Category: Hacker News

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
Mythos Didn’t Break Your Security Program. Your Exposure Window Could.
Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine
Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs
New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
World’s Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images
Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man
E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants
The Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace?
ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files
New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage
CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack
n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer
ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories
New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands
Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor
New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password
20+ Hijacked Government Websites Became
an Attack Channel
New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands
OpenAI’s GPT-Red Automates Prompt Injection Testing to Harden GPT-5.6 Sol
Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide
AI Can Find Bugs, But Human Knowledge Still Proves Them
Zoom Patches Critical Windows Flaw That Could Enable Account Takeover
TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development
OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps
Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws
New Webinar: Closing the Approval Gap in AI-Era Ad Tech
SASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough.
Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday
Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution
Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware
Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands
SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data
Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads
Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack
LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts
RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials