Eurail says stolen traveler data now up for sale on dark web

0

Eurail says stolen traveler data now up for sale on dark web

Eurail B.V., the operator that provides access to 250,000 kilometers of European railways, confirmed that data stolen in a breach earlier this year is being offered for sale on the dark web.

The company said that a threat actor also published a sample of the data on the Telegram messaging platform but it is still trying to determine the type of records and number of customers affected.

Eurail B.V. is a Netherlands-based firm that manages and sells passes (Eurail and Interrail) for train travel across Europe, offering flexibility for multi-country trips.

Wiz

Its passes are also very popular among young European travelers participating in the EU’s DiscoverEU program.

Last month, the company disclosed that it suffered a data breach when threat actors gained unauthorized access to its customer database, compromising sensitive information, including full names, passport details, ID numbers, bank account IBANs, health information, and contact details (email addresses, phone numbers).

“We have become aware that the data has been offered for sale on the dark web and a sample data set has been published on Telegram.

“We are currently investigating which specific data records or how many of the affected customers this concerns,” reads Eurail’s update.

Eurail states that it continues the investigation to determine exactly what data was compromised for each affected customer, and will send individual notifications for those impacted.

Meanwhile, concerned data protection authorities have been notified in accordance with the GDPR requirements, and authorities outside the EU will be alerted soon.

Customers who may have had their information exposed in this incident should be vigilant to potential phishing and scam attempts.

Eurail suggests that customers update their Rail Planner app account passwords and reset them on any other platform where they use the same credentials.

Also, customers should monitor their bank account activity closely and report any suspicious transactions to their bank immediately.

A FAQ page has been published to support customers, and any concerns may also be addressed directly via email to privacyhelp@eurail.com.

Modern IT infrastructure moves faster than manual workflows can handle.

In this new Tines guide, learn how your team can reduce hidden manual delays, improve reliability through automated response, and build and scale intelligent workflows on top of tools you already use.



Source link

Supporters mourn Alexey Navalny two years after his death | Politics

0

NewsFeed

Two years after Alexey Navalny’s death in an Arctic penal colony, supporters gathered at his Moscow grave as five European countries said he was poisoned with dart frog toxin. Russia denies wrongdoing, saying he died of natural causes.



Source link

Zimbabwe roared… vowed to over Australia’s game, Alexander roared before the match

0

homegameCricket

Zimbabwe roared…Vow to over the game of AUS, Alexander roared before the match

Last Updated:

T20 World Cup 2026 Zimbabwe vs Ireland: The first upset of the T20 World Cup 2026 happened with Australia’s defeat at the hands of Zimbabwe. Now this reversal seems to be taking a heavy toll on the Kangaroos. Australia has lost for the second time in Group B. After Zimbabwe, it is in danger of being out of the tournament after its crushing defeat against Sri Lanka.

news immediately

Zimbabwe roared...Vow to over the game of AUS, Alexander roared before the matchZoom
zimbabwe cricket team

Pallekkala: Zimbabwe has a golden opportunity to reach the Super-8 of the T20 World Cup 2026. Zimbabwe surprised former champions Australia by 23 runs in Colombo on Friday. Now co-host Sri Lanka has made all the arrangements to oust the Kangaroos from the tournament by defeating them on Monday night. If Zimbabwe somehow beats Ireland today, they will reach the Super-8 and with this Australia will be out of the World Cup.

On the eve of the match against Ireland, Zimbabwe captain Sikandar Raza said that the upset win over Australia will mean nothing if his team misses the next match of the T20 World Cup. Raza said in the pre-match press conference:

We know that winning over Australia is just one part of our journey, but every next match is the most important. If we slip now then the previous victory will mean nothing. All the players are completely focused on the target. Yesterday was the travel day, after that we got rest and today we practiced well. For me, tomorrow’s match is another match. Perhaps this is the most important match.

After the match against Ireland, Zimbabwe will face hosts Sri Lanka in the last match of the group stage on 19 February. The team is in a good position in the points table with four points in the first two matches. Raza admitted that with the possibility of making it to the Super Eights, there would be a different kind of pressure in the upcoming matches. He said:

This is a good situation. After two wins, the world is talking about Zimbabwe, but we have to focus on our game. The beauty of ICC tournaments is that every match feels like a knockout. The real challenge is to manage our own expectations more than the expectations of the world.

Raza said that good performance in ICC competitions can change the lives of players. He said, ‘Performing well against the top teams in the world brings recognition, respect, financial benefits, it changes lives in every way. If we do well, it will be a historic achievement and we would like to keep writing our story further.

About the Author

Anshul Talmale

Anshul Talmale is captaining the sports desk of Network18 Group from February 2025, wearing the jersey of Deputy News Editor. His unbeaten innings continues for the last decade with a tremendous strike rate. With his all-round ability…read more

Senate Democrats meet with Ukrainian President Volodymyr Zelenskyy

0

NEWYou can now listen to Fox News articles!

Ukrainian President Volodymyr Zelenskyy said in a post on X that he met with U.S. senators Richard Blumenthal, D-Conn., and Sheldon Whitehouse, D-R.I.

“Thank you for seeing us,” Blumenthal can be heard saying in a video included in Zelenskyy’s post. “We look forward to hearing from you, ah, about how we can be more helpful.”

Zelenskyy indicated in the post that during the meeting he “thanked the United States for its strong bipartisan support and work for peace.”

UK, GERMAN DEFENSE OFFICIALS DEFEND MILITARY BUILDUP UNDER RUSSIAN THREATS

Ukrainian President Volodymyr Zelenskyy

Volodymyr Zelenskyy during the dinner on the occasion of the 62nd Munich Security Conference (MSC) and Ewald-von-Kleist Award at Königssaal der Bayerischen Residenz on Feb. 14, 2026 in Munich, Germany. (Gisela Schober/Getty Images)

President Donald Trump has been trying to help broker peace between Russia and Ukraine, but the two nations remain locked in conflict.

“Before our meeting, the senators met with children whom Ukraine managed to return from Russia. Thank you, this is truly important,” Zelenskyy noted in the post.

RUBIO MEETS WITH ZELENSKYY AHEAD OF CRUCIAL GENEVA TALKS, SAYS TRUMP WANTS SOLUTION THAT ‘ENDS BLOODSHED’

Sens. Sheldon Whitehouse and Richard Blumenthal

U.S Senators Sheldon Whitehouse (L) and Richard Blumenthal speak at a press conference following a meeting with Ukraine’s President Volodymyr Zelensky in Kyiv on Feb. 16, 2026, amid the Russian invasion of Ukraine. (HENRY NICHOLLS / AFP via Getty Images)

“We see no better tools to influence Moscow than pressure. There is an important sanctioning act in the Senate right now, and we expect it to work. I also informed them about the constant Russian strikes on our people and, in particular, on American businesses as well. It is absolutely fair that Russian money should be used to defend against this terror, and we discussed the prospects of utilizing immobilized Russian assets to purchase missiles for the Patriot systems,” he added.

“I thank the President, Congress, and the people of the United States for their support,” Zelenskyy noted.

UKRAINE STRIKES MAJOR RUSSIAN AMMO DEPOT WITH ‘FLAMINGO’ MISSILE AS TRUMP URGES ZELENSKYY TO MOVE ON DEAL

CLICK HERE TO GET THE FOX NEWS APP

Fox News Digital reached out to the senators’ offices on Monday.



Source link

Infostealer Steals OpenClaw AI Agent Configuration Files and Gateway Tokens

0

Ravie LakshmananFeb 16, 2026Artificial Intelligence / Threat Intelligence

Cybersecurity researchers disclosed they have detected a case of an information stealer infection successfully exfiltrating a victim’s OpenClaw (formerly Clawdbot and Moltbot) configuration environment.

“This finding marks a significant milestone in the evolution of infostealer behavior: the transition from stealing browser credentials to harvesting the ‘souls’ and identities of personal AI [artificial intelligence] agents,” Hudson Rock said.

Alon Gal, CTO of Hudson Rock, told The Hacker News that the stealer was likely a variant of Vidar based on the infection details. Vidar is an off-the-shelf information stealer that’s known to be active since late 2018.

That said, the cybersecurity company said the data capture was not facilitated by a custom OpenClaw module within the stealer malware, but rather through a “broad file-grabbing routine” that’s designed to look for certain file extensions and specific directory names containing sensitive data.

