TechLogHub Blog — Page 6 of 22
Insights, guides, and product strategy for builders and product teams.

Oxford University discloses data breach after careers platform hack
Oxford University has disclosed a data breach involving its CareerConnect platform after third‑party provider Group GTI was compromised. The incident, dated May 28, exposed users’ first names, last names, email addresses, and encrypted passwords for those not using Single Sign-On; affected passwords have been invalidated and users will be asked to reset them. Oxford says no course data, uploaded files, appointments, or financial information were accessed, and the breach appears isolated to GTI’s system, though phishing attempts are possible; this is the second breach Oxford announced in 2026 after the Canvas incident.

Over 20,000 Instagram accounts stolen in Meta AI support hack
Meta disclosed that more than 20,000 Instagram accounts were hijacked after attackers exploited a flaw in its AI-powered High Touch Support (HTS) account-recovery tool, enabling password resets without verifying email addresses or using two-factor authentication. The breach appears to have begun in mid-April 2026, with Meta revealing the issue on May 31 and subsequently disabling HTS and the generated reset links. Affected users could have had personal data—such as email addresses, phone numbers, dates of birth, posts, DMs, and profile details—potentially exposed. Meta says it secured the compromised accounts, required password resets, and will fix authentication checks and review other recovery flows across its platforms.

Hands on with Intelligent Terminal, an AI-powered Windows Terminal
Microsoft has released Intelligent Terminal, an open-source fork of Windows Terminal that embeds an AI assistant directly into the terminal. The AI pane runs alongside the normal shell and supports multiple agents (GitHub Copilot, Claude, Codex, Gemini), with optional automatic error detection and error suggestions. It also adds session management so you can resume previous agent work across sessions. Not installed by default with Windows, Intelligent Terminal is available from the Microsoft Store or GitHub for those seeking in-terminal AI guidance for explaining errors, drafting commands, and coding tasks.

Critical Everest Forms Pro flaw exploited to take over WordPress sites
A critical vulnerability (CVE-2026-3300) in Everest Forms Pro for WordPress is being exploited to gain full control of sites, affecting versions up to 1.9.12 and enabling unauthenticated remote code execution via the Complex Calculation feature. A patch was released on March 18, 2026, but exploitation began by April 13, with attackers creating rogue administrator accounts (notably using the username 'diksimarina'). Wordfence blocked thousands of attempts; defenders should block known bad IPs (202.56.2.126 and 209.146.60.26), review logs, and scan for suspicious admin accounts.

Suspicious Polyfill login prompts pop up on Toshiba, Muji websites
Toshiba and Muji warned that suspicious sign-in prompts appearing on their websites, generated by the polyfill.io service, could be used to harvest credentials. Both companies suspended the service and advised users who saw the prompts to cancel and change passwords. The issue, linked to Polyfill’s historically compromised CDN, has affected other brands and even Samsung devices in late May to early June 2026, though no confirmed data breaches have been reported yet.

Chinese APT deploys new malware to keep access to hacked networks
Chinese APT UNC5221 (VerdantBamboo) quietly maintained access to multiple networks for at least 18 months, compromising MSPs and then infiltrating Microsoft 365 using the Brickstorm backdoor. The group introduced new malware—Plenet (Grimbolt) for Synology NAS and AgentPSD as a fallback reverse shell—after breaching and pivoting from the MSP into the victim environment, also deploying a BSD Brickstorm variant on pfSense. The operation, spanning 2023–2025 and evolving from Golang to Rust, demonstrates a highly sophisticated, cross‑platform campaign that evades detections; researchers published IOCs to aid defenders.

California Man Sentenced to More Than 26 Years for Fentanyl and Meth Trafficking on Nemesis Market (Dark Web)
California man Darren Hughes of San Jose was sentenced to over 26 years in federal prison for trafficking fentanyl and methamphetamine on Nemesis Market, a leading dark web marketplace. Prosecutors say he offered free meth samples and, in 2023, sold meth and fentanyl pills to an undercover agent for cryptocurrency; he was arrested June 28, 2023 in Redwood City. Nemesis Market launched in 2021 and was dismantled by German and U.S. authorities on March 20, 2024 after handling hundreds of thousands of orders. U.S. Attorney Andrew S. Boutros and IRS-CI SAC Adam Jobes touted the crackdown on online drug trafficking.

