The Hacker News
351 briefings written from The Hacker News's reporting, newest first. Each is a plain-language summary written here for Australian business, with a link to the original.
- Microsoft Fixes Maximum-Severity Flaw in Azure AI Foundry
- Old CDN Domain Resold: Thousands of Sites Still Loading Code From a Stranger
- 'Plugin4Shell' Flaw Lets Malicious Code Slip Past Version Locks in AI Coding Agents
- New 'WeaselBiscuit' Malware Found Hidden in 13 npm Packages Targeting Developers
- Fake 'Bug Bounty Hunter' Used AI-Written Malware to Raid npm Developer Secrets
- New Android Malware 'RatHat' Uses AI and Debug Tools to Keep Control After Uninstall
- Critical Check Point Flaw Lets Attackers Take Over Management Servers Without Logging In
- Weekly Threat Roundup: Gaming Videos and 'Trojanized' Software Used to Spread Malware
- Critical Docker Sandboxes Flaw Let Malicious Code Escape to macOS Host Files
- Iran-Linked 'Handala Hack' Group Uses Telegram Backdoor to Steal Passwords and Spy on Targets
- Critical Flaw in Unbound DNS Software Could Let Attackers Run Malicious Code
- New Webinar: How to Tell If a New Vulnerability Can Actually Be Used Against You
- Attackers Exploit New Flaws in Days, Businesses Take Weeks to Patch: Why Pentesting Needs to Change
- China-Linked Hackers Deploy New 'SparroWocky' Backdoor in Latin America Campaign
- OpenAI Discloses Six AI Model Incidents Involving Unauthorised Access and Hidden Failures
- Critical Issabel PBX Flaw Under Active Attack: Hard-Coded Key Lets Hackers Run Commands
- Three Distinct Threat Groups Hit Russian Enterprises With Backdoors, Ransomware and Wipers
- One Malicious Browser Extension Could Hijack AI Assistants in Chrome, Edge, Comet and Opera Neon
- Parallels Desktop Bug Lets Standard Mac Users Grab Root Access, No Fix Yet for Intel Macs
- New Phishing Kit 'N0va' Hijacks Logins by Abusing Real Authentication Systems
- Google Fixes Actively Exploited Pixel Modem Flaw, Patches 109 Other Bugs
- Why Threat Intelligence Alone Isn't Stopping Breaches
- Acronis Warns of Actively Exploited Flaw in cPanel Backup Plugin
- Critical WooCommerce Plugin Flaw Lets Hackers Plant Backdoors on WordPress Sites
- Critical WSO2 API Manager Flaw Under Active Attack: Patch Now
- New KREMLIN Malware Hijacks Chrome and Edge to Steal Banking Logins
- Iran-Linked Malware Spies on Dissidents via Telegram Control
- New BambooToken Malware Hijacks IoT Protocol to Control Windows and Linux Machines
- Why Testing Single Security Techniques Isn't Enough to Stop Real Attacks
- Attackers Are Scanning for Exposed Vite Dev Servers to Steal Cloud Credentials
- Critical LiteSpeed Flaw Could Let One Website Take Over a Shared Server
- Critical Cisco Email Gateway Flaw Under Active Attack: Patch Now
- China-Linked Hackers Chain Chrome and Windows Zero-Days to Deploy New Backdoor
- Attacker Used Legitimate Remote-Access Tool to Maintain Hidden Control Inside Major Thai ISP
- Telegram Desktop Bug Let Hidden Code Steal Messages From Exported Chat Files
- New 'DDRop' Attack Undermines Intel and AMD Confidential Computing Protections
- Suspected Chinese Hackers Exploit Gitea Flaw to Breach 13 Organisations Worldwide
- WordPress Adds Automated Security Scans to Catch Malicious Plugin Updates Before They Go Live
- Fake Twitch 'Enhancement' Extension Steals Account Tokens From 31,000 Users
- Microsoft Warns of AI-Powered CEO Fraud and Passkey Phishing Targeting Cloud Accounts
- CISA Flags Five Actively Exploited Flaws in Artifactory, ScreenConnect and RouterOS
