Cybersecurity
Ongoing coverage on Cybersecurity.
Latest coverage
Sunday Safety Dance
A MediaTek security flaw may have impacted more Android phones than previously thought, while US authorities have successfully dismantled botnets responsible for record-breaking cyberattacks. These events highlight ongoing challenges in mobile device security and the fight against large-scale cybercrime.
Saturday Safety Dance
The article discusses the increasing threat of iPhone spyware, noting that it is no longer exclusively a tool for governments. This indicates a broader accessibility and potential misuse of such surveillance technology.
Project Hail Mary screenwriter says his unmade Spider-Man spin-off movie didn't happen because of the 2014 Sony…
Screenwriter Drew Goddard revealed that his planned Sinister Six movie, a Spider-Man spin-off, was canceled due to the 2014 Sony Hack. The hack significantly disrupted Sony Pictures' operations, leading to the cancellation of several projects, including Goddard's film.
Star Citizen Reveals Content of Alpha 4.7 and Beyond, Including Crafting
Cloud Imperium Games experienced a data breach on January 21, 2026, where unauthorized access was gained to some backup systems, including limited personal user data for Star Citizen and Squadron 42 players. The company has contained the activity and updated security settings.
Blockchain Bridge Security: Key Risks, Challenges, and Effective Strategies
Blockchain bridges are essential for Web3 interoperability, enabling asset and data transfers between different networks. However, their complex nature and handling of significant digital assets make them prime targets for cyberattacks, with risks including compromised key management, insufficient monitoring, smart contract flaws, and lack of safeguards. Effective security strategies involve distributed management, active monitoring, preventive controls like rate limits, and continuous audits to ensure the robustness and resilience of these critical components.
Morning Safety Dance
The GlassWorm supply-chain attack has been identified as exploiting 72 open VSX extensions to target developers. This sophisticated attack highlights significant vulnerabilities within the software development ecosystem.
A new iPhone hacking tool puts some iOS 18 users at risk
A new fileless hacking technique called DarkSword poses a risk to iPhone users running specific versions of iOS 18 by exploiting malicious web pages to steal sensitive data and cryptocurrency. While Apple has released patches for the vulnerabilities in subsequent iOS updates, a portion of users may still be at risk if they have not updated their devices.
After Infecting PCs With Malware, Gacha Game Gives Out Free Loot Boxes To Apologize
The developers of the gacha RPG Duet Night Abyss, Pan Studio, have apologized for a cybersecurity incident that infected players' PCs with malware via a game launcher update patch. The malware, identified as Trojan:MSIL/UmbralStealer.DG!MTB, is an infostealer. In response, Pan Studio is offering players 10 free gacha pulls and other in-game rewards as compensation.
A new iPhone hacking tool puts anyone still on iOS 18 at risk
A new fileless hacking technique called DarkSword exploits vulnerabilities in iOS 18 versions, potentially affecting a quarter of iPhone users. The hack steals sensitive data, including cryptocurrency, and deletes itself without leaving a trace. Apple has released patches in later iOS versions, but users on iOS 18 are advised to update immediately.
Morning Safety Dance
Age-check technology is being implemented despite user dissatisfaction, with details on its functionality being revealed. Separately, Iran has launched a cyberattack against a medical technology firm, signaling potential future threats. A free privacy tool is also mentioned.
Microsoft Certifications: Empowering IT and Gaming Professionals - Walkthrough, Tips, Review
Microsoft certifications are valuable credentials for IT and gaming professionals, validating skills in areas like cloud computing, cybersecurity, data analytics, and software development. These certifications offer career advancement, higher earning potential, and professional recognition. The article outlines different certification levels, popular domains, and provides tips for exam preparation, emphasizing the importance of hands-on practice and official resources.
Tech companies are teaming up to combat scammers
A coalition of major tech companies, including Google, Microsoft, Meta, and Amazon, has signed the Online Services Accord Against Scams to combat online fraud. The agreement outlines measures such as enhanced fraud detection tools, new user security features, and improved verification processes. The coalition also plans to advocate for scam prevention to be declared a national priority by governments.
Intel has published a whole host of security vulnerabilities, with mitigations rolling out, but attackers will need…
Intel has disclosed numerous security vulnerabilities found in the UEFI firmware of its products, with some registering a CVSS score of 8.7. These vulnerabilities could allow for privilege escalation and local code execution. Mitigations are being rolled out, and users are advised to update their systems.
If you were scammed by malware hiding in your Steam games, the FBI wants to hear all about it
The FBI is seeking information from individuals who have been victims of malware distributed through games on the Steam platform. Several specific games, including BlockBlasters and Tokenova, have been identified as sources of malware that operated between May 2024 and January 2026, with some instances leading to significant financial loss through cryptocurrency theft.
Sunday Safety Dance
Google has released an urgent update for its Chrome browser to address two zero-day vulnerabilities that were actively being exploited. Users are strongly advised to update their Chrome installations immediately to protect against potential malware threats.
Evening Safety Dance
Meta is reportedly ending end-to-end encryption for Instagram direct messages soon. Separately, a credential-stealing group has been observed spoofing Ivanti, Fortinet, and Cisco VPNs to compromise user data.
The FBI is looking into Steam games loaded with malware—and one is still up on the store
The FBI's Seattle Division is investigating Steam games found to contain malware, with some titles released as recently as January 2024 still available on the platform. Games like Lampy, BlockBlasters, and PirateFi have been identified, with BlockBlasters reportedly stealing over $150,000 in crypto. While some games have been removed, Lampy remains active on Steam.
The FBI is hunting down malware-loaded games on Steam
The FBI is investigating a series of malware-infected games distributed on the Steam platform between May 2024 and January 2026. The agency is seeking information from players who downloaded titles like BlockBlasters, Chemia, and PirateFi, which contained malicious software capable of stealing personal data. Valve is cooperating with the investigation and has removed some affected games from its platform.
Morning Safety Dance
Researchers demonstrated how Perplexity's Comet AI browser can be tricked into a phishing scam in under four minutes. The article also touches on the broader risks of rogue AI agents working together to hack systems and mentions Google's rapid response to Chrome vulnerabilities.
FBI Launches Investigation Into Games Removed From Steam Over Malware Concerns
The FBI's Seattle Division has launched an investigation into several games removed from Steam for allegedly spreading malware. Players who downloaded titles like BlockBlasters, Chemia, and PirateFi between May 2024 and January 2026 are urged to report if they were victimized. Valve is not a target of the investigation.