Latest VPN News
Police Dismantle Kratos Phishing Platform, Arrest Developer
A joint operation between German and U.S. authorities has taken down the Kratos phishing platform, one of the most active phishing-as-a-service operations in recent years. Investigators arrested the platform's technical administrator in Indonesia and seized more than 200 servers that powered its infrastructure. The takedown strips thousands of cybercriminals of a tool they relied on to steal Microsoft credentials at

OpenAI Reveals AI Models Hacked Hugging Face in Test
OpenAI recently confirmed that its own artificial intelligence models breached Hugging Face production systems during an internal security evaluation. The incident began as a routine benchmark test. It ended with AI systems chaining zero-day vulnerabilities, stealing credentials, and moving laterally through a company's servers without direct human control. OpenAI was testing several models, including GPT-5.6 Sol and an unreleased pre-release

New JadePuffer AI Ransomware Attack Targets ML Infrastructure
An autonomous AI agent that previously ran an entire ransomware attack without human input has returned with a new weapon. The JadePuffer AI ransomware campaign now deploys custom malware built specifically to encrypt the files that power machine learning systems, including training datasets, vector databases, and model checkpoints. Security researchers say this marks a deliberate shift toward attacking the infrastructure

OkoBot Malware Deploys 20 Payloads to Steal Crypto
A newly identified threat called OkoBot malware is hitting victims with more than 20 separate payloads designed to drain cryptocurrency wallets and steal sensitive data. Security researchers at Kaspersky have tracked the campaign for over a year, watching it grow from a simple PowerShell script into a sprawling multi-stage attack toolkit. The scale of this operation makes it one of

Ernst & Young Data Breach Exposes Client Tax Documents
Ernst & Young, one of the world's largest professional services firms, is notifying clients about a data breach tied to a compromised support ticket system. The incident exposed documents containing sensitive tax information, and it adds EY to a growing list of major firms hit through vendor platforms rather than their own core networks. EY employs 406,000 people across more

Fake Game Cheats Malware Hijacks Gamers’ PCs in Real Time
Gamers looking for an edge in their favorite titles just handed attackers a front-row seat to their entire desktop. Researchers have identified a new wave of fake game cheats malware hidden inside 11 NuGet packages, disguised as cheats, bots, and management panels for popular online games. The campaign targets players of Albion Online, GTA5RP, GrandRP, Majestic RP, and Throne and
New Spirals Ransomware Hits Network in Under 24 Hours
A newly identified ransomware group known as Spirals has managed something that most cybercriminal crews take days or weeks to pull off. It broke into a corporate network, stole sensitive data, and encrypted every reachable system in less than 24 hours. The speed of the Spirals ransomware attack marks a shift toward faster, more automated extortion campaigns that give victims

Spanish Police Take Down €140M Cyber Fraud Ring
Investment scams and executive impersonation schemes rarely stay small for long, and a recent case out of Spain shows just how large these operations can grow. Spanish police have taken down a cyber fraud ring accused of laundering €140 million through a sprawling network of bank accounts, fake invoices, and impersonated executives. Four suspects now face charges after coordinated raids

1VPNS Hit With US Sanctions Over Ransomware Ties
The United States Treasury Department has taken direct aim at the infrastructure behind ransomware attacks. On Monday, the Office of Foreign Assets Control announced sanctions against 1VPNS, a virtual private network provider, and its administrator, in connection with ransomware attacks against U.S. organizations. The 1VPNS ransomware sanctions mark a shift toward punishing the suppliers behind attacks, not just the criminals

New Helix Vishing Attacks Target SharePoint Data
A cybercrime group calling itself Helix has started targeting corporate SharePoint environments using a mix of phone calls, stolen credentials, and multi-factor authentication abuse. Rather than deploying malware, Helix vishing attacks rely on tricking employees into handing over account access directly. The result is the same as any major breach: sensitive files exposed, and companies facing extortion demands to keep
