Category: Hacker News

SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users
Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS
The Verification Step Is the New ATO Battleground in 2026
GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code
GitHub ‘Verified’ Commits Can Be Rewritten Into New Hashes Without Breaking Signatures
China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware
CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV
15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros
Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots
RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service
Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data
DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts
Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants
Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker
What Changes When Your Software Supply Chain Includes AI Writing Your Code?
Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities
BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA
CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware
Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations
16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems
Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure
Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT
⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More
How to Evaluate an AI SOC Platform in 2026: 6 Capabilities That Separate Leaders from Bolt-On AI solutions
New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS
New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions
SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing
Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages
U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case
North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign
Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices
New Avalon Malware Framework Packs CrownX Ransomware Capabilities
New “Bad Epoll” Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android
North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets
Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer
European Parliament Member Investigating Spyware Was Hacked With Pegasus
PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords
Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials
Google Disrupts NetNut Residential Proxy Network Spanning 2 Million Home Devices
ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories
ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API
Identity Lifecycle Management Wasn’t Built for AI Agents 
FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations
AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack
New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos
SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation
SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT
VEIL#DROP Malware Chain Uses Blogger Platform to Deliver PureLogs Stealer
Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters
19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges