Category: Hacker News

What to Look for in an Exposure Management Platform (And What Most of Them Get Wrong)
Critical cPanel Authentication Vulnerability Identified — Update Your Server Immediately
CISA Adds Actively Exploited ConnectWise and Windows Flaws to KEV
LiteLLM CVE-2026-42208 SQL Injection Exploited within 36 Hours of Disclosure
Researchers Discover Critical GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git Push
Brazilian LofyGang Resurfaces After Three Years With Minecraft LofyStealer Campaign
VECT 2.0 Ransomware Irreversibly Destroys Files Over 131KB on Windows, Linux, ESXi
Why Secure Data Movement Is the Zero Trust Bottleneck Nobody Talks About
After Mythos: New Playbooks For a Zero-Window Era
Critical Unpatched Flaw Leaves Hugging Face LeRobot Open to Unauthenticated RCE
Chinese Silk Typhoon Hacker Extradited to U.S. Over COVID Research Cyberattacks
Microsoft Confirms Active Exploitation of Windows Shell CVE-2026-32202
Microsoft Patches Entra ID Role Flaw That Enabled Service Principal Takeover
Checkmarx Confirms GitHub Repository Data Posted on Dark Web After March 23 Attack
⚡ Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More
PhantomCore Exploits TrueConf Vulnerabilities to Breach Russian Networks
Researchers Uncover 73 Fake VS Code Extensions Delivering GlassWorm v2 Malware
Mythos Changed the Math on Vulnerability Discovery. Most Teams Aren’t Ready for the Remediation Side
Fake CAPTCHA IRSF Scam and 120 Keitaro Campaigns Drive Global SMS, Crypto Fraud
Researchers Uncover Pre-Stuxnet ‘fast16’ Malware Targeting Engineering Software
CISA Adds 4 Exploited Flaws to KEV, Sets May 2026 Federal Deadline
FIRESTARTER Backdoor Hit Federal Cisco Firepower Device, Survives Security Patches
NASA Employees Duped in Chinese Phishing Scheme Targeting U.S. Defense Software
Bridging the AI Agent Authority Gap: Continuous Observability as the Decision Engine
26 FakeWallet Apps Found on Apple App Store Targeting Crypto Seed Phrases
Tropic Trooper Uses Trojanized SumatraPDF and GitHub to Deploy AdaptixC2
LMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of Disclosure
UNC6692 Impersonates IT Helpdesk via Microsoft Teams to Deploy SNOW Malware
ThreatsDay Bulletin: $290M DeFi Hack, macOS LotL Abuse, ProxySmart SIM Farms +25 New Stories
Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign
Project Glasswing Proved AI Can Find the Bugs. Who’s Going to Fix Them?
[Webinar] Mythos Reality Check: Beating Automated Exploitation at AI Speed
China-Linked GopherWhisper Infects 12 Mongolian Government Systems with Go Backdoors
Vercel Finds More Compromised Accounts in Context.ai-Linked Breach
Apple Patches iOS Flaw That Stored Deleted Signal Notifications in FBI Forensic Case
Self-Propagating Supply Chain Worm Hijacks npm Packages to Steal Developer Tokens
Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain
Harvester Deploys Linux GoGra Backdoor in South Asia Using Microsoft Graph API
Toxic Combinations: When Cross-App Permissions Stack into Risk
Lotus Wiper Malware Targets Venezuelan Energy Systems in Destructive Attack
Microsoft Patches Critical ASP.NET Core CVE-2026-40372 Privilege Escalation Bug
Cohere AI Terrarium Sandbox Flaw Enables Root Code Execution, Container Escape
Mustang Panda’s New LOTUSLITE Variant Targets India Banks, South Korea Policy Circles
SystemBC C2 Server Reveals 1,570+ Victims in The Gentlemen Ransomware Operation
Ransomware Negotiator Pleads Guilty to Aiding BlackCat Attacks in 2023
22 BRIDGE:BREAK Flaws Expose 20,000 Lantronix and Silex Serial-to-IP Converters
5 Places where Mature SOCs Keep MTTR Fast and Others Waste Time
Google Patches Antigravity IDE Flaw Enabling Prompt Injection Code Execution
No Exploit Needed: How Attackers Walk Through the Front Door via Identity-Based Attacks
NGate Campaign Targets Brazil, Trojanizes HandyPay to Steal NFC Data and PINs