Related Threat Clusters
-
Critical WP Maps Pro Vulnerability Exposes 15,000 WordPress Sites to Admin Takeover
A critical vulnerability (CVE-2026-8732) in the WP Maps Pro WordPress plugin allows unauthenticated attackers to create administrator accounts on affected sites. The flaw affects all versions up to 6.1.0 and was…
16 articles · Updated May 31, 2026 -
Google API Key Vulnerability Exposes Gemini AI Access in Android Apps
A vulnerability in Google's API key system has allowed unauthorized access to the Gemini AI platform from numerous Android applications. CloudSEK identified that existing API keys, meant for public services,…
2 articles · Updated April 10, 2026 -
FBI and NCAA Collaborate to Combat Cyber-Enabled Sexual Exploitation of Athletes
The FBI and NCAA have partnered to address the rising threat of cyber-enabled sexual exploitation targeting college athletes. This initiative aims to protect athletes from scams that often involve sextortion, where…
2 articles · Updated August 11, 2026 -
Google API Keys Remain Active for Up to 23 Minutes After Deletion
Research by Aikido Security reveals that Google API keys can remain active for up to 23 minutes post-deletion, contrary to user expectations of immediate revocation. This delay allows attackers with leaked keys to…
7 articles · Updated May 21, 2026 -
Stolen Gemini API Key Leads to $82K in Unauthorized Charges
A three-person development team in Mexico faces financial ruin after a stolen Google Cloud API key resulted in $82,314.44 in unauthorized charges within 48 hours. The key was compromised between February 11 and 12,…
3 articles · Updated March 4, 2026 -
Malaysia's Cybercrimes Bill 2026 Passed Amid Controversy
On July 1, 2026, Malaysia's Dewan Rakyat passed the Cybercrimes Bill 2026, overhauling the Computer Crimes Act 1997. The bill introduces new offences for deepfakes and non-consensual intimate images, and tighter…
2 articles · Updated July 6, 2026 -
Google Maps Hack Alters Names of Major Spanish Football Stadiums
Hackers have tampered with the names of iconic football stadiums in Spain, including Real Madrid's Estadio Santiago Bernabeu and Barcelona's Spotify Camp Nou, on Google Maps. The alterations included humorous and…
2 articles · Updated May 21, 2026 -
Old Google API Keys Expose Sensitive Data via Gemini Access
Old Google API keys, previously deemed harmless, now pose a security risk as they can access sensitive data through the Gemini API. Security researchers found that nearly 3,000 keys, originally used for public services,…
12 articles · Updated February 26, 2026
Recent Intelligence Reports
- Sextortion scams now feature photos of your home, personal information — www.livenowfox.com · August 12, 2026
- The Cybercrimes Bill Just Passed. Now Malaysia Finds Out What "Checks and Balances ... — Newswav · July 6, 2026
- CVE-2026-8732: The WP Maps Pro Flaw That Lets Anyone Create a WordPress Admin Without a Password — Securityaffairs.Co · June 1, 2026
- WP Maps Pro bug exploited to create admin accounts on WordPress sites — Bleepingcomputer · May 31, 2026
- Google Api Keys Deletion — www.aikido.dev · May 23, 2026
- Deleted Google API keys keep working for up to 23 minutes, researchers warn — Feeds2.Feedburner · May 22, 2026
- Hackers also dubbed the Bernabeu 'Barcelona Training Ground' — www.dailystar.co.uk · May 21, 2026
- Google Maps hackers target Barcelona and Real Madrid stadiums in brutal name change — Mirror · May 21, 2026