TechLogHub Blog — Page 16 of 22

Insights, guides, and product strategy for builders and product teams.

Showing 20 of 423 articles
Over 20,000 crypto fraud victims identified in international crackdown
Apr 11, 2026

Over 20,000 crypto fraud victims identified in international crackdown

International law enforcement, led by the UK’s National Crime Agency in “Operation Atlantic,” identified over 20,000 cryptocurrency fraud victims across Canada, the UK and the US, froze more than $12 million in illicit proceeds from approval‑phishing scams, and uncovered $45 million in stolen crypto. The joint effort—partnering with the U.S. Secret Service, Ontario Police, Securities Commission and private industry—demonstrates the effectiveness of public‑private collaboration, a model that will underpin the UK’s new Fraud Strategy 2026‑29. The FBI’s parallel Operation Level Up has similarly rescued thousands of victims, highlighting the growing global threat of crypto investment scams.

By TechLogHub
ChatGPT launches a $100 Pro plan to compete with Claude's subscription.
Apr 11, 2026

ChatGPT launches a $100 Pro plan to compete with Claude's subscription.

OpenAI has introduced a new $100 ChatGPT Pro subscription tier, aligning its pricing with Anthropic’s Claude plan and filling the gap between its existing $20 Plus and $200 Max plans. The new Pro tier targets coders and enterprises needing higher usage limits—offering five times the limits of Plus and ten times Codex usage for a limited period—with all Pro plans granting access to advanced features such as GPT‑5, Codex, deep research, image creation, memory, and file uploads. The updated lineup now includes: Plus $20 (light use), Pro $100 (real projects with higher limits), and Pro $200 (heavy lifting).

By TechLogHub
Microsoft: Canadian employees targeted in payroll pirate attacks
Apr 10, 2026

Microsoft: Canadian employees targeted in payroll pirate attacks

Microsoft reports that the threat actor Storm‑2755 is targeting Canadian employees by hijacking Microsoft 365 accounts through phishing‑like sign‑in pages, stealing authentication tokens and bypassing MFA to gain full session access. Once inside, attackers create hidden inbox rules, intercept HR emails about direct deposits, and manipulate payroll systems such as Workday to redirect salaries to stolen bank accounts. The article warns that legacy authentication must be blocked, phishing‑resistant MFA enabled, and compromised sessions revoked immediately to defend against these “payroll pirate” attacks.

By TechLogHub
New ‘LucidRook’ malware used in targeted attacks on NGOs, universities
Apr 9, 2026

New ‘LucidRook’ malware used in targeted attacks on NGOs, universities

New Lua-based malware “LucidRook” is being used in spear‑phishing attacks against NGOs and universities in Taiwan, according to Cisco Talos researchers who attribute it to the threat group UAT‑10362. The malware arrives via phishing emails with password‑protected archives and can be delivered through either an LNK shortcut chain that drops LucidPawn or an EXE chain that masquerades as a fake Trend Micro antivirus. LucidRook uses a modular design with an embedded Lua interpreter to download and execute second‑stage payloads, allowing operators to update functionality without changing the core code. It performs system reconnaissance, encrypts data with RSA, stores it in password‑protected archives, and exfiltrates it via FTP or Gmail GMTP. The malware is heavily obfuscated, making reverse engineering difficult, and Talos has identified a related tool called LucidKnight for reconnaissance. While the exact post‑infection actions remain unknown due to an undecryptable Lua payload, the attacks are considered part of a targeted intrusion campaign.

By TechLogHub
New VENOM phishing attacks steal senior executives' Microsoft logins
Apr 9, 2026

New VENOM phishing attacks steal senior executives' Microsoft logins

New VENOM phishing-as-a-service attacks target senior executives, stealing Microsoft logins through highly personalized emails that masquerade as SharePoint notifications. The campaign uses a closed-access platform that hides targets via Base64‑encoded URLs and QR codes to bypass scanning tools. Once victims scan the QR code, they are redirected to a credential‑harvesting page that proxies real Microsoft login flows, capturing MFA codes and session tokens. VENOM also employs an adversary‑in‑the‑middle technique and device‑code phishing to establish persistent access. The attacks began in late 2025 and continue to target CEOs, CFOs, and VPs across multiple industries, highlighting the need for stronger authentication measures such as FIDO2 and stricter conditional access policies.

By TechLogHub
ChipSoft Healthcare Software Hit by Ransomware Attack, Service Outage in Netherlands
Apr 9, 2026

ChipSoft Healthcare Software Hit by Ransomware Attack, Service Outage in Netherlands

Dutch healthcare software vendor ChipSoft was hit by a ransomware attack, forcing its website and digital services for patients and providers offline. The company’s flagship EHR platform HiX is used by many Dutch hospitals; several facilities reported outages, while some patient‑facing systems remain operational. Dutch cybersecurity authorities are working with ChipSoft to assess the impact and help recover.

By TechLogHub
Google Chrome Adds Infostealer Protection Against Session Cookie Theft
Apr 9, 2026

Google Chrome Adds Infostealer Protection Against Session Cookie Theft

Google Chrome has introduced Device Bound Session Credentials (DBSC) in version 146 for Windows, a new security feature that cryptographically ties session cookies to the user’s hardware—using TPM on Windows and Secure Enclave on macOS—to prevent infostealer malware from harvesting and re‑using stolen session data. The protocol requires proof of possession of a private key stored within the device, making exfiltrated cookies immediately unusable without that key. This addition aims to block sophisticated malware families such as LummaC2 from gaining unauthorized access to user accounts by protecting session tokens with hardware-bound encryption.

By TechLogHub
Smart Slider updates hijacked to push malicious WordPress and Joomla versions
Apr 9, 2026

Smart Slider updates hijacked to push malicious WordPress and Joomla versions

Hackers hijacked the Smart Slider 3 Pro update system, distributing a malicious version (3.5.1.35) that installs multiple backdoors, creates hidden admin accounts, and steals data on WordPress and Joomla sites. The malware persists through hidden MU‑plugins, theme functions.php, and core‑file‑like PHP files that bypass database changes. Only the Pro 3.5.1.35 build is affected; users should upgrade to 3.5.1.36 or revert to a prior clean version, delete compromised files and users, reinstall core components, rotate credentials, regenerate salts, and enable 2FA. The vendor recommends restoring from an April 5 backup if available and provides a manual cleanup guide.

By TechLogHub
When attackers already have the keys, MFA is just another door to open
Apr 9, 2026

When attackers already have the keys, MFA is just another door to open

When attackers have already stolen email addresses, multi‑factor authentication (MFA) is just another door that can be opened. The recent Figure breach exposed 967,200 email records without any exploit, but those emails enable credential stuffing, AI‑generated phishing, and real‑time relay attacks that bypass MFA. Legacy MFA relies on human judgment to approve or reject prompts, making it vulnerable to phishing‑relay tools like Evilginx and Modlishka. A robust solution must cryptographically bind authentication to the exact domain, keep private keys in secure hardware, and require live biometric verification of the authorized user. Token’s Biometric Assured Identity platform delivers this by combining wireless proximity, hardware‑bound signatures, and real‑time fingerprint matching, eliminating phishing, replay, delegation, and human‑based exceptions. This architecture ensures that access is granted only when the legitimate person is physically present, addressing the structural gaps in current MFA deployments.

By TechLogHub
Webinar: From noise to signal – What threat actors are targeting next
Apr 9, 2026

Webinar: From noise to signal – What threat actors are targeting next

BleepingComputer will host a live webinar titled “From Noise to Signal – What Threat Actors Are Targeting Next” on Thursday, April 30, 2026 at 2:00 PM ET with Tammy Harper, Threat Intelligence Researcher at RansomLook. The session explores how security teams can detect early warning signs from underground communities—dark web forums, Telegram channels, and access broker marketplaces—to anticipate attacks weeks before they occur. It covers monitoring these hidden surfaces, identifying shifts in attacker tactics, translating threat intelligence into prioritized defenses, and shifting from reactive to proactive risk reduction. Register now to secure your spot.

By TechLogHub
Eurail Reports December Data Breach Affecting 300,000 Travelers
Apr 9, 2026

Eurail Reports December Data Breach Affecting 300,000 Travelers

Eurail B.V. disclosed that attackers breached its customer database on December 26, 2025, compromising the personal information of about 308,777 people—including names, passport numbers, ID details, bank IBANs, health data and contact info—some of whom obtained passes through the EU’s DiscoverEU program. The stolen data was posted on Telegram and is being sold on the dark web. Eurail urged affected customers to change passwords, monitor bank activity and watch for phishing attempts. The breach was reported to regulators in Oregon and flagged by the European Commission.

By TechLogHub
Hackers exploiting Acrobat Reader zero‑day flaw since December
Apr 9, 2026

Hackers exploiting Acrobat Reader zero‑day flaw since December

Hackers have been exploiting an unpatched zero‑day flaw in Adobe Reader since December by delivering malicious PDFs that automatically steal data and can lead to remote code execution or sandbox escape, according to researcher Haifei Li; the attack uses a sophisticated “fingerprinting” technique, targets users without their interaction, and includes Russian‑language phishing lures. Users are urged not to open unknown PDFs until Adobe releases a patch, and defenders can block traffic with “Adobe Synchronizer” in the User‑Agent header.

By TechLogHub
Hackers Steal $3.6 Million From Crypto‑ATM Giant Bitcoin Depot
Apr 9, 2026

Hackers Steal $3.6 Million From Crypto‑ATM Giant Bitcoin Depot

Bitcoin Depot, one of the world’s largest Bitcoin ATM operators, disclosed that attackers stole $3.665 million worth of Bitcoin—about 50.9 coins—from its crypto wallets after breaching its systems in March 2026. The breach was detected on March 23, prompting immediate incident response, external cyber‑security assistance, and law‑enforcement notification. While the company believes customer platforms were unaffected, it warned that insurance may not fully cover the losses and noted potential reputational, legal, and regulatory impacts. This follows previous data breaches affecting tens of thousands of users in 2024 and 2025.

By TechLogHub
Microsoft suspends dev accounts for high‑profile open source projects
Apr 9, 2026

Microsoft suspends dev accounts for high‑profile open source projects

Microsoft has suspended developer accounts used to sign and publish updates for several high‑profile open‑source projects—including WireGuard, VeraCrypt, MemTest86 and Windscribe—after a mandatory account verification deadline that was missed. The suspensions occurred without prior notice or an easy appeal process, preventing these teams from delivering Windows builds and security patches. Microsoft’s VP Scott Hanselman said the action followed failed verifications required by the Windows Hardware Program, but maintainers reported no warning and struggled to contact support. The issue has been highlighted in media coverage and is being addressed by Microsoft, though details remain scarce.

By TechLogHub
13‑Year‑Old Bug in ActiveMQ Lets Hackers Remotely Execute Commands
Apr 8, 2026

13‑Year‑Old Bug in ActiveMQ Lets Hackers Remotely Execute Commands

Apache ActiveMQ Classic suffers a 13‑year‑old remote code execution flaw (CVE‑2026‑34197) that lets attackers inject arbitrary commands via the Jolokia management API, especially on versions 6.0.0–6.1.1 where authentication is bypassed by another bug. The vulnerability was uncovered using Claude AI and patched in March 2026 for versions 5.19.4 and 6.2.3. Organizations running ActiveMQ should upgrade immediately and monitor broker logs for suspicious VM‑transport connections that trigger configuration errors, indicating possible exploitation.

