Category: Hacker News

Urgent: China-Linked Hackers Exploit New VMware Zero-Day Since October 2024
New Android Trojan “Datzbro” Tricking Elderly with AI-Generated Facebook Travel Events
Evolving Enterprise Defense to Secure the Modern AI Supply Chain
U.K. Police Just Seized £5.5 Billion in Bitcoin — The World’s Largest Crypto Bust
CISA Sounds Alarm on Critical Sudo Flaw Actively Exploited in Linux and Unix Systems
EvilAI Malware Masquerades as AI Tools to Infiltrate Global Organizations
⚡ Weekly Recap: Cisco 0-Day, Record DDoS, LockBit 5.0, BMC Bugs, ShadowV2 Botnet & More
The State of AI in the SOC 2025 – Insights from Recent Study 
First Malicious MCP Server Found Stealing Emails in Rogue Postmark-MCP Package
Microsoft Flags AI-Driven Phishing: LLM-Crafted SVG Files Outsmart Email Security
China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks
Researchers Expose SVG and PureRAT Phishing Threats Targeting Ukraine and Vietnam
New COLDRIVER Malware Campaign Joins BO Team and Bearlyfy in Russia-Focused Cyberattacks
Crash Tests for Security: Why BAS Is Proof of Defense, Not Assumptions
New macOS XCSSET Variant Targets Firefox with Clipper and Persistence Module
Fortra GoAnywhere CVSS 10 Flaw Exploited as 0-Day a Week Before Public Disclosure
Cisco ASA Firewall Zero-Day Exploits Deploy RayInitiator and LINE VIPER Malware
Urgent: Cisco ASA Zero-Day Duo Under Attack; CISA Triggers Emergency Mitigation Directive
Vane Viper Generates 1 Trillion DNS Queries to Power Global Malware and Ad Fraud Network
Salesforce Patches Critical ForcedLeak Bug Exposing CRM Data via AI Prompt Injection
North Korean Hackers Use New AkdoorTea Backdoor to Target Global Crypto Developers
CTEM’s Core: Prioritization and Validation
Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More
Tech Overtakes Gaming as Top DDoS Attack Target, New Gcore Radar Report Finds
Malicious Rust Crates Steal Solana and Ethereum Keys — 8,424 Downloads Confirmed
Cisco Warns of Actively Exploited SNMP Vulnerability Allowing RCE or DoS in IOS Software
Chinese Hackers RedNovember Target Global Governments Using Pantegana and Cobalt Strike
UNC5221 Uses BRICKSTORM Backdoor to Infiltrate U.S. Legal and Technology Sectors
Two Critical Flaws Uncovered in Wondershare RepairIt Exposing User Data and AI Models
How One Bad Password Ended a 158-Year-Old Business
New YiBackdoor Malware Shares Major Code Overlaps with IcedID and Latrodectus
iframe Security Exposed: The Blind Spot Fueling Payment Skimmer Attacks
Hackers Exploit Pandoc CVE-2025-51591 to Target AWS IMDS and Steal EC2 IAM Credentials
State-Sponsored Hackers Exploiting Libraesva Email Security Gateway Vulnerability
Two New Supermicro BMC Bugs Allow Malicious Firmware to Evade Root of Trust Security
Eurojust Arrests 5 in €100M Cryptocurrency Investment Fraud Spanning 23 Countries
U.S. Secret Service Seizes 300 SIM Servers, 100K Cards Threatening U.S. Officials Near UN
SolarWinds Releases Hotfix for Critical CVE-2025-26399 Remote Code Execution Flaw
Lean Teams, Higher Stakes: Why CISOs Must Rethink Incident Remediation
ShadowV2 Botnet Exploits Misconfigured AWS Docker Containers for DDoS-for-Hire Service
GitHub Mandates 2FA and Short-Lived Tokens to Strengthen npm Supply Chain Security
BadIIS Malware Spreads via SEO Poisoning — Redirects Traffic, Plants Web Shells
ComicForm and SectorJ149 Hackers Deploy Formbook Malware in Eurasian Cyberattacks
⚡ Weekly Recap: Chrome 0-Day, AI Hacking Tools, DDR5 Bit-Flips, npm Worm & More
How to Gain Control of AI Agents and Non-Human Identities
Microsoft Patches Critical Entra ID Flaw Enabling Global Admin Impersonation Across Tenants
DPRK Hackers Use ClickFix to Deliver BeaverTail Malware in Crypto Job Scams
LastPass Warns of Fake Repositories Infecting macOS with Atomic Infostealer
Researchers Uncover GPT-4-Powered MalTerminal Malware Creating Ransomware, Reverse Shell
ShadowLeak Zero-Click Flaw Leaks Gmail Data via OpenAI ChatGPT Deep Research Agent