A notorious ransomware gang claims to have stolen MyPillow's private data, but CEO Mike Lindell calls it a politically motivated "hit job." With the countdown ticking toward a massive dark web leak, who is telling the truth? Read more in my

The ransomware group known as Play is claiming to have exfiltrated data from the US-based pillow manufacturer MyPillow. The group posted on its dark web leak site that it had obtained private and personal confidential information. Play threatened to release an unspecified amount of this data on Friday, potentially exposing documents related to clients, budgets, payroll, identification, taxes, and financial information.
However, MyPillow's CEO, Mike Lindell, has refuted these claims, stating that the company has not experienced any security breach. Lindell, who is also a prominent supporter of former President Donald Trump and is seeking the Republican nomination for governor of Minnesota, told Straight Arrow News that he was unaware of any alleged attack until contacted by the press. He suggested that the accusations are politically motivated, calling it a "hit job" due to his gubernatorial campaign. Lindell asserted that MyPillow has no data breaches and does not store sensitive information internally, relying instead on third-party providers.
The veracity of Play's claims remains unconfirmed. MyPillow denies a breach, while the ransomware group insists otherwise. The situation is expected to become clearer by Friday, the deadline set by Play for an undeclared payment. If the data is not released after this deadline, it could indicate that the attackers do not possess MyPillow data or were compensated to withhold it.
Experts caution that a company's assertion of not holding sensitive data on its own systems does not negate the risk of a breach. Modern businesses frequently share customer records, payroll, and financial details with various third-party vendors, including payment processors, fulfillment partners, HR and payroll services, and cloud hosting providers. These external systems can also be targeted by attackers, as a single compromise can yield data from multiple organizations.
From the perspective of individuals whose data might be at risk, such as customers or employees, the distinction between a breach occurring on a company's own servers or those of a contractor is largely irrelevant. If personal information like names, addresses, payment details, or tax information appears on a ransomware leak site, the source of the compromise has minimal practical impact on the affected individuals. Outsourcing data storage and processing does not shield a business from reputational damage or lessen the severity of consequences for those whose data is exposed.
The outcome of Play's threat will likely be revealed by Friday. Ransomware groups typically target organizations they believe may be willing to pay, underscoring the need for robust security defenses across all businesses.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed