Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking
The Carnegie Mellon University CERT Coordination Center (CERT/CC) is warning that Skullcandy Dime 3 wireless earbuds accept Bluetooth pairing requests from nearby unpaired devices without requiring user interaction. Devices running firmware version 1.0.0.28 are affected by a high-severity vulnerability tracked as CVE-2025-20701 in the Airoha Bluetooth Audio SDK, which the Skullcandy Dime 3 (model S2DCW) […]
US says Chinese firms extracted billions of tokens from frontier AI models
U.S. cybersecurity and intelligence agencies say that six Chinese AI companies conducted industrial-scale distillation attacks on American frontier AI models since at least late 2024. A joint advisory from CISA, NSA, and the FBIÂ states that DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI extracted billions of tokens through millions of requests from frontier AI […]
Veradigm warns of patient data breach after ransomware gang claims attack
Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients’ personal data. The company says the incident did not cause operational disruptions but affected a small number of customers. Formerly known as Allscripts Healthcare Solutions, Veradigm is a Chicago-based healthcare technology company that supplies medical […]
Over 36,000 exposed Plex servers vulnerable to recent flaws
Over 36,000 Plex Media servers exposed online remain unpatched against multiple security vulnerabilities and are vulnerable to attacks. Plex urged users a week ago to secure their media servers immediately against security issues that still lack CVE IDs for easy tracking. While the company didn’t provide additional details on Tuesday when it issued the warning, these security […]
Man gets 15 years for extorting women with AI-generated porn videos
An Ohio man was sentenced to 15 years in prison for multiple cybercrimes, including sextortion and cyberstalking of numerous victims via phone calls, voicemails, text messages, and online posts. When he was arrested on federal charges on June 23, 2025, 37-year-old James Strahler II was also charged with anonymous telecommunications harassment and child pornography production and distribution. […]
New Microsoft Defender ‘ShieldCrash’ zero-day grants SYSTEM access
An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named “ShieldCrash” right after Microsoft rolled out its September 2026 Patch Tuesday security updates. ShieldCrash is described as a bypass for the ShieldBreak Defender privilege escalation flaw patched on Thursday, which itself bypassed RoguePlanet, another Defender flaw disclosed in June and patched by Microsoft […]
Google warns of new Chrome zero-day bug exploited in attacks
Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year. “Google is aware that an exploit for CVE-2026-87491 exists in the wild,” the company said in a Tuesday security advisory. The company began rolling out patched versions to Windows (153.0.8010.36), Mac […]
Microsoft adds age-awareness APIs that can tell if users are children, teens, or adults
Microsoft is adding new age-awareness APIs to Windows 11 that will allow apps to determine whether someone is a child, teenager, or adult without exposing their exact date of birth. The new Windows Age API uses information associated with a Microsoft account and can return age ranges such as under 10, 10-12, 13-15, 16-17, and […]
DoppelCart fraud network uses 119,000 fake shops to steal credit cards
A massive operation dubbed âDoppelCartâ uses more than 119,000 domains to run a network of fake e-shops that steal payment card details. Most of the domains are in the .SHOP top-level domain, accounting for 2.72% of all sites on the TLD. German cybersecurity startup Nebty discovered DoppelCart and describes it as the largest publicly documented fake-shop […]
Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit
A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk. The malware shows signs of being a second-stage payload that was likely deployed after exploiting CVE-2025-53521, a critical remote code execution (RCE) flaw […]