Category: Hacker News

$13.74M Hack Shuts Down Sanctioned Grinex Exchange After Intelligence Claims
Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDoS Botnet
Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched
Google Blocks 8.3B Policy-Violating Ads in 2025, Launches Android 17 Privacy Overhaul
NIST Limits CVE Enrichment After 263% Surge in Vulnerability Submissions
Operation PowerOFF Seizes 53 DDoS Domains, Exposes 3 Million Criminal Accounts
Apache ActiveMQ CVE-2026-34197 Added to CISA KEV Amid Active Exploitation
Newly Discovered PowMix Botnet Hits Czech Workers Using Randomized C2 Traffic
ThreatsDay Bulletin: Defender 0-Day, SonicWall Brute-Force, 17-Year-Old Excel RCE and 15 More Stories
Hidden Passenger? How Taboola Routes Logged-In Banking Sessions to Temu
Obsidian Plugin Abuse Delivers PHANTOMPULSE RAT in Targeted Finance, Crypto Attacks
Cisco Patches Four Critical Identity Services, Webex Flaws Enabling Code Execution
[Webinar] Find and Eliminate Orphaned Non-Human Identities in Your Environment
UAC-0247 Targets Ukrainian Clinics and Government in Data-Theft Malware Campaign
n8n Webhooks Abused Since October 2025 to Deliver Malware via Phishing Emails
April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and More
Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables Full Nginx Server Takeover
Deterministic + Agentic AI: The Architecture Exposure Validation Requires
Microsoft Issues Patches for SharePoint Zero-Day and 168 Other New Vulnerabilities
OpenAI Launches GPT-5.4-Cyber with Expanded Access for Security Teams
New PHP Composer Flaws Enable Arbitrary Command Execution — Patches Released
AI-Driven Pushpaganda Scam Exploits Google Discover to Spread Scareware and Ad Fraud
Google Adds Rust-Based DNS Parser into Pixel 10 Modem to Enhance Security
Mirax Android RAT Turns Devices into SOCKS5 Proxies, Reaching 220,000 via Meta Ads
108 Malicious Chrome Extensions Steal Google and Telegram Data, Affecting 20,000 Users
Analysis of 216M Security Findings Shows a 4x Increase In Critical Risk (2026 Report)
CISA Adds 6 Known Exploited Flaws in Fortinet, Microsoft, and Adobe Software
ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers
JanelaRAT Malware Targets Latin American Banks with 14,739 Attacks in Brazil in 2025
FBI and Indonesian Police Dismantle W3LL Phishing Network Behind $20M Fraud Attempts
⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and More
Your MTTD Looks Great. Your Post-Alert Gap Doesn’t
North Korea’s APT37 Uses Facebook Social Engineering to Deliver RokRAT Malware
OpenAI Revokes macOS App Certificate After Malicious Axios Supply Chain Incident
Adobe Patches Actively Exploited Acrobat Reader Flaw CVE-2026-34621
CPUID Breach Distributes STX RAT via Trojanized CPU-Z and HWMonitor Downloads
Citizen Lab: Law Enforcement Used Webloc to Track 500 Million Devices via Ad Data
GlassWorm Campaign Uses Zig Dropper to Infect Multiple Developer IDEs
Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of Disclosure
Browser Extensions Are the New AI Consumption Channel That No One Is Talking About
Google Rolls Out DBSC in Chrome 146 to Block Session Theft on Windows
Backdoored Smart Slider 3 Pro Update Distributed via Compromised Nextend Servers
EngageLab SDK Flaw Exposed 50M Android Users, Including 30M Crypto Wallets
UAT-10362 Targets Taiwanese NGOs with LucidRook Malware in Spear-Phishing Campaigns
ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache RCE and 18 More Stories
Bitter-Linked Hack-for-Hire Campaign Targets Journalists Across MENA Region
Adobe Reader Zero-Day Exploited via Malicious PDFs Since December 2025
The Hidden Security Risks of Shadow AI in Enterprises
Masjesu Botnet Emerges as DDoS-for-Hire Service Targeting Global IoT Devices
New Chaos Variant Targets Misconfigured Cloud Deployments, Adds SOCKS Proxy