Cisco warns of unpatched SD-WAN zero-day exploited in attacks (CVE-2026-20245)
Cisco warns of a high-severity, unpatched zero-day in Catalyst SD-WAN Manager (CVE-2026-20245) that is actively exploited to escalate privileges to root across all deployment types. Exploitation requires netadmin privileges—typically via valid credentials or by chaining with CVE-2026-20182 or CVE-2026-20127—and can be triggered by uploading a crafted file. There is no patch yet; admins should upgrade to the fixed release for CVE-2026-20182 (May 14) and monitor /var/log/scripts.log for IOCs, contacting Cisco TAC if a compromise is suspected. Cisco notes this follows a pattern of previously exploited SD-WAN vulnerabilities.

Credit card theft campaign abuses Stripe to host stolen payment info
Security researchers have uncovered a Magecart campaign that abuses Stripe's API and Google Tag Manager to host and exfiltrate stolen payment data from checkout pages. The attacker loads malicious code via GTM, captures card details (number, expiry, CVV), and stores them as fake Stripe customer records, with data exfiltration occurring on page load and at intervals before the local copy is wiped. A Firestore-based variant was also observed. The operation appears active since December 24, 2025, and targets Magento/Adobe Commerce checkout flows. Advice: use one-time virtual cards with strict limits and audit GTM/Stripe integrations for tampering.

DentaQuest Data Breach Exposes 2.6 Million Accounts
DentaQuest, one of the largest U.S. dental benefits administrators, confirmed a cybersecurity incident exposing data from 2.6 million accounts. The breach, linked to the ShinyHunters gang, leaked about 234 GB of information including email addresses, full names, phone numbers, government IDs, health-insurance data, genders, and dates of birth. DentaQuest reports limited disruption to its networks and has engaged external security experts as Have I Been Pwned validates the leak; recipients are urged to watch for phishing and social-engineering attempts as the investigation continues.

UN food agency discloses breach affecting 600,000 Gaza households
The United Nations’ World Food Programme disclosed a cyberattack on its Gaza self-registration platform, potentially exposing the personal data of about 600,000 Palestinian households, including names, IDs, phone numbers, and registration locations. The platform is temporarily suspended as security measures are strengthened; beneficiaries are advised to ignore suspicious requests, and aid distribution continues while the investigation proceeds.

Microsoft Blames Caching Issue for Unexpected Windows Driver Updates
Microsoft fixed a misconfiguration in the Windows Update caching service that temporarily dropped device enrollment data, causing some Windows devices with auto-update restrictions to install driver updates without notice. The affected drivers were Microsoft-approved and posed no security risk. The issue reportedly affected tens of thousands of devices and could disrupt peripherals, but has been resolved with an updated service cache and enrollment status, and a review to prevent recurrence.

French and Spanish Authorities Dismantle Fake ID Marketplace Used by Migrant Smugglers
French and Spanish authorities have dismantled an online marketplace selling forged identity and administrative documents to migrant-smuggling networks across the European Union. In Alicante, on May 27, a suspect was arrested and document-production equipment along with about 800 counterfeit European IDs were seized from an apartment rented under a false name. The platform allegedly supplied forged documents to help smugglers evade border controls, fraudulently obtain residence rights, and move within the Schengen Area. Europol says document fraud underpins migrant smuggling, a concern reflected in the EU’s new European Centre Against Migrant Smuggling (ECAMS) and the 2025 EU Serious and Organised Crime Threat Assessment, which call for stronger intelligence sharing and cross-border investigations.

Chinese Hackers Use New Atlas RAT Malware in European Cyberattacks
TA4922, a Chinese-speaking cybercrime group, has expanded from East Asia into Europe, targeting Germany, Italy, the United Kingdom, and South Africa with the Atlas RAT and a broader set of loaders. The operation is financially motivated but shows potential for surveillance, delivering payloads via tailored phishing lures and messaging apps such as WhatsApp, LINE, and Teams. Atlas RAT provides capabilities including file theft, keylogging, screen and webcam recording, and stealth features, while RomulusLoader, SilentRunLoader, and Winos4.0 (ValleyRAT) enable further payloads and remote access. Proofpoint notes TA4922 conducts more unique campaigns than any other tracked actor, with high tempo and diverse objectives that could attract espionage groups.