This included the following files –

  • openclaw.json, which contains details related to the OpenClaw gateway token, along with the victim’s redacted email address and workspace path.
  • device.json, which contains cryptographic keys for secure pairing and signing operations within the OpenClaw ecosystem.
  • soul.md, which contains details of the agent’s core operational principles, behavioral guidelines, and ethical boundaries.

It’s worth noting that the theft of the gateway authentication token can allow an attacker to connect to the victim’s local OpenClaw instance remotely if the port is exposed, or even masquerade as the client in authenticated requests to the AI gateway.

“While the malware may have been looking for standard ‘secrets,’ it inadvertently struck gold by capturing the entire operational context of the user’s AI assistant,” Hudson Rock added. “As AI agents like OpenClaw become more integrated into professional workflows, infostealer developers will likely release dedicated modules specifically designed to decrypt and parse these files, much like they do for Chrome or Telegram today.”

The disclosure comes as security issues with OpenClaw prompted the maintainers of the open-source agentic platform to announce a partnership with VirusTotal to scan for malicious skills uploaded to ClawHub, establish a threat model, and add the ability to audit for potential misconfigurations.

Last week, the OpenSourceMalware team detailed an ongoing ClawHub malicious skills campaign that uses a new technique to bypass VirusTotal scanning by hosting the malware on lookalike OpenClaw websites and using the skills purely as decoys, instead of embedding the payload directly in their SKILL.md files.

“The shift from embedded payloads to external malware hosting shows threat actors adapting to detection capabilities,” security researcher Paul McCarty said. “As AI skill registries grow, they become increasingly attractive targets for supply chain attacks.”

Another security problem highlighted by OX Security concerns Moltbook, a Reddit-like internet forum designed exclusively for artificial intelligence agents, mainly those running on OpenClaw. The research found that an AI Agent account, once created on Moltbook, cannot be deleted. This means that users who wish to delete the accounts and remove the associated data have no recourse.

What’s more, an analysis published by SecurityScorecard’s STRIKE Threat Intelligence team has also found hundreds of thousands of exposed OpenClaw instances, likely exposing users to remote code execution (RCE) risks.

Fake OpenClaw Website Serving Malware

“RCE vulnerabilities allow an attacker to send a malicious request to a service and execute arbitrary code on the underlying system,” the cybersecurity company said. “When OpenClaw runs with permissions to email, APIs, cloud services, or internal resources, an RCE vulnerability can become a pivot point. A bad actor does not need to break into multiple systems. They need one exposed service that already has authority to act.”

OpenClaw has had a viral surge in interest since it first debuted in November 2025. As of writing, the open-source project has more than 200,000 stars on GitHub. On February 15, 2026, OpenAI CEO Sam Altman said OpenClaw’s founder, Peter Steinberger, would be joining the AI company, adding, “OpenClaw will live in a foundation as an open source project that OpenAI will continue to support.”



Source link

What’s the fallout from Israel’s land grab? | Israel-Palestine conflict

0

Israel takes another step towards annexing the occupied West Bank.

Israel appears to be racing against time to tighten its grip on the occupied West Bank.

Last week, its security cabinet approved a move that makes it easier for settlers to buy land there, repealing decades-old laws and regulations.

This week, the Israeli government went a step further.

It has approved a proposal to reactivate land registration in the area for the first time since 1967.

The move paves the way for Israel to gain ownership of vast swaths of land Palestinians hoped would have been part of their future state.

What’s triggering this accelerated confiscation of Palestinian land?

And could it be a recipe for renewed violence?

Presenter: Rishaad Salamat

Guests:

Mohammad Dahleh – Human rights lawyer

Mitchell Barak – Founder of KEEVOON Research, Strategy and Communications

Simon Mabon – Professor of Middle Eastern and International Politics at Lancaster University



Source link

Paul Messer arrested for battery at Trump West Palm Beach golf course

0

NEWYou can now listen to Fox News articles!

Florida police arrested an agitator outside President Donald Trump‘s West Palm Beach golf course this weekend.

Police say the man, identified as Paul Messer, was engaging with anti-Trump protesters across from the golf club on Sunday when he got into a verbal dispute with another protester and struck her multiple times in the upper chest and neck with a metal flagpole, according to the Palm Beach County Sheriff’s Office.

