News & Protection
VPN and privacy news from the LiMP VPN team: data breaches, phone and account security, online scams, and practical advice on protecting your data in 2026.

WeChat WeWorm: Account Hijacked Before You Answer the Call
Calif's WeWorm exploits WeChat's VoIP stack to hijack accounts via an incoming call — no answer needed. Tencent deployed a server-side fix by 28 August 2026.

3,585 Security Flaws Found in Russia's Food Delivery Apps
AppSec Solutions found 3,585 flaws in 89 Russian delivery apps — 1,290 critical. DNS vulnerabilities in every app tested; hardcoded API keys expose user data an…
Read more
WhatsApp Flaw Exposes Android Gallery Without Unlocking
A WhatsApp bug on Android lets anyone preview private gallery photos via an incoming video call and Meta AI photo editing — no PIN needed, no patch yet.…
Read more
$7 SweepLED Gadget Spots Hidden Hotel Cameras in 5 Seconds
KAIST researchers built SweepLED, a $7 smartphone clip-on that detects hidden cameras in hotels and rental apartments in five seconds with 94% accuracy.…
Read more
153 Million US Driver's Licences Exposed in Darknet
153 million US and Canadian driver's licences and passports appeared in a darknet sale traced to IDScan.net. The identity verification firm processes 21M verifi…
Read more
Russian Indicted for TVRAT Attack on 80,000 Freelancers
Russian national Aktulaev faces US federal charges for infecting 80,000 freelance platform users with TVRAT and DarkVNC remote-access trojans via malicious Exce…
Read more
LG Smart TVs Scan Your Home Network and Record Standby Audio
LG Smart TVs deliberately map your home network and send device data to LG's ad platform. On vulnerable devices, audio is recorded while the screen is off — sto…
Read more
"Quiet Ransom": Hackers Exploit Russia's Data Breach Fine Laws
Hackers are exploiting Russia's turnover fine law as leverage: pay us to stay quiet about your breach, or we'll report it to Roskomnadzor ourselves.…
Read more
Unknown APT Spies on Russian Regional Governments
PT Expert Security Center tracked a new APT group running ISO-lure phishing against Russia's regional government, Defence, and FSIN since May 2026.…
Read more
StyleSmuggler: Magento Zero-Day Puts Shoppers’ Data at Risk
The StyleSmuggler zero-day gives attackers full server control over any Magento or Adobe Commerce store — all versions affected, no patch available yet.…
Read more
MikroTik Patches Critical RouterOS Flaw as Active Attacks Surge
Latvia's CERT.LV confirms active MikroTik RouterOS exploitation: attackers plant a hidden “ops” admin account on compromised routers. Patches are out — update i…
Read more