News archive — Page 2
Source-backed reporting on VPNs, privacy, scams, data breaches and online security—plus the practical steps worth taking next.
News archive
Reports 11–20
Clear summaries, visible dates and direct source links—without turning every security story into a VPN sales pitch.

X Password-Reset Email Flood: What Users Should Do
X is investigating a wave of password-reset messages as its X Money service expands. The company says it has found no evidence of a breach or successful account takeovers, but the genuine alerts can create cover for phishing and reset-code scams.
Read analysis
PaperCut Attacks Are Stealing Credentials From Education Networks
Researchers have now documented credential theft and privileged-account creation after attackers exploited two PaperCut flaws. Schools and universities should patch, restrict exposure and hunt for compromise rather than treating the update alone as proof they are clean.
Read analysis
Invisible Unicode Is Helping Phishing Emails Evade Filters
Microsoft found a finance-themed phishing campaign inserting non-rendering Unicode characters inside ordinary words. The message can look normal to a person while breaking simple keyword checks, so inbox placement must never be treated as proof an email is safe.
Read analysis
Chrome Zero-Day CVE-2026-85046: Update Your Browser Now
Google has released a Chrome update for an actively exploited V8 flaw. Desktop users should restart into the fixed build, while people using other Chromium-based browsers should watch for their vendor's update.
Read analysis
Plex Tells Server Owners to Install Security Update Now
Plex has released Media Server 1.43.3 and Plex Desktop 1.115.0 for multiple security issues. NAS users may need to install the package manually if their device's app store has not caught up.
Read analysis
Fake Job Interviews Are Spreading Malware: What to Check
A convincing recruiter, video call and familiar cloud document can still lead to a malicious interview task. UK jobseekers should verify the role independently and refuse unexpected software installs.
Read analysis
Single-Hop VPNs Face Fresh Traffic-Analysis Warning
US senator Ron Wyden has asked the NSA to update its VPN guidance after a congressional analysis said a powerful observer could correlate encrypted traffic entering and leaving a single VPN server. The concern does not mean ordinary VPN encryption has been broken.
Read analysis
Dropbox Accounts Accessed Through Lenovo ID Verification Flaw
Dropbox says an attacker registered fraudulent Lenovo IDs with other people's email addresses and used the linked sign-in route to enter some Dropbox accounts without their Dropbox passwords. Dropbox and Lenovo say they have mitigated the legacy integration issue.
Read analysis
Fake Downing Street Listing Exposes Booking.com Fraud Gaps
Which? created a fake Booking.com holiday listing for 10 Downing Street, accepted a controlled test booking and sent an external payment link through the platform's messaging system. Booking.com says the limited test does not reflect the experience of most listings.
Read analysis
UK SMS Blaster Case Shows Why Scam Texts Can Look Local
A Preston man has been jailed for using a rogue mobile-antenna system from a van near the Trafford Centre to send fraudulent texts directly to nearby phones. Investigators recovered thousands of compromised payment-card records.
Read analysis