Category: Hacker News

Microsoft Warns of Photo ZIP Phishing Campaign Targeting Hotels with Node.js Implant
Google Details Turla’s New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks
Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability
ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories
Surviving the Mythos Era: Richard Bejtlich on the Case for NDR
New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns
New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis
Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access
CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited
Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered
Dawn of the Apex Agentic Adversary
Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks
DoJ Seizes Huione Cloud Account Tied to Cyber Scam Money Laundering
Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root
FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation
Trump Order Sets 2030 Deadline for Federal Post-Quantum Crypto Migration
Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents
GitHub Updates actions/checkout to Block Common Pwn Request Attack Patterns
Agentic AI: The Weapon That No Longer Needs a Warrior
Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT
WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool
OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws
ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack
Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants
29-Year-Old Squid Proxy Bug ‘Squidbleed’ Can Leak Cleartext HTTP Requests
Stop Your Legacy Infrastructure from Hijacking Your AI Agents
⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More
Google Sets Sept. 30 Deadline for Android Developer Verification in Four Countries
New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer
Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices
AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network
INTERPOL Warns Phishing, Ransomware, and AI Scams Are Rising Across Asia-Pacific
Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys
The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes
Unpatchable ‘usbliter8’ Exploit Breaks Apple A12 and A13 SecureROM Boot Chain
AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution
CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices
Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites
From Assistive to Agentic: The AI Shift That’s Redefining Threat Management
Forget Data Leakage: Shadow AI’s Real Threat Is Access Control
Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data
Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone
F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution
ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories
INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023
Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2
Orphaned AI Agents: How to Find Hidden Access Risks Inside Your Network
DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic
The Scripts on Your Checkout Page Are Now a PCI DSS Problem
Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development