Skip to main content

Posts

Showing posts from April, 2025

Hackers Hit WooCommerce Users with Fake Security Updates

A widespread phishing campaign has been targeting WooCommerce administrators globally since April 2025. The operation deceives site owners into installing fraudulent security patches that give attackers full control over their WordPress sites. Researchers at Patchstack uncovered this operation , which mimics the widely used WooCommerce plugin through emails sent from help@security-woocommerce[.]com . The phishing emails alert recipients to a fictitious vulnerability related to unauthenticated administrative access and pressure them to install a "critical patch" by clicking an embedded button. Victims are then redirected to a counterfeit domain, woocommėrce[.]com , which uses a subtle character swap to appear authentic. Once the user downloads the file — authbypass-update-31297-id.zip — it installs a malicious plugin that creates a hidden administrator account and connects the compromised site to a remote command server. A cronjob runs every minute to maintain access and d...

Over 500k Records Including Customer PII Exposed in Ticket Reseller Data Breach

Cybersecurity Researcher, Jeremiah Fowler, discovered and reported to vpnMentor about a non-password-protected database that contained 520,054 records belonging to an event ticket resale platform. The publicly exposed database was not password-protected or encrypted. It contained ​​520,054 records with a total size of 200 GB. The name of the database indicated that it contained customer inventory files in PDF, JPG, PNG, and JSON formats. In a limited sampling of the exposed documents, I saw thousands of concert and live event tickets, proof of ticket transfers, user-submitted screenshots of receipts, and more. Some of these documents contained partial credit card numbers, full names, email addresses, and home addresses. Internal files and folder names indicated the records belonged to Ticket to Cash — an online ticket resale platform. I immediately sent a responsible disclosure notice to TicketToCash.com, but I received no reply, and the database remained open. It took several days...

Is Dailymotion Safe to Use? Legal & Security Risks in 2025

Dailymotion has been around for 20 years and is one of the largest video-sharing platforms, hosting everything from music and short films to news and sports. If you're considering it as an alternative to YouTube, it's important to assess Dailymotion’s risks before streaming. Is Dailymotion safe to watch movies? While it is a legitimate site, its safety depends on factors like ad security, data tracking, and how you use the platform. In 2016, the site experienced a breach where over 80 million account details were leaked1, so it's crucial to be cautious. While Dailymotion has made strides to improve security since then, there are potential cybersecurity loopholes you should be aware of. That’s why I’ve investigated Dailymotion’s legal standing, security risks, and best practices for safer streaming . Whether you're concerned about malware, child safety, or data privacy, you’ll find practical advice to help deliver a safer viewing experience. Pro Tip: If you’re look...

How Can a VPN Help You Manage Your Digital Footprint?

Every click, search, and interaction online leave behind traces that companies eagerly collect. Your digital footprint includes everything from your browsing habits to your location and personal preferences — information that advertisers, data brokers, and cybercriminals can exploit. How can a VPN hide my digital footprint? It encrypts your internet traffic and masks your actual IP address. This prevents websites, ISPs, and advertisers from tracking your activity or linking it to your identity. With 1.5 billion users worldwide 1 , VPNs have become a trusted tool for enhancing online privacy. After testing over 45 VPNs, I found ExpressVPN to be the best for managing your digital footprint . Its TrustedServer technology wipes data with every reboot, and its verified no-logs policy means your online activity isn’t stored and shared with third parties. Additionally, the Advanced Protection feature blocks ads and trackers. Better yet, you can try ExpressVPN risk-free with its 30-day mon...