Category: Hacker News

Model Security Is the Wrong Frame – The Real Risk Is Workflow Security
4 Outdated Habits Destroying Your SOC’s MTTR in 2026
Palo Alto Fixes GlobalProtect DoS Flaw That Can Crash Firewalls Without Login
Microsoft Legal Action Disrupts RedVDS Cybercrime Infrastructure Used for Online Fraud
Researchers Null-Route Over 550 Kimwolf and Aisuru Botnet Command Servers
AI Agents Are Becoming Privilege Escalation Paths
Hackers Exploit c-ares DLL Side-Loading to Bypass Security and Deploy Malware
Fortinet Fixes Critical FortiSIEM Flaw Allowing Unauthenticated Remote Code Execution
Microsoft Fixes 114 Windows Flaws in January 2026 Patch, One Actively Exploited
New Research: 64% of 3rd-Party Applications Access Sensitive Data Without Justification
Critical Node.js Vulnerability Can Cause Server Crashes via async_hooks Stack Overflow
PLUGGYAPE Malware Uses Signal and WhatsApp to Target Ukrainian Defense Forces
Long-Running Web Skimming Campaign Steals Credit Cards From Online Checkout Pages
Malicious Chrome Extension Steals MEXC API Keys by Masquerading as Trading Tool
[Webinar] Securing Agentic AI: From MCPs and Tool Access to Shadow API Key Sprawl
What Should We Learn From How Attackers Leveraged AI in 2025?
ServiceNow Patches Critical AI Platform Flaw Allowing Unauthenticated User Impersonation
New Advanced Linux VoidLink Malware Targets Cloud and container Environments
New Malware Campaign Delivers Remcos RAT Through Multi-Stage Windows Attack
CISA Warns of Active Exploitation of Gogs Vulnerability Enabling Code Execution
n8n Supply Chain Attack Abuses Community Nodes to Steal OAuth Tokens
⚡ Weekly Recap: AI Automation Exploits, Telecom Espionage, Prompt Poaching & More
GoBruteforcer Botnet Targets Crypto Project Databases by Exploiting Weak Credentials
Anthropic Launches Claude AI for Healthcare with Secure Health Record Access
Researchers Uncover Service Providers Fueling Industrial-Scale Pig Butchering Fraud
MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors
Europol Arrests 34 Black Axe Members in Spain Over €5.9M Fraud and Organized Crime
China-Linked Hackers Exploit VMware ESXi Zero-Days to Escape Virtual Machines
Russian APT28 Runs Credential-Stealing Campaign Targeting Energy and Policy Organizations
Cybersecurity Predictions 2026: The Hype We Can Ignore (And the Risks We Can’t)
Trend Micro Apex Central RCE Flaw Scores 9.8 CVSS in On-Prem Windows Versions
CISA Retires 10 Emergency Cybersecurity Directives Issued Between 2019 and 2024
FBI Warns North Korean Hackers Using Malicious QR Codes in Spear-Phishing
WhatsApp Worm Spreads Astaroth Banking Trojan Across Brazil via Contact Auto-Messaging
China-Linked UAT-7290 Targets Telecoms with Linux Malware and ORB Nodes
ThreatsDay Bulletin: RustFS Flaw, Iranian Ops, WebUI RCE, Cloud Leaks, and 12 More Stories
Cisco Patches ISE Security Vulnerability After Public PoC Exploit Release
Researchers Uncover NodeCordRAT Hidden in npm Bitcoin-Themed Packages
Coolify Discloses 11 Critical Flaws Enabling Full Server Compromise on Self-Hosted Instances
The State of Trusted Open Source
OpenAI Launches ChatGPT Health with Isolated, Encrypted Health Data Controls
CISA Flags Microsoft Office and HPE OneView Bugs as Actively Exploited
Black Cat Behind SEO Poisoning Malware Campaign Targeting Popular Software Searches
Critical n8n Vulnerability (CVSS 10.0) Allows Unauthenticated Attackers to Take Full Control
The Future of Cybersecurity Includes Non-Human Employees
Veeam Patches Critical RCE Vulnerability with CVSS 9.0 in Backup & Replication
Webinar: Learn How AI-Powered Zero Trust Detects Attacks with No Files or Indicators
n8n Warns of CVSS 10.0 RCE Vulnerability Affecting Self-Hosted and Cloud Versions
Microsoft Warns Misconfigured Email Routing Can Enable Internal Domain Phishing
Ongoing Attacks Exploiting Critical RCE Vulnerability in Legacy D-Link DSL Routers