search
email security
Trends
- 1
Sensitive parts for Australia's Lockheed Martin F-35 Lightning II fighter jets were mistakenly routed through Hong Kong, reportedly ending up in Chinese hands after a UPS shipping error linked to a missed email. The incident has raised concerns about supply-chain security for the stealth fighter programme, with reports drawing attention to how easily critical defence components can pass through rival jurisdictions.
- 2
A Times of India report details how China gained access to sensitive components of the US F-35 stealth fighter, tracing the loss to a missed email and a wrong turn. The story has drawn attention for highlighting apparent lapses in US supply-chain and export controls surrounding one of America's most advanced weapons programmes.
- 3Users report locked out of Google despite correct password●Ask HN: Locked out of Google despite knowing password and having email access
A Hacker News discussion describes being unable to access a Google account even with the correct password and access to the recovery email, highlighting frustrations with Google's account recovery and security systems. Commenters are sharing similar experiences, questions about automated account lockouts, and advice on restoring access to tied services like email, photos, and payments.
- 4MailAccess debuts as email OSINT framework on Hacker News●Show HN: MailAccess – the true Email OSINT framework
A new open-source-style tool called MailAccess, described by its developer as a framework for email-based OSINT (open-source intelligence), is being showcased on Hacker News. The launch has drawn attention from the security community, with engagement around the tool's claims to be a comprehensive solution for investigating email addresses and their exposure across data sources. Discussions typically focus on capabilities, ethics, and potential misuse.
- 5
The Pentagon has opened an investigation after F-35 fighter jet components were reportedly sent through Hong Kong, contrary to US restrictions on defense-related exports routed through mainland China. The incident allegedly stemmed from a missed email warning, and officials are examining how the shipment occurred and what security implications it may carry.
- 6
Attention is turning to Samsung's upcoming Galaxy S26 lineup after a report from Cybernews described a hack that allegedly compromises the phone using a single email and a zero-day attack, requiring no user interaction. The claim has sparked discussion about the security of the unreleased device and what it could mean for Samsung's next flagship launch.
- 7Readers urged to check if their email is in data breaches▼Data breach check: is your email or password exposed?
Guidance is circulating on how to check whether your email address or password has been exposed in a data breach, directing users to breach-notification lookup services such as Have I Been Pwned. Security writers recommend checking old passwords, changing any that appear in breach databases, and enabling two-factor authentication. The renewed interest follows a steady drumbeat of large credential leaks affecting major online services, leaving many users unsure which of their accounts may be compromised.
- 8
UPS is facing scrutiny over a reported shipping error in which F-35 fighter jet components were sent through Hong Kong and ended up in Chinese hands, reportedly after a missed email. The case has raised concerns about export controls on sensitive US military technology and how easily restricted parts can slip through major carriers' logistics networks.
- 9Concerns grow over giving AI access to Gmail accounts●If you’re uncomfortable with giving AI access to your Gmail account, you’re not alone — and not without reason. PC World
PC World examines what happens when an AI agent is granted access to a user's Gmail account, weighing both the benefits and the risks. The piece argues that unease about letting AI read and act on personal email is justified, but offers guidance on settings that limit what the AI can see and do for those who still want the convenience.
- 10Hacker News users ask if email leaked while traveling abroad▼Ask HN: Email leaked while traveling abroad?
A question posted on Hacker News asks whether traveling abroad can lead to email leakage, drawing attention from the tech community. The discussion stems from a user's concern about the security of their email when crossing borders or using foreign networks. Commenters are weighing in on how email data may be exposed through different infrastructure, surveillance, or unsecured connections while overseas.
- 11Online store offers GitHub accounts for sale●Looking for a GitHub account? Easily buy one from us. Buy NOW👉: https:// usavccstore.com/product/buy-gi thub-account/ ➥(
An online vendor calling itself UsaVccStore is advertising ready-made GitHub accounts for sale, promoting contact via Telegram, WhatsApp and email. Purchasing accounts this way typically violates GitHub's terms of service and is often linked to spam, fraud or evading platform bans. Security watchers regularly flag such listings as scams or vehicles for abuse, advising developers to create their own accounts instead.
- 12
Users of Grok are rushing to claim custom email addresses under the mail.grokbot.com domain, turning address sign-ups into a competitive grab for desirable handles. Early adopters are posting about securing short or personalized names before they are taken, and the scramble is driving wide discussion about how long the free sign-up window will stay open and what the service offers.
