August 25, 2026

MoYu Proxy Botnet Hijacks Android Car Head Units

A car's touchscreen looks harmless. It plays music, shows maps, and handles the climate controls. But researchers have now found malware that turns those screens into infrastructure for online crime. They traced the campaign to MoYu, a threat group that runs a proxy botnet built from hijacked consumer devices. This time the target was the Android head unit sitting in

MoYu proxy botnet
August 24, 2026

ToxicPanda Android Malware Blocks Google Play Via VPN

A banking trojan aimed at Android phones has returned with a much sharper set of tools. The ToxicPanda Android malware now asks victims to approve a VPN connection, then uses that access to cut the phone off from Google Play. Once that link goes dark, the device loses the checks that would normally catch a threat like this. Security scans,

ToxicPanda Android malware
August 19, 2026

Trezor Data Breach Exposes Nearly 14,000 Crypto Customers

Crypto owners buy hardware wallets so their private keys never touch the internet. That logic still holds. Yet the Trezor data breach exposed personal details for nearly 14,000 customers. Attackers never came close to the devices themselves. Instead, they walked in through a shipping company. The hardware wallet maker confirmed the incident on August 13, 2026, after its logistics partner

Trezor data breach
August 18, 2026

Pokémon Center Data Breach Hits UK and German Shoppers

Pokémon fans in the United Kingdom and Germany opened their inboxes this week to unwelcome news. The Pokémon Center data breach exposed personal details belonging to customers who ordered merchandise from the official online store. Attackers never touched Pokémon Center's own systems, though. They broke into CEVA Logistics, the shipping partner that handles deliveries for the site across both countries.

Pokémon Center data breach
August 17, 2026

Threema DDoS Attack Disrupts Secure Messaging for Two Days

Users of the Swiss messaging app Threema spent two days this week staring at messages that refused to send. Some watched the connection indicator flip between "Connecting" and "Connected." Others gave up and moved to another app. Behind the confusion sat a sustained Threema DDoS attack against the company and its hosting partner. A Two-Day Disruption With a Shifting Explanation

Threema DDoS attack
August 14, 2026

Polish Energy Plant Breach: Hackers Pivoted via Private APN

Investigators in Poland have now detailed a second victim from the destructive attacks that struck the country's energy sector in December 2025. The newly disclosed Polish energy plant breach hit a small combined heat-and-power facility that supplies warmth to roughly 50,000 residents. Attackers shut down its steam turbine and its process-water treatment system. Staff restored operations quickly, so people in

Polish energy plant breach
August 13, 2026

StormEncryptor Ransomware Linked to Ex-Medusa Affiliate

A new ransomware strain has surfaced, and the group behind it already has a long track record. Microsoft Threat Intelligence has connected StormEncryptor ransomware to Storm-1175, a financially motivated actor that spent months working as an affiliate of the Medusa operation. The group appears to have cut ties with that brand and built its own locker instead. So far, the

StormEncryptor Ransomware
August 10, 2026

ClickFix Attack Plants macOS Malware That Skims Crypto Wallets

Copy this command into Terminal and the problem fixes itself. That single instruction has become one of the most reliable ways to compromise an Apple computer. Researchers at Huntress traced a ClickFix campaign spreading macOS malware written in Go. The payload handles two jobs at once. It collects stored credentials, then reroutes cryptocurrency payments to the attacker before the owner

ClickFix macOS malware
August 7, 2026

COLDCARD Phishing Attack Uses Fake Audit to Hijack Computers

Bitcoin hardware wallet owners face a fresh threat, and it arrives dressed as a safety measure. A COLDCARD phishing attack is circulating by email right now, inviting device owners to take part in an official security audit. No such audit exists. Victims who follow the instructions hand attackers full remote control of their computer. The timing is deliberate. Attackers recently

COLDCARD phishing attack
August 5, 2026

Amgen Data Breach Hits Cloud Systems, Exposes Patient Info

Amgen has confirmed that intruders stole patient health information and proprietary corporate data from cloud systems that outside vendors run on its behalf. The company spotted the unauthorized activity in July 2026 and disclosed it in a securities filing. So far, the Amgen data breach has no named culprit, no victim count, and no public explanation of how the attackers

Amgen data breach