Category: Hacker News

Black Basta Ransomware Leader Added to EU Most Wanted and INTERPOL Red Notice
OpenAI to Show Ads in ChatGPT for Logged-In U.S. Adults on Free and Go Plans
GootLoader Malware Uses 500–1,000 Concatenated ZIP Archives to Evade Detection
Five Malicious Chrome Extensions Impersonate Workday and NetSuite to Hijack Accounts
Your Digital Footprint Can Lead Right to Your Front Door
LOTUSLITE Backdoor Targets U.S. Policy Entities Using Venezuela-Themed Spear Phishing
China-Linked APT Exploits Sitecore Zero-Day in Attacks on American Critical Infrastructure
Cisco Patches Zero-Day RCE Exploited by China-Linked APT in Secure Email Gateways
AWS CodeBuild Misconfiguration Exposed GitHub Repos to Potential Supply Chain Attacks
Researchers Reveal Reprompt Attack Allowing Single-Click Data Exfiltration From Microsoft Copilot
Critical WordPress Modular DS Plugin Flaw Actively Exploited to Gain Admin Access
ThreatsDay Bulletin: AI Voice Cloning Exploit, Wi-Fi Kill Switch, PLC Vulns, and 14 More Stories
Model Security Is the Wrong Frame – The Real Risk Is Workflow Security
4 Outdated Habits Destroying Your SOC’s MTTR in 2026
Palo Alto Fixes GlobalProtect DoS Flaw That Can Crash Firewalls Without Login
Microsoft Legal Action Disrupts RedVDS Cybercrime Infrastructure Used for Online Fraud
Researchers Null-Route Over 550 Kimwolf and Aisuru Botnet Command Servers
AI Agents Are Becoming Privilege Escalation Paths
Hackers Exploit c-ares DLL Side-Loading to Bypass Security and Deploy Malware
Fortinet Fixes Critical FortiSIEM Flaw Allowing Unauthenticated Remote Code Execution
Microsoft Fixes 114 Windows Flaws in January 2026 Patch, One Actively Exploited
New Research: 64% of 3rd-Party Applications Access Sensitive Data Without Justification
Critical Node.js Vulnerability Can Cause Server Crashes via async_hooks Stack Overflow
PLUGGYAPE Malware Uses Signal and WhatsApp to Target Ukrainian Defense Forces
Long-Running Web Skimming Campaign Steals Credit Cards From Online Checkout Pages
Malicious Chrome Extension Steals MEXC API Keys by Masquerading as Trading Tool
[Webinar] Securing Agentic AI: From MCPs and Tool Access to Shadow API Key Sprawl
What Should We Learn From How Attackers Leveraged AI in 2025?
ServiceNow Patches Critical AI Platform Flaw Allowing Unauthenticated User Impersonation
New Advanced Linux VoidLink Malware Targets Cloud and container Environments
New Malware Campaign Delivers Remcos RAT Through Multi-Stage Windows Attack
CISA Warns of Active Exploitation of Gogs Vulnerability Enabling Code Execution
n8n Supply Chain Attack Abuses Community Nodes to Steal OAuth Tokens
⚡ Weekly Recap: AI Automation Exploits, Telecom Espionage, Prompt Poaching & More
GoBruteforcer Botnet Targets Crypto Project Databases by Exploiting Weak Credentials
Anthropic Launches Claude AI for Healthcare with Secure Health Record Access
Researchers Uncover Service Providers Fueling Industrial-Scale Pig Butchering Fraud
MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors
Europol Arrests 34 Black Axe Members in Spain Over €5.9M Fraud and Organized Crime
China-Linked Hackers Exploit VMware ESXi Zero-Days to Escape Virtual Machines
Russian APT28 Runs Credential-Stealing Campaign Targeting Energy and Policy Organizations
Cybersecurity Predictions 2026: The Hype We Can Ignore (And the Risks We Can’t)
Trend Micro Apex Central RCE Flaw Scores 9.8 CVSS in On-Prem Windows Versions
CISA Retires 10 Emergency Cybersecurity Directives Issued Between 2019 and 2024
FBI Warns North Korean Hackers Using Malicious QR Codes in Spear-Phishing
WhatsApp Worm Spreads Astaroth Banking Trojan Across Brazil via Contact Auto-Messaging
China-Linked UAT-7290 Targets Telecoms with Linux Malware and ORB Nodes
ThreatsDay Bulletin: RustFS Flaw, Iranian Ops, WebUI RCE, Cloud Leaks, and 12 More Stories
Cisco Patches ISE Security Vulnerability After Public PoC Exploit Release
Researchers Uncover NodeCordRAT Hidden in npm Bitcoin-Themed Packages