Category: Hacker News

VEIL#DROP Malware Chain Uses Blogger Platform to Deliver PureLogs Stealer
Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters
19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges
Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands
Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic
Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures
AI-Generated Browser Ransomware Abuses Chromium API on Windows and Android
Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts
2026 Cybersecurity Assessment: The Gap Between Awareness and Resilience
Microsoft Accelerates Post-Quantum Cryptography Shift to 2029
Anthropic Restores Claude Fable 5 After U.S. Lifts Jailbreak-Linked Export Controls
Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware
Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API-Driven Malware Delivery
Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ Attempts
Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service
RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS
Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data
Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints
Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses
What the Numbers Say About FIFA 2026 Cyber Risk
282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study
GuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection Risks
Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer
AirDrop and Quick Share Flaws Let Nearby Attackers Trigger Crashes and Bypass Checks
Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth
New BioShocking Attack Tricks AI Browsers Into Leaking User Credentials
Apple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugs
Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild
Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input
Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks
WhatsApp is Finally Getting Usernames to Help Keep Phone Numbers Private
236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet Drainers
⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More
Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse
Why Post-Quantum Cryptography Starts With Credentials
Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts
Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw
Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer
Ukraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging Credentials
OpenAI Previews GPT-5.6 Sol With Restricted Access and Stronger Cyber Safeguards
FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys
New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks
Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign
Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs
CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets
Guardian Agents: The Next Layer of Identity Governance
New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries
Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack
Russia Used Cellebrite on Jailed Activist’s iPhone Months After Sales Cutoff