Two food industry giants hit in the same week: Jason’s Deli disclosed a credential stuffing attack that compromised 344,000 loyalty accounts using stolen credentials harvested from unrelated data breaches, while LockBit 3.0 claimed it exfiltrated hundreds of gigabytes from Subway’s internal SBS franchise network — a notable target shift for a ransomware group that typically […]
Blog
One Click Away: The Alarming Reality of Data Theft Exploits | HN 23
A single click on a malicious .url shortcut file is all it takes: attackers are weaponizing CVE-2023-36025, a CVSS 8.8 Windows SmartScreen bypass, to silently deliver Phemedrone Stealer — an open-source infostealer that drains cryptocurrency wallets, browser credentials, and messaging app sessions in one pass. Stories Covered CVE-2023-36025: One Click Deploys Phemedrone Stealer via Windows […]
Crypto Chaos: How a Fake SEC Tweet Triggered a Bitcoin Spike | HN 22
Three crypto stories in one week: the SEC’s X account was compromised via SIM swap and used to post a fake Bitcoin ETF approval — spiking BTC by $2,000 before the tweet was removed — while North Korea’s state-sponsored hackers confirmed $600 million stolen in 2023 (nearly a third of all global crypto theft), and […]
Underground Market for Twitter/X Accounts; Google OAuth Backdoor for Hackers | HN 21
Two account-takeover stories: dark web markets are selling compromised X Gold accounts for up to $2,000 each — one hijacked account drained $691,000 in crypto assets in 20 minutes — while a Google OAuth vulnerability allows info-stealer malware to maintain account access even after a password reset by preserving stolen session tokens. Stories Covered Compromised […]
T-Mobile's Watchful Eye, Big Brother, and the Misconstrued Fines | HN 20
A screenshot of T-Mobile compliance fees went viral on social media with claims that the carrier would start fining consumers for text messages containing hate speech — the reality is narrower and more technical: the fees apply only to enterprise businesses sending A2P SMS through carrier API partners, not to any individual consumer’s personal messages. […]
AI Conspiracy: Man's Deadly Plot Against the Queen Exposed | 23AndMe Data Leaked | HN 19
Two stories this episode: a 19-year-old was convicted of treason — the UK’s first such conviction in 40 years — after an AI companion chatbot encouraged his plan to assassinate Queen Elizabeth at Windsor Castle, while 23andMe disclosed that a credential stuffing attack exposed the DNA data and ancestry profiles of potentially millions of customers. […]





