Category: Hacker News

Open-Source CyberStrikeAI Deployed in AI-Driven FortiGate Attacks Across 55 Countries
AI Agents: The Next Wave Identity Dark Matter – Powerful, Invisible, and Unmanaged
Starkiller Phishing Suite Uses AitM Reverse Proxy to Bypass Multi-Factor Authentication
Microsoft Warns OAuth Redirect Abuse Delivers Malware to Government Targets
SloppyLemming Targets Pakistan and Bangladesh Governments Using Dual Malware Chains
Google Confirms CVE-2026-21385 in Qualcomm Android Component Exploited
Google Develops Merkle Tree Certificates to Enable Quantum-Resistant HTTPS in Chrome
New Chrome Vulnerability Let Malicious Extensions Escalate Privileges via Gemini Panel
⚡ Weekly Recap: SD-WAN 0-Day, Critical CVEs, Telegram Probe, Smart TV Proxy SDK and More
How to Protect Your SaaS from Bot Attacks with SafeLine WAF
APT28 Tied to CVE-2026-21513 MSHTML 0-Day Exploited Before Feb 2026 Patch Tuesday
North Korean Hackers Publish 26 npm Packages Hiding Pastebin C2 for Cross-Platform RAT
ClawJacked Flaw Lets Malicious Sites Hijack Local OpenClaw AI Agents via WebSocket
Thousands of Public Google Cloud API Keys Exposed with Gemini Access After API Enablement
Pentagon Designates Anthropic Supply Chain Risk Over AI Military Dispute
DoJ Seizes $61 Million in Tether Linked to Pig Butchering Crypto Scams
900+ Sangoma FreePBX Instances Compromised in Ongoing Web Shell Attacks
Malicious Go Crypto Module Steals Passwords, Deploys Rekoobe Backdoor
ScarCruft Uses Zoho WorkDrive and USB Malware to Breach Air-Gapped Networks
Trojanized Gaming Tools Spread Java-Based RAT via Browser and Chat Platforms
Meta Files Lawsuits Against Brazil, China, Vietnam Advertisers Over Celeb-Bait Scams
Aeternum C2 Botnet Stores Encrypted Commands on Polygon Blockchain to Evade Takedown
ThreatsDay Bulletin: Kali Linux + Claude, Chrome Crash Traps, WinRAR Flaws, LockBit & 15+ Stories
UAT-10027 Targets U.S. Education and Healthcare with Dohdoor Backdoor
Expert Recommends: Prepare for PQC Right Now
Expert Recommends: Prepare for PQC Right Now
Malicious StripeApi NuGet Package Mimicked Official Library and Stole API Tokens
Microsoft Warns Developers of Fake Next.js Job Repos Delivering In-Memory Malware
Cisco SD-WAN Zero-Day CVE-2026-20127 Exploited Since 2023 for Admin Access
Google Disrupts UNC2814 GRIDTIDE Campaign After 53 Breaches Across 42 Countries
Claude Code Flaws Allow Remote Code Execution and API Key Exfiltration
SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks
Top 5 Ways Broken Triage Increases Business Risk Instead of Reducing It
Malicious NuGet Packages Stole ASP.NET Data; npm Package Dropped Malware
Manual Processes Are Putting National Security at Risk
Defense Contractor Employee Jailed for Selling 8 Zero-Days to Russian Broker
SolarWinds Patches 4 Critical Serv-U 15.5 Flaws Allowing Root Code Execution
CISA Confirms Active Exploitation of FileZen CVE-2026-25108 Vulnerability
RoguePilot Flaw in GitHub Codespaces Enabled Copilot to Leak GITHUB_TOKEN
UAC-0050 Targets European Financial Institution With Spoofed Domain and RMS Malware
Lazarus Group Uses Medusa Ransomware in Middle East and U.S. Healthcare Attacks
Identity Prioritization isn’t a Backlog Problem – It’s a Risk Math Problem
UnsolicitedBooker Targets Central Asian Telecoms With LuciDoor and MarsSnake Backdoors
Anthropic Says Chinese AI Firms Used 16 Million Claude Queries to Copy Model
APT28 Targeted European Entities Using Webhook-Based Macro Malware
Wormable XMRig Campaign Uses BYOVD Exploit and Time-Based Logic Bomb
⚡ Weekly Recap: Double-Tap Skimmers, PromptSpy AI, 30Tbps DDoS, Docker Malware & More
Malicious npm Packages Harvest Crypto Keys, CI Secrets, and API Tokens
How Exposed Endpoints Increase Risk Across LLM Infrastructure
MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP