Category: Hacker News

Cisco Confirms Active Exploitation of Two Catalyst SD-WAN Manager Vulnerabilities
Preparing for the Quantum Era: Post-Quantum Cryptography Webinar for Security Leaders
ThreatsDay Bulletin: DDR5 Bot Scalping, Samsung TV Tracking, Reddit Privacy Fine & More
Where Multi-Factor Authentication Stops and Credential Abuse Starts
Dust Specter Targets Iraqi Officials with New SPLITDROP and GHOSTFORM Malware
APT28-Linked Campaign Deploys BadPaw Loader and MeowMeow Backdoor in Ukraine
FBI and Europol Seize LeakBase Forum Used to Trade Stolen Credentials
Europol-Led Operation Takes Down Tycoon 2FA Phishing-as-a-Service Linked to 64,000 Attacks
149 Hacktivist DDoS Attacks Hit 110 Organizations in 16 Countries After Middle East Conflict
Coruna iOS Exploit Kit Uses 23 Exploits Across Five Chains Targeting iOS 13–17.2.1
New RFP Template for AI Usage Control and AI Governance 
APT41-Linked Silver Dragon Targets Governments Using Cobalt Strike and Google Drive C2
Fake Laravel Packages on Packagist Deploy RAT on Windows, macOS, and Linux
CISA Adds Actively Exploited VMware Aria Operations Flaw CVE-2026-22719 to KEV Catalog
Fake Tech Support Spam Deploys Customized Havoc C2 Across Organizations
Building a High-Impact Tier 1: The 3 Steps CISOs Must Follow
Open-Source CyberStrikeAI Deployed in AI-Driven FortiGate Attacks Across 55 Countries
AI Agents: The Next Wave Identity Dark Matter – Powerful, Invisible, and Unmanaged
Starkiller Phishing Suite Uses AitM Reverse Proxy to Bypass Multi-Factor Authentication
Microsoft Warns OAuth Redirect Abuse Delivers Malware to Government Targets
SloppyLemming Targets Pakistan and Bangladesh Governments Using Dual Malware Chains
Google Confirms CVE-2026-21385 in Qualcomm Android Component Exploited
Google Develops Merkle Tree Certificates to Enable Quantum-Resistant HTTPS in Chrome
New Chrome Vulnerability Let Malicious Extensions Escalate Privileges via Gemini Panel
⚡ Weekly Recap: SD-WAN 0-Day, Critical CVEs, Telegram Probe, Smart TV Proxy SDK and More
How to Protect Your SaaS from Bot Attacks with SafeLine WAF
APT28 Tied to CVE-2026-21513 MSHTML 0-Day Exploited Before Feb 2026 Patch Tuesday
North Korean Hackers Publish 26 npm Packages Hiding Pastebin C2 for Cross-Platform RAT
ClawJacked Flaw Lets Malicious Sites Hijack Local OpenClaw AI Agents via WebSocket
Thousands of Public Google Cloud API Keys Exposed with Gemini Access After API Enablement
Pentagon Designates Anthropic Supply Chain Risk Over AI Military Dispute
DoJ Seizes $61 Million in Tether Linked to Pig Butchering Crypto Scams
900+ Sangoma FreePBX Instances Compromised in Ongoing Web Shell Attacks
Malicious Go Crypto Module Steals Passwords, Deploys Rekoobe Backdoor
ScarCruft Uses Zoho WorkDrive and USB Malware to Breach Air-Gapped Networks
Trojanized Gaming Tools Spread Java-Based RAT via Browser and Chat Platforms
Meta Files Lawsuits Against Brazil, China, Vietnam Advertisers Over Celeb-Bait Scams
Aeternum C2 Botnet Stores Encrypted Commands on Polygon Blockchain to Evade Takedown
ThreatsDay Bulletin: Kali Linux + Claude, Chrome Crash Traps, WinRAR Flaws, LockBit & 15+ Stories
UAT-10027 Targets U.S. Education and Healthcare with Dohdoor Backdoor
Expert Recommends: Prepare for PQC Right Now
Expert Recommends: Prepare for PQC Right Now
Malicious StripeApi NuGet Package Mimicked Official Library and Stole API Tokens
Microsoft Warns Developers of Fake Next.js Job Repos Delivering In-Memory Malware
Cisco SD-WAN Zero-Day CVE-2026-20127 Exploited Since 2023 for Admin Access
Google Disrupts UNC2814 GRIDTIDE Campaign After 53 Breaches Across 42 Countries
Claude Code Flaws Allow Remote Code Execution and API Key Exfiltration
SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks
Top 5 Ways Broken Triage Increases Business Risk Instead of Reducing It
Malicious NuGet Packages Stole ASP.NET Data; npm Package Dropped Malware