Category: Hacker News

Who Approved This Agent? Rethinking Access, Accountability, and Risk in the Age of AI Agents
CISA Adds Actively Exploited VMware vCenter Flaw CVE-2024-37079 to KEV Catalog
New DynoWiper Malware Used in Attempted Sandworm Attack on Polish Power Sector
CISA Updates KEV Catalog with Four Actively Exploited Software Vulnerabilities
Phishing Attack Uses Stolen Credentials to Install LogMeIn RMM for Persistent Access
Fortinet Confirms Active FortiCloud SSO Bypass on Fully Patched FortiGate Firewalls
TikTok Forms U.S. Joint Venture to Continue Operations Under 2025 Executive Order
Microsoft Flags Multi-Stage AitM Phishing and BEC Attacks Targeting Energy Firms
New Osiris Ransomware Emerges as New Strain Using POORTRY Driver in BYOVD Attack
Critical GNU InetUtils telnetd Flaw Lets Attackers Bypass Login and Gain Root Access
ThreatsDay Bulletin: Pixel Zero-Click, Redis RCE, China C2s, RAT Ads, Crypto Scams & 15+ Stories
SmarterMail Auth Bypass Exploited in the Wild Two Days After Patch Release
Filling the Most Common Gaps in Google Workspace Security
Malicious PyPI Package Impersonates SymPy, Deploys XMRig Miner on Linux Hosts
Automated FortiGate Attacks Exploit FortiCloud SSO to Alter Firewall Configurations
Cisco Fixes Actively Exploited Zero-Day CVE-2026-20045 in Unified CM and Webex
North Korean PurpleBravo Campaign Targeted 3,136 IP Addresses via Fake Job Interviews
Zoom and GitLab Release Security Updates Fixing RCE, DoS, and 2FA Bypass Flaws
Webinar: How Smart MSSPs Using AI to Boost Margins with Half the Staff
Exposure Assessment Platforms Signal a Shift in Focus
Chainlit AI Framework Flaws Enable Data Theft via File Read and SSRF Bugs
VoidLink Linux Malware Framework Built with AI Assistance Reaches 88,000 Lines of Code
LastPass Warns of Fake Maintenance Messages Targeting Users’ Master Passwords
CERT/CC Warns binary-parser Bug Allows Node.js Privilege-Level Code Execution
North Korea-Linked Hackers Target Developers via Malicious VS Code Projects
Hackers Use LinkedIn Messages to Spread RAT Malware Through DLL Sideloading
Three Flaws in Anthropic MCP Git Server Enable File Access and Code Execution
The Hidden Risk of Orphan Accounts
Evelyn Stealer Malware Abuses VS Code Extensions to Steal Developer Credentials and Crypto
Why Secrets in JavaScript Bundles are Still Being Missed
Cloudflare Fixes ACME Validation Bug Allowing WAF Bypass to Origin Servers
Tudou Guarantee Marketplace Halts Telegram Transactions After Processing Over $12 Billion
Google Gemini Prompt Injection Flaw Exposed Private Calendar Data via Malicious Invites
⚡ Weekly Recap: Fortinet Exploits, RedLine Clipjack, NTLM Crack, Copilot Attack & More
DevOps & SaaS Downtime: The High (and Hidden) Costs for Cloud-First Businesses
New StackWarp Hardware Flaw Breaks AMD SEV-SNP Protections on Zen 1–5 CPUs
CrashFix Chrome Extension Delivers ModeloRAT Using ClickFix-Style Browser Crash Lures
Security Bug in StealC Malware Panel Let Researchers Spy on Threat Actor Operations
Black Basta Ransomware Leader Added to EU Most Wanted and INTERPOL Red Notice
OpenAI to Show Ads in ChatGPT for Logged-In U.S. Adults on Free and Go Plans
GootLoader Malware Uses 500–1,000 Concatenated ZIP Archives to Evade Detection
Five Malicious Chrome Extensions Impersonate Workday and NetSuite to Hijack Accounts
LOTUSLITE Backdoor Targets U.S. Policy Entities Using Venezuela-Themed Spear Phishing
Your Digital Footprint Can Lead Right to Your Front Door
China-Linked APT Exploits Sitecore Zero-Day in Attacks on American Critical Infrastructure
Cisco Patches Zero-Day RCE Exploited by China-Linked APT in Secure Email Gateways
AWS CodeBuild Misconfiguration Exposed GitHub Repos to Potential Supply Chain Attacks
Researchers Reveal Reprompt Attack Allowing Single-Click Data Exfiltration From Microsoft Copilot
Critical WordPress Modular DS Plugin Flaw Actively Exploited to Gain Admin Access
ThreatsDay Bulletin: AI Voice Cloning Exploit, Wi-Fi Kill Switch, PLC Vulns, and 14 More Stories