Category: Hacker News

RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks
How Pentera Turns AI Security Workflows into Validation Engines
11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot
U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support
148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet
Grok Build Uploads Entire Git Repositories to xAI Storage, Not Just Files It Reads
Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths
Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found
CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks
New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email
⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More
Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory
Thinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst Copilots
Meta Files Patent for AI That Can Listen All Day and Track How You’re Feeling
Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft
Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365
iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns
Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions
URGENT – Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat
Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot
Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages
Laser Attack Resets Tangem Wallet Passwords on Cards That Can’t Be Patched
New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic
Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws
Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access
From 17,000 to 1.1 Million Assets: How Lumen Technologies Rebuilt Exposure Management at Scale
Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking
Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers
Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks
Attackers Exploit ‘Ill Bloom’ Vulnerability to Drain $3.1 Million From Cryptocurrency Wallets
New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware
Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs
ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories
npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk
AI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up
GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses
Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges
Summer of Clearinghouses
Meta’s New AI Image Tool Lets Others Use Your Public Instagram Photos in AI Images
Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It
Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes
GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents
AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers
New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware
New Ghost Phishing Wave Is Breaking Traditional Email Security