Newsletter IconFacebook IconX IconThreads IconInstagram IconYouTube IconPinterest Icon
Giveaway: AVerMedia Creator Bundle (4K Webcam, Capture Card, Charging Hub, and Mouse Pad)

Hacking, Security & Privacy

Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online.

Stay Updated

Follow TweakTown for breaking tech news, reviews, and daily updates.

Add TweakTown as a preferred source on GoogleFind TweakTown on Apple News

As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.

Microsoft warns travelers of Russian hackers hijacking hotel Wi-Fi networks to steal account credentials

| Aug 4, 2026 4:03 PM CDT

A Russian hacking group known as Midnight Blizzard, or Cozy Bear, has been running a campaign that specifically targets hotel Wi-Fi networks to get into the devices of government officials, diplomats, and defense industry employees while they travel. Microsoft's threat intelligence team published details of the campaign this week, and the technique being used is one worth understanding if you travel for work.

Microsoft warns travelers of Russian hackers hijacking hotel Wi-Fi networks to steal account credentials

The attack is called an Evil Twin, and the basic idea is that the hackers set up a rogue Wi-Fi network that mimics a legitimate hotel network. When a target connects, the attacker intercepts traffic and can steal credentials through a technique called NTLM relay, which captures Windows authentication hashes and uses them to access the victim's accounts and internal systems without ever needing the actual password. The attack is entirely passive from the victim's perspective. You connect to what looks like the hotel Wi-Fi, and that is it.

What makes Midnight Blizzard specifically dangerous is the infrastructure behind the operation. Microsoft found evidence that the group was chaining together compromised devices, including home routers and IoT hardware from previous campaigns, to route its attacks through. This makes the traffic harder to trace and the attackers harder to attribute. The group has been active since at least 2018 and is widely believed to be linked to Russia's SVR foreign intelligence service.

0:00 / 2:32

Continue reading: Microsoft warns travelers of Russian hackers hijacking hotel Wi-Fi networks to steal account credentials (full post)

The EU is preparing to hit ChatGPT and Roblox with its strictest content moderation rules

| Jul 30, 2026 5:15 PM CDT

The European Commission is considering placing ChatGPT and Roblox under the Digital Services Act's strictest regulatory tier, according to a Bloomberg report, with the designation potentially arriving as early as August.

The EU is preparing to hit ChatGPT and Roblox with its strictest content moderation rules

ChatGPT's search function would be classed as a Very Large Online Search Engine. At the same time, Roblox would become a Very Large Online Platform, joining a list that already includes Facebook, YouTube, TikTok, X, WhatsApp, and Amazon.

The DSA applies its heaviest obligations to services with more than 45 million monthly users in the EU. Commission spokesperson Thomas Regnier told Reuters the designation was "definitely possible" and could "come sooner or later." OpenAI said it continues to engage positively with Brussels, while Roblox did not comment.

0:00 / 2:46

Continue reading: The EU is preparing to hit ChatGPT and Roblox with its strictest content moderation rules (full post)

Hackers breach UK government and police systems, steal passwords and personal data

| Jul 30, 2026 4:33 AM CDT

Hackers known as ExfilSquad have stolen over 740,000 records from the UK Department for Education (DfE) and a police legal database, including personal and professional contact details of thousands of individuals.

Hackers breach UK government and police systems, steal passwords and personal data

The breach, as reported by The Guardian, involves 607,000 lines of data from the DfE's help-desk portal and 135,000 records from the Police National Legal Database. The stolen data includes names, email addresses, phone numbers, and job titles of parents, staff, government officials, university workers, and police officers. Additionally, another 135,000 pieces of data were extracted from the police national legal database (PNLD).

The cybercriminals are demanding ransom from the DfE and other victims to prevent the full release of the data. "Be smart and just pay," the hackers wrote in a message seen by Sophos, a cybersecurity company that provided the screenshots to The Guardian, adding that the payment would be a "rounding error" compared to the financial cost of litigation.

0:00 / 2:24

Continue reading: Hackers breach UK government and police systems, steal passwords and personal data (full post)

Pope's official prayer app exposed data of more than 700,000 users

| Jul 28, 2026 9:34 PM CDT

The Pope's official prayer app leaked the personal data of over 700,000 users for months, with the Vatican offering no response to the ethical hacker who first reported the flaw.

Pope's official prayer app exposed data of more than 700,000 users

The app, Click To Pray, is the Vatican-endorsed prayer app that attracted more than 700,000 users who are connected the global prayer network. However, Cybersecurity researcher BobDaHacker discovered a flaw in January 2026 and reported it directly to the app's operators. For six months, the bug remained unpatched, allowing anyone to access any user's data simply by altering a number in the URL. The vulnerability also let attackers register and confirm accounts using someone else's email, further increasing the risk of phishing and identity theft.

The user base, skewed toward elderly and devout Catholics, made the breach particularly dangerous. As BobDaHacker noted, "Grandma is clicking that. Every time," referencing how a bad actor could take the information from one of the elderly users and craft a phishing scam by posing as the app in some regard. The flaw was found to expose names, emails, birthdates, and locations due to a severe IDOR vulnerability, but it was quietly patched in late July 2026. However, the Vatican never acknowledged the researcher who originally discovered it, or the exposed users.

0:00 / 1:59

Continue reading: Pope's official prayer app exposed data of more than 700,000 users (full post)

Microsoft is using the TPM chip required for Windows 11 to crack down on KMS activation piracy

| Jul 26, 2026 5:50 PM CDT

Microsoft is putting the TPM chip it requires for Windows 11 to another use. The company has announced TPM-based attestation, a new security layer for Key Management Service (KMS), the activation system enterprises use to license Windows across large fleets of devices.

Microsoft is using the TPM chip required for Windows 11 to crack down on KMS activation piracy

Starting with the next Windows Server release, the feature will become mandatory, and Microsoft is beginning to push readiness notifications to Windows Server 2025 users from August 2026 to give organizations time to prepare.

KMS has been a persistent target for abuse. Pirates have long spun up fake KMS servers that mimic legitimate Microsoft activation infrastructure, effectively tricking Windows into believing it has been properly licensed. The Online KMS method used by the Massgrave collective, for example, keeps activations alive by periodically contacting a spoofed server every six months. TPM-based attestation is designed to make that approach significantly more difficult.

0:00 / 2:43

Continue reading: Microsoft is using the TPM chip required for Windows 11 to crack down on KMS activation piracy (full post)

Your Wi-Fi router could be helping Russian hackers, confirms US government in new warning

| Jul 15, 2026 6:05 AM CDT

Federal agencies have issued a stark warning to the public about Russia's state-backed hackers actively attempting to compromise home and small-business routers.

Your Wi-Fi router could be helping Russian hackers, confirms US government in new warning

According to the Cybersecurity and Infrastructure Security Agency (CISA), Russian cyber actors including groups tracked as Energetic Bear, Dragonfly, and Static Tundra are exploiting misconfigured or vulnerable networking devices to gain persistent access. These groups use compromised routers to mask their activities and launch further attacks once access has been gained. The advisory was co-issued with partners in Australia, Denmark, New Zealand, and the UK, as authorities have discovered these efforts are global and not just targeting the United States.

Russian and Chinese state actors have been attempting to infiltrate and compromise devices for many years now, and in some instances their efforts have paid off as critical infrastructure has been compromised and data has been extracted. While agencies like the FBI have temporarily disrupted botnets by resetting DNS settings, attackers simply rebuild their networks.

0:00 / 2:10

Continue reading: Your Wi-Fi router could be helping Russian hackers, confirms US government in new warning (full post)

Samsung is holding your health data hostage to train its AI

| Jul 13, 2026 4:15 AM CDT

Samsung is forcing users to consent to AI training in the Samsung Health app or face losing access to their health data.

Samsung is holding your health data hostage to train its AI

The controversial new toggle, now appearing in the app, requires users to allow their health information to be used for AI modeling or risk having it deleted. The notice, titled "Consent to the Use of Health Data for AI Training and Modeling," appears upon opening the app. Disabling it prevents users from syncing health data to their Samsung accounts, and the data is removed unless required by law. How-To Geek reported the first sightings of the toggle, which has since spread to more users.

