Category: Hacker News

Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flaws
Developer Workstations Are Now Part of the Software Supply Chain
MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems
Pre-Stuxnet Fast16 Malware Tampered with Nuclear Weapons Simulations
NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE
Grafana GitHub Token Breach Led to Codebase Download and Extortion Attempt
Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming
Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent Access
Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence
TanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS Updates
What 45 Days of Watching Your Own Tools Will Tell You About Your Real Attack Surface
On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email
CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits
Stealer Backdoor Found in 3 Node-IPC Versions Targeting Developer Secrets
Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access
ThreatsDay Bulletin: PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ Stories
Ghostwriter Targets Ukrainian Government With Geofenced PDF Phishing, Cobalt Strike
How AI Hallucinations Are Creating Real Security Risks
PraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours of Disclosure
Windows Zero-Days Expose BitLocker Bypasses And CTFMON Privilege Escalation
New Fragnesia Linux Kernel LPE Grants Root Access via Page Cache Corruption
18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE
Microsoft’s MDASH AI System Finds 16 Windows Flaws Fixed in Patch Tuesday
Azerbaijani Energy Firm Hit by Repeated Microsoft Exchange Exploitation
Most Remediation Programs Never Confirm the Fix Actually Worked
Microsoft Patches 138 Vulnerabilities, Including DNS and Netlogon RCE Flaws
[Webinar] Why Your AppSec Tools Miss the “Lethal Path” (and How to Fix It)
GemStuffer Abuses 150+ RubyGems to Exfiltrate Scraped U.K. Council Portal Data
Android Adds Intrusion Logging for Sophisticated Spyware Forensics
RubyGems Suspends New Signups After Hundreds of Malicious Packages Are Uploaded
New Exim BDAT Vulnerability Exposes GnuTLS Builds to Potential Code Execution
New TrickMo Variant Uses TON C2 and SOCKS5 to Create Android Network Pivots
Why Agentic AI Is Security’s Next Blind Spot
Webinar: What the Riskiest SOC Alerts Go Unanswered – and How Radiant Security Can Help
Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages
OpenAI Launches Daybreak for AI-Powered Vulnerability Detection and Patch Validation
Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65TB Canvas Leak
iOS 26.5 Brings Default End-to-End Encrypted RCS Messaging Between iPhone and Android
TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain Attack
cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager Backdoor
Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation
⚡ Weekly Recap: Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and More
Your Purple Team Isn’t Purple — It’s Just Red and Blue in the Same Room
Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K Downloads
Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak
cPanel, WHM Release Fixes for Three New Vulnerabilities — Patch Now
TCLBANKER Banking Trojan Targets Financial Platforms via WhatsApp and Outlook Worms
Fake Call History Apps Stole Payments From Users After 7.3 Million Play Store Downloads
Quasar Linux RAT Steals Developer Credentials for Software Supply Chain Compromise
New Linux PamDOORa Backdoor Uses PAM Modules to Steal SSH Credentials