Category: Hacker News

One Missed Threat Per Week: What 25M Alerts Reveal About Low-Severity Risk
Linux Kernel Dirty Frag LPE Exploit Enables Root Access Across Major Distributions
Ivanti EPMM CVE-2026-6973 RCE Under Active Exploitation Grants Admin-Level Access
PCPJack Credential Stealer Exploits 5 CVEs to Spread Worm-Like Across Cloud Systems
One Click, Total Shutdown: The “Patient Zero” Webinar on Killing Stealth Breaches
PAN-OS RCE Exploit Under Active Use Enabling Root Access and Espionage
Day Zero Readiness: The Operational Gaps That Break Incident Response
ThreatsDay Bulletin: Edge Plaintext Passwords, ICS 0-Days, Patch-or-Die Alerts and 25+ New Stories
PyPI Packages Deliver ZiChatBot Malware via Zulip APIs on Windows and Linux
vm2 Node.js Library Vulnerabilities Enable Sandbox Escape and Arbitrary Code Execution
Mirai-Based xlabs_v1 Botnet Exploits ADB to Hijack IoT Devices for DDoS Attacks
MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack
Your AI Agents Are Already Inside the Perimeter. Do You Know What They’re Doing?
The Hacker News Launches ‘Cybersecurity Stars Awards 2026’ — Submissions Now Open
Google’s Android Apps Get Public Verification to Stop Supply Chain Attacks
Windows Phone Link Exploited by CloudZ RAT to Steal Credentials and OTPs
Palo Alto PAN-OS Flaw Under Active Exploitation Enables Remote Code Execution
DAEMON Tools Supply Chain Attack Compromises Official Installers with Malware
Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE
China-Linked UAT-8302 Targets Governments Using Shared APT Malware Across Regions
We Scanned 1 Million Exposed AI Services. Here’s How Bad the Security Actually Is
The Back Door Attackers Know About — and Most Security Teams Still Haven’t Closed
MetInfo CMS CVE-2026-29014 Exploited for Remote Code Execution Attacks
ScarCruft Hacks Gaming Platform to Deploy BirdCall Malware on Android and Windows
Microsoft Details Phishing Campaign Targeting 35,000 Users Across 26 Countries
Weaver E-cology RCE Flaw CVE-2026-22679 Actively Exploited via Debug API
Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools
Progress Patches Critical MOVEit Automation Bug Enabling Authentication Bypass
⚡ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & More
Silver Fox Deploys ABCDoor Malware via Tax-Themed Phishing in India and Russia
2026: The Year of AI-Assisted Attacks
Critical cPanel Vulnerability Weaponized to Target Government and MSP Networks
Global Crackdown Arrests 276, Shuts 9 Crypto Scam Centers, Seizes $701M
CISA Adds Actively Exploited Linux Root Access Bug CVE-2026-31431 to KEV
Trellix Confirms Source Code Breach With Unauthorized Repository Access
30,000 Facebook Accounts Hacked via Google AppSheet Phishing Campaign
China-Linked Hackers Target Asian Governments, NATO State, Journalists, and Activists
Cybercrime Groups Using Vishing and SSO Abuse in Rapid SaaS Extortion Attacks
Two Cybersecurity Professionals Get 4-Year Sentences in BlackCat Ransomware Attacks
Top Five Sales Challenges Costing MSPs Cybersecurity Revenue
Poisoned Ruby Gems and Go Modules Exploit CI Pipelines for Credential Theft
PyTorch Lightning Compromised in PyPI Supply Chain Attack to Steal Credentials
ThreatsDay Bulletin: SMS Blaster Busts, OpenEMR Flaws, 600K Roblox Hacks and 25 More Stories
New Python Backdoor Uses Tunneling Service to Steal Browser and Cloud Credentials
EtherRAT Distribution Spoofing Administrative Tools via GitHub Facades
New Linux ‘Copy Fail’ Vulnerability Enables Root Access on Major Distributions
Google Fixes CVSS 10 Gemini CLI CI RCE and Cursor Flaws Enable Code Execution
New Wave of DPRK Attacks Uses AI-Inserted npm Malware, Fake Firms, and RATs
SAP npm Packages Compromised by “Mini Shai-Hulud” Credential-Stealing Malware
Webinar: How to Automate Exposure Validation to Match the Speed of AI Attacks