New HTTP/2 Bomb DoS Attack Crashes Web Servers in Under a Minute
A new DoS technique dubbed HTTP/2 Bomb can crash major web servers in seconds from a single machine by combining HPACK header compression amplification with HTTP/2 flow-control stalling (Slowloris-style). Discovered with OpenAI's Codex under Calif researchers, it can exhaust tens of gigabytes of RAM within seconds on a 100 Mbps link; in tests, Envoy hit 32 GB in ~10 seconds, Apache httpd ~18 seconds, Nginx ~45 seconds, and IIS ~45 seconds (64 GB RAM). Patches exist for nginx (1.29.8, max_headers) and Apache httpd (mod_http2 2.0.41, CVE-2026-49975); patches for IIS, Envoy, and Pingora are not yet available. Mitigations include disabling HTTP/2 where feasible or placing a proxy/firewall that enforces hard header-count limits. PoC exploits are public, and full technical details will be disclosed at the Real World AI Security conference.

CISA warns of active attacks exploiting Android, Linux bugs
CISA warns of active exploitation of two high-severity bugs: CVE-2025-48595 in Android (affecting Android 14–16; exploits require no user interaction; limited in-the-wild activity; patched in June 2026) and CVE-2022-0492 in the Linux kernel (cgroups v1; local privilege escalation and possible container escape; patches available for multiple kernel versions). Federal agencies must apply updates by June 5, 2026, and KEV serves as a warning to critical infrastructure and large organizations; neither flaw is currently flagged as ransomware-exploited.

What 345 Days of Untested Exposure Looks Like at a Bank
Annual penetration testing creates a 345-day gap of unvalidated exposure in modern banks, a risk highlighted by recent breaches and threat reports. A real-world finding shows a vendor-hosted mortgage portal exposing tenant data through an unauthenticated API, enabling possible fraudulent loan submissions. Regulators already expect testing to follow change, not just on a yearly cadence, making continuous external testing the recommended remedy to close the security gap in financial services.

Acer working to patch max severity zero-days in Wave 7 routers
Acer is patching two critical zero-day vulnerabilities in its Wave 7 mesh routers (firmware 1.01.000055 or earlier). CVE-2026-49200 could allow unauthenticated remote access to plaintext credentials stored in log archives via the acer_cgi.log file, while CVE-2026-49201 stems from a hardcoded AES key in upload.cgi that could enable persistent backdoor access. Patches are not yet available, but Acer says fixes are planned for deployment by the end of June 2026. Until then, users should disable remote management or restrict Internet remote access to trusted IPs and follow the firmware-update steps once updates are released.

Police dismantles 9 crime groups in illegal streaming crackdown
European and international law enforcement have dismantled nine organized crime groups behind illegal streaming in Operation KRATOS 2, coordinated by Bulgaria with Europol and spanning 13 countries. The seven-month crackdown led to 29 arrests, 86 identified suspects, 148 house searches, and ongoing investigations (72), with authorities removing more than 27,000 illegal streaming URLs and flagging hundreds of thousands of infringing items (including 18,000 IPs and 4,370 domains). Investigators say the networks separated consumer sites from hosting servers to evade detection, targeting the wider criminal ecosystem and warning users of cybersecurity risks such as malware and data theft. The operation follows earlier anti-piracy efforts including KRATOS in 2024, Operation Switch Off, and CINEMAGOAL.

Google Adds Android Protection Against AI Deepfake Scam Calls
Google announces a new Android feature, “fake call detection,” to counter AI deepfake scam calls on Android 12+ (starting with Pixel), enabled by default. The system uses Phone by Google, Contacts, and Google Messages with RCS to automatically verify calls via a real-time, encrypted signal; if no signal is received, the recipient’s device pings the caller’s actual device to confirm, and a warning appears if the call isn’t genuine. The feature addresses spoofed numbers and voice cloning, highlighting that caller ID is no longer reliable and advising users to use Phone by Google as their default dialer. This rollout expands Android’s in-call scam protections, with prior expansion to banking apps, amid FTC and INTERPOL warnings about impersonation fraud.
Showing 20 of 423 articles


