More than 185,000 accounts were reportedly exposed in a 7-Eleven breach tied to the ShinyHunters extortion campaign.
Leaked records included emails, DOBs, addresses & phone numbers connected to franchisee systems.
Uncovering #Cybersecurity | Expert insights, Pro Interviews, Latest Threats & Hacking News | #InfoSec #Malware #Ransomware #Streaming #TechNews
Posts
Anthropic’s Claude Mythos Preview reportedly uncovered 10K+ high/critical zero-days during Project Glasswing.
Cloudflare, Mozilla, Cisco, Microsoft, Apple & Google were linked to the initiative.
Big question:
Can defenders patch fast enough in the AI era?
Source: https://cybersecuritynews.com/anthropics-claude-mythos-preview-0-days/
Follow @technadu@infosec.exchange for more threat intel & AI security updates.
Canada’s proposed Bill C-22 is drawing strong responses from VPN providers.
▪️ Windscribe may relocate HQ
▪️ Surfshark may leave the Canadian market
▪️ ExpressVPN calls encryption “non-negotiable”
▪️ NordVPN warns mandated access creates exploitable vulnerabilities
Full responses from providers:
https://www.technadu.com/canadas-bill-c-22-vpn-providers-discuss-privacy-encryption-user-impact/628316/
Shashwat Sehgal, CEO & Co-Founder of P0 Security, warns that AI agents are recreating the same access problems that broke early cloud security.
🔐 Broad standing permissions are returning
🔐 Visibility alone does not reduce blast radius
🔐 Runtime governance matters more than authentication
“The organizations that avoid repeating the cloud security cycle will be the ones that treat agents as a new class of privileged non-human identity from day one.”
#Cybersecurity #AISecurity #IdentitySecurity #CloudSecurity #AIAgents
X-VPN has joined the VPN Trust Initiative (VTI) and i2Coalition to support stronger privacy, transparency, and security standards across the VPN industry.
The company says the memberships will help align with evolving best practices and safer internet initiatives.
https://www.technadu.com/x-vpn-joins-vpn-trust-initiative-and-i2coalition/628327/
Spanish court rejects LaLiga’s request to fine NordVPN over IPTV blocking compliance claims.
The dispute is intensifying concerns around overblocking after reports of disruptions affecting platforms like Cloudflare, GitHub, Docker & Vercel in Spain.
https://www.technadu.com/nordvpn-blocking-dispute-faces-new-spanish-court-ruling/628323/
CloudBees survey findings:
• 81% saw more production issues tied to AI-generated code
• 67% reported increased code volume
• 54% saw higher CI/CD costs
AI adoption is accelerating, but governance and validation still appear to lag behind.
Are organizations prioritizing speed over software quality?
Source: https://devops.com/cloudbees-survey-surfaces-increase-in-production-issues-attributable-to-ai/
Follow @technadu@infosec.exchange for more cybersecurity and DevOps updates.
Major cybercrime operations were dismantled this week, including malware-signing services, DDoS botnets, phishing infrastructure, and criminal VPN networks.
At the same time, researchers warned about AI-driven exploitation, poisoned VS Code extensions, Linux telecom malware, and healthcare data breaches.
Cloud Atlas APT campaigns targeting Russia & Belarus are leveraging phishing, CVE-2018-0802, SSH tunnels, and a new “PowerCloud” tool that exfiltrates data into Google Sheets.
Researchers say deleted Google API keys may stay active for up to 23 minutes due to cloud propagation delays.
The issue could reportedly allow continued access to Gemini uploads, APIs, and cloud resources after key deletion.
Black Lotus Labs identified “Showboat,” a Linux post-exploitation framework tied to PRC-aligned telecom targeting campaigns.
Researchers say the malware enabled persistence, proxying, remote shell execution, and maintained a 0% VirusTotal detection rate for months.
Canadian authorities arrested alleged KimWolf botnet admin “Dort” in connection with a DDoS-for-hire operation that reportedly infected 1M+ IoT devices and launched 25,000+ attacks.
Mozilla expanded Firefox’s free built-in VPN with selectable servers in 5 countries and new mobile privacy features in Firefox 151.
The free VPN has reportedly crossed 1 million sign-ups since launch.
https://www.technadu.com/firefox-free-vpn-expansion-adds-more-global-servers/628281/
Researchers allege Russia’s MAX messaging app may include VPN detection and surveillance-related capabilities.
RKS Global says multiple claims were supported through static code analysis, while MAX denies the accusations.
https://www.technadu.com/max-app-surveillance-claims-russia/628268/
Mullvad is rolling out fixes for a VPN fingerprinting issue that could let websites associate activity across different VPN servers through exit IP assignment patterns.
