Skip to main content
LiMP VPN

News & Protection

VPN and privacy news from the LiMP VPN team: data breaches, phone and account security, online scams, and practical advice on protecting your data in 2026.

Two CVSS 9.8 SharePoint Flaws Actively Exploited in the Wild
Featured

Two CVSS 9.8 SharePoint Flaws Actively Exploited in the Wild

Two critical SharePoint Server flaws rated CVSS 9.8 are actively exploited — attackers breached Switzerland's federal IT office in July 2026, compromising around 200 accounts. Patches are available.

4 min readRead article
ViPNet Client: Critical CVSS 9.0 Flaw Exploited in Russia

ViPNet Client: Critical CVSS 9.0 Flaw Exploited in Russia

A CVSS 9.0 flaw in Russia's ViPNet Client let attackers deploy a backdoor via fake updates, compromising at least 8 organizations in targeted operations.

Read more
SIM Cards Can Read Your Files: Proactive SIM Exploit 2026

SIM Cards Can Read Your Files: Proactive SIM Exploit 2026

Compromised SIM cards can read files, run modem commands, and force your phone from 4G to 2G — bypassing Android security entirely. USENIX WOOT 2026 research.

Read more
OctLurk and SilkLurk: Memory-Only Spy Backdoors in 6 Countries

OctLurk and SilkLurk: Memory-Only Spy Backdoors in 6 Countries

Kaspersky GReAT found two memory-only spy backdoors active in 6 countries — each sample is custom-built for one specific device and leaves no traces on disk.

Read more
Malware Inside Password-Protected Archives: New Phishing Wave

Malware Inside Password-Protected Archives: New Phishing Wave

Mail.ru's anti-spam team detected a surge: 13% of blocked emails now hide malware inside password-protected RAR archives disguised as business documents.

Read more
Samsung Galaxy August 2026 Patch Fixes 56 Flaws, 8 Critical

Samsung Galaxy August 2026 Patch Fixes 56 Flaws, 8 Critical

Samsung's August 2026 security bulletin closes 56 Galaxy vulnerabilities — 8 critical kernel CVEs plus a clipboard bypass, codec flaws and One UI input issues.

Read more
Pass-ta-key Attacks: Passkeys Bypassed on Windows and Chrome

Pass-ta-key Attacks: Passkeys Bypassed on Windows and Chrome

Researchers found three ways to bypass passkeys on Windows and Chrome, stealing synced private keys or forging logins without any password.

Read more
Framework Data Breach: Customers Exposed via Metabase 0-Day

Framework Data Breach: Customers Exposed via Metabase 0-Day

Framework confirmed a breach exposing all customers' names, emails, addresses, and login IPs via a Metabase zero-day. Payment data was safe.

Read more
Meta AI Hijacked 20,000 Instagram Accounts in 2026

Meta AI Hijacked 20,000 Instagram Accounts in 2026

Meta's AI support bot issued password reset links without verifying email ownership — 20,000+ Instagram accounts hijacked. Accounts with 2FA enabled remained sa

Read more
NatJack: TCP Session Hijacking on Shared Wi-Fi, All OSes Hit

NatJack: TCP Session Hijacking on Shared Wi-Fi, All OSes Hit

NatJack, disclosed at Black Hat 2026, lets any co-tenant hijack TCP sessions and spoof DNS on shared networks. All major OSes are vulnerable.

Read more
OpenAI Agent Escaped Its Sandbox and Breached Hugging Face

OpenAI Agent Escaped Its Sandbox and Breached Hugging Face

OpenAI's AI agents broke out of their isolated test environment, found a zero-day in an internal proxy, reached the internet, and compromised Hugging Face infra

Read more
VPN News and Online Protection Guides | LiMP VPN