Anonymous video chat app leaks data on millions of users — more than 22 million records exposed, including 3 million containing names and email addresses

A not-so-private anonymous video chat app has compromised credentials, including usernames, emails, and network information, thanks to a misconfigured Kibana dashboard.

Rapid7 observes new Palo Alto VPN flaw exploited in the wild to bypass GlobalProtect authentication

A flaw fixed last month is now being used in real-life attacks, and security researchers are urging users to patch.

Ransomware groups grow revenue by almost 40% in Q1 2026

Initial Access Brokers are removing a major pain point helping ransomware operators steal more.

Thousands of compromised websites abused by DriveSurge in active ClickFix and FakeUpdates campaigns

SilentPush is warning about an Intial Access Broker campaign called DriveSurge that uses thousands of websites to deploy a backdoor.

OpenAI Codex tool with over 29,000 downloads linked to malicious npm supply chain attack stealing authentication tokens

A tool started benign and turned sour after a little while, stealing tokens and granting persistent access.

Multiple Linux distros hit by major ‘CIFSwitch’ flaw that gives attackers root access

If you’re using Linux, make sure you patch up and disable unnecessary file sharing features.

17 million strong botnet of compromised devices dismantled by Dutch authorities

The botnet is theorized to be related to Asocks, with the possibility the proxy network has bitten the dust.