Users switching servers are advised to re-log to regenerate WireGuard keys and internal IPs.
https://www.technadu.com/mullvad-fingerprinting-issue-prompts-vpn-system-changes/628269/
IPVanish expanded its VPN network to 150+ global server locations with over 3,400 servers and nearly 1,000 RAM-only servers across 25 locations.
The provider says it aims to transition to a fully RAM-only infrastructure by 2027.
https://www.technadu.com/ipvanish-vpn-network-expands-beyond-150-locations/628264/
Müzeyyen Gökçen Arslan Tapkan of Black Kite says organizations still confuse compliance with actual security.
⚠️ Vendors can pass audits while exposing live risk
⚠️ Attackers rank vendors by exposure paths, not spend
⚠️ AI is worsening noise and confidence problems in cyber datasets
“Saying HITL in TPCRM is easy. Designing for it, vendor by vendor, signal by signal, decision by decision, this is the real work.”
https://www.technadu.com/why-attackers-understand-supply-chains-better-than-companies/628246/
Fortinet patched two critical RCE flaws affecting FortiAuthenticator and FortiSandbox.
The vulnerabilities could allow unauthenticated command execution on exposed systems.
Instructure confirmed it paid a ransom to ShinyHunters after the Canvas cyberattack allegedly exposed data tied to 9,000 customers.
The incident triggered FBI warnings and a congressional investigation.
Sophos reports that 71% of orgs faced identity-related breaches last year, with average costs reaching $1.64M.
Weak API keys, service accounts, and AI agents are now major ransomware entry points.
CyberArk + Palo Alto Networks launch Idira for AI-era identity security. 🔐
The platform focuses on securing human, machine & agentic identities with unified PAM and governance.
Is identity becoming the primary AI attack surface?
Follow @technadu@infosec.exchange for more.
Kaspersky’s 2026 ransomware report shows attacks declining in volume, but threat actors are becoming more sophisticated.
EDR killers, BYOVD tactics, credential theft, and encryptionless extortion are becoming more common, while post-quantum cryptography is entering ransomware workflows.
Red Hat warns that autonomous AI agents are becoming “high-privilege users that never sleep.”
As AI systems gain direct access to APIs, databases, and cloud infrastructure, security teams may face faster vulnerability discovery, unintended autonomous actions, and shrinking response windows.
https://www.technadu.com/the-risks-of-ai-agents-as-high-privilege-users-that-never-pause/627824/
CVE-2026-41940 is under active mass exploitation.
Researchers say threat group “Mr_Rot13” is exploiting the critical cPanel flaw to steal credentials, deploy webshells, and gain persistent access across hosting infrastructure.
2,000+ attacking IPs observed globally.
A malicious Checkmarx Jenkins AST plugin was reportedly deployed using credentials stolen in the Trivy supply-chain attack.
The rogue plugin bypassed the normal release pipeline and contained credential-stealing malware tied to TeamPCP.
Texas is suing Netflix over alleged user tracking and data sharing practices involving advertisers and data brokers.
The lawsuit claims Netflix tracked viewing habits, location data, devices, and kids’ profile activity without proper transparency.
Source: https://therecord.media/texas-sues-netflix-over-data-practices-surveillance
Follow @technadu@infosec.exchange
#Privacy #InfoSec #CyberSecurity
A U.K. water utility reportedly failed to detect attackers inside its network for nearly 2 years before a Cl0p-linked ransomware breach was uncovered.
Source: Source: https://therecord.media/uk-water-company-had-hackers-lurking-for-years
The incident exposed major gaps in OT, monitoring, patching, and critical infrastructure security.
Follow @technadu@infosec.exchange
Google researchers say they identified the first potentially AI-generated zero-day exploit used by cybercriminals.
The exploit reportedly bypassed 2FA via a semantic logic flaw in a web admin tool.
AI-driven offensive operations are evolving rapidly.
https://www.technadu.com/google-detects-first-potentially-ai-generated-zero-day-exploit/627772/
Canvas outages linked to a cyberattack reportedly forced universities across the U.S. to delay final exams.
ShinyHunters claimed responsibility after allegedly breaching Instructure again.
Source: https://therecord.media/universities-forced-to-reschedule-exams-canvas-incident.
Education platforms remain high-value cyber targets.
Follow @technadu@infosec.exchange
#CyberSecurity #InfoSec #DataBreach
Kingdom Market admin Alan Bill received a 16+ year sentence after pleading guilty to helping operate a major darknet marketplace tied to narcotics, malware, stolen data, fake IDs, and crypto transactions.
Another major international darknet takedown.
Source: https://therecord.media/kingdom-market-administrator-gets-16-year-sentence
Follow @technadu@infosec.exchange
Attackers are abusing Google Ads and legitimate Claude.ai shared chats to spread macOS malware.
• Fake install guides
• Malicious Terminal commands
• MacSync infostealer deployed
• Browser creds & Keychain targeted
Unoaerre confirmed a ransomware attack disrupting manufacturing operations.
