Latest VPN News
MoYu Proxy Botnet Hijacks Android Car Head Units
A car's touchscreen looks harmless. It plays music, shows maps, and handles the climate controls. But researchers have now found malware that turns those screens into infrastructure for online crime. They traced the campaign to MoYu, a threat group that runs a proxy botnet built from hijacked consumer devices. This time the target was the Android head unit sitting in

ToxicPanda Android Malware Blocks Google Play Via VPN
A banking trojan aimed at Android phones has returned with a much sharper set of tools. The ToxicPanda Android malware now asks victims to approve a VPN connection, then uses that access to cut the phone off from Google Play. Once that link goes dark, the device loses the checks that would normally catch a threat like this. Security scans,

Claude AI Watermarking: How Anthropic Will Tag Its Text
Anthropic has revealed how it plans to mark the text Claude produces, and the method avoids the usual tricks. Claude AI watermarking runs during generation rather than after it, so nothing attaches to the finished response. The technique draws on Google DeepMind's SynthID-Text research, and it leaves a statistical trail instead of a visible one. This matters because machine-written text

Evooo1Bot Botnet Hijacks Routers to Relay Criminal Traffic
A new strain of Linux malware has been turning routers into relay points for criminal traffic. Researchers call the threat Evooo1Bot. The Evooo1Bot botnet has been active since at least July. It hunts for internet-facing gateway devices. Then it turns each one into a SOCKS5 proxy node. The owner keeps browsing as normal. Meanwhile, someone else's traffic leaves the same

Trezor Data Breach Exposes Nearly 14,000 Crypto Customers
Crypto owners buy hardware wallets so their private keys never touch the internet. That logic still holds. Yet the Trezor data breach exposed personal details for nearly 14,000 customers. Attackers never came close to the devices themselves. Instead, they walked in through a shipping company. The hardware wallet maker confirmed the incident on August 13, 2026, after its logistics partner

Pokémon Center Data Breach Hits UK and German Shoppers
Pokémon fans in the United Kingdom and Germany opened their inboxes this week to unwelcome news. The Pokémon Center data breach exposed personal details belonging to customers who ordered merchandise from the official online store. Attackers never touched Pokémon Center's own systems, though. They broke into CEVA Logistics, the shipping partner that handles deliveries for the site across both countries.

Threema DDoS Attack Disrupts Secure Messaging for Two Days
Users of the Swiss messaging app Threema spent two days this week staring at messages that refused to send. Some watched the connection indicator flip between "Connecting" and "Connected." Others gave up and moved to another app. Behind the confusion sat a sustained Threema DDoS attack against the company and its hosting partner. A Two-Day Disruption With a Shifting Explanation

Polish Energy Plant Breach: Hackers Pivoted via Private APN
Investigators in Poland have now detailed a second victim from the destructive attacks that struck the country's energy sector in December 2025. The newly disclosed Polish energy plant breach hit a small combined heat-and-power facility that supplies warmth to roughly 50,000 residents. Attackers shut down its steam turbine and its process-water treatment system. Staff restored operations quickly, so people in

StormEncryptor Ransomware Linked to Ex-Medusa Affiliate
A new ransomware strain has surfaced, and the group behind it already has a long track record. Microsoft Threat Intelligence has connected StormEncryptor ransomware to Storm-1175, a financially motivated actor that spent months working as an affiliate of the Medusa operation. The group appears to have cut ties with that brand and built its own locker instead. So far, the

ChatGPT 5.6 Cyber: OpenAI Limits Access to Vetted Partners
OpenAI has released a security model that almost nobody will get to touch. ChatGPT 5.6 Cyber arrived with a short guest list, and regular subscribers are not on it. The company built the model for vulnerability research, penetration testing, incident response, and remediation. Access runs only through a set of approved consultancies and security vendors. That decision says plenty about
