Category: Hacker News

New AI DDoS Attacks Are Smarter. Learn How to Fight Back in This Webinar
Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions
CERT-In Mandates 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks
Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO Poisoning
KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike
⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos
The Alert Firehose Finally Meets Its Match
Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks
Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms
TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO
Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware
npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks
Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software
Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer
Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV
LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root
First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups
Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware
Making Vulnerable Drivers Exploitable Without Hardware – The BYOVD Perspective
Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows
Kimwolf DDoS Botnet Operator Arrested in Canada Over DDoS-for-Hire Attacks
CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV
Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data Access
Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor
ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New Stories
When Identity is the Attack Path
Microsoft Warns of Two Actively Exploited Defender Vulnerabilities
9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros
Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks
GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension
Microsoft Open-Sources RAMPART and Clarity to Secure AI Agents During Development
Microsoft Takes Down Malware-Signing Service Behind Ransomware Attacks
Agent AI is Coming. Are You Ready?
Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API
Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit
Typosquatting Is No Longer a User Problem. It’s a Supply Chain Problem
Grafana GitHub Breach Exposes Source Code via TanStack npm Attack
GitHub Investigating TeamPCP Claimed Breach of ~4,000 Internal Repositories
Trapdoor Android Ad Fraud Scheme Hit 659 Million Daily Bid Requests Using 455 Apps
DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability
Drupal to Release Urgent Core Security Updates on May 20, Sites Told to Prepare
The New Phishing Click: How OAuth Consent Bypasses MFA
SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access
Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer
Popular GitHub Action Tags Redirected to Imposter Commit to Steal CI/CD Credentials
Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account
INTERPOL Operation Ramz Disrupts MENA Cybercrime Networks with 201 Arrests
⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More
How to Reduce Phishing Exposure Before It Turns into Business Disruption
Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware