Latest VPN News

August 26, 2026

Operation Jackal IV: 58 Arrests in Global Fraud Takedown

Police forces in 22 countries have closed one of the biggest fraud investigations of the past year. Operation Jackal IV ran from November 2025 through June 2026, and it ended with 58 arrests. Investigators also identified 263 more suspects tied to cybercrime networks run by West African organized crime groups. INTERPOL coordinated the work, and the results open a rare

Operation Jackal IV
August 25, 2026

MoYu Proxy Botnet Hijacks Android Car Head Units

A car's touchscreen looks harmless. It plays music, shows maps, and handles the climate controls. But researchers have now found malware that turns those screens into infrastructure for online crime. They traced the campaign to MoYu, a threat group that runs a proxy botnet built from hijacked consumer devices. This time the target was the Android head unit sitting in

MoYu proxy botnet
August 24, 2026

ToxicPanda Android Malware Blocks Google Play Via VPN

A banking trojan aimed at Android phones has returned with a much sharper set of tools. The ToxicPanda Android malware now asks victims to approve a VPN connection, then uses that access to cut the phone off from Google Play. Once that link goes dark, the device loses the checks that would normally catch a threat like this. Security scans,

ToxicPanda Android malware
August 21, 2026

Claude AI Watermarking: How Anthropic Will Tag Its Text

Anthropic has revealed how it plans to mark the text Claude produces, and the method avoids the usual tricks. Claude AI watermarking runs during generation rather than after it, so nothing attaches to the finished response. The technique draws on Google DeepMind's SynthID-Text research, and it leaves a statistical trail instead of a visible one. This matters because machine-written text

Claude AI watermarking
August 20, 2026

Evooo1Bot Botnet Hijacks Routers to Relay Criminal Traffic

A new strain of Linux malware has been turning routers into relay points for criminal traffic. Researchers call the threat Evooo1Bot. The Evooo1Bot botnet has been active since at least July. It hunts for internet-facing gateway devices. Then it turns each one into a SOCKS5 proxy node. The owner keeps browsing as normal. Meanwhile, someone else's traffic leaves the same

Evooo1Bot botnet
August 19, 2026

Trezor Data Breach Exposes Nearly 14,000 Crypto Customers

Crypto owners buy hardware wallets so their private keys never touch the internet. That logic still holds. Yet the Trezor data breach exposed personal details for nearly 14,000 customers. Attackers never came close to the devices themselves. Instead, they walked in through a shipping company. The hardware wallet maker confirmed the incident on August 13, 2026, after its logistics partner

Trezor data breach
August 18, 2026

Pokémon Center Data Breach Hits UK and German Shoppers

Pokémon fans in the United Kingdom and Germany opened their inboxes this week to unwelcome news. The Pokémon Center data breach exposed personal details belonging to customers who ordered merchandise from the official online store. Attackers never touched Pokémon Center's own systems, though. They broke into CEVA Logistics, the shipping partner that handles deliveries for the site across both countries.

Pokémon Center data breach
August 17, 2026

Threema DDoS Attack Disrupts Secure Messaging for Two Days

Users of the Swiss messaging app Threema spent two days this week staring at messages that refused to send. Some watched the connection indicator flip between "Connecting" and "Connected." Others gave up and moved to another app. Behind the confusion sat a sustained Threema DDoS attack against the company and its hosting partner. A Two-Day Disruption With a Shifting Explanation

Threema DDoS attack
August 14, 2026

Polish Energy Plant Breach: Hackers Pivoted via Private APN

Investigators in Poland have now detailed a second victim from the destructive attacks that struck the country's energy sector in December 2025. The newly disclosed Polish energy plant breach hit a small combined heat-and-power facility that supplies warmth to roughly 50,000 residents. Attackers shut down its steam turbine and its process-water treatment system. Staff restored operations quickly, so people in

Polish energy plant breach
August 13, 2026

StormEncryptor Ransomware Linked to Ex-Medusa Affiliate

A new ransomware strain has surfaced, and the group behind it already has a long track record. Microsoft Threat Intelligence has connected StormEncryptor ransomware to Storm-1175, a financially motivated actor that spent months working as an affiliate of the Medusa operation. The group appears to have cut ties with that brand and built its own locker instead. So far, the

StormEncryptor Ransomware