This move raises serious privacy concerns, especially since the data in question may include highly sensitive information, such as medical records, medications, and menstrual cycle data. The broader AI industry is increasingly reliant on personal data, but requiring users to give up privacy or lose core functionality is a troubling trend. Samsung's decision may signal a shift in how health data is treated in the AI era.

0:00 / 2:23

Continue reading: Samsung is holding your health data hostage to train its AI (full post)

First 'agentic ransomware' run entirely by a large language model discovered

| Jul 6, 2026 8:03 AM CDT

Researchers have uncovered what they believe is the first documented case of a ransomware operation fully conducted by an AI agent powered by a large language model (LLM).

First 'agentic ransomware' run entirely by a large language model discovered

The ransomware has been dubbed JadePuffer, and this new threat was autonomously discovered conducting reconnaissance, stealing credentials, and executing full-scale encryption - all without human instruction. JadePuffer exploited a zero-day vulnerability in Langflow, an open-source tool commonly used to build apps that run workflows around large language models. The exploit allowed the agentic ransomware to gain access.

From there, it pivoted to a Nacos server and a MySQL database, demonstrating its ability to adapt in real time - even correcting errors on-the-fly. According to Sysdig, a cloud security company, the ransomware agent self-corrected a failed backdoor attempt in under 31 seconds, something that was eyebrow-raising to security researchers.

0:00 / 2:12

Continue reading: First 'agentic ransomware' run entirely by a large language model discovered (full post)

Security researchers trick AI browsers into revealing passwords using BioShock-inspired prompt injection

| Jul 4, 2026 12:30 AM CDT

Security researchers at LayerX have discovered a new prompt injection technique that tricks AI browsers into revealing saved passwords and login credentials by leading them to believe they are playing a game.

Security researchers trick AI browsers into revealing passwords using BioShock-inspired prompt injection

The attack is called BioShocking, named after the 2007 video game BioShock. The game follows a brainwashed character who follows commands after hearing the phrase "Would you kindly?" That is pretty much what's going on here. Essentially, the AI agent believes whatever information it is given, and changing the information changes what it will do.

The attack starts on a malicious webpage designed as a puzzle called Rapture Games, themed after BioShock's underwater world. The puzzle rewards wrong answers, training the agent to accept that 2+2=5 and that incorrect actions are the winning move. Once the agent learns this, its safety protections stop working. The last step of the puzzle tells the agent to navigate to a GitHub repository and copy the login details stored there.

0:00 / 2:45

Continue reading: Security researchers trick AI browsers into revealing passwords using BioShock-inspired prompt injection (full post)

Hackers are using Steam's Wallpaper Engine to distribute malware that can steal your logins

| Jun 17, 2026 8:14 PM CDT

If you use Wallpaper Engine, now's a good time to pay attention. Kaspersky researchers have discovered that hackers are hiding malware inside wallpaper packages on the Steam Workshop, using them to steal Steam accounts and install additional malicious software on victims' PCs. The bad actors are exploiting the popularity of Steam's Wallpaper Engine to funnel users to the Workshop, from which they distribute malware.

Hackers are using Steam's Wallpaper Engine to distribute malware that can steal your logins

Here's why this works so well: unlike a regular JPEG or PNG, Wallpaper Engine's "application wallpapers" are actual Windows executables that run on your system like any other program. That makes them a pretty convenient hiding spot for bad actors. The Wallpaper Engine also houses wallpapers in other formats, but it is these "application wallpapers' that are the primary source of the attack.

Once you launch one of these infected wallpapers, it drops a backdoor onto your system, part of the DarkKomet malware family, and quietly installs a modified system library designed to hunt down your Steam credentials and hijack your active session. After taking over your Steam account, the attackers use it to upload additional infected wallpapers, perpetuating the cycle by compromising more PCs.

0:00 / 2:58

Continue reading: Hackers are using Steam's Wallpaper Engine to distribute malware that can steal your logins (full post)

Microsoft sets a Patch Tuesday record with 206 fixes, and finally patches every zero-day Nightmare Eclipse disclosed

| Jun 10, 2026 6:50 PM CDT

Microsoft has released its June 2026 Patch Tuesday update, and it is a record-breaker. The company patched 206 vulnerabilities this month, surpassing the previous record of 175 set in October 2025. Of the 206 vulnerabilities patched, 33 are rated Critical, with 28 of those being remote code execution flaws.

Microsoft sets a Patch Tuesday record with 206 fixes, and finally patches every zero-day Nightmare Eclipse disclosed

The full breakdown covers 65 Elevation of Privilege vulnerabilities, 55 Remote Code Execution vulnerabilities, 30 Information Disclosure vulnerabilities, 27 Spoofing vulnerabilities, 19 Security Feature Bypass vulnerabilities, and 7 Denial of Service vulnerabilities. Five are zero-day vulnerabilities, and one is already being actively exploited in the wild.

CVE-2026-41091 is an Elevation of Privilege flaw in Microsoft Defender that lets attackers gain system privileges. Microsoft has already pushed out a fix through the daily automatic Defender updates, with the patched Malware Protection Engine carrying version 1.1.26040.8 or later. To check your engine version, open Settings > Privacy and Security > Windows Security > About.

0:00 / 2:59

Continue reading: Microsoft sets a Patch Tuesday record with 206 fixes, and finally patches every zero-day Nightmare Eclipse disclosed (full post)

Microsoft threatened a security researcher with criminal charges, and the cybersecurity community isn't having it

| May 30, 2026 8:03 PM CDT

A public dispute between Microsoft and security researcher Nightmare Eclipse has escalated into a full-scale backlash from the cybersecurity community, after Microsoft threatened criminal prosecution over a series of uncoordinated zero-day disclosures.

Microsoft threatened a security researcher with criminal charges, and the cybersecurity community isn't having it

Between early April and mid-May 2026, Nightmare Eclipse published proof-of-concept exploit code for six Windows vulnerabilities without coordinating with Microsoft. Three of those, BlueHammer, RedSun, and UnDefend, were confirmed as being used in live attacks shortly after going public, prompting emergency patches and CISA adding them to its Known Exploited Vulnerabilities catalog. Three others, YellowKey, GreenPlasma, and MiniPlasma, remain unpatched.

Following these discoveries, Microsoft published a formal blog post describing uncoordinated disclosures as "never justifiable" and warning its Digital Crimes Unit could pursue criminal charges against those responsible. The company also had Nightmare Eclipse's GitHub account suspended around May 23, followed by their GitLab account between May 26 and 27.

0:00 / 3:31

Continue reading: Microsoft threatened a security researcher with criminal charges, and the cybersecurity community isn't having it (full post)

Microsoft warns AI chatbots are luring users to cryptojacking malware disguised as trusted PC utility downloads

| May 28, 2026 12:45 PM CDT

Microsoft has warned users about an active cryptojacking campaign that uses AI chatbots to serve malicious downloads disguised as trusted PC utilities. Microsoft Defender Experts and the Security Research Team said in a report published Tuesday that "this emerging delivery technique extends social engineering beyond conventional search results and increases the visibility of malicious software recommendations."

Microsoft warns AI chatbots are luring users to cryptojacking malware disguised as trusted PC utility downloads

The campaign impersonates legitimate system utilities like CrystalDiskInfo, HWMonitor, Display Driver Uninstaller, FurMark, K-Lite Codec Pack, and PDFgear. The idea is to target applications favored by PC users with high-performance GPUs to gain access to systems with higher cryptocurrency mining potential, rather than infecting a large number of machines at random.

Downloads from this cryptojacking campaign have also been found to establish persistent remote access through ScreenConnect deployments. ScreenConnect, also known as ConnectWise Control, is a legitimate remote management tool widely used by IT administrators, but it can also be leveraged for data theft, lateral movement, or ransomware.

0:00 / 3:10

Continue reading: Microsoft warns AI chatbots are luring users to cryptojacking malware disguised as trusted PC utility downloads (full post)

Trump Mobile website is reportedly leaking customer data including names, addresses and order numbers

| May 20, 2026 8:50 PM CDT

Last week, Trump Mobile announced that its T1 phone was finally shaping up to be an actual product ready to ship after months of delays and controversy. Now, the Trump Mobile website is allegedly facing serious security issues that have reportedly led to the leakage of customers' private information and order numbers.

