Data Breaches & Scandals

ClarityCheck promised ‘private and secure’ face searches—then researchers found 9 million exposed photos of kids and adults

A people-search tool left 9 million unprotected face photos exposed for months. Researchers found images…

41 fake download sites show you Steam, then install malware—and hovering over the link won’t save you

Scammers are using a deceptive technique to trick users into downloading malware. Even hovering over…

More News

NGINX vulnerability CVE-2026-42945 exploited in the wild within days of disclosure — 9.2 severity score

Critical NGINX flaw with 9.2 severity score actively exploited days after disclosure. Millions of servers at risk of remote code…

Microsoft’s Azure Backup quietly fixed a critical vulnerability in May 2026 — but rejected the researcher’s report and issued no CVE

Microsoft patched a critical Azure Backup vulnerability without a CVE or acknowledgment. The security researcher's report was rejected. What this…

Hackers actively exploiting Funnel Builder WordPress plugin flaw to steal WooCommerce checkout payment data this week

A critical WordPress plugin vulnerability is under active exploitation to inject malicious code into WooCommerce checkouts and steal payment data…

Exim’s Dead.Letter vulnerability just exposed thousands of mail servers to remote code execution in May 2026

Critical zero-day CVE-2026-45185 in Exim mail servers enables remote code execution. What you need to know about patching now.