- 13Samsung Galaxy S26 hacked via email vulnerability▼Samsung Galaxy S26 hacked via simple email vulnerability
Reports claim the Samsung Galaxy S26 has been hacked through a simple email vulnerability. According to the headline, attackers could compromise the device via a flaw tied to email handling. Few details are available about how the attack works, who carried it out, or whether Samsung has responded, so the scope and severity of the alleged security flaw remain uncertain.
- 14OpenAI used AI to write email warning Australia of AI hack▼OpenAI used AI to help write email warning Australian government AI had hacked its websites
OpenAI reportedly used AI to help draft an email warning the Australian government that hackers, also using AI, had targeted and breached its websites. The episode highlights how artificial intelligence is now involved on both sides of cyberattacks and in responses to them, drawing attention to the growing security risks governments face from AI-enabled intrusions.
- 15Fighting GenAI Email Threats with GenAI Defenses●Fighting GenAI with GenAI: The New Email Security Landscape SPONSORED FEATURE: Old attack, new protections https://www.
Email security is being reshaped as attackers use generative AI to craft more convincing phishing and social engineering, while defenders deploy AI-driven tools to detect and block them. A new Register sponsored feature outlines this 'old attack, new protections' landscape, arguing that traditional filters are no longer enough and that generative AI must now be met with generative AI defenses.
- 16Discord Bot Breach Exposes Emails of One Million Users▼Double Counter Breach Exposes 1M Discord User Emails [2026]
A security breach at Double Counter, a verification bot used widely on Discord servers, has reportedly exposed the email addresses of around one million Discord users. The incident is being reported as a 2026 data exposure, raising concerns about third-party bots handling user credentials. Users are advised to watch for phishing attempts using their email addresses.
- 17Discord bot Double Counter breach exposes one million emails▼A security breach has compromised the Discord protection bot Double Counter, resulting in the exposure of approximately 1 million email addresses
A security breach has hit Double Counter, a widely used Discord bot that blocks alt accounts, exposing the email addresses of roughly one million users. The incident raises concerns about how third-party Discord bots store user data, since many servers rely on such verification tools without auditing their security practices.
- 18Apple to tighten macOS Full Disk Access controls against AI agents▼Apple rafforzerà su macOS i controlli per Full Disk Access per evitare che gli agenti IA possono leggere file, mail, mes
Apple plans to strengthen Full Disk Access controls on macOS to prevent AI agents from freely reading files, emails, messages and browsing history. Reports describe the move not as a new restriction, but as introducing clearer, more explicit user consent, aimed at reducing privacy and security risks as AI tools increasingly operate directly on people's computers.
- 19Arizona man arrested over alleged White House bomb threat email●Arizona man arrested after allegedly emailing White House bomb threat to Tucson news station Jacob Aaron Hicks allegedly
Jacob Aaron Hicks, an Arizona man, was arrested after allegedly emailing a Tucson news station a threat claiming an imminent bomb strike against the White House. The message prompted an FBI investigation leading to his arrest. Authorities have not detailed a motive, and the case adds to a string of recent threats against federal buildings and officials.
- 20US agencies warn of China-linked hackers stealing government emails●FBI, NSA, and CISA alerted today on China-linked hackers (Integrity Technology Group) actively stealing emails from gove
The FBI, NSA and CISA issued an alert on Chinese hackers linked to Integrity Technology Group, who are actively stealing emails from government and critical infrastructure organizations worldwide. The advisory highlights ongoing state-backed cyber espionage, and comes amid heightened geopolitical tension, with the US reportedly weighing potential renewed military strikes against Iran.
- 21Neogen data breach exposes 436,000 email addresses●🟡 DATA BREACH ALERT Neogen - 436K accounts exposed Compromised data: Email Addresses Check if you're affected and what t
A data breach affecting Neogen has exposed roughly 436,000 accounts, with email addresses listed as the compromised data. The leak is attributed to the hacking group ShinyHunters. Security watchers are urging users to check whether their accounts are affected and to change passwords and watch for phishing attempts linked to the exposed addresses.
- 22MapRoulette fixes backend security vulnerabilities disclosed by researcher●@ jakelow has disclosed a few now-fixed security issues related to the backend of @ MapRoulette . “TL;DR: # MapRoulette
Security researcher Jake Low has disclosed several now-fixed vulnerabilities in the backend of MapRoulette, the OpenStreetMap mapping challenge platform. According to the disclosure, the flaws may have exposed access credentials — though not passwords — and user email addresses to attackers. The issues have since been patched, and the disclosure is drawing attention within the OpenStreetMap and open-source mapping communities.
- 23Offboarding failures leave ex-employees with working accounts▼Someone leaves on a Friday. By Monday the account still works and their phone still has the mail profile. Joiners, mover
A cybersecurity commentator has highlighted a common corporate security gap: employees who leave a company on Friday often still have active accounts and email access on their devices by Monday. The post points to the UK's NCSC guidance on joiners, movers and leavers processes, arguing that while leavers are often overlooked, internal job movers are the most neglected group, with old access rights quietly lingering.
- 24How to Set Up Email on Your Own Domain Without Running a Server●How to Set Up Email on Your Own Domain. And Why You Usually Don’t Need Your Own Server You have a domain. Now comes the
A new guide explains how to set up an email address on your own domain, arguing that a custom address gives you a lasting identity independent of any provider. It also makes the case that most people do not need to host their own mail server, since managed services can handle delivery, security and maintenance. The piece is being shared in privacy and open-source focused information security circles.
- 25US probes F-35 technical documents mistakenly shipped to Hong Kong●Кєк. Секретні деталі американського F-35 випадково відправили до Гонконгу через те, що працівник UPS просто пропустив ім
Classified technical details of the American F-35 fighter jet were accidentally sent to Hong Kong after a UPS employee missed an email. The shipment was meant to travel to the US via South Korea and Taiwan, but the route was changed following a delay. The US Congress is now investigating the incident.
- 26Widely used WordPress booking plugin LatePoint hit by security flaw▼LatePoint, a WordPress booking plugin on 100,000+ sites, has a flaw: any logged-in user can rewrite every customer's ema
LatePoint, a WordPress booking plugin installed on more than 100,000 websites, contains a vulnerability tracked as CVE-2026-17538. Any logged-in user can change the email address and phone number of every customer, and sites with open registration make this reachable by anyone. A related setting can escalate the flaw to full account takeover. Administrators are urged to update to version 5.7.4, which fixes the issue.
- 27Hoxhunt launches Respond tool to automate phishing triage▼Hoxhunt Respond automates phishing triage and email removal https:// fawkes.rocks/2026/10/08/hoxhun t-respond-automates-
Hoxhunt has introduced Respond, a security tool that automates the triage of reported phishing emails and removes malicious messages from user inboxes. The product aims to cut the time security teams spend handling human-reported threats. Coverage of the launch is drawing attention from cybersecurity professionals interested in AI-driven email defence.
- 28Hackers Abuse Microsoft Power BI to Deploy Rogue Remote Access Tools●(huntress.com) Threat Actors Abuse Microsoft Power BI in Phishing Campaign to Deploy Rogue ScreenConnect RMM Clients In
Security firm Huntress reports a phishing campaign in which attackers abuse legitimate Microsoft Power BI domains to bypass email security filters and trick users into installing rogue ScreenConnect remote monitoring and management clients. Because the malicious links come from trusted Microsoft infrastructure, they evade common detection methods. Cybersecurity researchers are warning organizations to scrutinize Power BI sharing invitations and monitor for unauthorized ScreenConnect installations.
- 29Data center firm CyrusOne reports breach affecting 373,000 records●💾 🟠 CyrusOne (cyrusone.com) ✓ Verified 📊 ~373K records compromised 📂 Email addresses, Employers, Job titles, Names +3 mo
Data center operator CyrusOne has disclosed a security incident in which roughly 373,000 records were compromised, including names, email addresses, employers and job titles. The disclosure reportedly came 63 days after the incident, and the company's email setup is flagged as lacking SPF and DMARC protections. Cybersecurity observers are circulating the details and questioning the disclosure delay.
- 30Outlook blocks .msix file types over security concerns●Microsoft extends the Outlook naughty step with two more file types You didn't really want to be sending around .msix an
Microsoft has added .msix and .msixbundle files to the list of file types Outlook blocks from being sent as email attachments. The change targets Windows app package formats that attackers can abuse to deliver malware, adding to a long list of restricted extensions. Reactions are largely sarcastic, with users joking that few people were sending such files anyway, while security-minded observers welcome the tightening of email protections.
- 31Discord bot breach exposes 275,000 email addresses●Popular Discord server bot breach leaks 275,000 email addresses and usernames, including paying subscribers
A security breach involving a bot used by a popular Discord server has leaked the email addresses and usernames of roughly 275,000 users, including paying subscribers. The incident raises concerns about how third-party bots on the platform handle user data, and whether paid members face added risks such as targeted phishing.
