Nigerians extradited to US for sextortion, deaths of two teens
Two Nigerian men extradited to the U.S. on Thursday have been charged with involvement in sextortion schemes that resulted in the deaths of two minor victims in Mississippi and North Carolina. Sextortion is a form of online blackmail in which cybercriminals threaten victims with leaking nude images and videos they stole (through hacking) or obtained (through […]
Microsoft asks users to ignore ‘Antivirus is turned off’ errors
Microsoft asked customers this week to ignore incorrect alerts that Defender Antivirus has been turned off after installing the latest Defender updates. Although this issue has been affecting users in the Release Preview Channel of the Windows Insider program since June, it appears Microsoft didn’t notice it until now. The erroneous alerts appear on affected systems in the Windows […]
FulcrumSec claims Manchester Airports hack, theft of 86 GB of data
The Manchester Airports Group data breach has been claimed by extortion group FulcrumSec, which told GeekFeed that it stole approximately 86 GB of data. Samples reviewed by GeekFeed contained information consistent with MAG’s disclosure while indicating that the breach exposed considerably more detailed customer, booking, and travel information than initially revealed. Hackers claim theft of 86 […]
Anthropic warns infostealer malware is hijacking Claude sessions to drain usage
Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers to access accounts and consume their usage. The company is signing affected users out of Claude, removing saved payment methods, and refunding charges it identifies as unauthorized. “We have recently become aware of a bad […]
Chrome Web Store extensions caught stealing crypto, browser data
Multiple extensions for Google Chrome and Microsoft Edge delivered a malware framework that deployed modules to steal cryptocurrency, sensitive data, and browser history, and to inject ClickFix lures. Researchers say all 19 malicious modules uncovered in the campaign serve distinct purposes and are designed to be “highly extensible.” The operation was uncovered by application security […]
Anthropic is cutting Claude Code’s current weekly limits by 17%
Anthropic is permanently increasing Claude Code’s standard weekly usage limits by 25% for Pro, Max, Team, and seat-based Enterprise plans, but it’s not as good as it sounds. If you use Claude, you’re actually getting a 17% reduction compared to what you have today. Claude Code currently has a temporary 50% increase in weekly limits, which […]
Brave browser adds email aliases to help users evade tracking
The latest version of the Brave browser, 1.94, introduces a feature called ‘Email Aliases’ that allows users to generate disposable email addresses when signing up to a new service. Using an alias address keeps the user’s real email address hidden from the website while still forwarding messages from the service. Brave already uses data isolation to […]
McKesson discloses breach after ShinyHunters claims patient data theft
Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records. McKesson is a major U.S. healthcare company and pharmaceutical distributor that provides medicines, medical supplies, technology, and services to healthcare providers and […]
PaperCut releases second emergency patch for exploited flaws
PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial fixes. As GeekFeed reported yesterday, PaperCut warned that hackers were exploiting a vulnerability in zero-day attacks against customer servers and released an initial emergency patch […]
GiveWP WordPress donation plugin flaw lets hackers execute server commands
A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server. The security issue is identified as CVE-2026-82222 and affects GiveWP through version 4.16.7.1. It was reported by bug researcher Udin Chan on July 28 through the Patchstack vulnerability intelligence platform. The GiveWP plugin has more […]