Latest VPN News

July 15, 2026

Spanish Police Take Down €140M Cyber Fraud Ring

Investment scams and executive impersonation schemes rarely stay small for long, and a recent case out of Spain shows just how large these operations can grow. Spanish police have taken down a cyber fraud ring accused of laundering €140 million through a sprawling network of bank accounts, fake invoices, and impersonated executives. Four suspects now face charges after coordinated raids

Spanish police cyber fraud ring
July 14, 2026

1VPNS Hit With US Sanctions Over Ransomware Ties

The United States Treasury Department has taken direct aim at the infrastructure behind ransomware attacks. On Monday, the Office of Foreign Assets Control announced sanctions against 1VPNS, a virtual private network provider, and its administrator, in connection with ransomware attacks against U.S. organizations. The 1VPNS ransomware sanctions mark a shift toward punishing the suppliers behind attacks, not just the criminals

1VPNS ransomware sanctions
July 13, 2026

New Helix Vishing Attacks Target SharePoint Data

A cybercrime group calling itself Helix has started targeting corporate SharePoint environments using a mix of phone calls, stolen credentials, and multi-factor authentication abuse. Rather than deploying malware, Helix vishing attacks rely on tricking employees into handing over account access directly. The result is the same as any major breach: sensitive files exposed, and companies facing extortion demands to keep

Helix Vishing Attacks
July 10, 2026

Fake Paysafe, Skrill npm Packages Steal Developer Data

Developers building payment integrations just became the target of a coordinated supply chain attack. Security researchers uncovered fake Paysafe and Skrill npm packages designed to look like legitimate SDKs, but built instead to steal credentials from anyone who installed them. The campaign also spread through PyPI, Python's package repository, hitting developers across two of the most widely used software ecosystems

fake Paysafe Skrill npm packages
July 9, 2026

KDDI Data Breach Exposes Email Data of 12 Million People

A single vulnerability in shared email infrastructure has triggered one of Japan's largest data breaches in recent memory. KDDI, the country's second-largest mobile carrier, confirmed that a security incident tied to its email platform has exposed personal information belonging to more than 12 million people. The KDDI data breach also touches customers of five smaller internet service providers that rely

KDDI Data Breach
July 8, 2026

LONGLEASH Malware Expands Chinese Hacker Router Network

A Chinese state-linked hacking group has developed a new piece of malware that turns ordinary routers into hidden relay points for cyberattacks. Researchers at Cisco Talos have traced this activity to a group tracked as UAT-7810, and the tool at the center of it is called LONGLEASH. The LONGLEASH malware is not just another backdoor. It's built to expand what

LONGLEASH Malware
July 7, 2026

Inside the NetNut Botnet Takedown: 2M Devices Freed

A quiet piece of internet infrastructure just got a lot less useful for cybercriminals. The NetNut botnet takedown, carried out by Google's Threat Intelligence Group, the FBI, Lumen Technologies, and The Shadowserver Foundation, has dismantled a residential proxy network built from roughly 2 million hijacked devices. The network, also known as "Popa," gave hackers a way to disguise malicious traffic

NetNut botnet
July 6, 2026

JadePuffer Ransomware: The First Fully AI-Run Cyberattack

A ransomware attack usually needs a human behind the keyboard, at least at the critical moments. That assumption just broke. Security researchers at Sysdig have documented what appears to be the first ransomware operation carried out from start to finish by an autonomous AI agent, and they've named it JadePuffer ransomware. No operator typed commands during the intrusion. An AI

JadePuffer Ransomware
July 3, 2026

Microsoft 365 Password Spraying Attack Hits 78 Accounts

A large-scale password spraying attack has hit Microsoft 365 accounts across dozens of organizations, generating more than 81 million login attempts in just two weeks. Security researchers at Huntress tracked the campaign between June 12 and June 26, and confirmed that attackers successfully compromised 78 accounts spanning 64 organizations. What makes this campaign stand out isn't just its scale. The

Microsoft 365 password spraying attack
July 2, 2026

ChocoPoC Malware Hides in Fake GitHub Security Exploits

Security researchers have uncovered a malware campaign that turns the tools of the trade against the people who use them. A newly identified threat called ChocoPoC malware is spreading through fake proof-of-concept exploits on GitHub, targeting the very researchers and penetration testers who download these files to study vulnerabilities. The campaign flips a familiar trust relationship on its head, using

ChocoPoC malware