Researchers at Oasis Security revealed last week that a flaw in Microsoft’s OneDrive File Picker was allowing external apps, such as Zoom, ChatGPT, Trello, Slack, and ClickUp, access to users’ content. The experts warn that millions of users could be affected, with potential risks of data leakage
Latest News
vpnMentor’s Research Team observed a significant spike in the demand for VPN services in France. The surge comes after Aylo’s Pornhub, the largest adult website in the world, stated users would not be allowed access to its site from within the country and subsequently geo-blocked French IP
Cybersecurity Researcher, Jeremiah Fowler, discovered and reported to vpnMentor about an unencrypted and non-password-protected database that contained 3,637,107 records that presumably belong to a no-coding app-building platform. The publicly exposed database was not password-protected or
Researchers from the cybersecurity firm GreyNoise reported this week that an ongoing exploitation campaign is targeting over 9,000 internet-exposed ASUS routers. Cybercriminals gained long-term access by exploiting an undisclosed vulnerability. Experts suggest that attackers were planning on
The FBI issued a warning about the cybercriminal group Silent Ransom Group (SRG) and its recent social engineering calls and callback phishing emails targeting law firms in the United States. The government agency noted that while the group has historically targeted multiple industries, it has
Leading VPN provider NordVPN has announced that it will roll out post-quantum encryption on all its major app-supported platforms. In NordVPN’s implementation, post-quantum encryption is integrated with its proprietary NordLynx protocol. Based on WireGuard, NordLynx is available on all of its
Cybersecurity researcher Jeremiah Fowler discovered an unprotected cloud system exposing 184 million credentials. The collection, containing around 47.42 gigabytes of data, included sensitive information from popular platforms such as Instagram, Facebook, and Snapchat, as well as government
Crypto exchange giant Coinbase is reeling from a cyberattack that exposed sensitive customer data, prompted a $20 million extortion attempt, and could cost the company up to $400 million in remediation. The breach, disclosed this week via Coinbase’s official blog and a filing with U.S. regulators,
The White House has officially withdrawn a major data privacy proposal that would have made it harder for data brokers to sell Americans’ personal and financial information. The move reverses a key effort launched in late 2024 by the Consumer Financial Protection Bureau (CFPB) to crack down on the
Marks & Spencer has confirmed that personal customer data was stolen in the recent cyberattack that disrupted its services for weeks. The breach exposed names, addresses, phone numbers, and order histories. While account passwords and full card details were not compromised, the retailer urged