TechLogHub Blog — Page 12 of 22

Insights, guides, and product strategy for builders and product teams.

Showing 20 of 423 articles
15-year-old detained over French govt agency data breach
May 1, 2026

15-year-old detained over French govt agency data breach

France detains a 15-year-old suspected of selling data from the ANTS breach that affected about 11.7 million accounts; investigators say 12–18 million records were offered for sale on a cybercrime forum. The minor faces charges for unauthorized access, persistence and data exfiltration, plus possession of hacking tools, with penalties up to seven years in prison and €300,000. A judge is reviewing the case, and formal charges have not yet been filed.

By TechLogHub
BleepingComputer retracts Instructure data breach story
May 1, 2026

BleepingComputer retracts Instructure data breach story

BleepingComputer retracts its May 1, 2026 article about a purported Instructure data breach after confirming the information was incorrect and based on outdated details; the editors apologize for the error.

By TechLogHub
Criminal IP and Securonix ThreatQ Collaborate to Enhance Threat Intelligence Operations
May 1, 2026

Criminal IP and Securonix ThreatQ Collaborate to Enhance Threat Intelligence Operations

Criminal IP is partnering with Securonix to embed Criminal IP’s exposure-based threat intelligence into ThreatQ, enabling real-time enrichment of IP indicators within ThreatQ and automated workflows that keep context current. The integration adds contextual data such as maliciousness scores, VPN/proxy detection, remote access exposure, open ports, and known vulnerabilities, helping security teams triage faster and prioritize more accurately. Analysts can perform on-demand lookups and access enriched indicators directly in the ThreatQ dashboard, while the investment in the ThreatQ Orchestrator automates ingestion and filtering of exposure intelligence, enhancing investigation graphs and overall incident response workflows.

By TechLogHub
Microsoft fixes Remote Desktop warnings displaying incorrectly
May 1, 2026

Microsoft fixes Remote Desktop warnings displaying incorrectly

Microsoft has fixed a bug that caused Remote Desktop (.rdp) security warnings to render incorrectly on multi-monitor systems with different scaling after the April 2026 updates. The fix, in the Windows 11 preview cumulative update KB5083631 (and related KBs for Windows 10/Server), introduces an educational prompt and renders the warning correctly, with publisher verification shown before connections; unsigned RDP files trigger a caution warning. The article also notes prior issues from KB5083769 (backup app failures due to VSS timeouts) and highlights ongoing phishing risks using RDP files, including campaigns attributed to APT29.

By TechLogHub
Two Former Ransomware Negotiators Sentenced to Four Years in Prison Over BlackCat (ALPHV) Attacks
May 1, 2026

Two Former Ransomware Negotiators Sentenced to Four Years in Prison Over BlackCat (ALPHV) Attacks

Two former cybersecurity incident responders were sentenced to four years in prison each for conspiring to extort U.S. companies through the BlackCat/ALPHV ransomware operation, working as affiliates from May to November 2023 with accomplice Angelo Martino. They shared about 20% of ransoms and targeted multiple U.S. victims, including a Tampa medical device maker that paid $1.27 million on a $10 million demand. The FBI links BlackCat to more than 60 breaches and estimates at least $300 million in ransom payments from over 1,000 victims through September 2023.

By TechLogHub
New Bluekit phishing service includes an AI assistant, 40 templates
May 1, 2026

New Bluekit phishing service includes an AI assistant, 40 templates

BlueKit debuts as a phishing toolkit with over 40 templates for services like Outlook, Gmail, iCloud, GitHub, and Ledger, plus an AI Assistant panel that supports models such as Llama, GPT-4.1, Claude, Gemini, and DeepSeek to draft campaigns. It offers end-to-end functionality—from domain purchase and phishing-page setup to campaign management and real-time monitoring, with data exfiltration possible via Telegram. Early reviews from Varonis say the AI drafts are skeletal and contain placeholders, indicating the feature set is still evolving, but the kit exemplifies the growing AI-enabled, all-in-one phishing platforms.

By TechLogHub
Romanian leader of online swatting ring gets 4 years in prison
May 1, 2026

Romanian leader of online swatting ring gets 4 years in prison

Thomasz Szabo, a Romanian national who led an online swatting ring targeting more than 75 officials, journalists, and four religious institutions, was sentenced to four years in federal prison plus three years of supervised release after pleading guilty to conspiracy and explosives-threat charges. Extradited from Romania in 2024, Szabo operated since 2020 under multiple aliases, orchestrating false reports that drew armed police responses and wasted taxpayer resources; his followers targeted members of Congress, federal officials, judges, and churches, with one member boasting of 25 swatting calls in a single day.

