Software

Trezor data breach impact now reaches 81,000 customers

Cryptocurrency hardware wallet maker Trezor says an August data breach at its shipping and logistics provider, ShipMonk, affects an additional 67,000 U.S. customers. In total, the breach has affected 81,000 customers after Trezor initially disclosed on August 13 that attackers accessed the data of nearly 14,000 customers, including their full names, shipping addresses, email addresses, […]

Trezor data breach impact now reaches 81,000 customers Read More »

New CrowdStrike ‘FalconFlank’ zero-day grants SYSTEM privileges

An anonymous security researcher who uses the “Nightmare Eclipse” handle released a CrowdStrike Falcon zero-day exploit named “FalconFlank” that lets attackers escalate privileges on up-to-date Windows systems. Nightmare Eclipse says the new vulnerability (which has yet to be assigned a CVE ID) affects devices running the latest versions of Windows 11 and Windows Server, as

New CrowdStrike ‘FalconFlank’ zero-day grants SYSTEM privileges Read More »

US military disabled ad tracking on troops’ devices following reports of targeted attacks

The U.S. Department of Defense has disabled advertising tracking on troops’ phones and computers as part of an effort to protect them from threats that target their locations, according to a letter shared with Sen. Ron Wyden. Per a letter shared with the senior Democrat on the Senate Intelligence Committee, Wyden said that the U.S.

US military disabled ad tracking on troops’ devices following reports of targeted attacks Read More »

Google warns of new Chrome zero-day flaw exploited in attacks

Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities. The exploited security issue, identified as CVE-2026-85046, is described as a type confusion. It was reported to Google by researcher Salvatore Gulizia, known online as “Serotav.” The update brings Chrome to version 152.0.7977.82/.83

Google warns of new Chrome zero-day flaw exploited in attacks Read More »

Google warns of new Chrome zero-day flaw exploited in attacks

Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities. The exploited security issue, identified as CVE-2026-85046, is described as a type confusion. It was reported to Google by researcher Salvatore Gulizia, known online as “Serotav.” The update brings Chrome to version 152.0.7977.82/.83

Google warns of new Chrome zero-day flaw exploited in attacks Read More »

Nvidia puts its money where its mouth is on open weight AI, moving to buy Hugging Face for $13 billion

Nvidia has just announced that it intends to acquire Hugging Face, the biggest open platform dedicated to developing machine-learning applications. Considering Nvidia has been all-in on AI for the past few years—to the point that I barely remember the last time the company even mentioned gaming in an earnings call—it’s hardly a surprising move. What

Nvidia puts its money where its mouth is on open weight AI, moving to buy Hugging Face for $13 billion Read More »

This Google Chrome alternative is the most exciting Android browser I’ve used all year

Affiliate links on Android Authority may earn us a commission. Learn more. Andy Walker / Android AuthorityAdd Android Authority on Google: Preferred SourceGoogle DiscoverIt’s usually difficult to get excited about a new Android browser. Unlike the launcher space, which includes a puzzle piece for almost every conceivable niche, browsers are mostly limited to two major

This Google Chrome alternative is the most exciting Android browser I’ve used all year Read More »

Plex warns users to patch security vulnerabilities immediately

Plex urged users this week to update their desktop clients and media servers immediately to patch multiple security vulnerabilities. These flaws have not yet been assigned CVE IDs for easy tracking, and while Plex didn’t provide additional details on Tuesday, the security issues are known to affect Plex Media Server v1.43.2 and earlier. Plex also

Plex warns users to patch security vulnerabilities immediately Read More »

Your Employee’s Password Appeared in an Infostealer Log. Now What?

Infostealer logs have evolved from an underground commodity into an operational security problem. For defenders, finding an exposed credential is only the beginning. In today’s reality many security analysts start their morning with an alert: an employee’s corporate email address has appeared in a newly collected infostealer log. The log contains a username and password

Your Employee’s Password Appeared in an Infostealer Log. Now What? Read More »

Critical Elementor Pro flaw exploited to take over WordPress sites

A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server. Elementor Pro is a popular WordPress plugin with more than 6 million active installations, allowing users to build websites using a drag-and-drop interface. The CVE-2026-32475

Critical Elementor Pro flaw exploited to take over WordPress sites Read More »