Category: Hacker News

When Cloud Outages Ripple Across the Internet
APT28 Uses Microsoft Office CVE-2026-21509 in Espionage-Focused Malware Attacks
Mozilla Adds One-Click Option to Disable Generative AI Features in Firefox
Notepad++ Hosting Breach Attributed to China-Linked Lotus Blossom Hacking Group
Researchers Find 341 Malicious ClawHub Skills Stealing Data from OpenClaw Users
OpenClaw Bug Enables One-Click Remote Code Execution via Malicious Link
Microsoft Begins NTLM Phase-Out With Three-Stage Plan to Move Windows to Kerberos
Securing the Mid-Market Across the Complete Threat Lifecycle
⚡ Weekly Recap: Proxy Botnet, Office Zero-Day, MongoDB Ransoms, AI Hijacks & New Threats
Notepad++ Official Update Mechanism Hijacked to Deliver Malware to Select Users
eScan Antivirus Update Servers Compromised to Deliver Multi-Stage Malware
Open VSX Supply Chain Attack Used Compromised Dev Account to Spread GlassWorm
Iran-Linked RedKitten Cyber Campaign Targets Human Rights NGOs and Activists
Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms
CERT Polska Details Coordinated Cyber Attacks on 30+ Wind and Solar Farms
Researchers Uncover Chrome Extensions Abusing Affiliate Links and Stealing ChatGPT Access
China-Linked UAT-8099 Targets IIS Servers in Asia with BadIIS SEO Malware
Badges, Bytes and Blackmail

Badges, Bytes and Blackmail

SmarterMail Fixes Critical Unauthenticated RCE Flaw with CVSS 9.3 Score
Ex-Google Engineer Convicted for Stealing 2,000 AI Trade Secrets for China Startup
Two Ivanti EPMM Zero-Day RCE Flaws Actively Exploited, Security Updates Released
Researchers Find 175,000 Publicly Exposed Ollama AI Servers Across 130 Countries
ThreatsDay Bulletin: New RCEs, Darknet Busts, Kernel Bugs & 25+ More Stories
Survey of 100+ Energy Systems Reveals Critical OT Cybersecurity Gaps
3 Decisions CISOs Need to Make to Prevent Downtime Risk in 2026
SolarWinds Fixes Four Critical Web Help Desk Flaws With Unauthenticated RCE and Auth Bypass
Google Disrupts IPIDEA — One of the World’s Largest Residential Proxy Networks
Russian ELECTRUM Tied to December 2025 Cyber Attack on Polish Power Grid
Fake Moltbot AI Coding Assistant on VS Code Marketplace Drops Malware
Mustang Panda Deploys Updated COOLCLIENT Backdoor in Government Cyber Attacks
From Triage to Threat Hunts: How AI Accelerates SecOps
Two High-Severity n8n Flaws Allow Authenticated Remote Code Execution
Critical vm2 Node.js Flaw Allows Sandbox Escape and Arbitrary Code Execution
Fake Python Spellchecker Packages on PyPI Delivered Hidden Remote Access Trojan
Password Reuse in Disguise: An Often-Missed Risky Workaround
Google Warns of Active Exploitation of WinRAR Vulnerability CVE-2025-8088
Fortinet Patches CVE-2026-24858 After Active FortiOS SSO Exploitation Detected
WhatsApp Rolls Out Lockdown-Style Security Mode to Protect Targeted Users From Spyware
Experts Detect Pakistan-Linked Cyber Campaigns Aimed at Indian Government Entities
ClickFix Attacks Expand Using Fake CAPTCHAs, Microsoft Scripts, and Trusted Web Services
CTEM in Practice: Prioritization, Validation, and Outcomes That Matter
China-Linked Hackers Have Used the PeckBirdy JavaScript C2 Framework Since 2023
Critical Grist-Core Vulnerability Allows RCE Attacks via Spreadsheet Formulas
Microsoft Office Zero-Day (CVE-2026-21509) – Emergency Patch Issued for Active Exploitation
Indian Users Targeted in Tax Phishing Campaign Delivering Blackmoon Malware
Malicious VS Code AI Extensions with 1.5 Million Installs Steal Developer Source Code
⚡ Weekly Recap: Firewall Flaws, AI-Built Malware, Browser Traps, Critical CVEs & More
Winning Against AI-Based Attacks Requires a Combined Defensive Approach
Konni Hackers Deploy AI-Generated PowerShell Backdoor Against Blockchain Developers
Multi-Stage Phishing Campaign Targets Russia with Amnesia RAT and Ransomware