Category: Hacker News

Fortinet Patches CVE-2026-24858 After Active FortiOS SSO Exploitation Detected
WhatsApp Rolls Out Lockdown-Style Security Mode to Protect Targeted Users From Spyware
Experts Detect Pakistan-Linked Cyber Campaigns Aimed at Indian Government Entities
ClickFix Attacks Expand Using Fake CAPTCHAs, Microsoft Scripts, and Trusted Web Services
CTEM in Practice: Prioritization, Validation, and Outcomes That Matter
China-Linked Hackers Have Used the PeckBirdy JavaScript C2 Framework Since 2023
Critical Grist-Core Vulnerability Allows RCE Attacks via Spreadsheet Formulas
Microsoft Office Zero-Day (CVE-2026-21509) – Emergency Patch Issued for Active Exploitation
Indian Users Targeted in Tax Phishing Campaign Delivering Blackmoon Malware
Malicious VS Code AI Extensions with 1.5 Million Installs Steal Developer Source Code
⚡ Weekly Recap: Firewall Flaws, AI-Built Malware, Browser Traps, Critical CVEs & More
Winning Against AI-Based Attacks Requires a Combined Defensive Approach
Konni Hackers Deploy AI-Generated PowerShell Backdoor Against Blockchain Developers
Multi-Stage Phishing Campaign Targets Russia with Amnesia RAT and Ransomware
Who Approved This Agent? Rethinking Access, Accountability, and Risk in the Age of AI Agents
CISA Adds Actively Exploited VMware vCenter Flaw CVE-2024-37079 to KEV Catalog
New DynoWiper Malware Used in Attempted Sandworm Attack on Polish Power Sector
CISA Updates KEV Catalog with Four Actively Exploited Software Vulnerabilities
Phishing Attack Uses Stolen Credentials to Install LogMeIn RMM for Persistent Access
Fortinet Confirms Active FortiCloud SSO Bypass on Fully Patched FortiGate Firewalls
TikTok Forms U.S. Joint Venture to Continue Operations Under 2025 Executive Order
Microsoft Flags Multi-Stage AitM Phishing and BEC Attacks Targeting Energy Firms
New Osiris Ransomware Emerges as New Strain Using POORTRY Driver in BYOVD Attack
Critical GNU InetUtils telnetd Flaw Lets Attackers Bypass Login and Gain Root Access
ThreatsDay Bulletin: Pixel Zero-Click, Redis RCE, China C2s, RAT Ads, Crypto Scams & 15+ Stories
SmarterMail Auth Bypass Exploited in the Wild Two Days After Patch Release
Filling the Most Common Gaps in Google Workspace Security
Malicious PyPI Package Impersonates SymPy, Deploys XMRig Miner on Linux Hosts
Automated FortiGate Attacks Exploit FortiCloud SSO to Alter Firewall Configurations
Cisco Fixes Actively Exploited Zero-Day CVE-2026-20045 in Unified CM and Webex
North Korean PurpleBravo Campaign Targeted 3,136 IP Addresses via Fake Job Interviews
Zoom and GitLab Release Security Updates Fixing RCE, DoS, and 2FA Bypass Flaws
Webinar: How Smart MSSPs Using AI to Boost Margins with Half the Staff
Exposure Assessment Platforms Signal a Shift in Focus
Chainlit AI Framework Flaws Enable Data Theft via File Read and SSRF Bugs
VoidLink Linux Malware Framework Built with AI Assistance Reaches 88,000 Lines of Code
CERT/CC Warns binary-parser Bug Allows Node.js Privilege-Level Code Execution
LastPass Warns of Fake Maintenance Messages Targeting Users’ Master Passwords
North Korea-Linked Hackers Target Developers via Malicious VS Code Projects
Hackers Use LinkedIn Messages to Spread RAT Malware Through DLL Sideloading
Three Flaws in Anthropic MCP Git Server Enable File Access and Code Execution
The Hidden Risk of Orphan Accounts
Evelyn Stealer Malware Abuses VS Code Extensions to Steal Developer Credentials and Crypto
Why Secrets in JavaScript Bundles are Still Being Missed
Cloudflare Fixes ACME Validation Bug Allowing WAF Bypass to Origin Servers
Tudou Guarantee Marketplace Halts Telegram Transactions After Processing Over $12 Billion
Google Gemini Prompt Injection Flaw Exposed Private Calendar Data via Malicious Invites
⚡ Weekly Recap: Fortinet Exploits, RedLine Clipjack, NTLM Crack, Copilot Attack & More
DevOps & SaaS Downtime: The High (and Hidden) Costs for Cloud-First Businesses
New StackWarp Hardware Flaw Breaks AMD SEV-SNP Protections on Zen 1–5 CPUs