Non-technical · Plain language · Daily

Security news that
anyone can understand.

Cybersecurity news written for everyone — hover over any underlined term for an instant plain-English definition.

Subscribe Free →
cybersecurityCyberBubbleSignal

Russia's Signal Attack Just Got Nastier — Here's the 30-Second Fix

Russian intelligence upgraded its Signal phishing campaign to steal your entire message history with one key. Plus: a $3M crypto heist, new Chinese espionage malware, and why Windows 10 users just got a surprise reprieve.

· 7 min read
cybersecurityCyberBubbleSignal

Russian Spies Are After Your Signal Backup Key — Here's the 30-Second Fix

The FBI upgraded its Signal warning: Russian intelligence is now stealing backup recovery keys that let attackers read your entire message history — even after you switch phones. Plus: Scattered Spider guilty pleas, a $3M crypto heist, and malware designed to fool AI.

· 7 min read
cybersecurityCyberBubbleransomware

Your $30 Streaming Box Is Moonlighting for Criminals

Scattered Spider members plead guilty in the UK, two Cisco zero-days are under active attack, and that cheap Android TV box on your shelf may be routing criminal traffic through your home network.

· 7 min read
cybersecurityCyberBubbleFortinet

FortiBleed Exposes 73,000 Firewalls — And a NATO Contractor

A Russian-linked crew ran 1.16 billion login attempts against Fortinet firewalls and walked away with credentials for 73,000 devices — including a NATO defense contractor. Plus: Splunk's emergency patch deadline and WordPress plugins secretly backdoored.

· 7 min read
cybersecurityCyberBubbleFortinet

FortiBleed, Unpatchable iPhones, and a 15,000-Site Cleanup

Russian hackers compromised 86,644 Fortinet firewalls using default passwords — CISA says change them now. Plus: an unpatchable exploit hits iPhones XS through 11, and international police clean 15,000 infected sites.

· 7 min read
cybersecurityCyberBubblezero-day

Your Antivirus Has a Zero-Day

A zero-day in Windows Defender lets attackers seize full control of any Windows PC — with no patch yet available. Plus: 144 poisoned npm packages, a CVSS 10.0 Joomla flaw, and a hacker who stayed inside a network for 33 days after his server went offline.

· 7 min read
cybersecurityCyberBubbleClickFix

Fake Browser Updates Are Now a Professional Malware Delivery Business

The ClickFix technique has evolved into a sophisticated malware delivery industry — three new loader families this week alone. Plus: three critical Fortinet zero-days being actively exploited, Cisco SD-WAN compromised in the wild, and a cPanel plugin flaw added to CISA's 'must-patch' list.

· 7 min read