Data Breaches & Scandals
Amazon’s Customer Support Trapped Identity Theft Victims in a Kafkaesque Nightmare — FTC just fined them $2.25 million
Amazon refused to help identity theft victims access fraud records, violating federal law. The FTC…
Signal’s Backup Recovery Key Just Became Russia’s Master Skeleton Key—FBI Issues Urgent June Warning
FBI warns Russian intelligence hackers now steal Signal backup recovery keys to permanently access private…
Chrome’s Featured Adblock for YouTube Extension Harbors Hidden Code Injection Capability—10M Users at Risk
A Chrome extension with 10M+ installs and a Featured badge was found capable of executing…
More News
SAP npm packages just got hijacked by hackers calling themselves mini Shai-Hulud — stealing developer credentials at scale
Five security firms expose coordinated supply chain attack on SAP npm packages. Developers' credentials stolen via malware-laced code.
Critical GitHub flaw CVE-2026-3854 lets attackers execute code with single git push command
A critical GitHub vulnerability (CVE-2026-3854) allows authenticated users to execute remote code with a single git push command, threatening millions…
Checkmarx’s own GitHub repository just leaked on the dark web after March 23 supply chain attack
Security software maker Checkmarx confirms its own GitHub data was stolen and posted on the dark web following a March…
Hackers hid malware in 73 OpenVSX extensions that turned malicious after April 2026 update
73 developer extensions in OpenVSX marketplace turned malicious after update. GlassWorm campaign targets coders with dormant malware. What you need…