By TechLogHub
Is a $30,000 GPU Good at Password Cracking?
Apr 8, 2026

Is a $30,000 GPU Good at Password Cracking?

A $30,000 AI‑accelerator like Nvidia’s H200 or AMD’s MI300X is surprisingly ineffective at password cracking compared to a consumer GPU such as the RTX 5090. Benchmarks with Hashcat show that the RTX 5090 hashes passwords up to twice as fast as the AI GPUs across all tested algorithms (MD5, NTLM, bcrypt, SHA‑256, SHA‑512). Despite its ten‑fold higher price, the AI hardware offers no performance advantage for brute‑force attacks. This highlights that attackers already have sufficient computing power with readily available consumer GPUs, and that protecting passwords through length, complexity, MFA, and continuous breach monitoring is far more critical than relying on expensive GPU upgrades. Specops provides tools like Password Policy to enforce strong passwords and detect compromised credentials, reinforcing the need for multi‑factor authentication and robust security practices.

By TechLogHub
Microsoft rolls out fix for broken Windows Start Menu search
Apr 8, 2026

Microsoft rolls out fix for broken Windows Start Menu search

Microsoft has released a server‑side fix that restores the Start Menu search feature on Windows 11 23H2 devices affected by a recent Bing update. The issue, which caused blank or unresponsive search results for a small number of users since April 6, was traced to the Bing update and is being resolved automatically as the rollback rolls out. Users should ensure their device is online and that Web Search isn’t disabled via Group Policy to receive the fix.

By TechLogHub
Hackers exploit critical flaw in Ninja Forms WordPress plugin
Apr 7, 2026

Hackers exploit critical flaw in Ninja Forms WordPress plugin

Hackers have exploited a critical flaw (CVE‑2026‑0740) in the Ninja Forms WordPress plugin’s File Uploads premium add‑on, allowing unauthenticated attackers to upload arbitrary files—including PHP scripts—to any location on the server, enabling remote code execution and potential site takeover. The vulnerability, discovered by security researcher Sélim Lanouar, was reported to Wordfence in January 2026, prompting temporary firewall mitigations and a full patch released in version 3.3.27 on March 19. With over 600,000 downloads and more than 3,600 attacks detected in the past 24 hours, users of Ninja Forms File Upload are urged to upgrade immediately to prevent exploitation.

By TechLogHub
FBI: Americans lost a record $21 billion to cybercrime last year
Apr 7, 2026

FBI: Americans lost a record $21 billion to cybercrime last year

The FBI reports that Americans lost a record $21 billion to cybercrime last year, an increase of 26% over 2024’s $16.6 billion. The losses were driven mainly by investment scams, business email compromise, tech‑support fraud, and data breaches, with cryptocurrency attacks causing the largest loss (over $11 billion). The Internet Crime Complaint Center received more than a million complaints, up from 859,000, with phishing, extortion, and investment scams being the most common. Older adults (60+) suffered the greatest losses, while AI‑related scams also appeared in the report for the first time. The FBI has intensified efforts to block attacks, freeze stolen funds, and notify victims, highlighting the need for cautious verification of urgent requests and reporting incidents to IC3.

By TechLogHub
Snowflake Customers Hit in Data Theft Attacks After SaaS Integrator Breach
Apr 7, 2026

Snowflake Customers Hit in Data Theft Attacks After SaaS Integrator Breach

Snowflake customers have been hit by data‑theft attacks after a breach of a SaaS integration provider that stole authentication tokens. The attackers, linked to the ShinyHunters extortion gang and allegedly originating from an incident at Anodot (now owned by Glassbox), targeted Snowflake accounts and attempted to steal data from Salesforce but were thwarted by AI detection. Snowflake confirmed unusual activity in a few customer accounts, locked them down, and advised affected users. The breach has not compromised Snowflake’s own systems, and only one company—Payoneer—reported no impact. Google’s Threat Intelligence Group is monitoring the incident.

By TechLogHub

Showing 20 of 423 articles