News archive — Page 9
Source-backed reporting on VPNs, privacy, scams, data breaches and online security—plus the practical steps worth taking next.
News archive
Reports 81–90
Clear summaries, visible dates and direct source links—without turning every security story into a VPN sales pitch.

24,000 Exposed Server BMCs Leak Password Hashes: Why Remote Admin Should Not Be Public
Lava researchers say thousands of internet-facing IPMI/BMC interfaces can leak password-derived authentication material before login, reviving a long-known remote-management risk.
Read analysis
CISA Adds Fortinet and Arista Flaws to KEV: What Network-Edge Users Should Do
CISA says two actively exploited flaws affecting Fortinet FortiOS and Arista VeloCloud Orchestrator On-Prem have joined its Known Exploited Vulnerabilities catalog.
Read analysis
Zimbra Zero-Click Phishing Warning: Why Email Security Still Needs Patch Discipline
NSA, CISA and allied agencies warn that Russian state-supported actors used a view-based Zimbra exploit that can trigger when a vulnerable webmail user simply views a malicious email.
Read analysis
UK Rules Out a VPN Ban: What Age-Check Changes Mean for Privacy
The UK government says it will not ban or age-gate VPNs, even as platforms are told to stop under-18s using workarounds to bypass online safety checks.
Read analysis
Hotel Wi-Fi DNS Hijacking Warning: Why Travellers Should Use a Full-Tunnel VPN
BleepingComputer reports that attackers are compromising hotel and conference Wi-Fi gateways to redirect Microsoft 365 users to fake login pages.
Read analysis
Free VPN Extensions Caught Stealing Clipboard Data: What to Check Now
Socket researchers found Chrome and Firefox extensions posing as free VPNs that added clipboard-stealing code through updates, while CyberInsider later amplified the warning for browser users.
Read analysis
Craneware Healthcare Data Breach Shows Why Supplier Attacks Matter
Edinburgh-based Craneware says attackers accessed part of its data environment and exfiltrated file names plus some employee, customer and partner records, while services remained operational.
Read analysis
CISA Adds SharePoint and Check Point Flaws to Exploited-Vulnerability List
CISA says CVE-2026-50522 in Microsoft SharePoint and CVE-2026-16232 in Check Point SmartConsole have evidence of active exploitation, making patching and compromise checks urgent for exposed systems.
Read analysis
Origin Energy Data Breach Raises AI Scam Risks for Utility Customers
Origin Energy says some customer data was accessed and disclosed without authorisation, while ABC reports experts are warning that names, dates of birth, addresses and partial payment details can fuel more convincing AI-assisted scams.
Read analysis
23andMe Settlement Is a Reminder to Review Genetic Data and Reused Passwords
State attorneys general announced an $18 million bankruptcy recovery tied to the 23andMe breach, while the court-authorized settlement site says class member payments from a separate $46.75 million settlement are expected in September.
Read analysis