Category: Hacker News

Seven npm Packages Use Adspect Cloaking to Trick Victims Into Crypto Scam Pages
Microsoft Mitigates Record 5.72 Tbps DDoS Attack Driven by AISURU Botnet
Google Issues Security Fix for Actively Exploited Chrome V8 Zero-Day Vulnerability
New EVALUSION ClickFix Campaign Delivers Amatera Stealer and NetSupport RAT
⚡ Weekly Recap: Fortinet Exploited, China’s AI Hacks, PhaaS Empire Falls & More
5 Reasons Why Attackers Are Phishing Over LinkedIn
Dragon Breath Uses RONINGLOADER to Disable Security Tools and Deploy Gh0st RAT
Rust Adoption Drives Android Memory Safety Bugs Below 20% for First Time
RondoDox Exploits Unpatched XWiki Servers to Pull More Devices Into Its Botnet
Five U.S. Citizens Plead Guilty to Helping North Korean IT Workers Infiltrate 136 Companies
North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels
Iranian Hackers Launch ‘SpearSpecter’ Spy Operation on Defense & Government Targets
Researchers Find Serious AI Bugs Exposing Meta, Nvidia, and Microsoft Inference Frameworks
Ransomware’s Fragmentation Reaches a Breaking Point While LockBit Returns
Chinese Hackers Use Anthropic’s AI to Launch Automated Cyber Espionage Campaign
Fortinet FortiWeb Flaw Actively Exploited in the Wild Before Company’s Silent Patch
Russian Hackers Create 4,300 Fake Travel Sites to Steal Hotel Guests’ Payment Data
Fake Chrome Extension “Safery” Steals Ethereum Wallet Seed Phrases Using Sui Blockchain
Operation Endgame Dismantles Rhadamanthys, Venom RAT, and Elysium Botnet in Global Crackdown
When Attacks Come Faster Than Patches: Why 2026 Will be the Year of Machine-Speed Security
ThreatsDay Bulletin: Cisco 0-Days, AI Bug Bounties, Crypto Heists, State-Linked Leaks and 20 More Stories
CISA Flags Critical WatchGuard Fireware Flaw Exposing 54,000 Fireboxes to No-Login Attacks
Over 46,000 Fake npm Packages Flood Registry in Worm-Like Spam Attack
 Google Sues China-Based Hackers Behind $1 Billion Lighthouse Phishing Platform
Amazon Uncovers Attacks Exploited Cisco ISE and Citrix NetScaler as Zero-Day Flaws
[Webinar] Learn How Leading Security Teams Reduce Attack Surface Exposure with DASR
Active Directory Under Siege: Why Critical Infrastructure Needs Stronger Security
Microsoft Fixes 63 Security Flaws, Including a Windows Kernel Zero-Day Under Active Attack
Google Launches ‘Private AI Compute’ — Secure AI Processing with On-Device-Level Privacy
WhatsApp Malware ‘Maverick’ Hijacks Browser Sessions to Target Brazil’s Biggest Banks
GootLoader Is Back, Using a New Font Trick to Hide Malware on WordPress Sites
Researchers Detect Malicious npm Package Targeting GitHub-Owned Repositories
Android Trojan ‘Fantasy Hub’ Malware Service Turns Telegram Into a Hub for Hackers
CISO’s Expert Guide To AI Supply Chain Attacks
Hackers Exploiting Triofox Flaw to Install Remote Access Tools via Antivirus Feature
Konni Hackers Turn Google’s Find Hub into a Remote Data-Wiping Weapon
⚡ Weekly Recap: Hyper-V Malware, Malicious AI Bots, RDP Exploits, WhatsApp Lockdown and More
New Browser Security Report Reveals Emerging Threats for Enterprises
Large-Scale ClickFix Phishing Attacks Target Hotel Systems with PureRAT Malware
GlassWorm Malware Discovered in Three VS Code Extensions with Thousands of Installs
Microsoft Uncovers ‘Whisper Leak’ Attack That Identifies AI Chat Topics in Encrypted Traffic
Samsung Zero-Click Flaw Exploited to Deploy LANDFALL Android Spyware via WhatsApp
From Log4j to IIS, China’s Hackers Turn Legacy Bugs into Global Espionage Tools
Hidden Logic Bombs in Malware-Laced NuGet Packages Set to Detonate Years After Installation
Enterprise Credentials at Risk – Same Old, Same Old?
Google Launches New Maps Feature to Help Businesses Report Review-Based Extortion Attempts
Vibe-Coded Malicious VS Code Extension Found with Built-In Ransomware Capabilities
Trojanized ESET Installers Drop Kalambur Backdoor in Phishing Attacks on Ukraine
Cisco Warns of New Firewall Attack Exploiting CVE-2025-20333 and CVE-2025-20362
From Tabletop to Turnkey: Building Cyber Resilience in Financial Services