HeadFlash

Security

Fake VPNs Flood Chrome Store; CareCloud Breach Hits 3.75M

Hundreds of fake VPNs target Russian users, plus a massive data breach revision and new charges in a $6M Bitcoin extortion case.

Listen

This edition was produced with artificial intelligence. Text and voice are generated automatically.

Hundreds of Fake VPN Extensions Flood Chrome Web Store

Socket’s threat research team has identified 737 suspicious Chrome extensions claiming to offer VPN and SOCKS5 proxy services, published by 40 developer accounts and amassing 75,486 installs. Detailed analysis of 525 extensions revealed that 274 plagiarized branding from reputable VPN platforms like Proton VPN, Surfshark, NordVPN, ExpressVPN, CyberGhost, and TunnelBear. Two extensions specifically impersonated AmneziaVPN and AntiZapret, tools used to bypass internet censorship, and many extensions routed all traffic through fixed servers without split tunneling or per-site controls.

The extensions employed various deceptive tactics, including DNS-over-HTTPS evasion to bypass Chrome’s blocklists and advertising paid tiers with nonexistent private servers in Japan, Singapore, Canada, Australia, and Turkey. One extension, Burёnka VPN, was a fake UI that routed no traffic at all. The attackers exploited Chrome’s review process by studying its procedures, and opening a new developer account costs only $5, allowing the 40 accounts to be created for under $200. Most of these fake VPNs targeted Russian citizens bypassing regional censorship, and Google issued a similar warning about fake VPN activity on the Play Store in 2025.

Hundreds of Fake VPNs Are Flooding the Chrome Web Store →

US Charges 17 in Iranian Hacking Campaign Tied to HBO and $6M Bitcoin Extortion

U.S. prosecutors have charged 17 alleged members of Iran-based Mabna Institute in a years-long hacking campaign, including six defendants linked to the 2017 HBO hack and an attempt to extort the company for roughly $6 million in Bitcoin. The group allegedly stole at least 31.5 terabytes of academic data and intellectual property, targeting hundreds of universities, companies, government agencies, and other organizations worldwide. The Justice Department stated the defendants carried out hacks for Iran’s Islamic Revolutionary Guard Corps (IRGC) and other Iranian government and university clients.

The indictment alleges the group targeted more than 100,000 professor accounts worldwide and compromised roughly 8,000 accounts across 144 U.S. universities and 178 foreign universities, using spearphishing and stolen credentials to steal research, journals, theses, and other material. The State Department is offering rewards of up to $10 million for information leading to the location of five defendants. Assistant Attorney General John A. Eisenberg emphasized that the defendants hacked into universities and research institutions worldwide, stealing vast amounts of information and intellectual property of untold value.

Iranian Hackers Tied to $6 Million Bitcoin Extortion Charged in Massive Cyber Campaign →

Nearly 2,000 WordPress Sites Compromised in StopAndProtect Malware Operation

Check Point Research has identified nearly 2,000 compromised WordPress sites used by the StopAndProtect malware operation, with more than 6,000 unique IP addresses compromised as of July 24, including 1,852 in the United States and 630 each in Russia and India. The hacked websites hosted malware, sent commands to infected computers, and stored stolen documents, screenshots, and activity logs. The malware targets Windows users through a fake CAPTCHA on compromised websites, prompting victims to run a PowerShell command that installs malware capable of stealing credentials, cryptocurrency wallet seed phrases, and spreading through networks and USB drives.

Operational security failures by the developer exposed detailed infection logs, screenshots from infected computers, and source code of tools used to mass-manage compromised websites. Researchers collected over 31,000 screenshots and more than 700 archives containing stolen data, including documents, passwords, and cryptocurrency wallet files. Check Point believes the threat actor accidentally infected themselves, as one archive contained unusual files with suspicious content, helping researchers understand the operation’s scale and the actor’s methods.

Nearly 2,000 Hacked WordPress Sites Turned Into Criminal Infrastructure →

CareCloud Breach Victim Count Revised to 3.75 Million Patients

CareCloud, an American medical record storage company, has revised the number of victims affected in its March breach from 350,000 to roughly 3.75 million. The hackers gained access to medical data held in CareCloud’s cloud over six days, with the intrusion spotted on 16 March and access to an AWS environment lasting several days. The initial filing noted an eight-hour network outage and that hackers claimed to have exfiltrated data from databases within that environment, though no hacking group has claimed responsibility.

Leaked data includes names, addresses, bank accounts, payment card numbers, medical data, and government identification including driver’s licenses, passports, and Social Security numbers. Ross Filipek, CISO at Corsica Technologies, called the revision a warning, highlighting the disastrous impact of cyber attacks on healthcare organizations and the significant legal and regulatory exposure for CareCloud. The company says it is continuing to investigate and lockdown systems, and disclosure letters note no attempts at identity fraud to date but warn recipients to be mindful of misuse of the stolen information.

Data belonging to 3.75 million patients was exposed in the CareCloud breach – not the 350,000 originally reported →

US Agencies Warn of AI-Assisted Attacks on Water Systems and PLCs

CISA, the FBI, and the NSA warned on Wednesday that hackers are targeting all Siemens S7 programmable logic controllers (PLCs), devices used to control automated processes in energy, water systems, manufacturing, and agriculture. The agencies said the attacks are part of broader activity targeting water supply and wastewater systems across the United States, with disruption potentially causing downtime, safety incidents, or equipment damage to critical infrastructure. The hackers are using AI to generate exploit scripts that rely on publicly available information to find and exploit vulnerable PLCs running out-of-date software or otherwise poorly secured.

CISA has long warned critical infrastructure owners to keep these devices disconnected from the internet, and officials acknowledged that rural communities are often the most affected. The warning follows a series of cyberattacks by suspected Iranian hackers targeting U.S. water suppliers and wastewater providers in recent months, with intrusions reported at water facilities in Minnesota, Michigan, Arkansas, Georgia, and New Jersey. An incident response professional noted that while the use of AI to identify and target vulnerable PLCs is noteworthy, the devices are already highly vulnerable to begin with.

US says hackers are targeting vulnerable water systems with the help of AI →

Daily tech-news flash

The flash, every weekday.

Five minutes on AI, privacy and security — one short email per niche you pick, with a podcast to match.

Your niches