7

Incogni was built by Surfshark in 2021 and is now owned by Cyberspace B.V., the Netherlands-registered holding company created when Surfshark merged with Nord Security in February 2022. That same corporate family, traced back to Lithuanian venture builder Tesonet, also backs Oxylabs, one of the largest residential proxy and web-scraping infrastructure providers on earth

[-] WPSteam@lemmy.world 8 points 1 day ago* (last edited 1 day ago)

As if current version of recaptcha isn't inconvenient enough...clicking all the proper boxes yet it shows up as failed😑

14
20
19

FortiBleed exposed how a Russian-speaking threat group quietly compromised around 75,000 Fortinet firewalls worldwide by abusing old credential leaks, infostealer logs, automated login testing, offline cracking, and compromised FortiGate devices. The campaign turned exposed firewalls into credential-harvesting nodes, creating a self-feeding access pipeline for future attacks and possible ransomware operations.

[-] WPSteam@lemmy.world 6 points 4 days ago

Regarding announcing more specific prefixes — we did exactly that, and Reliance responded with even more specific ones. That’s when we realized this might not be incompetence, but malevolence.

https://x.com/durov/status/2067241316463886549

Durov's Reply to the BGP Prefix issue

85
submitted 5 days ago* (last edited 5 days ago) by WPSteam@lemmy.world to c/technology@lemmy.world

Telegram faced major connectivity disruptions after researchers reported that Reliance Communications’ AS18101 allegedly announced Telegram’s 91.108.56.0/22 IP prefix, a route normally originated by Telegram’s AS62041. The announcement reportedly spread through FLAG Telecom and reached international peers, causing Telegram traffic in India and parts of the UAE, Europe, and Asia to be misrouted or dropped.

The incident came around the same time as India’s temporary Telegram restriction linked to NEET exam security, but the network-layer impact went far beyond a domestic block. Researchers say the route should have been flagged as RPKI-invalid and filtered, raising fresh concerns about weak BGP security enforcement, poor route filtering, and how a single unauthorized routing announcement can disrupt a major platform across borders.

8

A single support ticket allegedly became the entry point for one of the biggest EdTech security incidents of 2026. The Canvas breach shows how stored XSS, weak session scoping, and missing browser-layer defenses can turn a routine help-desk workflow into a large-scale data exposure.

This breakdown walks through the attack chain: malicious ticket content, hijacked support session, API abuse, ShinyHunters’ role, CSP failures, and the practical lessons SaaS and EdTech teams should take seriously.

[-] WPSteam@lemmy.world 1 points 1 week ago

https://md.archlinux.org/s/SxbqukK6IA

This is a community edited list of packages that are affected

5

A newly disclosed Jenkins vulnerability, tracked as CVE-2026-53435, is now being actively exploited in the wild. The flaw allows an authenticated attacker with relatively low privileges to POST a malicious config.xml file, abuse Jenkins’ deserialization handling, and route requests through Stapler to access sensitive files on the Jenkins controller.

The issue affects Jenkins weekly versions up to 2.567 and LTS versions up to 2.555.2. Successful exploitation can lead to arbitrary file read, user impersonation, Script Console access, and possible exposure of SSH keys, credentials, and internal Jenkins secrets. Administrators are urged to upgrade immediately to Jenkins weekly 2.568 or LTS 2.555.3, review logs for suspicious createView requests, and audit users with View/Configure, Item/Configure, or Agent/Configure permissions.

15

CVE-2026-20253 is a critical Splunk Enterprise flaw where the PostgreSQL sidecar’s unauthenticated backup/restore API can be reached through Splunk Web, letting an attacker abuse pg_dump/pg_restore to pull a malicious database from attacker infrastructure, restore attacker-controlled SQL locally, write files as the Splunk user, and eventually overwrite a scheduled Python script for remote code execution. This all highlights that Splunk Enterprise on AWS is especially exposed by default, affected versions below 10.2.4 / 10.0.7 should be patched immediately, and the impact is severe because compromising Splunk means compromising a system that often stores logs, auth events, firewall data, EDR telemetry, and other sensitive enterprise visibility data.

