Category: Hacker News

Microsoft Office Zero-Day (CVE-2026-21509) – Emergency Patch Issued for Active Exploitation
Indian Users Targeted in Tax Phishing Campaign Delivering Blackmoon Malware
Malicious VS Code AI Extensions with 1.5 Million Installs Steal Developer Source Code
⚡ Weekly Recap: Firewall Flaws, AI-Built Malware, Browser Traps, Critical CVEs & More
Winning Against AI-Based Attacks Requires a Combined Defensive Approach
Konni Hackers Deploy AI-Generated PowerShell Backdoor Against Blockchain Developers
Multi-Stage Phishing Campaign Targets Russia with Amnesia RAT and Ransomware
Who Approved This Agent? Rethinking Access, Accountability, and Risk in the Age of AI Agents
CISA Adds Actively Exploited VMware vCenter Flaw CVE-2024-37079 to KEV Catalog
New DynoWiper Malware Used in Attempted Sandworm Attack on Polish Power Sector
CISA Updates KEV Catalog with Four Actively Exploited Software Vulnerabilities
Phishing Attack Uses Stolen Credentials to Install LogMeIn RMM for Persistent Access
Fortinet Confirms Active FortiCloud SSO Bypass on Fully Patched FortiGate Firewalls
TikTok Forms U.S. Joint Venture to Continue Operations Under 2025 Executive Order
Microsoft Flags Multi-Stage AitM Phishing and BEC Attacks Targeting Energy Firms
New Osiris Ransomware Emerges as New Strain Using POORTRY Driver in BYOVD Attack
Critical GNU InetUtils telnetd Flaw Lets Attackers Bypass Login and Gain Root Access
ThreatsDay Bulletin: Pixel Zero-Click, Redis RCE, China C2s, RAT Ads, Crypto Scams & 15+ Stories
SmarterMail Auth Bypass Exploited in the Wild Two Days After Patch Release
Filling the Most Common Gaps in Google Workspace Security
Malicious PyPI Package Impersonates SymPy, Deploys XMRig Miner on Linux Hosts
Automated FortiGate Attacks Exploit FortiCloud SSO to Alter Firewall Configurations
Cisco Fixes Actively Exploited Zero-Day CVE-2026-20045 in Unified CM and Webex
North Korean PurpleBravo Campaign Targeted 3,136 IP Addresses via Fake Job Interviews
Zoom and GitLab Release Security Updates Fixing RCE, DoS, and 2FA Bypass Flaws
Exposure Assessment Platforms Signal a Shift in Focus
Webinar: How Smart MSSPs Using AI to Boost Margins with Half the Staff
Chainlit AI Framework Flaws Enable Data Theft via File Read and SSRF Bugs
VoidLink Linux Malware Framework Built with AI Assistance Reaches 88,000 Lines of Code
LastPass Warns of Fake Maintenance Messages Targeting Users’ Master Passwords
CERT/CC Warns binary-parser Bug Allows Node.js Privilege-Level Code Execution
North Korea-Linked Hackers Target Developers via Malicious VS Code Projects
Hackers Use LinkedIn Messages to Spread RAT Malware Through DLL Sideloading
Three Flaws in Anthropic MCP Git Server Enable File Access and Code Execution
The Hidden Risk of Orphan Accounts
Evelyn Stealer Malware Abuses VS Code Extensions to Steal Developer Credentials and Crypto
Why Secrets in JavaScript Bundles are Still Being Missed
Cloudflare Fixes ACME Validation Bug Allowing WAF Bypass to Origin Servers
Tudou Guarantee Marketplace Halts Telegram Transactions After Processing Over $12 Billion
Google Gemini Prompt Injection Flaw Exposed Private Calendar Data via Malicious Invites
⚡ Weekly Recap: Fortinet Exploits, RedLine Clipjack, NTLM Crack, Copilot Attack & More
New StackWarp Hardware Flaw Breaks AMD SEV-SNP Protections on Zen 1–5 CPUs
DevOps & SaaS Downtime: The High (and Hidden) Costs for Cloud-First Businesses
CrashFix Chrome Extension Delivers ModeloRAT Using ClickFix-Style Browser Crash Lures
Security Bug in StealC Malware Panel Let Researchers Spy on Threat Actor Operations
Black Basta Ransomware Leader Added to EU Most Wanted and INTERPOL Red Notice
OpenAI to Show Ads in ChatGPT for Logged-In U.S. Adults on Free and Go Plans
GootLoader Malware Uses 500–1,000 Concatenated ZIP Archives to Evade Detection
Five Malicious Chrome Extensions Impersonate Workday and NetSuite to Hijack Accounts
Your Digital Footprint Can Lead Right to Your Front Door