Hacking, Security & Privacy - Page 2
Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 2
Stay Updated
Follow TweakTown for breaking tech news, reviews, and daily updates.
As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.
12 years after release, the Xbox One has finally been hacked
The Xbox One was a polarizing console. Many gamers preferred the PlayStation 4 over Microsoft's offering. Yet, the Xbox One's security stood out. For over a decade, numerous attempts to bypass its protections failed, giving it an "impenetrable" reputation until now.
At the recently held RE//verse 2026 conference, security researcher Markus Gaasedelen unveiled the "Bliss" double glitch. This security exploit bypasses the Xbox One's encryption by precisely adjusting the device's voltage (the electrical power supplied) at specific times. By doing so, it interrupts the typical security checks that the hardware performs to keep the device secure.
This is a monumental milestone: the first public, reproducible bypass of the Xbox One since its launch in November 2013. Although Markus successfully demonstrated the "Bliss" glitch, it is not as straightforward as jailbreaking a PS4 or JTAGging an Xbox 360.
Continue reading: 12 years after release, the Xbox One has finally been hacked (full post)
Authorities seize crypto wallet... then accidentally publish the password - $4.4m gone
South Korea's National Tax Service accidentally exposed the mnemonic recovery phrase of a seized cryptocurrency wallet, leading to $4.4 million in crypto assets being stolen.
The stolen funds were stored in a Ledger cold wallet that was seized by local law enforcement during an operation targeting tax evaders. Law enforcement celebrated the success of the raid by releasing photos of the Ledger device containing the stolen funds, but failed to realize that the image also showed a piece of paper with a handwritten note containing the wallet recovery phrase. That phrase enables a user to recover the device's assets onto another device, and since it was made public, it was only a matter of time before the funds were stolen.
That's exactly what happened. Shortly after the press release was published, 4 million Pre-Retogeum (PRTG) tokens were transferred out of the confiscated wallet to a new address. Blockchain data analysis expert Cho Jae-woo, a professor at Hansung University in Seoul, commented on the theft of the digital assets, and said the mistake of law enforcement is comparable to the police finding a full wallet on the side of the street and advertising it to the nation that it's open and the money is free to take if they want it.
US government seizes one of the internet's largest hacker forums
The Department of Justice (DOJ) has announced it has seized LeakBase, a leading hacker forum that is home to more than a hundred thousand members.
In a press release posted to the DOJ website, it states authorities seized LeakBase, a forum that was commonly used by cybercriminals to buy and sell stolen data, and tools used to commit cybercrimes. LeakBase had more than 142,000 members and more than 215,000 messages between the accounts. The DOJ goes on to describe the forum had an "enormous, continuously updated archive of hacked databases, including many from high-profile attacks, including hundreds of millions of account credentials."
Some of this data included information that was illegally obtained from "U.S. corporations and individuals, and offered credit and debit card numbers, banking account and routing information, usernames and associated passwords which could facilitate additional account takeovers, as well as other sensitive business and personally identifiable information."
Continue reading: US government seizes one of the internet's largest hacker forums (full post)
Notepad++ hack detailed - and what to do if you think you might be affected
The developer of Notepad++ has furnished us with more information about how the popular text editor was compromised by hackers for some six months.
Ars Technica picked up the blog post which supplies further details about the exploitation of some Notepad++ users, which was leveraged via an "infrastructure-level compromise that allowed malicious actors to intercept and redirect update traffic destined for notepad-plus-plus.org".
Meaning that the compromise was enacted at the web hosting provider level, and wasn't a direct hack of the Notepad++ software itself - targeted users were redirected to download compromised updates, essentially.
'Largest-ever' cloud DDoS attack recorded in Australia, 3.64 billion packets per second
On October 24, 2025, the largest DDoS attack "ever observed in the cloud" on a single endpoint of Microsoft's Azure services in Australia was recorded. Measuring 3.64 billion packets per second or 15.72 Tbps, enough data to stream millions of movies, the good news is that Microsoft's Azure DDOS Protection automatically detected and mitigated the attack before it caused any harm.
With DDoS attacks and recorded instances on the rise, this particular record-breaking attempt was carried out by the Aisuru botnet. Botnets and DDoS attacks are fundamentally straightforward: multiple IP addresses and devices target specific IP addresses and attempt to flood them, aiming to overwhelm them and take them offline.
According to Microsoft's Sean Whalen, this attack originated from over 500,000 source IPs across various regions, indicating it was a global attack targeting a single point in Australia. Aisuru is a Turbo Mirai-class IoT botnet behind many recent record-breaking DDoS attacks, exploiting devices such as home routers, cameras, and other smart devices, mainly located in residential homes.
Nintendo allegedly hacked, with data stolen by hacking group 'Crimson Collective'
Although we're still waiting for an official response or acknowledgement from Nintendo, there are reports that the hacking group Crimson Collective has breached Nintendo and stolen data. Cybersecurity firm Hackmanac, which tracks and verifies cyber attacks, posted a screenshot on social media showcasing directories and folders from the group as proof of the successful hack.
The files and folders reportedly cover everything from manuals to administrative items, assets, development data, backups, and more. As of writing, the scale of the breach and whether it will become as high-profile as the Insomniac breach remain to be seen. This breach led to the leak of an early playable build of the studio's upcoming Marvel's Wolverine game, so hacked Nintendo data could include a lot of game-related stuff the company wouldn't want to see released.
Crimson Collective recently made a name for itself among hacking groups when it breached Red Hat's private GitHub repositories in September 2025, reportedly stealing 570GB of data, including sensitive information.
Discord confirms government ID photos of users were stolen by hackers
Discord has responded to the recent reports that an unauthorized party stole 1.5 terabytes worth of age verification images from a third-party customer service provider. The claims were that the group responsible for the hack stole 2 million images of Discord users.
Discord has responded to these reports, with a spokesperson informing Insider Gaming that 2 million age verification images isn't an accurate figure, and that Discord has identified around 70,000 users "that may have had government-ID photos exposed, which our vendor used to review age-related appeals."
Discord also notes that this hack was not a breach of Discord itself, but a breach of a third-party customer service provider that has since been severed from Discord's ticketing process.
Continue reading: Discord confirms government ID photos of users were stolen by hackers (full post)
Cloudflare blocks record-breaking DDoS attack, billions of packets at 11.5Tbps
A distributed denial-of-service attack, or DDoS attack, is designed to bring down a network, site, or online service by flooding it with fake requests to the point that it becomes overwhelmed and becomes inaccessible to all. It's a very serious issue that can lead to the loss of service for critical infrastructure, and over the years, the scale and complexity of DDoS attacks have continued to increase.
Cloudflare, a "connectivity cloud" solution designed to protect websites and networks, block bot traffic, and generally make the internet faster and more accessible, has announced that it recently blocked the largest recorded DDoS attack in history, which peaked at 11.5 terabits per second (Tbps) of traffic. Which is around 5.1Bpps, or 'billions of packets per second,'
"Cloudflare's defenses have been working overtime," Cloudflare wrote in a post on social media. "Over the past few weeks, we've autonomously blocked hundreds of hyper-volumetric DDoS attacks, with the largest reaching peaks of 5.1 Bpps and 11.5 Tbps."
Hacker downloads sensitive data on every single Intel employee
A security researcher has claimed they have discovered significant vulnerabilities within Intel's websites, leading to the exposure of sensitive data on every single employee at the company.
The claims originate from security researcher Eaton Z, who outlined their findings in a blog post. According to the researcher, they discovered a business card portal that failed due to manipulation attempts, which resulted in Eaton being able to access deeper into Intel's database. Eaton writes that they were able to download a file of nearly a gigabyte in size, which contained the personal details of Intel's 270,000 employees.
Notably, Intel recently reduced its headcount size to 75,000, down from 109,800 at the end of 2024. So, if Eaton's reporting is correct, the file contains sensitive data on more than just Intel's employees. The sensitive data included roles at the company, addresses, phone numbers, and managerial positions. Furthermore, the vulnerability wasn't exclusive to one portal, as Eaton says three other Intel websites suffered from the same issue.
Continue reading: Hacker downloads sensitive data on every single Intel employee (full post)
When a 'free' VPN costs you dearly: Security experts warn popular Chrome extension spies on you
A security firm has warned about a free VPN extension for Google's Chrome browser which is spying on those who've been unfortunate enough to install the add-on.
This is FreeVPN.One, and the worrying thing is that as Koi Security - which offers a platform for managing self-provisioned software for enterprises - points out in a blog post (flagged by Neowin), this extension not only has over 100K users, alongside 1,100 mostly positive reviews, but it's featured by Google (for "following recommended practices").
I'm betting, though, that a recommended practice isn't secretly taking screenshots of every website the Chrome user visits, and then sending those grabs back to the app developer.
Brave and AdGuard block Windows 11's divisive Recall feature - is this the start of a trend?
The Brave web browser, which is a privacy-focused affair, just announced that it's blocked Microsoft's Recall feature, and AdGuard has as well - leaving us wondering if this is going to be a move other software developers follow.
In Brave version 1.81 on Windows, there's a new slider to 'Block Microsoft Recall' which prevents the feature from taking snapshots (screenshots) of Brave browser windows. The key part here is that this will be on by default - though you can, of course, turn it off, so Recall can screenshot Brave if you prefer that way of working.
Previously, messaging app Signal blocked Recall in the same vein, and AdGuard is also introducing a toggle in its latest version (v7.21 in Windows) - this is part of its tracking protection suite of features. It's not on by default, mind, you must choose to turn on this functionality.
Microsoft responds to global security vulnerability, points finger at China
Microsoft's SharePoint server platform was confirmed to be suffering from an exploit that has resulted in at least 54 organizations being breached, including a private university, a federal government health organization, and a California-based energy operator.
Microsoft has since responded to the vulnerability in a new security blog post, stating that over the last few days, it has evaluated the vulnerability along with the breaches associated with it and determined that they are linked to hacking groups affiliated with the Chinese government.
According to Microsoft, it has observed two named Chinese nation-state actors, Linen Typhoon and Violet Typhoon, who are exploiting the vulnerabilities in the SharePoint platform. Additionally, Microsoft says it has identified another China-based group taking advantage of the vulnerabilities, known as Storm-2603.
Hackers use Microsoft service to launch serious global attack at governments and businesses
Microsoft has confirmed that vulnerabilities within its SharePoint service are being actively exploited by hackers who are targeting government entities and multinational corporations.
The serious security vulnerability dates back to May 2025 when researchers from Viettel Cyber Security discovered and demonstrated a Microsoft SharePoint exploit in a "ToolShell" attack that is now being actively exploited by hackers around the world.
For those unfamiliar, Microsoft SharePoint is a service used by organizations to store and manage documents, create internal websites, share files, build workflows, and facilitate team collaboration. The security flaws are related to SharePoint servers being hosted by organizations themselves, not cloud-based SharePoint.
US government confirms Chinese hackers have stolen vital intelligence from the US Army
The Department of Homeland Security has confirmed that Chinese state-sponsored hackers were within the network of the US Army National Guard for many months without anyone knowing.
The attackers, known as Salt Typhoon, were within the National Guard's network for as long as nine months, and during this time, they stole sensitive data such as administrator credentials, network traffic diagrams, personally identifiable information (PII) of service members, and geographical maps. Notably, during its stay within the National Guard network, Salt Typhoon also accessed the data traffic between the state's network and every other US state, along with four territories.
Unfortunately, due to Salt Typhoon gaining access to the state's network traffic, there is a possibility of the attackers jumping to other networks as well, further compromising additional government infrastructure. The Department of Homeland Security (DHS) didn't confirm how Salt Typhoon gained access to the network, but the group, which is part of the wider Chinese state-sponsored hacking group "Typhoon", is known for infiltrating networks through various means, such as exploiting existing vulnerabilities in routers and other network-related hardware.
McDonald's AI chatbot for hiring is compromised in embarrassing fashion with '123456' password
We're all familiar with the passwords that should never, ever be used - like 'password' for example - but people still employ such cringeworthy efforts, and so do big organizations, it seems.
In this case, as TechSpot reports, a security researcher, Ian Carroll, managed to gain access to an admin account for the McHire platform, used to facilitate recruitment for McDonald's. It does this using a chatbot (Olivia) made by Paradox.ai.
Carroll achieved this when looking at the portal for McDonald's restaurant owners to log in to view their applicants, where there was also a link for Paradox.ai staff to log in. Clicking through to the latter, and using '123456' for both the user and password allowed a successful sign-in - to the researcher's disbelief - but only to a sample restaurant and related details (for internal testing).
'Long con' browser extensions infect 2.3M Chrome and Edge users - here's what you need to know
A sophisticated and alarming malware campaign has been enacted through web browser extensions, with the result that 2.3 million users across both Chrome and Edge have fallen victim to this large-scale scam.
Koi Security carried out an investigation into a color picker extension (software that lets you copy any color from a website, if you want to use that particular shade in a project of your own) and discovered the 'RedDirection' malware campaign behind it (and 17 other extensions for Chrome and Edge).
The gist of it is that these extensions are essentially the software equivalent of a long con. They have been around for a long time, are professionally implemented, and do what they say on the tin - and they do it well. As such, the extensions have accrued a whole load of positive reviews, Google certification (the verified badge), plus a ton of installs.
Call of Duty: WWII taken offline after RCE vulnerability let hackers take over PCs
Over the weekend, the Call of Duty team at Activision Blizzard announced that the PC version of Call of Duty: WWII on the Xbox App (recently made available as part of Xbox Game Pass) was taken offline so it could "investigate reports of an issue." The issue? A remote code execution (RCE) vulnerability has been discovered in the game.
A serious issue allows hackers to gain remote access to a PC running Call of Duty: WWII on PC, specifically the version available via the Xbox App or Microsoft Store, and take control. As seen in the social media post above and other reports of the vulnerability, hackers have primarily been exploiting the flaw as a means to harass or troll gamers and streamers.
From opening the command prompt to sending messages in Notepad, changing desktop wallpapers, and shutting down PCs, this exploit has led to numerous cases of PCs being hijacked by hackers. In some extreme cases of trolling, hackers have also been changing the desktop wallpaper of Call of Duty gamers to display gay porn.
Qantas confirms Australia's biggest cyber attack in years exposing 6 million customers
Australia's Qantas has confirmed it has suffered from a cyberattack that has now exposed six million Qantas customer names, email addresses, phone numbers, birth dates, and frequent flyer numbers.
The airline has confirmed the breach in a recent statement on Wednesday, with the attack being described as the biggest breach in Australia in years. Qantas explained the cyberattack can be traced to a third-party customer service platform (call center), but the airline didn't say where or which call center was targeted. The Australian airline said that it was made aware of the breach after it detected unusual activity on its network and that it acted immediately to prevent any further exploitation.
It was only last week that the US Federal Bureau of Investigation (FBI) said cybercrime group Scattered Spider was targeting airlines. The FBI warned that Hawaiian Airlines and Canada's WestJet have already reported breaches. Qantas didn't provide the name of the hacking group, so it's not confirmed whether Scattered Spider is behind the attack.
Hackers that tried to influence the US election are back threatening to release Trump emails
Hackers claiming to have stolen emails from US President Donald Trump's inner circle are now threatening to release the documents.
The hacking group is associated with Iran and previously distributed hacked documents from the Trump campaign in 2024 to both Biden staffers and select US media organizations. Those same hackers, who use the pseudonym Robert, are now threatening to do the same thing, but with files allegedly obtained from Trump's inner circle.
According to Robert, they have extracted 100 gigabytes of data that includes a trove of internal emails, specifically mentioning individuals such as the chief of staff, Susie Wiles, Trump adviser Roger Stone, Trump's attorney Lindsey Halligan, Stormy Daniels, and others. Notably, Robert suggested they could sell the material, but didn't specifically state what they will be doing with it.
61 million records allegedly from Verizon leak online: names, tax IDs, addresses, phone numbers
The cybersecurity team at Safety Detectives has discovered a threat actor offering for sale a database containing 61 million records allegedly belonging to Verizon USA.
The team of cybersecurity experts has penned a new post that claims online hackers compiled a huge data set containing 3.1GB of reportedly 61 million "Verizon USA" records. The author of the file has dated the information as recently as 2025, suggesting the breach, if it is one, happened relatively recently.
The data set contains information that is sensitive, such as dates of birth, tax IDs, addresses, phone numbers, and full names. As with any breach of this scale, releasing that information would pose a risk to any of the affected individuals for identity theft.






