20

Atomic Arch is a major AUR supply-chain attack (over 1.5K packages affected as of now) where attackers hijacked orphaned Arch packages and used malicious install hooks to pull npm payloads that executed a Linux ELF infostealer. It targeted developer secrets like SSH keys, GitHub/npm tokens, browser sessions, Docker/Vault credentials, and chat app data, while also using an eBPF rootkit to hide itself when run as root.

[-] WPSteam@lemmy.world 13 points 1 week ago

Nightmare Eclipse 2.0 incoming. 10K for such a thing is absolutely nothing for companies like AMD. Why promise rewards if at the end, you don't intend to pay? This has been a growing trend in the bug bounty space. Many times a bug is marked as duplicate and is fixed secretly. Other times, they're straightaway rejected..

[-] WPSteam@lemmy.world 41 points 1 week ago

Payment integrations with AI is NOT a good idea. I still remember a few years back a controversy that happened with Amazon's Alexa. Apparently, alexa speakers started ordering people dollhouses after hearing its name on TV. Yes ik ik you can disable purchases from amazon from the alexa app but by default, it was enabled.

This article covers it all: https://www.theverge.com/2017/1/7/14200210/amazon-alexa-tech-news-anchor-order-dollhouse

This is the main part

At the end of the story, Anchor Jim Patton remarked: “I love the little girl, saying ‘Alexa ordered me a dollhouse,’” According to CW6 News, Echo owners who were watching the broadcast found that the remark triggered orders on their own devices.

12

University of Nottingham has confirmed a major breach of its Campus Solutions system, with ShinyHunters claiming responsibility. Around 454,600 students and alumni were reportedly affected, with exposed data including names, emails, addresses, phone numbers, passport numbers, ethnicity/disability information, academic enrolment records, and fee/payment details. The suspected attack vector is Oracle PeopleSoft, a platform widely used by universities for student records and administration. Nottingham says it detected the incident on June 9, 2026, took systems offline, notified affected users, reported it to the ICO and Action Fraud, and launched a forensic investigation.

[-] WPSteam@lemmy.world 2 points 1 week ago

Same for my 5800X

[-] WPSteam@lemmy.world 7 points 1 week ago

Nope but they used to be priced reasonably but soon expect their prices to increase to 200-300 on average

[-] WPSteam@lemmy.world 25 points 1 week ago

Something similar happening in the smartphone industry. 4G-only smartphones are making a comeback in the $200-$300 range...Imagine buying a new 4G-only smartphone for $300 in 2026 which obviously won't even have a midrange processor as currently (but soon might change) only low end especially UNISOC SoCs support 4G-only capabilities...what a time to live in!

1

cross-posted from: https://lemmy.world/post/47960526

The Miasma supply chain worm just went open source. Here's an analysis of it... Initial observations - 5-layer obfuscation, GitHub-as-C2, AI tool config hijacking, dead-man switches, and a self-perpetuating PAT flywheel.

[-] WPSteam@lemmy.world 1 points 1 week ago

Deepseek 4.1 or 5 will launch with 1/4th the cost and similar capabilities as Mythos😶‍🌫️

[-] WPSteam@lemmy.world 9 points 1 week ago

AI Bubble burst coming sooner?

[-] WPSteam@lemmy.world 4 points 1 week ago

And it'll increase further in the near future... Only for background play and Advert removal, 16/month is absurd considering they don't have any content licensing headache and as such unlike Netflix, Disney + etc. Also, in case of YT Music, royalties paid out to artists are pretty opaque and pretty turbulent. Better to buy albums directly to support them. Brave FTW otherwise for YouTube

27
view more: next ›

WPSteam

0 post score
0 comment score
joined 2 weeks ago