Category: Hacker News

OceanLotus Hits Vietnam Investors With SPECTRALVIPER in FireAnt Attack
AI Broke Vulnerability Management. That’s Why CISOs Are Moving Budget to BAS.
GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks
CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active Exploitation
Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities
Unpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCE
China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance
Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs
Your Automated Pentest Looks Clean. See What It Missed in This Expert Webinar
ServiceNow Flaw Exploited to Gain Unauthorized Access to Customer Instances
Anthropic Releases Claude Fable 5, Its Most Powerful AI Yet, With Cyber Safeguards
Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS
Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows
Veeam Backup & Replication RCE Flaw Lets Domain Users Run Remote Code
Meta to Use Off-Site Business Data for Feed and AI Personalization
Microsoft Restores Some GitHub Repos, Keeps Others Offline as Miasma Probe Continues
Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Models
Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild – Patch Now
The Hidden Security Risk in Modern Networks: The Work Between Tools
WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine
New FROST Attack Lets Websites Track What Sites and Apps You Open via SSD Timing
Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer
LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE
One-Character Linux Kernel Flaw Enables Local Root Access, Exploits Now Public
Meta Blocks NSO Group’s New WhatsApp Phishing Attack, Files Contempt Order
Critical Check Point VPN Flaw Exploited to Bypass Passwords in IKEv1 Setups
⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More
The Hardest Fork

The Hardest Fork

AI Phishing Is Crushing SOCs with Alert Volume: How to Reduce Tier 1 Overload
VerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Appliances
VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks
UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign
New ChatGPT Lockdown Mode Limits Tools That Could Enable Data Exfiltration
Free Apps Are Quietly Turning Smart TVs Into Web-Scraping Proxies for AI
CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog
Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack
AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs
Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available
IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks
Android Spyware Asin Targets Arabic Users via Fake News, PDF and War Map Apps
New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework
Only 10% of SOCs Say They’re Getting Excellent Value From AI. Here’s What the Second Wave Has to Deliver
Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites
FIFA World Cup 2026 Scams Are Already Live: Fake Sites, Banking Malware, and Stolen Logins
PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network
Agentic AI Is Transforming Defense, But Only Secure IT Infrastructure Will Maximize It
Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public
Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories
ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New Stories
FlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube Ads