By TechLogHub
New Linux Copy Fail flaw gives hackers root on major distros
Apr 30, 2026

New Linux Copy Fail flaw gives hackers root on major distros

A new Linux local privilege escalation called Copy Fail (CVE-2026-31431) lets an unprivileged user gain root by performing a 4-byte write into the page cache via the AF_ALG crypto interface and splice(), affecting kernels back to 2017. The exploit has been demonstrated on Ubuntu 24.04 LTS, Amazon Linux 2023, RHEL 10.1, and SUSE 16; upstream fixes were released on April 1, 2026, with distributions racing to push patches. Interim mitigations include disabling the AF_ALG interface or the algif_aead module, and promptly patching multi-tenant environments.

By TechLogHub
Hackers Exploit Authentication Bypass Flaws in Qinglong Task Scheduler to Deploy Cryptominers
Apr 29, 2026

Hackers Exploit Authentication Bypass Flaws in Qinglong Task Scheduler to Deploy Cryptominers

Hackers exploited two authentication-bypass flaws in Qinglong’s open-source task scheduler (CVE-2026-3965 and CVE-2026-4047) to deploy cryptomining on exposed servers, beginning in February before public disclosure. The issues stemmed from a mismatch between middleware authorization and Express.js routing, allowing access to protected admin endpoints via unauthenticated paths. Infections were observed across multiple setups, with a rogue process named “.fullgc” consuming heavy CPU and attackers modifying config.sh to download miners from an external host; a fix was finally merged in PR #2941 after earlier mitigations in PR #2924 proved insufficient.

By TechLogHub
Hackers arrested for hijacking and selling 610,000 Roblox accounts
Apr 29, 2026

Hackers arrested for hijacking and selling 610,000 Roblox accounts

Ukrainian police in Lviv arrested three hackers who hijacked over 610,000 Roblox accounts and sold them for about $225,000. The operation, led by a 19-year-old, used credential-stealing malware disguised as a game-enhancer to target high-value accounts, with ten searches yielding cash and electronic evidence. The suspects, aged 19, 21, and 22, face up to 15 years in prison on theft and unauthorized IT interference charges, as investigations continue.

By TechLogHub
cPanel, WHM emergency update fixes critical auth bypass bug
Apr 29, 2026

cPanel, WHM emergency update fixes critical auth bypass bug

cPanel and WHM issued an emergency update to fix a critical authentication bypass vulnerability that could grant unauthorized access to the hosting control panel. Admins must run the manual patch command (/scripts/upcp --force) to upgrade to patched builds (11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, 11.136.0.5). Namecheap temporarily blocked WHM/cPanel ports 2083 and 2087 to protect users until patches were available, and users on unsupported versions should upgrade immediately. If exploited, the flaw could let attackers fully control hosting accounts, plant backdoors, and conduct other malicious activities.

By TechLogHub
European police dismantles €50 million crypto investment fraud ring
Apr 29, 2026

European police dismantles €50 million crypto investment fraud ring

European authorities, led by Austria and Albania with Europol and Eurojust, dismantled a €50 million cryptocurrency investment fraud ring operating through call centers in Tirana. The scheme lured victims with fake platforms, diverted funds to an international money-laundering network, and included a secondary scam asking for fees to recover losses; 10 suspects were arrested and assets seized across multiple countries.

By TechLogHub
Learning from the Vercel breach: Shadow AI & OAuth sprawl
Apr 29, 2026

Learning from the Vercel breach: Shadow AI & OAuth sprawl

The article examines how shadow AI and OAuth sprawl threaten enterprise security, using the Vercel breach as a cautionary tale. It shows how a simple OAuth connection to Context.ai allowed attackers to pivot into Vercel’s data when Context.ai was compromised. Shadow IT is framed as broader than shadow apps, including shadow tenants, extensions, and especially shadow integrations that connect dangerous third-party tools to core systems. Recommended defenses include a default-deny policy for new OAuth grants, routine auditing of all active integrations, and visibility across all SaaS apps—not just the primary cloud platforms. The piece also notes a rising, widespread abuse of OAuth in attacks, including device code phishing, and highlights a new browser-based attacks report. It closes by promoting Push Security’s platform as a way to monitor, block, and remediate OAuth requests and related threats across the organization.

