Software

Ukraine shuts down 94 fraudulent call centers, seize millions in cash

Authorities in Ukraine shut down 94 fraudulent call centers across the country that lured people into investment scams or tried to obtain access to bank accounts. The operation occurred this week, and police officers conducted a total of 411 searches following an investigation that involved the National Police, Ukraine’s Security Service, the Prosecutor General’s Office, […]

Ukraine shuts down 94 fraudulent call centers, seize millions in cash Read More »

Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt

An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking. The attack occurred on August 4 after the hacker obtained initial access through an exposed SonicWall VPN device without multi-factor authentication (MFA). Managed detection and response (MDR) services company Huntress

Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt Read More »

Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks

You’re not alone if you just received an “Apple Threat Notification” saying it detected a “mercenary spyware attack targeted at your iPhone.” Some users on Reddit are reporting that they received these alerts today after Apple sent out a new batch of threat notifications on August 13, but the feature itself is not new. Apple

Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks Read More »

White House taps security firms for offensive hack-back operations

A new White House memo signed by U.S. President Donald Trump instructs the National Coordination Center (NCC) to establish a program that would allow private security companies to apply for approval to hack foreign cybercrime organizations. Signed on Wednesday, the national security presidential memorandum (NSPM) enables the NCC (part of the Homeland Security Task Force)

White House taps security firms for offensive hack-back operations Read More »

Chrome could soon let Gemini auto-fix your bad passwords, and I’m not sure if that’s a good idea

Affiliate links on Android Authority may earn us a commission. Learn more. Keeping track of dozens of online logins and staying safe online gets exhausting fast. But it’s also very frustrating when reused passwords finally come back to bite you, so Google might be building an AI shortcut to clean up that mess. Instead of

Chrome could soon let Gemini auto-fix your bad passwords, and I’m not sure if that’s a good idea Read More »

WhatsApp rolls out new feature that flags potential scam messages

WhatsApp has begun rolling out a new optional “Scam Alert” feature, which uses a local machine learning model to warn users when scammers are targeting them. Scam Alert is now available as part of a limited beta rollout while the company tests this new warning system with researchers in its Bug Bounty community. “Today, we’re

WhatsApp rolls out new feature that flags potential scam messages Read More »

PSA: Don’t trust that Chrome update popup — it could be malware

Affiliate links on Android Authority may earn us a commission. Learn more. We all have our favorite Chrome extensions that make daily web browsing effortless, whether it’s a quick screen snip tool, a right-click unlocker, or a simple tab manager. But what happens when one of those trusty add-ons quietly turns against you? Over the

PSA: Don’t trust that Chrome update popup — it could be malware Read More »

Plug and Pwn attack uses fake USB devices for Windows SYSTEM access

Security researchers have disclosed new “Plug and Pwn” attacks that abuse the Windows Plug and Play feature to trigger Windows into installing vulnerable or insecure vendor software and gain SYSTEM privileges. The research, presented at DEF CON 34 by security researchers Alejandro Hernando and Borja Martínez, exploits how Windows automatically identifies new connected hardware, locates

Plug and Pwn attack uses fake USB devices for Windows SYSTEM access Read More »

Hundreds of fake Chrome VPN extensions route traffic through a proxy

More than 737 browser extensions published on the Chrome Web Store impersonated well-known VPN and proxy services while routing users’ traffic through SOCKS5 proxies operated by a single provider. Some of the extensions impersonated dozens of established brands, including Proton VPN, NordVPN, Surfshark, ExpressVPN, and Cloudflare’s 1.1.1.1 public domain name system (DNS) resolver. Researchers at

Hundreds of fake Chrome VPN extensions route traffic through a proxy Read More »

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe’s Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts. The flaw is described as an incorrect authorization vulnerability that could be leveraged to “gain elevated access to sensitive resources” without authentication and is one of the seven issues that Adobe

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts Read More »