Trump Mobile website is reportedly leaking customer data including names, addresses and order numbers

According to YouTubers Coffeezilla and Cr1TiKaL, the official Trump Mobile website has been leaking customer information, including full names, email addresses, mailing addresses, and order numbers. Customers' credit card information appears to be safe. Anyone who ordered the phone or opted for Trump Mobile's cellular service could be affected.

Coffeezilla received the information via an anonymous source who shared personal data to prove they had access. The anonymous individual claimed to have exploited a vulnerability in the Trump Mobile website, allowing access to the entire pre-order database and even the ability to place fake orders for the T1 phone. "Long story short, I found a vulnerability in the Trump T1 Mobile preorder website and gained the ability to both place fake orders, but also to scrape and search the entire preorder database," the person told Coffeezilla.

0:00 / 3:03

Continue reading: Trump Mobile website is reportedly leaking customer data including names, addresses and order numbers (full post)

Security researcher finds zero-day exploit that defeats Windows 11 BitLocker, calls it an insane 'backdoor' discovery

| May 15, 2026 12:58 PM CDT

A security researcher going by the alias Nightmare-Eclipse has uncovered a zero-day exploit they describe as one of the most insane discoveries ever, saying it "almost feels like a backdoor." Dubbed YellowKey, the exploit allows anyone with physical access to a Windows 11 system to bypass default BitLocker protections and gain complete access to an encrypted device within seconds.

Security researcher finds zero-day exploit that defeats Windows 11 BitLocker, calls it an insane 'backdoor' discovery

BitLocker is Microsoft's full-volume encryption that protects storage disks and their contents from anyone without the decryption key. That key is stored in a Trusted Platform Module (TPM), and BitLocker is a mandatory protection for many organizations, including government contractors.

The researcher refers to it as a backdoor because the bug appears only in WinRE (Windows Recovery Environment) and not in Windows itself, which lacks the required functionality needed to trigger the bypass. Additionally, the bypass affects only Windows 11, Windows Server 2022, and Windows Server 2025 systems with the default BitLocker configuration, while Windows 10 machines are unaffected.

0:00 / 3:04

Continue reading: Security researcher finds zero-day exploit that defeats Windows 11 BitLocker, calls it an insane 'backdoor' discovery (full post)

Google finds hackers using AI to discover and develop a zero-day exploit for the first time for mass attacks

| May 11, 2026 10:47 PM CDT

With AI models achieving new milestones, it was inevitable that security experts' fears would come true. Google's Threat Intelligence Group has, for the first time, discovered a threat actor using a zero-day exploit likely developed with AI. A zero-day vulnerability is a software or hardware flaw that is unknown to developers, leaving them with zero days to patch it before attackers can exploit it.

Google finds hackers using AI to discover and develop a zero-day exploit for the first time for mass attacks

The exploit targeted a popular open-source web-based system administration tool. Google called the threat actor a prominent cybercrime group that allegedly planned to use the flaw in a mass exploitation campaign. Had it gone undetected, the flaw would have allowed hackers to bypass two-factor authentication and access victim accounts with just a password.

Google investigators suspect, with "high confidence," that the exploit was developed with the help of an unidentified AI program, based on the Python code's structure and content. The report says the script has educational docstrings, a fake CVSS score, and a Pythonic format typical of LLM training data.

0:00 / 3:14

Continue reading: Google finds hackers using AI to discover and develop a zero-day exploit for the first time for mass attacks (full post)

North Korean hackers weaponize gaming platform to spy on ethnic Koreans in China

| May 7, 2026 10:15 AM CDT

North Korean hackers have compromised a gaming platform popular with ethnic Koreans in China, delivering a Trojanized backdoor that steals data and executes commands.

North Korean hackers weaponize gaming platform to spy on ethnic Koreans in China

The threat, allegedly carried out by the state-sponsored group ScarCruft (APT37), has been active since late 2024 and targets users of the SQgame platform, which hosts traditional card and board games. The malware, dubbed BirdCall, exfiltrates everything from messages and media to ambient audio and clipboard data.

ESET researchers uncovered the BirdCall backdoor embedded in both Windows and Android versions of the platform. On Windows, it captures screenshots, logs keystrokes, and executes shell commands, while on Android, it steals contact lists, SMS, and call logs. All stolen data is uploaded to cloud services such as Dropbox. The malware has been updated seven times, indicating active development and maintenance.

