Cybersecurity
Ongoing coverage on Cybersecurity.
Latest coverage
Morning Safety Dance
Google acknowledged a researcher's discovery of a security flaw but denied a bug bounty, stating the issue is still unfixed. The article also briefly mentions a privacy watchdog quitting due to poor judgment.
Evening Safety Dance
A significant password-stealing attack has compromised approximately 75,000 Fortinet firewalls. The incident highlights a major cybersecurity vulnerability affecting a large number of devices.
Uh oh, your favorite anime girl could be conceal-carrying a malware payload through Wallpaper Engine
Wallpaper Engine users are at risk of downloading malware disguised as anime wallpapers. The application, popular for its animated backgrounds, has been identified as a potential vector for malicious payloads, posing a cybersecurity threat to users.
Hackers are using Steam Workshop and Wallpaper Engine to spread malware and steal accounts
Cybersecurity firm Kaspersky has reported that hackers are exploiting Steam Workshop and the popular Wallpaper Engine application to distribute malware. These malicious packages, disguised as custom wallpapers, are used to steal Steam accounts and other sensitive information, with users in China and Russia being primary targets, though victims have been found globally. Attackers bundle malware within executable wallpaper files or password-protected archives, posing a significant risk to PC gamers even on trusted platforms.
Morning Safety Dance
Users of Windows and Linux are reminded of an upcoming deadline to update Secure Boot keys. Additionally, Kaspersky has warned that hackers are distributing malware through anime-themed wallpapers on the Steam platform.
Warning all weebs: Kaspersky says hackers are distributing malware via anime girl wallpapers on Steam Workshop's…
Kaspersky has warned that hackers are distributing malware through anime-themed desktop wallpapers on Steam Workshop, primarily targeting users of Wallpaper Engine. These malicious packages have been downloaded thousands of times and can deploy backdoors and steal Steam account information, with users in China and Russia appearing to be the main targets.
Ransomware group wants $2 million from Nintendo for Tinypulse hack, Nintendo says its aware
A ransomware group is demanding $2 million from Nintendo after allegedly compromising HR data through a hack of the TinyPulse platform. Nintendo of America has acknowledged awareness of an issue involving TinyPulse but stated that no personal customer or financial information was affected.
Evening Safety Dance
Nintendo has stated that the stolen employee data by a hacker group is limited and outdated, despite a $2 million ransom demand. The company is investigating the extent of the breach.
Morning Safety Dance
A critical vulnerability in Microsoft's Copilot has been discovered, allowing hackers to steal two-factor authentication codes from users. This exploit poses a significant security risk, potentially compromising user accounts.
Evening Safety Dance
The Cybersecurity and Infrastructure Security Agency (CISA) released its weekly summary of vulnerabilities for the week of June 8, 2026. The report details potential security risks and provides guidance for mitigation.
Hacker Group Steals Nintendo Employee Data, Posts $2 Million Ransom
A hacking group named ShadowByt3$ claims to have stolen 859MB of Nintendo employee data, including personal information and financial statements, via the third-party HR service TinyPulse. The group is demanding a $2 million ransom. Nintendo of America confirmed a limited breach of internal survey data from several years ago, stating that no customer or financial data was compromised and that they are working with the service provider to address the issue.
Hacker Group Claims To Have Stolen Nintendo Data, Posts $2 Million Ransom
A hacking group named ShadowByt3$ claims to have stolen 859MB of Nintendo employee data, including personal and financial information, and is demanding a $2 million ransom. The group alleges the data was accessed through a third-party HR program used by Nintendo. The company has not yet commented on the unverified breach.
Rumor: Nintendo hit with data breach, hacker steals 859MB of data via TINYpulse
A hacker claims to have stolen 859MB of data from TINYpulse systems, potentially affecting Nintendo employees. The stolen data reportedly includes employee names, emails, surveys, analytics reports, and financial documents like bank statements and W-9 forms. This alleged breach follows previous security incidents involving Nintendo and Game Freak.
Evening Safety Dance
Microsoft has largely fixed a flaw in its Surface hardware that could render unprotected devices unusable with a single packet. Separately, a zero-day vulnerability affecting PeopleSoft is impacting hundreds of organizations.
Morning Safety Dance
A new malware campaign is reportedly tricking AI security scanners by using fake nuclear weapon prompts. This method allows malicious code to bypass safety failsafes, enabling the scanner to skip the actual payload. Additionally, AMD has denied a researcher a $10,000 bug bounty.
Evening Safety Dance
Hackers utilized Google Cloud links and fabricated New York Times web pages to operate a large-scale global phishing operation. This method was employed to distribute malicious content and deceive users.
7 Mistakes Gamers Make When Creating New Accounts
This guide outlines seven common mistakes gamers make when setting up new accounts, focusing on account security and recovery. Key errors include using weak or reused passwords, skipping two-factor authentication, providing inaccurate recovery information, choosing poor usernames, leaving privacy settings at default, linking unverified payment methods, and not reading platform terms of service. Implementing best practices for account setup can prevent future issues and protect progress, in-game items, and personal details.
Evening Safety Dance
CISA has alerted US agencies to critical security vulnerabilities in Windows Defender, urging them to apply patches within three days due to emerging AI-driven threats. Nightmare Eclipse has published details on a new zero-day exploit affecting the software.
Evening Safety Dance
The Miasma supply-chain attack toolkit has been publicly released on GitHub. This toolkit is designed to facilitate supply chain attacks, posing a significant cybersecurity threat.
Conan O'Brien is hosting educational videos for an AI cybersecurity company
Conan O'Brien is lending his comedic talents to Wiz, an AI cybersecurity company, by hosting educational videos for the company. The partnership aims to make corporate training more engaging.