
A concise security roundup covering a data breach at a premium streaming hub, AI browser prompt-injection via URL fragments, and NFC-based banking malware arrests.
– Data breach: alleged 94 GB stolen by Shiny Hunters; premium users’ emails, watch and search logs exposed; origin disputed (Mixpanel vs internal access).
– AI browsers: “hashjack” uses URL fragments to inject hidden instructions into assistants (e.g., lethal paracetamol dosing); some vendors patched, Google declined to fix.
– NFC banking: Russian police arrested a gang abusing NFC Gate with fake APKs and relayed NFC transactions to withdraw victims’ funds.
Quotes:
They’re threatening to leak everything unless the hub pays in crypto.
Encouraging us to take enough paracetamol to kill a whole herd of elephants.
A URL can grab your banking info and send it straight to an attacker-controlled site.
Statistics
| Upload date: | 2025-12-16 |
|---|---|
| Likes: | 7502 |
| Comments: | 1513 |
| Statistics updated: | 2025-12-19 |
Specification: 200 Million User Records… Breached
|