News

Apple Hide My Email Bug Exposes Real Addresses

Apple’s Hide My Email has a Vulnerability in it and the company has known for over a year

The CyberSec Guru

Apple's Hide My Email has an unpatched flaw that reveals real addresses in minutes. Reported in June 2025, still exploitable. Full technical breakdown

KIDS Act Passes House

The KIDS Act Just Passed the House – Here’s Every Detail about it

The CyberSec Guru

The KIDS Act (H.R. 7757) passed the House 267-117. Here's what age verification, encryption rules, and chatbot mandates actually require, in detail

PlayStation Removes 551 Purchased StudioCanal Movies with No Refunds

Sony Just Pulled 551 Movies from PlayStation Libraries. Again. And Here’s What Nobody Is Talking About.

The CyberSec Guru

Sony is deleting 551 purchased StudioCanal movies from PlayStation libraries on September 1, 2026 with zero refunds. Here's the full technical and legal breakdown

Discord Is Testing Incode for Age Verification

Discord Is Testing Incode for Age Verification, and the Privacy Concerns Are Legitimate

The CyberSec Guru

Discord is running a limited trial with Incode for facial age estimation and ID scanning. Here is what the vendor actually does, what are the privacy concerns

Booking.com Hotel Extranet Breach

Booking.com’s Hotel Extranet Is a Fraud Supermarket – and Japan Is Paying the Price

The CyberSec Guru

Hackers are using ClickFix malware to steal Booking.com hotel extranet credentials, then draining bank accounts and phishing guests with real reservation data

EU Chat Control Is Back

EU Chat Control Is Back – And This Time It Might Actually Pass (Update: It Has Passed)

The CyberSec Guru

EU Chat Control is back in its final legislative round on June 29, 2026. This complete guide covers what Chat Control proposes, the full timeline from 2021, why it keeps returning, and what happens if it passes

Linux page cache privilege escalation CVE-2026-46331 CVE-2026-43503

Two new Linux LPEs hit page cache from opposite ends of the kernel

The CyberSec Guru

Two new Linux kernel LPEs, CVE-2026-46331 (pedit COW) and CVE-2026-43503 (DirtyClone), corrupt page-cache memory to gain root without touching disk. Working exploits are public

CVE-2026-20896 Gitea authentication bypass

Three Vulnerabilities, One Platform: Why Your Self-Hosted Gitea/Gogs Instance Is Probably Already Owned

The CyberSec Guru

Three critical Gitea and Gogs CVEs disclosed in 2026: a CVSS 9.8 auth bypass via X-WEBAUTH-USER header, a stored DOM XSS through Semantic UI's preserveHTML, and an incomplete SSRF fix exposing AWS IMDS credentials

Alibaba Distilled Claude AI

Alibaba Stole Claude’s Brain. Here’s Exactly How They Did It.

The CyberSec Guru

How Alibaba-linked operators ran 25,000 fake accounts and 28.8M Claude exchanges to steal Anthropic's AI capabilities via distillation

ShinyHunters MSG Breach

ShinyHunters MSG Breach: 26M Records, Facial Recognition Dossiers, and a Vishing Attack That Started With a Phone Call

The CyberSec Guru

ShinyHunters leaked 45GB of Madison Square Garden data after a vishing attack on Microsoft Entra exposed 26 million records, biometric facial recognition profiles, and secret activist dossiers