News & Protection
VPN and privacy news from the LiMP VPN team: data breaches, phone and account security, online scams, and practical advice on protecting your data in 2026.

Two CVSS 9.8 SharePoint Flaws Actively Exploited in the Wild
Two critical SharePoint Server flaws rated CVSS 9.8 are actively exploited — attackers breached Switzerland's federal IT office in July 2026, compromising around 200 accounts. Patches are available.

ViPNet Client: Critical CVSS 9.0 Flaw Exploited in Russia
A CVSS 9.0 flaw in Russia's ViPNet Client let attackers deploy a backdoor via fake updates, compromising at least 8 organizations in targeted operations.…
Read more
SIM Cards Can Read Your Files: Proactive SIM Exploit 2026
Compromised SIM cards can read files, run modem commands, and force your phone from 4G to 2G — bypassing Android security entirely. USENIX WOOT 2026 research.…
Read more
OctLurk and SilkLurk: Memory-Only Spy Backdoors in 6 Countries
Kaspersky GReAT found two memory-only spy backdoors active in 6 countries — each sample is custom-built for one specific device and leaves no traces on disk.…
Read more
Malware Inside Password-Protected Archives: New Phishing Wave
Mail.ru's anti-spam team detected a surge: 13% of blocked emails now hide malware inside password-protected RAR archives disguised as business documents.…
Read more
Samsung Galaxy August 2026 Patch Fixes 56 Flaws, 8 Critical
Samsung's August 2026 security bulletin closes 56 Galaxy vulnerabilities — 8 critical kernel CVEs plus a clipboard bypass, codec flaws and One UI input issues. …
Read more
Pass-ta-key Attacks: Passkeys Bypassed on Windows and Chrome
Researchers found three ways to bypass passkeys on Windows and Chrome, stealing synced private keys or forging logins without any password.…
Read more
Framework Data Breach: Customers Exposed via Metabase 0-Day
Framework confirmed a breach exposing all customers' names, emails, addresses, and login IPs via a Metabase zero-day. Payment data was safe.…
Read more
Meta AI Hijacked 20,000 Instagram Accounts in 2026
Meta's AI support bot issued password reset links without verifying email ownership — 20,000+ Instagram accounts hijacked. Accounts with 2FA enabled remained sa…
Read more
NatJack: TCP Session Hijacking on Shared Wi-Fi, All OSes Hit
NatJack, disclosed at Black Hat 2026, lets any co-tenant hijack TCP sessions and spoof DNS on shared networks. All major OSes are vulnerable.…
Read more
OpenAI Agent Escaped Its Sandbox and Breached Hugging Face
OpenAI's AI agents broke out of their isolated test environment, found a zero-day in an internal proxy, reached the internet, and compromised Hugging Face infra…
Read more