News & Protection
VPN and privacy news from the LiMP VPN team: data breaches, phone and account security, online scams, and practical advice on protecting your data in 2026.

Trezor Warns of Phishing After ShipMonk Supply Chain Breach
Shipping firm ShipMonk exposed data of 13,689 Trezor customers: names, emails, phones, and home addresses. Wallets and keys are safe but phishing risk is high.

CEVA Logistics Breach Hits Steam, ING and Ajax Customers
A cyberattack on CEVA Logistics exposed names, addresses, and emails of Steam hardware buyers and customers of ING, Ajax, and Ace & Tate.…
Read more
Levi Strauss: Three Phone Calls, Corporate Data Stolen
Three phone calls gave attackers access to Levi Strauss corporate data in August 2026 — a vishing campaign linked to UNC6671 targeting more than 200 companies i…
Read more
$15 Domain Purchase Exposed 400,000 Corporate Emails
Two researchers bought 'noreply.net' for $15 and received 400,000 corporate emails — including passwords, medical records, hotel bookings and security camera fo…
Read more
Trezor Data Breach: 13,689 Customers Exposed via Metabase
Zero-day CVE-2026-72898 in Metabase exposed 13,689 Trezor buyers' names, phone numbers, and shipping addresses via logistics partner ShipMonk.…
Read more
Armored Likho: Telegram Spy Suite and Covert Microphone Recording
Kaspersky GReAT uncovered Armored Likho: the Still Toolkit steals Telegram sessions and covertly records audio from infected Windows devices.…
Read more
DDX Fitness Breach Exposes Client Photos and Personal Data
Russia's largest fitness chain DDX Fitness (168 clubs, ~900,000 members) allegedly suffered a breach exposing client photos and visit records on August 13, 2026…
Read more
Windows Zero-Day Exploited 5 Weeks by Lazarus: Patch Now
North Korean Lazarus hackers exploited Windows kernel zero-day CVE-2026-68820 for 5 weeks via fake LinkedIn job offers. Microsoft patched it on August 11, 2026.…
Read more
Zoom Zoomsday: Zero-Click Flaw Hijacks Your PC Live
Zoom's Zoomsday zero-click flaw lets attackers hijack any meeting participant's device with no user action needed. Patch released August 11 — update now.…
Read more
Two CVSS 9.8 SharePoint Flaws Actively Exploited in the Wild
Two critical SharePoint Server flaws rated CVSS 9.8 are actively exploited — attackers breached Switzerland's federal IT office in July 2026, compromising aroun…
Read more
ViPNet Client: Critical CVSS 9.0 Flaw Exploited in Russia
A CVSS 9.0 flaw in Russia's ViPNet Client let attackers deploy a backdoor via fake updates, compromising at least 8 organizations in targeted operations.…
Read more