome VPN extensions route traffic through a proxy

Hackers Behind Fake VPN Extensions Exposed, Thousands of Users Affected A massive campaign to deceive users has been uncovered by researchers at Socket, with over 737 fake Chrome browser extensions impersonating well-known VPN and proxy services. These extensions were downloaded nearly 75,000 times from the Chrome Web Store, primarily by Russian users seeking tools to … Read more

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

Lazarus Group Exploits Windows Zero-Day Vulnerability, Leaves Trail of Backdoors in Its Wake A devastating cyber attack has been unleashed by the notorious Lazarus group, leveraging a previously unknown vulnerability in Microsoft’s Windows operating system to gain SYSTEM access and deploy a sophisticated backdoor. The group’s malicious activities have left a trail of compromised systems … Read more

Lazarus hackers exploited Windows zero-day to target defense firms

North Korean Hackers Exploit Windows Zero-Day Vulnerability to Target Defense Firms In a brazen attack, North Korea’s Lazarus threat group has been exploiting a previously unknown vulnerability in Microsoft Windows to infiltrate defense-sector companies across Europe and India. The hackers have been using the flaw, known as CVE-2026-68820, as part of their long-running Operation Dream … Read more

Plug and Pwn attack uses fake USB devices for Windows SYSTEM access

Windows Plug and Play Vulnerabilities Allow SYSTEM Access via Fake USB Devices A new wave of attacks has emerged, leveraging the Windows Plug and Play feature to compromise system security. Researchers Alejandro Hernando and Borja Martínez have revealed a family of “Plug and Pwn” attacks that exploit how Windows automatically identifies and installs software from … Read more

Enterprise Defenses Recovered at the Edge and Collapsed Inside

As enterprises continue to struggle with cybersecurity threats, a new trend has emerged that’s catching many off guard. It appears that defenses are being compromised from within, but not in the way you might think. Instead of traditional insider threats, we’re seeing a more insidious issue – identity exposure. This vulnerability is exposing active attack … Read more

OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models’ Reasoning

Recent research has uncovered a significant vulnerability in the way AI models interact with each other’s reasoning processes. Specifically, a flaw in the Google API used by several top AI companies, including OpenAI and Anthropic, allows weaker AI models to decode the internal workings of stronger models. The issue arises from a feature called “cross-domain … Read more

737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One

A recent investigation has uncovered a shocking number of Chrome VPN extensions that are secretly routing user traffic through proxies, potentially exposing sensitive data and compromising online security. The affected extensions, totaling 737, have been installed by millions of users worldwide, making this a significant threat to internet safety. These VPN extensions, designed to protect … Read more

FBI: Hackers target online accounts to steal nude photos

The FBI has issued a public warning that hackers are targeting social media and online accounts to steal sexually explicit images or videos, often with the intention of blackmailing victims or selling the content on dark web marketplaces. This disturbing trend affects not only adults but also children, with cybercriminals using stolen personal information to … Read more

Lazarus hackers exploited Windows zero-day to target defense firms

Lazarus Hackers Unleash Sophisticated Attack on Defense Sector Using Zero-Day Vulnerity North Korean threat group Lazarus has been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense firms in Europe and India as part of its long-standing Operation Dream Job campaign. The hackers have used the flaw, which was patched by Microsoft earlier this month, … Read more