Category: Hacker News

ThreatsDay Bulletin: AI Prompt RCE, Claude 0-Click, RenEngine Loader, Auto 0-Days & 25+ Stories
The CTEM Divide: Why 84% of Security Programs Are Falling Behind
83% of Ivanti EPMM Exploits Linked to Single IP on Bulletproof Hosting Infrastructure
Apple Fixes Exploited Zero-Day Affecting iOS, macOS, and Apple Devices
First Malicious Outlook Add-In Found Stealing 4,000+ Microsoft Credentials
APT36 and SideCopy Launch Cross-Platform RAT Campaigns Against Indian Entities
Over 60 Software Vendors Issue Security Fixes Across OS, Cloud, and Network Platforms
SSHStalker Botnet Uses IRC C2 to Control Linux Systems via Legacy Kernel Exploits
Exposed Training Open the Door for Crypto-Mining in Fortune 500 Cloud Environments
Microsoft Patches 59 Vulnerabilities Including Six Actively Exploited Zero-Days
North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations
DPRK Operatives Impersonate Professionals on LinkedIn to Infiltrate Companies
From Ransomware to Residency: Inside the Rise of the Digital Parasite
Reynolds Ransomware Embeds BYOVD Driver to Disable EDR Security Tools
Warlock Ransomware Breaches SmarterTools Through Unpatched SmarterMail Server
ZAST.AI Raises $6M Pre-A to Scale “Zero False Positive” AI-Powered Code Security
Dutch Authorities Confirm Ivanti Zero-Day Exploit Exposed Employee Contact Data
Fortinet Patches Critical SQLi Flaw Enabling Unauthenticated Code Execution
China-Linked UNC3886 Targets Singapore Telecom Sector in Cyber Espionage Campaign
SolarWinds Web Help Desk Exploited for RCE in Multi-Stage Attacks on Exposed Servers
⚡ Weekly Recap: AI Skill Malware, 31Tbps DDoS, Notepad++ Hack, LLM Backdoors and More
How Top CISOs Solve Burnout and Speed up MTTR without Extra Hiring
Bloody Wolf Targets Uzbekistan, Russia Using NetSupport RAT in Spear-Phishing Campaign
TeamPCP Worm Exploits Cloud Infrastructure to Build Criminal Infrastructure
BeyondTrust Fixes Critical Pre-Auth RCE Vulnerability in Remote Support and PRA
OpenClaw Integrates VirusTotal Scanning to Detect Malicious ClawHub Skills
German Agencies Warn of Signal Phishing Targeting Politicians, Military, Journalists
China-Linked DKnife AitM Framework Targets Routers for Traffic Hijacking, Malware Delivery
Asian State-Backed Group TGR-STA-1030 Breaches 70 Government, Infrastructure Entities
CISA Orders Removal of Unsupported Edge Devices to Reduce Federal Network Risk
How Samsung Knox Helps Stop Your Network Security Breach
Compromised dYdX npm and PyPI Packages Deliver Wallet Stealers and RAT Malware
Claude Opus 4.6 Finds 500+ High-Severity Flaws Across Major Open-Source Libraries
AISURU/Kimwolf Botnet Launches Record-Setting 31.4 Tbps DDoS Attack
ThreatsDay Bulletin: Codespaces RCE, AsyncRAT C2, BYOVD Abuse, AI Cloud Intrusions & 15+ Stories
Infy Hackers Resume Operations with New C2 Servers After Iran Internet Blackout Ends
The Buyer’s Guide to AI Usage Control
Malicious NGINX Configurations Enable Large-Scale Web Traffic Hijacking Campaign
Critical n8n Flaw CVE-2026-25049 Enables System Command Execution via Malicious Workflows
Microsoft Develops Scanner to Detect Backdoors in Open-Weight Large Language Models
DEAD#VAX Malware Campaign Deploys AsyncRAT via IPFS-Hosted VHD Phishing Files
China-Linked Amaranth-Dragon Exploits WinRAR Flaw in Espionage Campaigns
Orchid Security Introduces Continuous Identity Observability for Enterprise Applications
The First 90 Seconds: How Early Decisions Shape Incident Response Investigations
Microsoft Warns Python Infostealers Target macOS via Fake Ads and Installers
Eclipse Foundation Mandates Pre-Publish Security Checks for Open VSX Extensions
CISA Adds Actively Exploited SolarWinds Web Help Desk RCE to KEV Catalog
Docker Fixes Critical Ask Gordon AI Flaw Allowing Code Execution via Image Metadata
[Webinar] The Smarter SOC Blueprint: Learn What to Build, Buy, and Automate
Hackers Exploit Metro4Shell RCE Flaw in React Native CLI npm Package