281 Google Play VPN Apps Found Leaking Data and Transmitting Unencrypted
A study revealed that 281 popular Android VPN apps on the Google Play Store suffer from critical security flaws, including unencrypted data transfer and traffic leaks.
Stories cluster related articles into a single narrative, linked to the underlying CVEs and affected products. 3,725 stories synthesized.
A study revealed that 281 popular Android VPN apps on the Google Play Store suffer from critical security flaws, including unencrypted data transfer and traffic leaks.
Rapid7's Metasploit Framework has released new modules targeting a critical RCE vulnerability in FlowiseAI's CSV Agent and a privilege escalation flaw in macOS PackageKit.
The EPA conducted a national cyber drill simulating a three-day internet outage to test water utilities' resilience and manual operational capabilities.
Healthcare vendors are increasingly becoming the primary targets for cyberattacks, with AI tools poised to amplify the scale and sophistication of these threats.
A recently disclosed vulnerability, dubbed 'Squidbleed,' in the widely-used Squid proxy server allows for the leakage of sensitive HTTP requests, potentially impacting numerous organizations.
An open-source tool named ScamBuster employs AI to impersonate potential victims, engaging with phishing attackers to gather intelligence on their operations and infrastructure.
CISA has added CVE-2026-48939 and CVE-2026-56291 to its Known Exploited Vulnerabilities Catalog, citing active exploitation of file upload flaws.
Key findings • Three Coturn vulnerabilities disclosed on July 10, 2026, including arbitrary code execution via SQL injection. • CVE-2026-53450 allows localhost services to be exposed through …
Two significant legal actions against ransomware actors, including a guilty plea from a Ryuk operator and a lengthy prison sentence for a Blackcat/AlphV conspirator, underscore ongoing global efforts to dismantle cybercrime syndicates.
Cyberattacks targeting healthcare businesses, particularly service providers, more than doubled in frequency during the first half of 2026, outpacing attacks on hospitals and clinics.
Operation First Light 2026 arrests 5,811 suspects and seizes $293 million, while a new PhaaS operation, Forg365, targets Microsoft 365 accounts with AI-powered lures.
Progress Software has issued an urgent warning to customers using its on-premises ShareFile Storage Zone Controllers, advising them to immediately shut down their servers due to a credible external security threat.
CISA has detailed its incident response to a breach involving exposed AWS GovCloud credentials and sensitive internal data found in a public GitHub repository.
A Bulgarian national already serving time for crypto money laundering is now charged with stealing $290,000 in seized cryptocurrency from behind bars.
Fortinet FortiGate has been named the top Unified Threat Management (UTM) solution for 2026, lauded for its value and comprehensive security features, though a recent CISA KEV addition underscores the critical need for diligent patching.
The Department of Homeland Security confirmed a breach of its HSIN database, while Adobe announced a move to bi-monthly security updates and Canadian authorities revealed successful disruption of ransomware operations.
Researchers have demonstrated a sophisticated laser fault injection attack capable of resetting passwords on Tangem hardware cryptocurrency wallets, posing a risk to unpatchable cards.
A researcher has detailed how three patched vulnerabilities in the OpenClaw AI assistant can be chained to achieve credential theft, privilege escalation, and arbitrary code execution, potentially leading to full host compromise.
The rapid proliferation of AI agents within organizations is creating a significant identity security gap, overwhelming traditional governance models and increasing the risk of breaches.
Security flaws have been identified in a wrapper used with Microsoft BitLocker, potentially exposing ATMs and organizational systems to unauthorized access.
Researchers demonstrate how AI assistants from Anthropic and OpenAI, designed for cybersecurity tasks, can be exploited for remote code execution.
A new Rust-based RAT, MODBEACON, attributed to the China-linked Silver Fox group, employs gRPC streaming for encrypted C2 traffic and SEO poisoning for distribution.
Cloudflare's Smart Tiered Cache now supports origins hosted on public cloud platforms by allowing users to specify a cloud region hint, improving cache efficiency and reducing latency.
A sophisticated attack campaign uses disguised Windows shortcuts to deliver a backdoor, leveraging PowerShell and Node.js for execution and the TON blockchain for command and control.