Japan isn't planning an under-16 social media ban. Instead, it's considering stronger age verification rules that could vary by platform, while putting more responsibility on companies to verify users. With public support for bans relatively low... #SocialMedia #OnlineSafety #ChildSafety
TechNadu
@technadu.com
Cybersecurity, VPNs, & digital privacy, decoded. Smart takes, real insights, and expert reviews to keep you safe online. 👉 Subscribe to our newsletter → technadu.com/newsletter
Attackers are increasingly targeting trusted pipeline identities instead of software vulnerabilities. Recent incidents involving Trivy and Checkmarx GitHub Actions show how service accounts, bots, and automation tools can become valuable attack paths... #SupplyChainSecurity #DevSecOps #AppSec
Ransomware affiliate gets banned... for hitting the wrong victim. After infecting Eriell Group, a RAlord affiliate reportedly broke the cybercrime world's unwritten rule: don't target Russia/CIS organizations... #Cybersecurity #Ransomware #ThreatIntelligence #InfoSec #CyberCrime
Attackers don’t always need to break MFA. Aaron Painter CEO Nametag, explains why help desks are becoming one of the easiest entry points for attackers. 🪪 Identity verification should become a security layer of its own, rather than a support process... #CyberSecurity #IdentitySecurity #AskTheExperts
The VPN vs. antivirus debate may be becoming irrelevant. NordVPN is expanding its focus beyond VPNs, combining threat protection, phishing defense, malware detection, identity monitoring, and privacy tools into a broader security platform. #Cybersecurity #VPN #Privacy #OnlineSecurity #Threat
Mobile malware isn't just stealing data anymore. Kern Smith of Zimperium explains how Android apps silently enroll victims into premium SMS services, intercept OTPs, and generate recurring carrier-billed charges. #MobileSecurity #Android #SMSFraud #CyberSecurity #Malware #ThreatResearch
Attackers reportedly didn't need a victim's email password to take over some Instagram accounts. Instead, they allegedly abused Meta's AI Support Assistant to add a new email and trigger account recovery. Instagram says the vulnerability has now been patched. #Cybersecurity #AI #AccountSecurity
Braden Russell, CTO at Bugcrowd, says cybersecurity's biggest problem isn't detection it's prioritization. 🧑💻 "The LLMs and the AI models that are coming out now are just dumping thousands of vulnerabilities." External researchers often identify risks internal teams... #CyberSecurity #BugBounty
Think using a niche gaming service keeps you under the radar? Nearly 64,000 Atlas Menu accounts were exposed after an attacker allegedly breached the GTA V and CS2 cheat platform and published the database online. Emails, IPs, usernames, support tickets, password hashes were included. #Cybersecurity
Fake Claude Code installer pages are turning routine developer actions into credential theft and persistent access attacks. Rhys Downing of Ontinue explains how attackers abuse: 🟪 Lookalike documentation 🟪 One-line install commands 🟪 PowerShell loaders 🟪 Trusted developer workflows #Cybersecurity
A recently disclosed Cline vulnerability is exposing a larger AI agent security gap. Oasis Security’s Sagi Layani explains how attackers can abuse browser-to-localhost trust assumptions to reach high-privilege AI coding agents with shell-level access. #Cybersecurity #AISecurity #AIAgents
4 men. 57+ years in prison. 12 people dead from pills sold as Oxycodone and Xanax ac,tually laced with fentanyl and a synthetic opioid 20-40x stronger than fentanyl. Darknet marketplace. U.S. Postal Service. Three years of operation. Final sentence just handed down. #Cybercrime #LawEnforcement
Chinese-language phishing-as-a-service platforms are evolving fast. GTIG says attackers now use AI-generated phishing infrastructure, real-time OTP interception, Puppeteer automation, localized phishing templates to bypass MFA and target financial accounts globally. #CyberSecurity #Phishing #AI
7-Eleven says a breach linked to the ShinyHunters extortion campaign exposed more than 185,000 accounts. The leaked data reportedly included names, emails, phone numbers, DOBs & addresses tied to franchisee systems. #Cybersecurity #DataBreach #InfoSec
