VPNCentral
Online/Digital
Started in 2020, VPNCentral.com was built by a team of VPN experts and privacy advocates who strive every day to keep readers informed on all VPN-related matters. The mission of the website was to be the top source for unbiased purchase information and to help readers make an informed decision when it comes to their privacy.
Considering the amount of buzz in this market, VPNCentral.com is still a small player but one that catches more and more traction each day. Check out the dedicated About page for more info. Source
Actions
Media Outlet details
| Scope | International |
|---|---|
| Language | English |
| Country | Romania |
|
Similarweb UVM |
Request pricing |
|
Comscore UVM |
Request pricing |
Recent Articles
Search ArticlesScattered Spider Hackers Jailed for TfL Cyberattack That Disabled 148 Systems
Two Scattered Spider hackers have each been sentenced to five years and six months in prison for the 2024 cyberattack on Transport for London. The breach disabled 148 systems, forced 27,000 employees to reset their passwords in person and caused about £29 million in losses and recovery costs. Thalha Jubair, from East London, and Owen Flowers, from Walsall, received their sentences at Woolwich Crown Court on July 16, 2026.
7-Zip CVE-2026-14266 Heap Overflow Can Enable Code Execution
A security vulnerability in 7-Zip can allow attackers to execute code after a user opens a malicious file or visits a page containing specially crafted XZ data. The flaw is tracked as CVE-2026-14266 and has been fixed in 7-Zip 26.02. The vulnerability affects 7-Zip’s processing of chunked XZ-compressed data. Malformed input can overflow a heap buffer, corrupting memory inside the 7-Zip process and potentially giving an attacker control of its execution.
TP-Link Kasa Camera Flaws Expose Credentials and Enable Local MitM Attacks
TP-Link has released security updates for two information-disclosure vulnerabilities affecting Kasa EC70 v4 and EC71 v4 cameras. The more serious flaw can enable passive traffic decryption or active man-in-the-middle attacks against the cameras’ web management communications. The vulnerabilities are tracked as CVE-2026-9770 and CVE-2026-13230. Both require the attacker to reach the same local network as the vulnerable camera, and neither requires authentication or user interaction.
Codex Users Report Serious File Deletions, but GPT-5.6 Root Cause Remains Unconfirmed
Users have reported incidents in which coding agents allegedly deleted files outside their intended project directories, including documents and parts of Windows user profiles. One recent report involved GPT-5.6 Sol, the flagship model available through OpenAI Codex. The available evidence does not establish that GPT-5.6 itself caused the deletion.
CISA Warns Attackers Are Exploiting Critical FortiSandbox Command Injection Flaws
CISA has warned that attackers are actively exploiting two critical Fortinet FortiSandbox vulnerabilities that allow remote command execution without authentication. The flaws, tracked as CVE-2026-39808 and CVE-2026-25089, can let an attacker send malicious HTTP requests that cause a vulnerable FortiSandbox system to run unauthorized operating-system commands. BEST SPRING 2026 DEALS CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog on July 16, 2026.
CISA Warns Attackers Are Exploiting Critical SharePoint RCE Vulnerability CVE-2026-58644
The U.S. Cybersecurity and Infrastructure Security Agency has warned that attackers are exploiting a critical Microsoft SharePoint Server vulnerability tracked as CVE-2026-58644. The flaw allows an unauthenticated attacker to execute code remotely over a network. Microsoft assigned it a CVSS score of 9.8 out of 10 and released security updates on July 14, 2026. BEST SPRING 2026 DEALS CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on July 16.
OpenSSL HollowByte Flaw Lets Attackers Drain Server Memory With an 11-Byte Request
A denial-of-service vulnerability called HollowByte can allow an unauthenticated attacker to consume substantial server memory by sending an incomplete TLS request containing as little as 11 bytes. The Okta Red Team, which discovered the issue, found that affected OpenSSL versions allocate memory based on a size declared by the attacker before receiving the complete TLS handshake message.
EY Data Breach Exposes Client Tax Documents Through Third-Party Support Platform
Ernst & Young LLP has disclosed a data breach in which an unauthorized third party accessed an external IT service management platform and downloaded documents connected to the firm’s tax-related client work. The attacker accessed the platform between March 28 and April 12, 2026. EY detected unusual activity on April 23 and began investigating with help from an independent cybersecurity company. BEST SPRING 2026 DEALS EY reported the incident to the California Attorney General on July 15.
AWS Cost Explorer Bug Shows Trillion-Dollar Estimates, but Actual Charges Remain Unaffected
An Amazon Web Services billing error caused some customers to see cost estimates reaching billions or trillions of dollars. AWS says these figures were inaccurate and did not represent actual cloud usage or charges. The global incident affected estimated data in the AWS Billing and Cost Management Console, Cost Explorer, and some Cost and Usage Reports. AWS traced the problem to incorrect unit pricing inside its estimated billing computation system.
Fairlife Ransomware Attack Suspends Production Across the United States
Fairlife has temporarily suspended its production operations across the United States after a ransomware attack gave an unauthorized third party access to part of the dairy company’s computer systems. The Coca-Cola Company, which owns Fairlife, disclosed the incident on July 16, 2026. Its Form 8-K filing says the accessed environment included systems related to production. BEST SPRING 2026 DEALS Coca-Cola says the attack has not affected product quality or safety.