Category: Hacker News

The Time-Saving Guide for Service Providers: Automating vCISO and Compliance Services
Watch Out for Salty2FA: New Phishing Kit Targeting US and EU Enterprises
Adobe Commerce Flaw CVE-2025-54236 Lets Hackers Take Over Customer Accounts
SAP Patches Critical NetWeaver (CVSS Up to 10.0) and Previously Exploited S/4HANA Flaws
Axios Abuse and Salty 2FA Kits Fuel Advanced Microsoft 365 Phishing Attacks
RatOn Android Malware Detected With NFC Relay and ATS Banking Fraud Capabilities
From MostereRAT to ClickFix: New Malware Campaigns Highlight Rising AI and Phishing Risks
TOR-Based Cryptojacking Attack Expands Through Misconfigured Docker APIs
[Webinar] Shadow AI Agents Multiply Fast —  Learn How to Detect and Control Them
How Leading CISOs are Getting Budget Approval
20 Popular npm Packages With 2 Billion Weekly Downloads Compromised in Supply Chain Attack
45 Previously Unreported Domains Expose Longstanding Salt Typhoon Cyber Espionage
GitHub Account Compromise Led to Salesloft Drift Breach Affecting 22 Companies
GPUGate Malware Uses Google Ads and Fake GitHub Commits to Target IT Firms
⚡ Weekly Recap: Drift Breach Chaos, Zero-Days Active, Patch Warnings, Smarter Threats & More
You Didn’t Get Phished — You Onboarded the Attacker
Noisy Bear Targets Kazakhstan Energy Sector With BarrelFire Phishing Campaign
Malicious npm Packages Impersonate Flashbots, Steal Ethereum Wallet Keys
CISA Orders Immediate Patch of Critical Sitecore Vulnerability Under Active Exploitation
TAG-150 Develops CastleRAT in Python and C, Expanding CastleLoader Malware Operations
SAP S/4HANA Critical Vulnerability CVE-2025-42957 Exploited in the Wild
Automation Is Redefining Pentest Delivery
VirusTotal Finds 44 Undetected SVG Files Used to Deploy Base64-Encoded Phishing Pages
Russian APT28 Deploys “NotDoor” Outlook Backdoor Against Companies in NATO Countries
GhostRedirector Hacks 65 Windows Servers Using Rungan Backdoor and Gamshen IIS Module
Simple Steps for Attack Surface Reduction
Google Fined $379 Million by French Regulator for Cookie Consent Violations
CISA Flags TP-Link Router Flaws CVE-2023-50224 and CVE-2025-9377 as Actively Exploited
Cybercriminals Exploit X’s Grok AI to Bypass Ad Protections and Spread Malware to Millions
Iranian Hackers Exploit 100+ Embassy Email Accounts in Global Phishing Targeting Diplomats
Threat Actors Weaponize HexStrike AI to Exploit Citrix Flaws Within a Week of Disclosure
Detecting Data Leaks Before Disaster
Android Security Alert: Google Patches 120 Flaws, Including Two Zero-Days Under Attack
Malicious npm Packages Exploit Ethereum Smart Contracts to Target Crypto Developers