The woman stumbled backward and had visible redness on the right side of her neck. Messer was taken into custody and transported to the Palm Beach County Jail on a battery charge.

The White House press pool following Trump witnessed the altercation, saying Messer was holding a pro-Trump flag during the incident.

ATTEMPTED TRUMP ASSASSIN TO LEARN SENTENCE, WITH PROSECUTORS SEEKING LIFE

President Donald Trump in Mar-a-Lago

U.S. President Donald Trump spent the weekend at his Mar-a-Lago resort this weekend. (REUTERS/Nathan Howard)

“As we continue to hold across from the golf club, a small group of protesters gathered by a barricade. Some had signs that read ‘F— ICE,’ while another couple displayed pro-Trump flags. A man with a Trump flag was then arrested by a sheriff’s deputy. A small group continues to stand by the barricade with their signs,” a pool report said.

The altercation came just weeks after Trump played golf with Florida Gov. Ron DeSantis at the Trump International Golf Club. Rounding out their foursome were college football coaching legends Urban Meyer and Nick Saban.

Trump golfing in Scotland

President Trump golfed at the Trump International Golf Course last weekend. (Brendan Smialowski/AFP/Getty Images)

SMILING ANTI-ICE AGITATOR ACCUSED OF PUNCHING FLORIDA TROOPER AS DESANTIS ASSERTS ‘THIS IS NOT MINNEAPOLIS’

Trump signaled warmer relations with the Florida governor last summer, and Florida has in turn increasingly aligned itself with key Trump administration priorities.

Split of Florida Gov. Ron DeSantis and President Trump, both wearing golf attire

Florida Gov. Ron DeSantis (l.) and President Trump played golf in late January, in what could be a sign of a thaw in their relationship.

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Among those priorities is the “Make America Healthy Again” initiative launched by Trump’s Department of Health and Human Services, which DeSantis has moved to embrace. As a result, DeSantis’ state kicked off its “Healthy Florida First” initiative in January, an effort across the state to test for contaminants in food products that DeSantis said is in lockstep with the administration’s priorities.



Source link

Barbican arts director to leave, months after revealing creative vision for centre | Barbican

0

Devyani Saltzman is leaving the Barbican, as the arts institution undergoes another significant leadership change just a few weeks after its new CEO joined.

The shock departure of Saltzman, who became director of arts and participation at the Barbican in February 2024, comes two years after her arrival and months after she unveiled a five-year creative vision for the venue.

Saltzman was named recently as one of the 40 most influential women working in the arts in the UK, and described as the “driving force behind the organisation”.

The Barbican refused to confirm the exit, with a spokesperson telling the Guardian it would be “unable to comment on individual staffing matters”.

It is unclear when she will leave the organisation and there are no plans to replace her.

Saltzman’s departure will leave a vacuum at the top of the Barbican. Her role involved curation of the artistic programme at the centre and community engagement, and in the last 18 months she had become its public face, laying out her vision in several interviews.

She was vocal about the need for London’s cultural institutions to have leadership reflecting the diverse city they inhabit. “We are actually in a new wave of next-generation leadership that hopefully is going to shift the model,” she said in 2024.

Saltzman’s exit is the latest departure at an organisation that has had several changes over the past five years.

In 2021, Sir Nicholas Kenyon resigned after 14 years as managing director after staff told the Guardian that the Barbican was “institutionally racist”. He was followed by the former BBC arts correspondent Will Gompertz, who left to join Sir John Soane’s Museum after being in the job for only two years.

Saltzman started as director of arts and participation in 2024, and was one of seven senior leaders installed after the Barbican replaced the managing director model. They all report to chief executive Abigail Pogson, who started in January 2026.

Saltzman joined during a row caused by the Barbican backing out of hosting a talk by Pankaj Mishra about the Holocaust and allegations that Israel was committing genocide in Gaza. The decision resulted in several artists pulling their work out of an exhibition at the venue.

One of her first acts was to speak to Mishra, and she has been seen as a figure who helped repair trust between the organisation and sections of the artistic community.

Pogson, who joined from the Glasshouse International Centre for Music in Gateshead, is overseeing the first major renewal work in the venue’s history, involving a 12-month closure of its theatre, music venue and galleries from June 2028. The first phase of the project will cost £231m, while the overall bill is estimated to be £451m.

Opened in 1982, the Barbican arts centre is a unique cultural institution. The centre’s cultural offering was originally designed primarily for the 4,000 residents of the flats set around the site.

Today, more than 1.5 million people visit annually, making it one of the most popular cultural attractions in the UK.



Source link

Father allegedly commented about needing to sacrifice baby before stabbing

0

NEWYou can now listen to Fox News articles!

A 44-year-old father was arrested last week after allegedly stabbing his 3-month-old baby in Pennsylvania.

“The City of Coatesville Police Department and Chester County District Attorney’s Office announce the arrest of Michael Phillips, 44, of Coatesville, who is charged with Attempted Homicide, Aggravated Assault, and other charges after he stabbed his 3-month-old child in the abdomen,” a Facebook post on the Chester County District Attorney Facebook page noted last week.

An affidavit by City of Coatesville Police Department Detective Corporal Kirt Guyer indicated that the child’s mother, Dominique Cialini, had said that the man, Michael Phillips, had spoken of needing to sacrifice the baby.

The mother said “she was in her bedroom with her 3-month-old and the Defendant was staring at her blankly and making comments about having to sacrifice the baby,” according to the affidavit

CALIFORNIA MOM CONVICTED AFTER SON DIES IN HOT CAR WHILE MOTHER GOT LIP FILLERS: ‘DEFENDANT CHOSE HER LOOKS’

A father who allegedly stabbed his son is apprehended.

A Pennsylvania father is in custody after allegedly stabbing his infant baby. (WTXF)

“She said the Defendant then came at her and started stabbing the baby. She said he tried stabbing the baby several times, but only stabbed him once. She then ran out of the house with the baby and her 9-year-old son. She told the 9-year-old to run and get someone to call 911. The Defendant followed her out of the house and ripped the baby out of her arms. She said she thought he was going to kill the baby when he grabbed him. He eventually threw the baby in the snow. She said she laid on top of the baby in the snow and she saw his guts. She thought her baby was dead,” the affidavit noted.

The affidavit reported that the baby suffered “at least one deep stab wound in the abdomen,” and the mother suffered “lacerations to fingers on her right hand.”

NEW MEXICO MOTHER ACCUSED OF DROWNING NEWBORN IN PORTABLE TOILET AFTER GIVING BIRTH

Police arrest father accused of stabbing his baby.

Michael Phillips was arrested after allegedly stabbing his baby. (WTXF)

She told authorities that she believed Phillips “was having a psychotic episode, but was also known to abuse drugs,” the affidavit noted. 

The woman “said she saw the Defendant holding the babies feet with a knife in his hand and that is when she picked up the baby. Then the Defendant started stabbing the baby.”

Phillips said “this was all part of God’s plan” and “I did it God, I did it,” according to the affidavit.

The Coatsville Police Department indicated last week that the baby was “in the ICU at the Children’s Hospital of Philadelphia and is listed in critical but stable condition.” The child’s current condition was unclear as of Monday.

PUERTO RICO GOVERNOR SIGNS LAW RECOGNIZING UNBORN BABIES AS HUMAN BEINGS

An ambulance parked near where a child was stabbed.

A 44-year-old father allegedly stabbed his infant child in Pennsylvania. (WTXF)

CLICK HERE TO GET THE FOX NEWS APP

Fox News Digital reached out to the district attorney’s office and to the police department on Monday to request an update on the situation.



Source link

Password managers don’t protect secrets if pwned • The Register

0

Academics say they found a series of flaws affecting three popular password managers, all of which claim to protect user credentials in the event that their servers are compromised.

The team, comprised of researchers from ETH Zurich and Università della Svizzera italiana (USI), examined the “zero-knowledge encryption” promises made by Bitwarden, LastPass, and Dashlane, finding all three could expose passwords if attackers compromised servers.

The premise of zero-knowledge encryption is that user passwords are encrypted on their device, and the password manager’s server acts merely as a dumb storage box for the encrypted credentials. Therefore, in the event that the vendor’s servers are controlled by malicious parties, attackers wouldn’t be able to view users’ secrets.

As one of the most popular alternatives to Apple and Google’s own password managers, which together dominate the market, the researchers found Bitwarden was most susceptible to attacks, with 12 working against the open-source product. Seven distinct attacks worked against LastPass, and six succeeded in Dashlane.

The attacks don’t exploit weaknesses in the same way that remote attackers could exploit vulnerabilities and target specific users. Instead, the researchers worked to test each platform’s ability to keep secrets safe in the event they were compromised.

In most cases where attacks were successful, the researchers said they could retrieve encrypted passwords from the user, and in some cases, change the entries.

They used a malicious server model to test all of this – setting up servers that behaved like hacked versions of those used by the password managers. Seven of Bitwarden’s 12 successful attacks led to password disclosure, whereas only three of LastPass’s attacks led to the same end, and one for Dashlane.

All three vendors claim their products come with zero-knowledge encryption. The researchers noted that none of them outline the specific threat model their password manager secures against.

The researchers said: “The majority of our attacks require simple interactions which users or their clients perform routinely as part of their usage of the product, such as logging in to their account, opening the vault and viewing the items, or performing periodic synchronization of data. 

“We also present attacks that require more complex user actions, such as key rotations, joining an organization, sharing credentials, or even clicking on a misleading dialog. Although assessing the probability of these actions is challenging, we believe that, within a vast user base, many users will likely perform them.”

In the full paper [PDF], they went on to argue that password managers have escaped deep academic scrutiny until now, unlike end-to-end encrypted messaging apps. It is perhaps due to a perception that password managers are simple applications – deriving keys and then encrypting them. However, their codebases are more complex than that, often offering features such as the ability to share accounts with family members and featuring various ways to maintain backward-compatibility with older encryption standards.

Kenneth Paterson, professor of computer science at ETH Zurich, said “we were surprised by the severity of the security vulnerabilities” affecting the password managers.

“Since end-to-end encryption is still relatively new in commercial services, it seems that no one had ever examined it in detail before.” 

The team’s primary recommendation for vendors is to ensure that new users have access to the latest cryptographic standards by default.

One of the main reasons password manager providers haven’t upgraded their codebases is that they fear doing so would irrevocably lose existing users’ secrets. The researchers said that some vendors have gone to extreme lengths to support older formats, which in turn creates complexity in the code.

The best way forward? The researchers suggested ensuring all new users are onboarded with the latest cryptographic standards, while offering existing customers the choice between migrating to them or staying put, but with the knowledge of the vulnerabilities.

“We want our work to help bring about change in this industry,” said Paterson. He claimed: “The providers of password managers should not make false promises to their customers about security but instead communicate more clearly and precisely what security guarantees their solutions actually offer.”  

Vendor response

Dashlane published a comprehensive response, thanking the researchers, and said the infoseccers’ decision to test using a malicious server model represented “a useful exercise.”

The vendor also confirmed it had fixed the most serious issue – the attack researchers showed could lead to the disclosure of a password, and published a separate security advisory devoted to that.

“Dashlane has fixed an issue that, if Dashlane’s servers were fully compromised, could have allowed a downgrade of the encryption model used to generate encryption keys and protect user vaults,” it said. “This downgrade could result in the compromise of a weak or easily guessable Master Password, and the compromise of individual ‘downgraded’ vault items.

“This issue was the result of the allowed use of legacy cryptography. This legacy cryptography was supported by Dashlane in certain cases for backward compatibility and migration flexibility.

“Dashlane has removed support for this legacy cryptography, which means these downgrade attacks are no longer possible.”

Bitwarden, meanwhile, said in a post: “Bitwarden has never been breached and believes third-party security assessments like these are critical to continue providing state of the art security to individuals and organizations.”

It added: “Thank you ETH Zurich for your insights and commitment to stronger password security.”

A LastPass spokesperson told The Reg: “Our Security team is grateful for the opportunity to engage with ETH Zurich and benefit from their research. While our own assessment of these risks may not fully align with the severity ratings assigned by the ETH Zurich team, we take all reported security findings seriously. We have already implemented multiple near‑term hardening measures while also establishing plans to remediate or reinforce the relevant components of our service on a timeline commensurate with the assessed risk.”

The researchers said the vendors responded constructively to their outreach attempts and were working to mitigate the exploited weaknesses. 

The researchers said it is highly likely that the same weaknesses they highlighted in the study apply to other vendors across the industry, and couldn’t rule out the possibility the attacks are already known to the more advanced hackers, including those with government backing. ®



Source link