0:00 / 2:26

Continue reading: North Korean hackers weaponize gaming platform to spy on ethnic Koreans in China (full post)

How to Protect Personal Data Online From Hackers and Avoid Identity Theft

Sponsored Content | Apr 24, 2026 1:42 PM CDT

Updated drivers. Active antivirus. A router with a strong password. Everything is locked down tight. Most tech-savvy people stop there and assume the job is done. It is not. A hacker does not always need to breach your device to steal your personal information. Sometimes your data is already sitting in public view - harvested by a data broker long before any breach ever happens.

How to Protect Personal Data Online From Hackers and Avoid Identity Theft

Clearnym fills the gap that cybersecurity software ignores. Their opt-out guides walk through exactly how to remove your personal information from people search sites and data broker databases. Beyond guides, Clearnym automates the entire removal process, submitting opt-out requests on your behalf and monitoring for re-listing so your personal data does not quietly reappear. It is the protection layer that no antivirus covers. Learn how to protect what lives outside your devices - because that exposure is just as real.

For a hacker to get into your financial accounts does not always need malware. They need your name, phone number, and the answers to your security questions. That information sits on people search sites right now. Thieves use it to pass verbal verification at your bank and gain access to your bank accounts without touching a single device.

0:00 / 8:54

Continue reading: How to Protect Personal Data Online From Hackers and Avoid Identity Theft (full post)

HWMonitor and CPU-Z download links were infected with malware for 6 hours before devs caught it

| Apr 10, 2026 4:21 PM CDT

Two of the most popular hardware monitoring utilities, HWMonitor 1.63 and CPU-Z, were recently found to be infected with malware. The official websites were hacked, and users trying to download the latest version were getting flagged by antivirus software. After roughly six hours of investigation, the developers identified the breach and removed the malware. Both of the monitoring utilities are now safe to download.

HWMonitor and CPU-Z download links were infected with malware for 6 hours before devs caught it

The issue first surfaced on Reddit, where users reported that the official download links had been replaced with malware-infected executable files instead of the legitimate installers. User u/DMkiller shared that while updating HWMonitor from version 1.42 to 1.63, the downloaded file was named "HWiNFO_Monitor_Setup.exe" rather than the expected "hwmonitor_1.62."

When he ran the file, Windows Defender flagged it as a virus, and a quick check on VirusTotal returned 32 security flags. Further analysis by u/Hattix under the same post revealed that the official download links on CPUID's website pointed to a Russian domain with the page header "Установка - HWiNFO Monitor, версия 1.63".

0:00 / 3:05

Continue reading: HWMonitor and CPU-Z download links were infected with malware for 6 hours before devs caught it (full post)

Apple confirms an iOS 18 patch for the DarkSword exploit, even for users who skipped upgrading to iOS 26

| Apr 1, 2026 5:04 PM CDT

Last month, a malware toolkit called DarkSword had Apple users holding their iPhones a little tighter. The exploit could be used to break into older iPhones and iPads running iOS 18.4 through 18.7 simply by visiting a website hosting malicious code. Even legitimate websites that had been breached could be affected. The exploit could steal messages, browser histories, location data, and cryptocurrency, then upload everything to an attacker-controlled server. Bad news all around.

Apple confirms an iOS 18 patch for the DarkSword exploit, even for users who skipped upgrading to iOS 26

Apple responded by rolling out updates to address the two known exploits: Coruna, which affects devices running iOS 13 through iOS 17.2.1, and DarkSword, which targets iPhones running iOS 18.4 through 18.7.

There was a catch, though. Apple only patched iOS 18 for devices unable to run iOS 26. This left anyone who could upgrade but chose not to completely exposed. That is how Apple typically operates. If you are running an older version of iOS on a device that can be updated, Apple will withhold security patches until you make the jump to the latest version.

0:00 / 2:46

Continue reading: Apple confirms an iOS 18 patch for the DarkSword exploit, even for users who skipped upgrading to iOS 26 (full post)

Join Our Newsletter

Join the TweakTown Newsletter for daily tech updates delivered to your inbox.

See previous giveaways.

Newsletter Subscription