• €3.8M ransom reportedly demanded
• Manufacturing plant evacuated
• IT systems isolated
• Data exposure investigation ongoing
https://www.technadu.com/unoaerre-ransomware-attack-disrupts-manufacturing-operations/627708/
Are manufacturing firms becoming prime ransomware targets?
#InfoSec #CyberSecurity #Ransomware
Taiwan’s train cyber incident is putting legacy wireless infrastructure under the spotlight.
Reports suggest replay attacks and low-cost SDR tools may have contributed to the disruption.
Critical infrastructure modernization can’t wait.
Follow @technadu@infosec.exchange for more.
Researchers say fake Android apps promising access to call logs and WhatsApp records reportedly reached 7.3M+ downloads before removal.
The apps allegedly generated completely fake data while charging users subscription fees.
Curiosity-driven mobile scams remain highly effective.
Source: https://cybernews.com/security/fake-call-logs-apps-android-users-fraud/
Follow @technadu@infosec.exchange for more.
#CyberSecurity #Android #MobileSecurity
Researchers say fake Android apps promising access to call logs and WhatsApp records reportedly reached 7.3M+ downloads before removal.
The apps allegedly generated completely fake data while charging users subscription fees.
Curiosity-driven mobile scams remain highly effective.
Source: https://cybernews.com/security/fake-call-logs-apps-android-users-fraud/
Follow @technadu@infosec.exchange for more.
AI dictation tools and vibe coding platforms are changing office culture fast.
Some startup leaders say future workplaces may sound “more like a sales floor” as employees increasingly talk to AI assistants instead of typing.
Would you work in a voice-first office?
Source: https://techcrunch.com/2026/05/10/get-ready-for-the-whisper-filled-office-of-the-future/
Follow @technadu@infosec.exchange for more AI updates.
UK online safety law raises concerns.
• Privacy risks from age verification
• Expanded govt powers
• Possible VPN restrictions
https://www.technadu.com/uk-online-safety-law-concerns-raise-privacy-debate/627353/
Safety vs privacy - your take?
#InfoSec #Privacy #CyberSecurity
Russia’s VPN crackdown is now impacting core services ⚠️
• Banking outages
• E-commerce disruptions
• Messaging app restrictions
• Govt systems affected
DPI filtering causing unintended traffic blocks.
https://www.technadu.com/russia-vpn-crackdown-impacts-banking-and-online-services/627170/
European Commission rolls out age verification
Anonymous + ID-based
Security vs privacy debate
💬 Thoughts?
Follow TechNadu
Bluesky hit by DDoS
• No breach
• No data loss
• Major disruption
Availability = attack surface
Source: https://techcrunch.com/2026/04/17/its-not-just-you-bluesky-is-sorta-down/
💬 Thoughts?
Follow TechNadu
AI is creating “ghost breaches”
• Fake incidents
• Real responses
• No compromise
Risk = narrative-driven
SOC + Comms must align
Source: https://cyberscoop.com/ai-generated-breach-narratives-ghost-threat-vector-op-ed/
💬 Thoughts?
Follow TechNadu
#InfoSec #CyberSecurity #AI
Cloud security ≠ failing
It’s hitting human limits
• Exploits in hours
• Identity sprawl
• Manual remediation bottleneck
Future:
Humans set guardrails
Machines respond
Source: https://www.sysdig.com/blog/sysdig-2026-cloud-native-security-and-usage-report
💬 Agree?
Follow @technadu@infosec.exchange
Grinex hit by $13M cyberattack 🚨
• Operations suspended
• State actor suspected
• Sanctions-linked
New KEV added 🚨
CVE-2026-34197 (Apache ActiveMQ)
• Active exploitation confirmed
• High-risk entry point
KEV = patch now, not later
💬 How fast is your patch cycle?
Follow @technadu@infosec.exchange
OT malware ZionSiphon targets water systems 🚨
• Alters chlorine & pressure
• ICS protocol scanning
• USB propagation
Third-party breach hits Inditex 🚨
• Transaction data accessed
• Vendor compromised
• No financial data exposed
Operation PowerOFF 🚨
• 53 domains seized
• 75K+ users targeted
• 3M+ accounts exposed
Global DDoS crackdown 👇
https://www.technadu.com/europol-ddos-crackdown-operation-poweroff-dismantles-over-50-domains-targets-75000-criminals-worldwide-secures-4-arrests/626025/
Cyber → Physical theft is scaling
• Load board compromise
• RMM persistence
• Signed malware
• Financial + cargo targeting
$6.6B losses in 2025
Supply chain = high-value attack surface
Source: https://therecord.media/cargo-thieving-hackers-running-sophisticated-campaigns
💬 Thoughts
Follow @technadu@infosec.exchange