By TechLogHub
GitHub fixes RCE flaw that gave access to millions of private repos
Apr 29, 2026

GitHub fixes RCE flaw that gave access to millions of private repos

GitHub fixed a critical remote code execution flaw (CVE-2026-3854) that could have allowed attackers to read or write millions of private repositories with a single malicious git push. Reported by Wiz on March 4, 2026, GitHub reproduced and patched the issue on GitHub.com within hours, and patches were released for GitHub Enterprise Server across multiple supported releases with a strong upgrade directive. The vulnerability could have given full server access on GHES, but no exploitation was found before disclosure and no customer data was accessed. Nonetheless, about 88% of reachable GHES instances remained vulnerable at the time, prompting an urgent upgrade for administrators.

By TechLogHub
CISA orders feds to patch Windows flaw exploited as zero-day
Apr 29, 2026

CISA orders feds to patch Windows flaw exploited as zero-day

CISA has ordered federal agencies to patch Windows endpoints against CVE-2026-32202, a zero-day that enables NTLM hash leakage in low‑complexity, remote code‑execution scenarios. The flaw stems from an incomplete patch for CVE-2026-21510 and has been linked to APT28 activity targeting Ukraine and EU networks. Agencies must patch by May 12 under Binding Operational Directive 22-01, with guidance to apply vendor mitigations and monitor ongoing exploit activity including BlueHammer, RedSun, and UnDefend.

By TechLogHub
Microsoft Says Backend Change Broke Teams Free Chat and Calls
Apr 29, 2026

Microsoft Says Backend Change Broke Teams Free Chat and Calls

Microsoft confirms a backend change for Teams Free is causing chat and call failures for new users by skipping onboarding and privacy screens, leaving profiles as “Unknown” and unsearchable. Labeled a service degradation, the issue first appeared April 8 with regions and scope still unclear, and Microsoft says it will share more details later today as they work on a fix. This follows other recent Teams troubles, including Edge-update–related meeting join failures and a prior service update launch problem.

By TechLogHub
Video service Vimeo confirms Anodot breach exposed user data
Apr 29, 2026

Video service Vimeo confirms Anodot breach exposed user data

Vimeo has disclosed that data from some customers and users was accessed in the wake of the Anodot breach. The exposed information reportedly includes email addresses for some users, plus technical details, video titles, and metadata, with no video content, credentials, or payment card data affected. The incident is linked to the ShinyHunters extortion group, which had threatened to publish stolen data by April 30; Vimeo has disabled Anodot credentials, severed the integration, and is collaborating with third-party security experts and law enforcement while it investigates and promises updates.

By TechLogHub
US reportedly charges Scattered Spider hacker arrested in Finland
Apr 28, 2026

US reportedly charges Scattered Spider hacker arrested in Finland

A 19-year-old dual U.S.-Estonian citizen, online alias Bouquet, was arrested in Helsinki on April 10 while trying to fly to Japan and now faces U.S. charges as a member of the Scattered Spider hacking group. Prosecutors allege he helped breach multiple high-profile targets and extort millions in ransoms, with incidents dating back to 2023 and 2025. The case comes as another Scattered Spider leader pleaded guilty earlier this month.

By TechLogHub
Checkmarx confirms LAPSUS$ hackers leaked its stolen GitHub data
Apr 28, 2026

Checkmarx confirms LAPSUS$ hackers leaked its stolen GitHub data

Checkmarx confirms LAPSUS$ leaked data from its private GitHub repository after a March 23 supply-chain attack tied to the Trivy incident; attackers used stolen credentials to publish malicious artifacts, including Docker images and VSCode/Open VSX extensions for Checkmarx’s KICS scanner. A 96 GB data pack was posted on the LAPSUS$ portal and accessible on clearnet, with Checkmarx saying the exposed data originated from its GitHub and does not appear to contain customer information. Access to the affected repository has been blocked and a forensic investigation is ongoing, with more details expected within 24 hours.

By TechLogHub
Microsoft to Deprecate Legacy TLS in Exchange Online Starting July 2026
Apr 28, 2026

Microsoft to Deprecate Legacy TLS in Exchange Online Starting July 2026

Microsoft will begin blocking legacy TLS for POP and IMAP in Exchange Online starting July 2026. After deprecation, POP3/IMAP4 connections must use TLS 1.2 or newer, and any connections using TLS 1.0 or 1.1 will fail. Most users are unaffected since TLS 1.2+ is already standard, but those using legacy endpoints or custom/embedded applications may face disruption and will need updates. Admins are advised to verify their clients support TLS 1.2+ and update devices or applications accordingly as part of this broader move to secure, modern TLS.

By TechLogHub

Showing 20 of 423 articles