Category: Hacker News

Microsoft Issues Security Fixes for 56 Flaws, Including Active Exploit and Two Zero-Days
Fortinet, Ivanti, and SAP Issue Urgent Patches for Authentication and Code Execution Flaws
North Korea-linked Actors Exploit React2Shell to Deploy New EtherRAT Malware
Four Threat Clusters Using CastleLoader as GrayBravo Expands Its Malware Service Infrastructure
Storm-0249 Escalates Ransomware Attacks with ClickFix, Fileless PowerShell, and DLL Sideloading
Google Adds Layered Defenses to Chrome to Block Indirect Prompt Injection Threats
How to Streamline Zero Trust Using the Shared Signals Framework
STAC6565 Targets Canada in 80% of Attacks as Gold Blade Deploys QWCrypt Ransomware
Researchers Find Malicious VS Code, Go, npm, and Rust Packages Stealing Developer Data
Experts Confirm JS#SMUGGLER Uses Compromised Sites to Deploy NetSupport RAT
⚡ Weekly Recap: USB Malware, React2Shell, WhatsApp Worms, AI IDE Bugs & More
How Can Retailers Cyber-Prepare for the Most Vulnerable Time of the Year?
Android Malware FvncBot, SeedSnatcher, and ClayRat Gain Stronger Data Theft Features
Sneeit WordPress RCE Exploited in the Wild While ICTBroadcast Bug Fuels Frost Botnet Attacks
MuddyWater Deploys UDPGangster Backdoor in Targeted Turkey-Israel-Azerbaijan Campaign
Researchers Uncover 30+ Flaws in AI Coding Tools Enabling Data Theft and RCE Attacks
Critical React2Shell Flaw Added to CISA KEV After Confirmed Active Exploitation
Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
“Getting to Yes”: An Anti-Sales Guide for MSPs
Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
5 Threats That Reshaped Web Security This Year [2025]
GoldFactory Hits Southeast Asia with Modified Banking Apps Driving 11,000+ Infections
Record 29.7 Tbps DDoS Attack Linked to AISURU Botnet with up to 4 Million Infected Hosts
Critical RSC Bugs in React and Next.js Allow Unauthenticated Remote Code Execution
Brazil Hit by Banking Trojan Spread via WhatsApp Worm and RelayNFC NFC Relay Fraud
WordPress King Addons Flaw Under Active Attack Lets Hackers Make Admin Accounts
Microsoft Silently Patches Windows LNK Flaw After Years of Active Exploitation
Discover the AI Tools Fueling the Next Cybercrime Wave — Watch the Webinar
Malicious Rust Crate Delivers OS-Specific Malware to Web3 Developer Systems
Chopping AI Down to Size: Turning Disruptive Technology into a Strategic Advantage
Picklescan Bugs Allow Malicious PyTorch Models to Evade Scans and Execute Code
India Orders Messaging Apps to Work Only With Active SIM Cards to Prevent Fraud and Misuse
Researchers Capture Lazarus APT’s Remote-Worker Scheme Live on Camera
GlassWorm Returns with 24 Malicious Extensions Impersonating Popular Developer Tools
Malicious npm Package Uses Hidden Prompt and Script to Evade AI Security Tools
Iran-Linked Hackers Hits Israeli Sectors with New MuddyViper Backdoor in Targeted Attacks
SecAlerts Cuts Through the Noise with a Smarter, Faster Way to Track Vulnerabilities
Google Patches 107 Android Flaws, Including Two Framework Bugs Exploited in the Wild
India Orders Phone Makers to Pre-Install Sanchar Saathi App to Tackle Telecom Fraud
ShadyPanda Turns Popular Browser Extensions with 4.3 Million Installs Into Spyware
⚡ Weekly Recap: Hot CVEs, npm Worm Returns, Firefox RCE, M365 Email Raid & More
Webinar: The “Agentic” Trojan Horse: Why the New AI Browsers War is a Nightmare for Security Teams
New Albiriox MaaS Malware Targets 400+ Apps for On-Device Fraud and Screen Control
Tomiris Shifts to Public-Service Implants for Stealthier C2 in Attacks on Government Targets