Exploited now
8 this week
Data breaches
CyrusOne
Is it safe?
check a site
Browser updates
Chrome 155.0.8059.40
Scam emails
examples
12,194
guides
5,441
members
Removal guides
Pop-ups & adware
Browser hijackers
Ransomware
Trojans & backdoors
Spyware & keyloggers
Rogue anti-spyware
Malware
Unwanted programs
Scams
Scam alerts
Fake alerts
News
Malware news
Data breaches
Exploited flaws
Browser security
Security
Browsers & vulnerabilities
General
Software
Files
System files
Spyware-related files
Log in
Exploited now
8 this week
Data breaches
CyrusOne
Is it safe?
check a site
Browser updates
Chrome 155.0.8059.40
Scam emails
examples
Now
8 Oct
porterneuman.mx: PowerShell and JavaScript files tied to the AveMaria remote access trojan, and what to do
8 Oct
donutclientsmods.xyz: fake DonutSMP Minecraft mods tagged SilentNet, and what to do if you ran one
8 Oct
sqpengg.com: a server handing out crypted PowerShell scripts, and what to do if one ran on your PC
8 Oct
donutsmpcheats.org: fake Minecraft cheat mods with the SilentNet stealer, and what to do if you installed one
8 Oct
maciejbi.hosting24.pl: a hosting subdomain that served Remcos scripts and a stego picture, and what to do if your PC fetched them
8 Oct
87130921-60-20220830152356.webstarterz.com: an open folder serving Formbook and XWorm PowerShell scripts, and what to do if one ran
8 Oct
ficus.in: picture files hiding the Remcos remote access trojan, and what to do if a script fetched them
8 Oct
OpenDrive virus: why web.opendrive.com shows up in malware alerts, and what to do if a file from it installed Remcos
5,441 members
· read and write here
All members
Rubric
News
Page
@news
Reporting on attacks, breaches and security fixes.
Viruses and parasites
Data breaches
Exploited flaws
Browser security
Security
Web browsers and vulnerabilities
General
Anti-spyware software
Spam and phishing
Spyware related issues
Tutorials
Vulnerabilities
Web browsers
What's new
Everything
Posts 23
TYPE
News
FILED
Oct 7, 2026
News
Bulgaria Tax Agency Data Leak: 2026 Facts and Status
News
Bulgaria Tax Agency Data Leak: 2026 Facts and Status
The July 2019 hack of Bulgaria's tax agency exposed data on about 5 million people. What was taken, who was charged, what is unknown in 2026 and what to do.
Jake Doevan ·
Oct 7, 2026
TYPE
Viruses and parasites
FILED
Oct 7, 2026
Viruses and parasites
Flappy Birr Dog Spyware in 2026: MobSTSPY Facts
Viruses and parasites
Flappy Birr Dog Spyware in 2026: MobSTSPY Facts
Flappy Birr Dog was a Google Play game with MobSTSPY spyware. Google has removed it. Here is what it stole, which apps carried it and how to check your phone.
2-Spyware Editorial Team ·
Oct 7, 2026
TYPE
Viruses and parasites
FILED
Oct 7, 2026
Viruses and parasites
Clop MOVEit Breach 2026: Siemens Energy and Victims
Viruses and parasites
Clop MOVEit Breach 2026: Siemens Energy and Victims
Clop's MOVEit attack hit Siemens Energy and over 600 organizations. CVE-2023-34362, the timeline, what changed and how to protect file transfer tools.
Gabriel E. Hall ·
Oct 7, 2026
TYPE
Viruses and parasites
FILED
Oct 7, 2026
Viruses and parasites
Is the TikTok Pro App Safe in 2026? No, It Is Spyware
Viruses and parasites
Is the TikTok Pro App Safe in 2026? No, It Is Spyware
The TikTok Pro app is not safe: it is Android spyware that steals SMS, photos, location and Facebook logins. There is no real TikTok Pro. How to remove it.
Julie Splinters ·
Oct 7, 2026
TYPE
Security
FILED
Oct 7, 2026
Security
Nissan Data Breach 2026: Settlement and New Notices
Security
Nissan Data Breach 2026: Settlement and New Notices
Nissan North America's 2023 breach reached a $1.5 million settlement in 2026, and new notices followed in June. Dates, deadlines and steps to take.
2-Spyware Editorial Team ·
Oct 7, 2026
TYPE
Security
FILED
Oct 7, 2026
Security
Facebook Privacy Scandal 2026: Fines and Settlements
Security
Facebook Privacy Scandal 2026: Fines and Settlements
Jake Doevan ·
Oct 7, 2026
TYPE
Anti-spyware software
FILED
Oct 7, 2026
Anti-spyware software
CCleaner and Avast Bundle: 2026 Update
Anti-spyware software
CCleaner and Avast Bundle: 2026 Update
Julie Splinters ·
Oct 7, 2026
TYPE
News
FILED
Oct 7, 2026
News
UNNAMED1989 WeChat Ransomware: 2026 Facts and Tencent Strings
News
UNNAMED1989 WeChat Ransomware: 2026 Facts and Tencent Strings
Gabriel E. Hall ·
Oct 7, 2026
TYPE
Security
FILED
Oct 7, 2026
Security
Fxmsp Antivirus Breach 2026: Charges and Lessons
Security
Fxmsp Antivirus Breach 2026: Charges and Lessons
Lucia Danes ·
Oct 7, 2026
Exploited flaws
2 h ago
SecurityWeek reports that Citrix is urging immediate patching of a critical NetScaler vulnerability that could lead to remote code execution or denial of service. The flaw affects NetScaler ADC and NetScaler Gateway appliances in specific SAML configurations, as well as Secure Private Access Hybrid deployments. Citrix says it is not aware of unmitigated exploits, but users should update to the fixed versions as soon as possible.
Malware news
15 h ago
Malwarebytes Labs reports that attackers compromised infrastructure behind the .gh, .sl, and .as country-code domain namespaces and used it to obtain unauthorized HTTPS certificates for Google domains and other organizations. Google blocked the certificates in Chrome and worked with certificate authorities to revoke them. Windows users should keep their browser and operating system updated and never bypass certificate warnings.
Browser security
19 h ago
Chrome OS has received a Long Term Support Channel update to version 150.0.7871.256. Google says it includes selected security fixes, including issues in Browser, Omnibox, Extensions, WebRTC, GPU, PDF, and other components. Devices in the LTC channel will be updated to this version, so users should install it when it arrives.
Exploited flaws
21 h ago
SecurityWeek reports that TP-Link has disclosed five vulnerabilities in its Aginet line of ISP-managed mesh systems, routers and modems. The bugs can let an attacker on the same network take over an affected device, create a super-administrator account, enable SSH access, or recover passwords and Wi-Fi credentials from configuration files. TP-Link says firmware updates are distributed by ISPs, so users should check the device management interface or app for updates and contact their ISP if none are available.
TYPE
Security
FILED
Oct 7, 2026
Security
HappyHotel Data Breach 2026: Love Hotel Leak Facts
Security
HappyHotel Data Breach 2026: Love Hotel Leak Facts
HappyHotel, a Japanese love hotel search site run by Almex, was breached on December 22, 2019. What was exposed, what is unknown in 2026, and what to do.
2-Spyware Editorial Team ·
Oct 7, 2026
TYPE
Viruses and parasites
FILED
Oct 7, 2026
Viruses and parasites
Hermes Ransomware Flash Zero-
Day: 2026 Status
Viruses and parasites
Hermes Ransomware Flash Zero-Day: 2026 Status
Hermes ransomware used a Flash zero-day in 2018. What CVE-2018-4878 was, what changed after Flash ended in 2020, and what to do now in 2026.
2-Spyware Editorial Team ·
Oct 7, 2026
TYPE
Security
FILED
Oct 7, 2026
Security
Zoom Hack 2026: The UNC Link Flaw and Fix
Security
Zoom Hack 2026: The UNC Link Flaw and Fix
The Zoom Windows chat flaw that leaked login hashes was fixed in client 4.6.9 in April 2020. Facts, what changed, and how to protect meetings in 2026.
Julie Splinters ·
Oct 7, 2026
TYPE
Spam and phishing
FILED
Oct 7, 2026
Spam and phishing
Emily MacDonagh iCloud Leak 2018: 2026 Facts and Fixes
Spam and phishing
Emily MacDonagh iCloud Leak 2018: 2026 Facts and Fixes
Three private photos were taken from Emily MacDonagh's iCloud in March 2018. What is confirmed in 2026, what is not, and how to lock your own account.
Lucia Danes ·
Oct 7, 2026
TYPE
Web browsers and vulnerabilities
FILED
Oct 7, 2026
Web browsers and vulnerabilities
HackerOne Rogue Employee Case: What We Know in 2026
Web browsers and vulnerabilities
HackerOne Rogue Employee Case: What We Know in 2026
A HackerOne employee stole bug reports in 2022 to claim bounties and was fired. What happened next, HackerOne news since then, and insider threat lessons.
Gabriel E. Hall ·
Oct 7, 2026
TYPE
News
FILED
Oct 7, 2026
News
Adobe FTC Lawsuit: 2026 Settlement Explained
News
Adobe FTC Lawsuit: 2026 Settlement Explained
Gabriel E. Hall ·
Oct 7, 2026
TYPE
Security
FILED
Oct 7, 2026
Security
Alibaba Log4j Suspension in 2026: What Happened
Security
Alibaba Log4j Suspension in 2026: What Happened
Gabriel E. Hall ·
Oct 7, 2026
TYPE
Viruses and parasites
FILED
Oct 7, 2026
Viruses and parasites
EvilQuest ThiefQuest Mac Malware in 2026: Facts and Fixes
Viruses and parasites
EvilQuest ThiefQuest Mac Malware in 2026: Facts and Fixes
Lucia Danes ·
Oct 7, 2026
TYPE
Security
FILED
Oct 7, 2026
Security
TA505 ServHelper and FlawedGrace RAT: 2026 Guide
Security
TA505 ServHelper and FlawedGrace RAT: 2026 Guide
2-Spyware Editorial Team ·
Oct 7, 2026
Malware news
22 h ago
The Hacker News reports that 16 malicious Firefox extensions were found posing as Rabby and OKX Wallet tools to steal cryptocurrency wallet recovery phrases and private keys. The add-ons intercepted those secrets during wallet import flows and sent them to attacker-controlled Cloudflare Workers. Users who installed any of the extensions and entered a real recovery phrase or private key should assume compromise and move their assets from a clean system.
Data breaches
23 h ago
SecurityWeek reports that Oracle Health says personal and medical information from its legacy Cerner systems was compromised in a cyberattack. The data may have included names, Social Security numbers, and medical record details such as diagnoses, medicines, test results, images, and care information. People affected should watch for suspicious account activity and follow any notice from Oracle Health or their healthcare provider.
Data breaches
2 d ago
SecurityWeek reports that Southern Company is notifying roughly 400,000 customers that an unauthorized third party accessed utility account information through its online customer portal. The exposed data may include names, mailing addresses, phone numbers, email addresses, the last 4 digits of Social Security numbers, and other basic account details. The company says it stopped the activity and is offering affected customers a year of free credit monitoring.
Browser security
2 d ago
Google has released Chrome 155 for Windows with 247 security fixes, including four rated critical. Google says the update will roll out over the coming days and weeks, and users can check for it in Chrome by opening the menu, then Help, then About Google Chrome, and relaunching when the download finishes.
TYPE
Security
FILED
Oct 7, 2026
Security
Microsoft OneNote Malware in 2026: Is OneNote Safe Now?
Security
Microsoft OneNote Malware in 2026: Is OneNote Safe Now?
Microsoft OneNote is safer in 2026: since 2023 it blocks 120 risky embedded file types on Windows. How OneNote malware worked and what phishing still does.
2-Spyware Editorial Team ·
Oct 7, 2026
TYPE
Viruses and parasites
FILED
Oct 7, 2026
Viruses and parasites
Moneybird Ransomware News 2026: Agrius Update
Viruses and parasites
Moneybird Ransomware News 2026: Agrius Update
Moneybird is a C++ ransomware linked to Iran's Agrius group. What it does, what we could confirm in 2026, and how Israeli firms can cut the risk.
Gabriel E. Hall ·
Oct 7, 2026
TYPE
Viruses and parasites
FILED
Oct 7, 2026
Viruses and parasites
Eternity Project on Telegram: 2026 Status of the Malware Shop
Viruses and parasites
Eternity Project on Telegram: 2026 Status of the Malware Shop
Eternity Project sold stealers, clippers and ransomware through Telegram from 2022. What became of it, LilithBot, and how to avoid Eternity files in 2026.
Jake Doevan ·
Oct 7, 2026
TYPE
Web browsers and vulnerabilities
FILED
Oct 7, 2026
Web browsers and vulnerabilities
vBulletin Hack and Exploits: 2026 Security Update
Web browsers and vulnerabilities
vBulletin Hack and Exploits: 2026 Security Update
vBulletin had a 2019 zero-day, a 2020 patch bypass and 2025 API flaws exploited in the wild. Which versions are at risk in 2026 and how to secure a forum.
Gabriel E. Hall ·
Oct 7, 2026
TYPE
Viruses and parasites
FILED
Oct 7, 2026
Viruses and parasites
WannaCry Ransomware Attack: 2017 Facts and 2026 Status
Viruses and parasites
WannaCry Ransomware Attack: 2017 Facts and 2026 Status
WannaCry hit over 200,000 computers on May 12, 2017 via EternalBlue. Who was charged, the 2018 Connecticut attack, the 2026 status and how to stay patched.
Julie Splinters ·
Oct 7, 2026
TYPE
Viruses and parasites
FILED
Oct 7, 2026
Viruses and parasites
Accenture Ransomware Attack: LockBit 2021 and 2026 Breach
Viruses and parasites
Accenture Ransomware Attack: LockBit 2021 and 2026 Breach
2-Spyware Editorial Team ·
Oct 7, 2026
TYPE
Spam and phishing
FILED
Oct 7, 2026
Spam and phishing
Facebook Messenger Video Virus in 2026: Is This You Scam
Spam and phishing
Facebook Messenger Video Virus in 2026: Is This You Scam
Jake Doevan ·
Oct 7, 2026
TYPE
Security
FILED
Oct 7, 2026
Security
Ubisoft DDoS Lawsuit and R6 Siege Attacks: 2026 Update
Security
Ubisoft DDoS Lawsuit and R6 Siege Attacks: 2026 Update
Gabriel E. Hall ·
Oct 7, 2026
TYPE
Web browsers and vulnerabilities
FILED
Oct 7, 2026
Web browsers and vulnerabilities
Is Bisq Safe in 2026? The 2020 Hack and the 2026 Exploit
Web browsers and vulnerabilities
Is Bisq Safe in 2026? The 2020 Hack and the 2026 Exploit
Julie Splinters ·
Oct 7, 2026
Malware news
2 d ago
The FBI and Secret Service warn that the FortiBleed credential-harvesting campaign is still active and is targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. The agencies say attackers are scanning exposed devices, using stolen credentials, and may be passing access on to ransomware groups. Windows users in small offices should make sure their VPN and admin passwords are changed, active sessions are ended, and device logs are checked for suspicious activity.
Exploited flaws
2 d ago
Help Net Security reports that attackers have already started trying to exploit a critical arbitrary file access flaw in Atlassian’s self-managed Data Center products, including Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo, Crowd, Crucible and Fisheye. Atlassian urged customers to upgrade to a fixed version as soon as possible. Those who cannot update quickly should remove vulnerable instances from the internet or block external access, and check access logs for signs of compromise.
Data breaches
2 d ago
Infosecurity Magazine reports that unauthorized access to Denmark’s Central Register of Persons exposed names, addresses and CPR numbers for about 8.8 million registered people. The government said the access happened through a private Danish company’s legal access to the system. People should watch for unusual account activity, use unique passwords, keep devices updated and be careful if anyone asks for sensitive information by email, phone or other channels.
Malware news
2 d ago
The Hacker News reports that a malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker’s code as soon as the file is opened, without a macro warning. The attack works only when Java support is enabled. LibreOffice has already fixed the flaw, and Apache OpenOffice users should turn off Java or avoid opening spreadsheets they do not trust.
Loading…
No more articles
Could not load, try again
Try again
1
2
3
…
8
Next »
5,441 members already here
Reading, writing, commenting and voting. 0 verified · 166 joined this year
All members
Join
News
Members
Publish
Me