Data Breaches & Scandals
ClarityCheck promised ‘private and secure’ face searches—then researchers found 9 million exposed photos of kids and adults
A people-search tool left 9 million unprotected face photos exposed for months. Researchers found images…
41 fake download sites show you Steam, then install malware—and hovering over the link won’t save you
Scammers are using a deceptive technique to trick users into downloading malware. Even hovering over…
Aylo pays $120 million to settle child abuse lawsuits — but the fine comes with a stunning ‘no admission of liability’ clause
Pornhub's parent company Aylo settles for $120M over child sexual abuse material but admits no…
More News
NGINX vulnerability CVE-2026-42945 exploited in the wild within days of disclosure — 9.2 severity score
Critical NGINX flaw with 9.2 severity score actively exploited days after disclosure. Millions of servers at risk of remote code…
Microsoft’s Azure Backup quietly fixed a critical vulnerability in May 2026 — but rejected the researcher’s report and issued no CVE
Microsoft patched a critical Azure Backup vulnerability without a CVE or acknowledgment. The security researcher's report was rejected. What this…
Hackers actively exploiting Funnel Builder WordPress plugin flaw to steal WooCommerce checkout payment data this week
A critical WordPress plugin vulnerability is under active exploitation to inject malicious code into WooCommerce checkouts and steal payment data…
Exim’s Dead.Letter vulnerability just exposed thousands of mail servers to remote code execution in May 2026
Critical zero-day CVE-2026-45185 in Exim mail servers enables remote code execution. What you need to know about patching now.