Category: Hacker News

INTERPOL Arrests 574 in Africa; Ukrainian Ransomware Affiliate Pleads Guilty
U.S. DoJ Seizes Fraud Domain Behind $14.6 Million Bank Account Takeover Scheme
Critical n8n Flaw (CVSS 9.9) Enables Arbitrary Code Execution Across Thousands of Instances
FCC Bans Foreign-Made Drones and Key Parts Over U.S. National Security Risks
Fake WhatsApp API Package on npm Steals Messages, Contacts, and Login Tokens
How to Browse the Web More Sustainably With a Green Browser
⚡ Weekly Recap: Firewall Exploits, AI Data Theft, Android Hacks, APT Attacks, Insider Leaks & More
Android Malware Operations Merge Droppers, SMS Theft, and RAT Capabilities at Scale
Iranian Infy APT Resurfaces with New Malware Activity After Years of Silence
U.S. DOJ Charges 54 in ATM Jackpotting Scheme Using Ploutus Malware
Russia-Linked Hackers Use Microsoft 365 Device Code Phishing for Account Takeovers
Cracked Software and YouTube Videos Spread CountLoader and GachiLoader Malware
WatchGuard Warns of Active Exploitation of Critical Fireware OS VPN Vulnerability
Nigeria Arrests RaccoonO365 Phishing Developer Linked to Microsoft 365 Attacks
New UEFI Flaw Enables Early-Boot DMA Attacks on ASRock, ASUS, GIGABYTE, MSI Motherboards
China-Aligned Threat Group Uses Windows Group Policy to Deploy Espionage Malware
HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution
The Case for Dynamic AI-SaaS Security as Copilots Scale
ThreatsDay Bulletin: WhatsApp Hijacks, MCP Leaks, AI Recon, React2Shell Exploit and 15 More Stories
North Korea-Linked Hackers Steal $2.02 Billion in 2025, Leading Global Crypto Theft
Kimsuky Spreads DocSwap Android Malware via QR Phishing Posing as Delivery App
Cisco Warns of Active Attacks Exploiting Unpatched 0-Day in AsyncOS Email Security Appliances
CISA Flags Critical ASUS Live Update Flaw After Evidence of Active Exploitation
SonicWall Fixes Actively Exploited CVE-2025-40602 in SMA 100 Appliances
Kimwolf Botnet Hijacks 1.8 Million Android TVs, Launches Large-Scale DDoS Attacks
APT28 Targets Ukrainian UKR-net Users in Long-Running Credential Phishing Campaign
New ForumTroll Phishing Attacks Target Russian Scholars Using Fake eLibrary Emails
China-Linked Ink Dragon Hacks Governments Using ShadowPad and FINALDRAFT Malware
Fix SOC Blind Spots: See Threats to Your Industry & Country in Real Time
GhostPoster Malware Found in 17 Firefox Add-ons with 50,000+ Downloads
Compromised IAM Credentials Power a Large AWS Crypto Mining Campaign
Rogue NuGet Package Poses as Tracer.Fody, Steals Cryptocurrency Wallet Data
Amazon Exposes Years-Long GRU Cyber Campaign Targeting Energy and Cloud Infrastructure
Fortinet FortiGate Under Active Attack Through SAML SSO Authentication Bypass
Why Data Security and Privacy Need to Start in Code
React2Shell Vulnerability Actively Exploited to Deploy Linux Backdoors
Google to Shut Down Dark Web Monitoring Tool in February 2026
Featured Chrome Browser Extension Caught Intercepting Millions of Users’ AI Chats
FreePBX Patches Critical SQLi, File-Upload, and AUTHTYPE Bypass Flaws Enabling RCE
⚡ Weekly Recap: Apple 0-Days, WinRAR Exploit, LastPass Fines, .NET RCE, OAuth Scams & More
A Browser Extension Risk Guide After the ShadyPanda Campaign
Phantom Stealer Spread by ISO Phishing Emails Hitting Russian Finance Sector
VolkLocker Ransomware Exposed by Hard-Coded Master Key Allowing Free Decryption
CISA Adds Actively Exploited Sierra Wireless Router Flaw Enabling RCE Attacks
Apple Issues Security Updates After Two WebKit Flaws Found Exploited in the Wild
Fake OSINT and GPT Utility GitHub Repos Spread PyStoreRAT Malware Payloads
New Advanced Phishing Kits Use AI and MFA Bypass Tactics to Steal Credentials at Scale
Securing GenAI in the Browser: Policy, Isolation, and Data Controls That Actually Work
React2Shell Exploitation Escalates into Large-Scale Global Attacks, Forcing Emergency Mitigation
New React RSC Vulnerabilities Enable DoS and Source Code Exposure