Latest VPN News

October 9, 2026

Ninja Forms Vulnerability Hides Admin Accounts on WordPress

Attackers are exploiting a Ninja Forms vulnerability to plant hidden admin accounts on WordPress sites. The plugin runs on more than 500,000 sites, so the pool of targets is huge. Researchers logged the first attempts on 4 October 2026, and the campaign is still live. The Ninja Forms vulnerability matters far less than what attackers do once they are through

Ninja Forms vulnerability
October 8, 2026

Rogue OpenAI Agents Edited Wikipedia Without Permission

Wikipedia runs on donated cash, volunteer hours and servers that nobody built for heavy machine traffic. So the Wikimedia Foundation went looking for AI activity across its sites. Staff traced edits nobody approved, a probe of a public tool and millions of automated requests back to rogue OpenAI agents. The foundation went public with the lot on Monday, and its

rogue OpenAI agents
October 7, 2026

Nikkei Data Breach Exposes 1,646 Contacts in Email Hack

Two Nikkei staff mailboxes fell into the wrong hands this year, and one of them became a phishing machine. Over the weekend, the Japanese media group that owns the Financial Times confirmed both break-ins. The Nikkei data breach exposed the names and email addresses of 1,646 people. But the bigger blow came later, when about 9,000 scam emails went out

Nikkei data breach
October 5, 2026

ChatGPT Ads Are Coming, and They Bring Tracking With Them

OpenAI is bringing ChatGPT ads to one of the app's most used features. The company will test a visual ad format during image generation later this month, starting in the United States with a small group of advertisers. These ChatGPT ads sit next to the picture a user waits on, and they carry a clear label. For a product that

ChatGPT ads
October 2, 2026

Agentic AI Attack Breached a Dutch Security Nonprofit

A Dutch group that warns other firms about exposed systems has become its own case study. The Dutch Institute for Vulnerability Disclosure, or DIVD, says intruders broke into its network. What followed was an agentic AI attack that ran with almost no human at the keyboard. Seven quiet years ended in seconds, and the software left a huge mess behind.

agentic AI attack
October 1, 2026

Keio Corporation Cyberattack Halts Hotel and Payment Systems

Japan's trains run on a reputation for being on time, and that record rarely slips. It took a hit over the weekend of September 26, when a cyberattack reached Keio Corporation and the group pulled its network offline. Ransomware had already landed on its servers. Trains kept running, but the business systems behind them went dark, and that is where

Keio Corporation cyberattack
September 30, 2026

Malicious Custom GPTs Deliver RAT Malware via ClickFix

A new malware campaign starts where almost nobody thinks to check: inside a ChatGPT page. The operators built malicious custom GPTs, then paid Google to push them to the top of search. Victims trusted what they saw and followed the steps. At the end of those steps sat a remote access trojan with full control of the machine. How malicious

malicious custom GPTs
September 29, 2026

JadePuffer Ransomware Wipes 100+ Azure Accounts in 7 Minutes

Seven minutes was all it took to wipe more than 100 storage accounts from a single Microsoft Azure tenant. No human sat at the keyboard, because AI agents did the scouting, stole the keys, and started deleting on their own. Microsoft researchers have tied two of these break-ins to the JadePuffer ransomware operation. The ending everyone expects from a ransomware

JadePuffer ransomware
September 28, 2026

OpenAI Always-On Assistant Could Soon Read Your Inbox

A line of text that was never meant for the public spent a short while sitting on OpenAI's website, and it named a product the company has yet to announce. The $100 ChatGPT Pro plan listed "o, your always-on assistant" among its benefits, right beside the storage and usage perks that buyers already pay for. Then it vanished. Users on

OpenAI always-on assistant
September 25, 2026

RemControl: New Android Malware Hides Inside a Fake IPTV App

A free app that promises live TV and sports streams is the kind of download many people grab without a second thought, and criminals know it. Researchers at Group-IB have found RemControl, a new strain of Android malware hiding inside a fake TVTap streaming app. Once it lands on a phone, it switches off one of Google's key defences and

RemControl Android malware