Category: Hacker News

Axios Supply Chain Attack Pushes Cross-Platform RAT via Compromised npm Account
OpenAI Patches ChatGPT Data Exfiltration Flaw and Codex GitHub Token Vulnerability
DeepLoad Malware Uses ClickFix and WMI Persistence to Steal Browser Credentials
3 SOC Process Fixes That Unlock Tier 1 Productivity
⚡ Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and More
The State of Secrets Sprawl 2026: 9 Takeaways for CISOs
Russian CTRL Toolkit Delivered via Malicious LNK Files Hijacks RDP via FRP Tunnels
Three China-Linked Clusters Target Southeast Asian Government in 2025 Cyber Campaign
Iran-Linked Hackers Breach FBI Director’s Personal Email, Hit Stryker With Wiper Attack
Citrix NetScaler Under Active Recon for CVE-2026-3055 (CVSS 9.3) Memory Overread Bug
CISA Adds CVE-2025-53521 to KEV After Active F5 BIG-IP APM Exploitation
TA446 Deploys Leaked DarkSword iOS Exploit Kit in Targeted Spear-Phishing Campaign
Apple Sends Lock Screen Alerts to Outdated iPhones Over Active Web-Based Exploits
TeamPCP Pushes Malicious Telnyx Versions to PyPI, Hides Stealer in WAV Files
Open VSX Bug Let Malicious VS Code Extensions Bypass Pre-Publish Security Checks
AitM Phishing Targets TikTok Business Accounts Using Cloudflare Turnstile Evasion
We Are At War

We Are At War

Bearlyfy Hits 70+ Russian Firms with Custom GenieLocker Ransomware
LangChain, LangGraph Flaws Expose Files, Secrets, Databases in Widely Used AI Frameworks
China-Linked Red Menshen Uses Stealthy BPFDoor Implants to Spy via Telecom Networks
ThreatsDay Bulletin: PQC Push, AI Vuln Hunting, Pirated Traps, Phishing Kits & 20 More Stories
Masters of Imitation: How Hackers and Art Forgers Perfect the Art of Deception
Claude Extension Flaw Enabled Zero-Click XSS Prompt Injection via Any Website
Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in New Mass Attacks
[Webinar] Stop Guessing. Learn to Validate Your Defenses Against Real Attacks
WebRTC Skimmer Bypasses CSP to Steal Payment Data from E-Commerce Sites
LeakBase Admin Arrested in Russia Over Massive Stolen Credential Marketplace
GlassWorm Malware Uses Solana Dead Drops to Deliver RAT and Steal Browser, Crypto Data
Russian Hacker Sentenced to 2 Years for TA551 Botnet-Driven Ransomware Attacks
Device Code Phishing Hits 340+ Microsoft 365 Orgs Across Five Countries via OAuth Abuse
The Kill Chain Is Obsolete When Your AI Agent Is the Threat
FCC Bans New Foreign-Made Routers Over Supply Chain and Cyber Risk Concerns
TeamPCP Backdoors LiteLLM Versions 1.82.7–1.82.8 Likely via Trivy CI/CD Compromise
Tax Search Ads Deliver ScreenConnect Malware Using Huawei Driver to Disable EDR
Hackers Use Fake Resumes to Steal Enterprise Credentials and Deploy Crypto Miner
5 Learnings from the First-Ever Gartner Market Guide for Guardian Agents
Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials
TeamPCP Hacks Checkmarx GitHub Actions Using Stolen CI Credentials
The Hidden Cost of Cybersecurity Specialization: Losing Foundational Skills
U.S. Sentences Russian Hacker to 6.75 Years for Role in $9M Ransomware Damage
Citrix Urges Patching Critical NetScaler Flaw Allowing Unauthenticated Data Leaks
North Korean Hackers Abuse VS Code Auto-Run Tasks to Deploy StoatWaffle Malware
⚡ Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & More
We Found Eight Attack Vectors Inside AWS Bedrock. Here’s What Attackers Can Do with Them
Microsoft Warns IRS Phishing Hits 29,000 Users, Deploys RMM Malware
Trivy Hack Spreads Infostealer via Docker, Triggers Worm and Kubernetes Wiper
Hackers Exploit CVE-2025-32975 (CVSS 10.0) to Hijack Unpatched Quest KACE SMA Systems
FBI Warns Russian Hackers Target Signal, WhatsApp in Mass Phishing Attacks
Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager
CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026