Category: Hacker News

Zimbra Zero-Day Exploited to Target Brazilian Military via Malicious ICS Files
Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks
CometJacking: One Click Can Turn Perplexity’s Comet AI Browser Into a Data Thief
Scanning Activity on Palo Alto Networks Portals Jump 500% in One Day
Detour Dog Caught Running DNS-Powered Malware Factory for Strela Stealer
Rhadamanthys Stealer Evolves: Adds Device Fingerprinting, PNG Steganography Payloads
Researchers Warn of Self-Spreading WhatsApp Malware Named SORVEPOTEL
Product Walkthrough: How Passwork 7 Addresses Complexity of Enterprise Security
New “Cavalry Werewolf” Attack Hits Russian Agencies with FoalShell and StallionRAT
CISA Flags Meteobridge CVE-2025-4008 Flaw as Actively Exploited in the Wild
Confucius Hackers Hit Pakistan With New WooperStealer and Anondoor Malware
Alert: Malicious PyPI Package soopsocks Infects 2,653 Systems Before Takedown
Automating Pentest Delivery: 7 Key Workflows for Maximum Impact
ThreatsDay Bulletin: CarPlay Exploit, BYOVD Tactics, SQL C2 Attacks, iCloud Backdoor Demand & More
Google Mandiant Probes New Oracle Extortion Wave Possibly Linked to Cl0p Ransomware
How to Close Threat Detection Gaps: Your SOC’s Action Plan
Warning: Beware of Android Spyware Disguised as Signal Encryption Plugin and ToTok Pro
New WireTap Attack Extracts Intel SGX ECDSA Key via DDR4 Memory-Bus Interposer
OneLogin Bug Let Attackers Use API Keys to Steal OIDC Secrets and Impersonate Apps
Red Hat OpenShift AI Flaw Exposes Hybrid Cloud Infrastructure to Full Takeover
How Leading Security Teams Blend AI + Human Workflows (Free Webinar)
2025 Cybersecurity Reality Check: Breaches Hidden, Attack Surfaces Growing, and AI Misperceptions Rising
Hackers Exploit Milesight Routers to Send Phishing SMS to European Users
New Android Banking Trojan “Klopatra” Uses Hidden VNC to Control Infected Smartphones
Ukraine Warns of CABINETRAT Backdoor + XLL Add-ins Spread via Signal ZIPs
$50 Battering RAM Attack Breaks Intel and AMD Cloud Security Protections
Phantom Taurus: New China-Linked Hacker Group Hits Governments With Stealth Malware
Researchers Disclose Google Gemini AI Flaws Allowing Prompt Injection and Cloud Exploits
Microsoft Expands Sentinel Into Agentic Security Platform With Unified Data Lake
Stop Alert Chaos: Context Is the Key to Effective Incident Response
Urgent: China-Linked Hackers Exploit New VMware Zero-Day Since October 2024
New Android Trojan “Datzbro” Tricking Elderly with AI-Generated Facebook Travel Events
Evolving Enterprise Defense to Secure the Modern AI Supply Chain
U.K. Police Just Seized £5.5 Billion in Bitcoin — The World’s Largest Crypto Bust
CISA Sounds Alarm on Critical Sudo Flaw Actively Exploited in Linux and Unix Systems
EvilAI Malware Masquerades as AI Tools to Infiltrate Global Organizations
⚡ Weekly Recap: Cisco 0-Day, Record DDoS, LockBit 5.0, BMC Bugs, ShadowV2 Botnet & More
The State of AI in the SOC 2025 – Insights from Recent Study 
Microsoft Flags AI-Driven Phishing: LLM-Crafted SVG Files Outsmart Email Security
First Malicious MCP Server Found Stealing Emails in Rogue Postmark-MCP Package
China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks
Researchers Expose SVG and PureRAT Phishing Threats Targeting Ukraine and Vietnam
New COLDRIVER Malware Campaign Joins BO Team and Bearlyfy in Russia-Focused Cyberattacks
Crash Tests for Security: Why BAS Is Proof of Defense, Not Assumptions
New macOS XCSSET Variant Targets Firefox with Clipper and Persistence Module
Fortra GoAnywhere CVSS 10 Flaw Exploited as 0-Day a Week Before Public Disclosure
Cisco ASA Firewall Zero-Day Exploits Deploy RayInitiator and LINE VIPER Malware
Urgent: Cisco ASA Zero-Day Duo Under Attack; CISA Triggers Emergency Mitigation Directive
Vane Viper Generates 1 Trillion DNS Queries to Power Global Malware and Ad Fraud Network
Salesforce Patches Critical ForcedLeak Bug Exposing CRM Data via AI Prompt Injection