Category: Hacker News

DoJ Disrupts Southeast Asia Crypto Fraud Networks, Freezes $3.8 Million in Assets
Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag
Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479)
WhatsApp, Slack Notifications Could Hijack Google Gemini on Android
Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT
Beyond the Zero-Day: See Your Network Like an Attacker | Webinar with HD Moore
One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens
Shrinking the IAM Attack Surface through Identity Visibility and Intelligence Platforms (IVIP)
Unpatched Windows Search URI Vulnerability Lets Attackers Steal NTLMv2 Hashes
New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare
Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content
Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited
Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation
Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine
How Leading Organizations Are Turning EDR Into Operational Resilience
AI-Driven Exploitation is Destroying Vulnerability Management. Here’s How to Handle It.
Pakistan-Linked SideCopy Targets Afghanistan Finance Ministry with Xeno RAT
Dashlane Discloses Brute-Force Attack, Encrypted Vaults of Fewer Than 20 Users Downloaded
Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm
⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More
China-Aligned Groups Ramp Up Attacks: Dragon Weave Hits Czech Republic & Taiwan
OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack
The Security Growth Platform: Why MSPs Are Moving Beyond vCISO Tools
Critical WP Maps Pro Flaw Actively Exploited to Create Admin Accounts
Dutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices
PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation
ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface
Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit
What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks
New Russian-Linked GREYVIBE Targets Ukraine with AI-Powered Cyberattacks
Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets
Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels
Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer
Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code
New AI Usage Report: Enterprise AI Risk Is Heavily Concentrated Among a Small Group of AI “Power users”
Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal
ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More
JINX-0164 Targets Cryptocurrency Firms with Fake Recruiter Lures and macOS Malware
Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users
Malicious npm Package Stole Files From Claude AI User Directory via GitHub
3 SOC Steps that Shut Down Incident Risks Early
Gitea Vulnerability Exposes Private Container Images without Authentication
GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure
5 Steps to Managing Shadow AI Tools Without Slowing Down Employees
AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites
MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries
MFA Prompt Bombing: Why Your Second Factor Isn’t Saving You
New AI DDoS Attacks Are Smarter. Learn How to Fight Back in This Webinar
Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions
CERT-In Mandates 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks