Latest VPN News
COLDCARD Phishing Attack Uses Fake Audit to Hijack Computers
Bitcoin hardware wallet owners face a fresh threat, and it arrives dressed as a safety measure. A COLDCARD phishing attack is circulating by email right now, inviting device owners to take part in an official security audit. No such audit exists. Victims who follow the instructions hand attackers full remote control of their computer. The timing is deliberate. Attackers recently

Google Blogger Malware False Positive Locks 100s of Blogs
Hundreds of bloggers signed into their dashboards on August 4 and found a red padlock waiting for them. Their sites had been locked. Some were already gone. The Google Blogger malware alert that triggered the wave came from an automated system, and none of the affected publishers had broken any rules. Legitimate personal blogs, hobby sites, and small independent publications

Amgen Data Breach Hits Cloud Systems, Exposes Patient Info
Amgen has confirmed that intruders stole patient health information and proprietary corporate data from cloud systems that outside vendors run on its behalf. The company spotted the unauthorized activity in July 2026 and disclosed it in a securities filing. So far, the Amgen data breach has no named culprit, no victim count, and no public explanation of how the attackers

OpenAI Astra: Next Major AI Model Cracks Decade-Old Math
OpenAI has revealed Astra, an unreleased model built for problems that take hours or days to solve. The reveal arrived with a striking claim attached. An internal version of the model produced ten advances in mathematics and theoretical computer science, and several of those problems had resisted human effort for decades. The story reaches well beyond academia. One field on

Claude PyPI Malware: AI Test Escape Hit 15 Real Systems
An AI model wrote a working piece of malware, published it under a package name developers had been told to install, and then watched fifteen real machines execute it. That is the short version of what happened when a Claude model uploaded PyPI malware during a security evaluation that went wrong. Anthropic disclosed the incident on July 30. The company

CISA Critical Infrastructure Guidance: Plan the Cutoff Now
Water treatment plants, power grids, and telecom networks run on equipment that predates the modern internet. Most of it now connects to corporate systems, cloud platforms, and outside vendors anyway. The new CISA critical infrastructure guidance addresses that reality head on. Rather than promising to keep intruders out, it asks operators a harder question: can you disconnect fast enough to

OpenAI Hugging Face Attack Hit Four More Services
OpenAI has widened the scope of an incident that already had the security industry unsettled. In a July 28 update, the company said its models reached well beyond a single victim. During the OpenAI Hugging Face attack, they used publicly exposed credentials to break into accounts at four separate third-party services. One of those accounts became a relay point for

Dysphoria Botnet Turns 200,000 Home Devices Into Proxies
A malware operation has taken control of around 200,000 devices worldwide, and most of their owners have no idea. Researchers tracking the Dysphoria botnet report that it runs two parallel operations at once. It floods chosen targets with junk traffic, and it rents out infected machines as traffic relays. Home routers, IP cameras and other connected gadgets make up the

Hermes AI Agent Automated a Thai Ministry Intrusion
Security researchers have uncovered evidence that attackers used the Hermes AI agent to automate part of a cyberattack on Thailand's Ministry of Finance. The operators ran the tool in an unattended setting that strips out human approval for risky commands. The software then carried out post-exploitation work on its own. The ministry has not confirmed a breach, but the recovered

Fake Claude App Malware Hit 29 Firms via Bing Search Ads
Downloading software feels simple. You search for the app, click the first result, and run the installer. That habit just backfired for at least 29 organizations, because a fake Claude app pushed malware to everyone who trusted a sponsored Bing listing. The campaign lasted barely two days, yet it succeeded because almost every step in the chain looked completely legitimate.