Anthropic says Claude Mythos Preview uncovered 10,000+ high & critical zero-days during Project Glasswing. Cloudflare, Mozilla, Microsoft, Apple & Google were reportedly involved. Is AI vulnerability discovery now outpacing human remediation? #Cybersecurity #AI #ClaudeAI #ZeroDay
Canada’s Bill C-22 is raising major privacy & encryption concerns. VPN providers including NordVPN, ExpressVPN, Surfshark, and Windscribe are now publicly responding — with some warning they may reconsider operations if mandatory access requirements expand. #VPN #Privacy #CyberSecurity #Encryption
“AI agents are recreating the access problems that broke early cloud security.” Shashwat Sehgal of P0 Security explains why enterprises are repeating cloud-era privilege sprawl through autonomous non-human identities. #Cybersecurity #AISecurity #CloudSecurity #AIAgents
X-VPN has joined the VPN Trust Initiative and i2Coalition to strengthen its focus on privacy, transparency, and internet security standards. The move reflects growing emphasis on trust and accountability across the VPN industry. #VPN #Privacy #Cybersecurity
A Spanish court refused LaLiga’s request to fine NordVPN in an IPTV blocking dispute. The case is fueling wider debate around overblocking, VPN enforcement, and disruptions affecting legitimate services like GitHub, Docker & Cloudflare. #Cybersecurity #VPN #DigitalRights
CloudBees says 81% of IT leaders saw more production issues linked to AI-generated code, even as AI adoption boosts developer productivity. Rising code volume, testing overhead, and CI/CD costs are becoming major concerns. Are enterprises scaling AI too fast? #AI #DevOps #CloudBees #Cybersecurity
This week’s cybersecurity roundup covered global takedowns of malware networks, DDoS botnets, phishing ops, and ransomware infrastructure - alongside growing concerns around AI-driven exploits, supply-chain compromises, and legacy software abuse. #CyberSecurity #InfoSec #ThreatIntel
Cloud Atlas APT is reportedly targeting government & diplomatic entities in Russia and Belarus using phishing emails, CVE-2018-0802 exploits, and a new “PowerCloud” exfiltration tool that writes stolen data into Google Sheets. #CyberSecurity #APT #ThreatIntel #InfoSec
Researchers report Google API keys can remain active for up to 23 minutes after deletion due to revocation propagation delays across cloud infrastructure. #Cybersecurity #CloudSecurity #APIKeys #GoogleCloud
Researchers uncovered “Showboat,” a stealthy Linux malware framework linked to PRC-aligned telecom targeting activity. The malware reportedly stayed undetected on VirusTotal for nearly a year. #Cybersecurity #Linux #Malware #APT
Canadian authorities arrested the suspected KimWolf botnet admin tied to a DDoS-for-hire operation that allegedly infected over 1M IoT devices worldwide. #Cybersecurity #DDoS #IoT #Botnet
Firefox 151 expands Mozilla’s free VPN with selectable server locations, new mobile tools, and Android support for “Shake to Summarize.” Mozilla says the built-in VPN has already surpassed 1 million sign-ups. #Firefox #VPN #Privacy #Cybersecurity
Researchers claim Russia’s MAX messaging app may include VPN detection and surveillance-related features. Digital rights analysts say several allegations were supported through static code analysis, while MAX denies the claims. #Cybersecurity #Privacy #VPN #AndroidSecurity
Mullvad disclosed a VPN fingerprinting issue that could allow websites to correlate user activity across different VPN servers through exit IP assignment behavior. The provider is testing a new assignment system and recommends users re-log before switching servers. #VPN #Privacy #Cybersecurity
IPVanish expanded its VPN infrastructure to 150+ global server locations, including nearly 1,000 RAM-only servers across 25 locations. The company says it plans to transition to a fully RAM-only network by 2027. #VPN #Cybersecurity #Privacy
“Companies often rank vendors by spend. Attackers rank them by exposure path.” Müzeyyen Gökçen Arslan Tapkan from Black Kite explains why compliance ≠ security and why AI is amplifying noise inside cyber risk programs. #CyberSecurity #TPRM #SupplyChainSecurity #AI