- 32New BPFDoor variant hides as mail traffic on telecom edge devices●A new BPFDoor backdoor variant and the AVERAT implant hide on telecom edge devices by posing as mail traffic. See how th
Security researchers at Rapid7 have detailed a new variant of the BPFDoor backdoor and a related implant called AVERAT that operate on Linux-based telecom network edge devices. The malware disguises its command traffic as ordinary email, making it hard to detect, and is linked to an operations-relay infrastructure. Researchers have published guidance on how organisations can hunt for infections.
- 33Phishing site flagged impersonating Kawartha webmail●Possible Phishing 🎣 on: ⚠️hxxps[:]//webmail-kawartha-inbox[.]weebly[.]com 🧬 Analysis at: https:// urldna.io/scan/6ac5619
Cybersecurity researchers are warning about a phishing site at webmail-kawartha-inbox.weebly.com, which mimics a webmail login page, apparently targeting Kawartha users to steal email credentials. The site was flagged and submitted for automated URL analysis, with security specialists sharing the findings to warn others to avoid entering login details on the fake page.
- 34Apple Cash to require ID verification for money reloads●Apple Cash Adds ID Check for Reloads, Teases Bank Funding Apple Cash will soon require identity verification to add mone
Apple has begun emailing Apple Cash customers to say that, starting November 9, Green Dot Bank will require identity verification before users can add money to their balances. The change tightens compliance around the peer-to-peer payment service, and the same notices reportedly hint at upcoming support for funding Apple Cash directly from bank accounts.
- 35Discord bot Double Counter breach exposes one million email addresses●🎮 Discord protection bot Double Counter hit by breach exposing around 1 million email addresses Double Counter, a servic
Double Counter, a bot used by Discord server administrators to block raids and alt accounts, has suffered a data breach exposing roughly one million email addresses along with Discord user IDs. The incident raises concerns about security practices for third-party bots with access to large community data, and affected users are being warned to stay alert for phishing attempts using their exposed details.
- 36Hackers steal millions of Discord IDs in Double breach●📰 Hackers steal millions of Discord IDs and email address in "deliberate, multi-stage attack" on security service Double
Attackers have stolen an estimated one million email addresses and Discord user IDs in what security firm Double describes as a deliberate, multi-stage attack. Double Counter, a verification tool used across Discord gaming servers, was hit in the breach, and fears are growing that the number of affected accounts could be far higher. It is the latest in a string of data incidents involving Discord-linked services, raising fresh concerns about how third-party apps handle user data.
- 37Security researcher flags phishing link abusing Google redirect●Possible Phishing 🎣 on: ⚠️hxxps[:]//www[.]google[.]co[.]kr/url?q=hxxps[:]//b4bm4n-b0b-0r1q1n4l-ytrewqhgfdsa-1oi[.]netlif
A cybersecurity analyst has warned about a suspected phishing campaign using a Google Korea redirect link to send victims to a suspicious Netlify-hosted page. The URL embeds what looks like an encoded email address, a common tactic to track targeted recipients. Analysts advise treating unexpected links claiming to come from Google with caution.
- 38NCSC urges 'browse down' to protect admin accounts from phishing▼An admin account that also reads email is one spear phish away from handing over the estate. The NCSC's name for the fix
UK's National Cyber Security Centre is promoting a principle called 'browse down': administrators should carry out privileged work only from dedicated high-trust devices, never from the same machine they use to read email. A security researcher highlighted the risk that a single spear-phishing email can compromise a combined admin and mailbox account, handing attackers control of an entire estate. The advice is paired with just-in-time privilege, where elevated rights are granted only when needed.
- 39Free Breach-Check Alternatives to Have I Been Pwned in 2026●By Marcus Hale. Originally published on Meikuio on August 7, 2026. Reviewed for syndication October... # security # priv
A new guide by Marcus Hale, first published on Meikuio in August 2026 and recently reviewed for syndication, surveys free alternatives to Have I Been Pwned, the popular service for checking whether your email or credentials have appeared in data breaches. The piece covers open-source options aimed at beginners, with attention to security and privacy trade-offs, and is being shared widely in developer and open-source communities.
- 40Massive X data breach allegedly leaks 200 million user emails▼Massive breach of Elon Musk's X allegedly leaks over 200 million users' email addresses
Reports claim that X, the social media platform owned by Elon Musk, has suffered a major data breach in which the email addresses of more than 200 million users were leaked. The alleged exposure of such a large volume of account data has raised fresh concerns about the platform's security practices and the risk of phishing and spam targeting its users.