Category: Hacker News

UNC1549 Hacks 34 Devices in 11 Telecom Firms via LinkedIn Job Lures and MINIBIKE Malware
SystemBC Powers REM Proxy With 1,500 Daily VPS Victims Across 80 C2 Servers
Fortra Releases Critical Patch for CVSS 10.0 GoAnywhere MFT Vulnerability
17,500 Phishing Domains Target 316 Brands Across 74 Countries in Global PhaaS Surge
How To Automate Alert Triage With AI Agents and Confluence SOPs Using Tines
Russian Hackers Gamaredon and Turla Collaborate to Deploy Kazuar Backdoor in Ukraine
U.K. Arrests Two Teen Scattered Spider Hackers Linked to August 2024 TfL Cyber Attack
CISA Warns of Two Malware Strains Exploiting Ivanti EPMM CVE-2025-4427 and CVE-2025-4428
SonicWall Urges Password Resets After Cloud Backup Breach Affecting Under 5% of Customers
CountLoader Broadens Russian Ransomware Operations With Multi-Version Malware Loader
SilentSync RAT Delivered via Two Malicious PyPI Packages Targeting Python Developers
How CISOs Can Drive Effective AI Governance
Google Patches Chrome Zero-Day CVE-2025-10585 as Active V8 Exploit Threatens Millions
TA558 Uses AI-Generated Scripts to Deploy Venom RAT in Brazil Hotel Attacks
Chinese TA415 Uses VS Code Remote Tunnels to Spy on U.S. Economic Policy Experts
From Quantum Hacks to AI Defenses – Expert Guide to Building Unbreakable Cyber Resilience
Rethinking AI Data Security: A Buyer’s Guide 
Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims
DOJ Resentences BreachForums Founder to 3 Years for Cybercrime and Possession of CSAM
RaccoonO365 Phishing Network Shut Down After Microsoft and Cloudflare Disrupt 338 Domains
Chaos Mesh Critical GraphQL Flaws Enable RCE and Full Kubernetes Cluster Takeover
SlopAds Fraud Ring Exploits 224 Android Apps to Drive 2.3 Billion Daily Ad Bids
New FileFix Variant Delivers StealC Malware Through Multilingual Phishing Site
Securing the Agentic Era: Introducing Astrix’s AI Agent Control Plane
Apple Backports Fix for CVE-2025-43300 Exploited in Sophisticated Spyware Attack
Phoenix RowHammer Attack Bypasses Advanced DDR5 Memory Protections in 109 Seconds
40 npm Packages Compromised in Supply Chain Attack Using bundle.js to Steal Credentials
Mustang Panda Deploys SnakeDisk USB Worm to Deliver Yokai Backdoor on Thailand IPs
6 Browser-Based Attacks Security Teams Need to Prepare For Right Now
⚡ Weekly Recap: Bootkit Malware, AI-Powered Attacks, Supply Chain Breaches, Zero-Days & More
AI-Powered Villager Pen Testing Tool Hits 11,000 PyPI Downloads Amid Abuse Concerns
HiddenGh0st, Winos and kkRAT Exploit SEO, GitHub Pages in Chinese Malware Attacks
FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks
Samsung Fixes Critical Zero-Day CVE-2025-21043 Exploited in Android Attacks
Apple Warns French Users of Fourth Spyware Campaign in 2025, CERT-FR Confirms
New HybridPetya Ransomware Bypasses UEFI Secure Boot With CVE-2024-7344 Exploit
Critical CVE-2025-5086 in DELMIA Apriso Actively Exploited, CISA Issues Warning
Cloud-Native Security in 2025: Why Runtime Visibility Must Take Center Stage
Cursor AI Code Editor Flaw Enables Silent Code Execution via Malicious Repositories
Google Pixel 10 Adds C2PA Support to Verify AI-Generated Media Authenticity
Senator Wyden Urges FTC to Probe Microsoft for Ransomware-Linked Cybersecurity Negligence
SonicWall SSL VPN Flaw and Misconfigurations Actively Exploited by Akira Ransomware Hackers
Fake Madgicx Plus and SocialMetrics Extensions Are Hijacking Meta Business Accounts
Cracking the Boardroom Code: Helping CISOs Speak the Language of Business
AsyncRAT Exploits ConnectWise ScreenConnect to Steal Credentials and Crypto
Chinese APT Deploys EggStreme Fileless Malware to Breach Philippine Military Systems
CHILLYHELL macOS Backdoor and ZynorRAT RAT Threaten macOS, Windows, and Linux Systems
Apple iPhone Air and iPhone 17 Feature A19 Chips With Spyware-Resistant Memory Safety
Microsoft Fixes 80 Flaws — Including SMB PrivEsc and Azure CVSS 10.0 Bugs
China-Linked APT41 Hackers Target U.S. Trade Officials Amid 2025 Negotiations