- AI Tools Are Flooding SOCs With Alerts, But Most Are False Alarms
- OpenAI Agent Swarm Linked to Mass RubyGems Spam Attack
- Maximum-Severity GitLab Flaw Under Active Attack Within Hours of Disclosure
- Anthropic Uncovers Large-Scale Effort to Clone Its Claude AI Model
- Anthropic Warns Hackers Are Using Claude AI to Automate Cyber Attacks
- Russian State-Backed Hackers Used Claude AI to Automatically Rebuild Detected Malware
- Why a 'Critical' Vulnerability Alert Might Not Be Your Real Risk
- Hackers Chain Two JFrog Artifactory Bugs to Seize Admin Control and Plant Backdoors
- China-Linked Hacking Group Exploited Popular Chinese Typing Tool to Plant Backdoor
- PaperCut Rolls Out Full Fixes as Attackers Use AI Agents to Exploit Print Software Flaws
- Cisco Firewall Bugs Under Active Attack: Qilin Ransomware and State-Backed Hackers Exploiting Two Flaws
- Fake Browser Extensions Caught Stealing Crypto Wallet Data and Login Tokens
- Scammers Exploit Google Play's Early Access Feature to Spread Fake Reward Apps
- Check Point Patches Two Critical VPN Certificate Flaws Rated 9.8 Severity
- AI-Powered Attacker Compromises 440+ PaperCut Servers Worldwide
- Gigabud Banking Trojan Hides Inside Android Work Profiles to Dodge Bank Security Checks
- CISA Warns of Active Attacks on Cisco, Citrix and Fortinet Flaws, Sets Patch Deadline
- Default Admin Key Left Thousands of AI Gateways Wide Open
- Anthropic Confirms Fourth Real-World Breach Caused by AI Model During Testing
- US Authorities Freeze $52.8 Million Linked to Xinbi Guarantee Scam Network
- BlueMoon Exploit Kit Spreads Across Multiple State-Backed Spy Groups
- Stolen AI Login Tokens Let Hackers Skip Passwords and MFA Entirely
- Webinar Tackles the Toughest Question After a New CVE: Are We Exposed?
- DeepSeek AI Coding Tool Flaw Let Agents Turn Off Their Own Security Sandbox
- Critical Flaw in Alby Hub Bitcoin Wallet Software: Update Now if Internet-Exposed
- US Agencies Warn of Industrial-Scale AI Model Extraction by China-Based Firms
- Google Patches Actively Exploited Chrome Zero-Day: Update Now
- cPanel Patches Flaw Letting a Single Mail Account Seize Root Control of Your Server
- F5 BIG-IP APM Attackers Hide Malware in Memory to Dodge Disk Scans
- Microsoft Defender's ShieldBreak Fix Bypassed: New PoC Shows Flaw Still Exploitable
- Maximum-Severity SAP Flaw Lets Attackers Take Over Systems Without a Password
- Microsoft's Biggest Patch Tuesday Ever: 974 Flaws Fixed, Two Already Under Attack
- Critical N-able N-central Flaw Actively Exploited, CISA Sets Patch Deadline
- New Cybercrime Group 'Slim Spider' Targets Brazilian Banks' Crypto and Instant Payment Systems
- Liquid Network Hackers Return Most of $320M in Bitcoin After Elements Bug Exploit
- Hidden ChatGPT Prompt Could Quietly Leak Your Gmail Data
- AI-Powered Attackers Are Now Stealing Credentials in Hours, Not Days
- Chainguard Hits 1 Billion Build Manifests: What It Means for Software Supply Chain Security
- Critical FreeIPA Bug Lets Anonymous Users Create Their Own Admin Account
- Critical Magento Flaw Under Active Attack: Patch Now to Block Backdoor Installs
- BengalSEO Campaign Poisons Bing Results to Spread MayaBot Malware and Scam Call Centres
- Grindr to Pay £26 Million Over Alleged Sharing of Users' HIV Status Data
- PEEP Malware Turns Chrome and Edge Into Backdoors on Already-Compromised Machines
- Fake IT Help Desk Calls Used to Steal Microsoft 365 Logins and Extort Executives
- Weekly Threat Recap: Trusted Software Turned Malicious, Critical N-central Flaws Under Attack
- One-Size Cloud Security Checklists Don't Work: Each Provider Fails Differently
- Worm-Like Attack Turns ScreenConnect Into a Malware Delivery Chain
- Public Exploit Released for Telerik UI Flaw Chain Enabling Unauthenticated Server Takeover
- N-able Rushes Out Fourth N-central Hotfix in Five Weeks for Critical Unauthenticated RCE Bug
- JSCeal Malware Steals Browser Sessions to Bypass Google Login Security
- MikroTik Router Alert: Attackers Gaining Full Control via Exposed SSH, No Password Needed
- New Malware Toolkit Disables Windows Defender and Updates to Hide a Crypto Miner
- Active Zero-Day Attacks Hit Magento and Adobe Commerce Stores, No Patch Yet
- JetBrains Cadence Breach: Attackers Exploited Unpatched TeamCity to Steal AWS Credentials
- VMware Patches Critical Flaw That Lets VM Users Break Out to the Host Machine
- Trezor Reveals Further 67,000 Customers Affected by ShipMonk Data Breach
- Autonomous AI Agents Found Using Abandoned Wiki as Secret Coordination Board
- Schools and Universities Targeted as Hackers Exploit PaperCut Print Software Flaws
- Phishing Campaign Uses Invisible Characters to Slip Past Email Filters
- PostgreSQL Patches Decade-Old Flaw Allowing Code Execution via Replication Accounts
- Trojanized HAProxy Builds Used to Hijack Web Traffic in South Korea
- 440,000+ Attacks Target Critical WordPress Plugin Flaws — Is Your Site at Risk?
- Plex Patches Multiple Undisclosed Security Flaws — Update Now
- Google Patches Actively Exploited Chrome Zero-Day: Update Now
- OpenAI's New GPT-6 Astra Can Hunt Exploits at Expert Level — Here's What SMBs Need to Know
- Phishing Kits, Dropbox Breach and OAuth Tricks: Weekly Threat Roundup
- Cisco Patches Critical Flaw Allowing Root Access on Nexus 9000 Switches
- BraZetsu Malware Fuels Underground Market for Hacked Windows Computers
- Thomson Reuters Court Software Breach Exposes Sensitive Case Records
- Global Phishing Campaign Abuses Remote Access Tools — US Now the Top Target
- Hackers Exploit Trusted Node.js Tool to Sneak Malware Past Defences
- Shai-Hulud Worm Expands Credential Theft Reach Dramatically
- Pegasus Spyware Used to Target Serbian Student Activist via Zero-Click iPhone Exploit
- Researcher Publishes Proof-of-Concept for CrowdStrike Falcon Privilege Escalation Flaw
- CISA Flags Seven Actively Exploited Vulnerabilities Used to Plant Reverse Shells and Crypto Miners
- Google, Anthropic and OpenAI Roll Out AI Tools to Strengthen Cyber Defence
- Fake Software Download Sites Used to Disable Windows Security Defences
- Malicious Git Configs Can Trick AI Coding Assistants Into Running Attacker Commands
- Government and Education Websites Hijacked to Push Betting Scams
- BGP Hijack Used to Push Malicious Update, Granting Attackers Root Access to Servers
- Fake TV-Streaming Ads on Meta Spread StreamRat Android Trojan
- Securing AI at Speed: What Every Business Needs Before Scaling Up
- SonicWall Patches Two Zero-Day Flaws in SMA 1000 VPN Appliances Actively Exploited by Attackers
- Critical Flaw Chain in GeoNetwork Could Let Attackers Take Over Government Geoportal Systems
- Russian National Extradited to US Over Excel Malware Scheme That Hit Thousands of Freelancers
- AI Tool Used to Adapt Industrial Control System Exploit Across PLC Models
- Critical Flaw in Sangoma Switchvox VoIP Systems Being Actively Exploited
- Long-Running Sality Botnet Dismantled in Global Law Enforcement Operation
- Hackers Race to Exploit Critical JFrog Artifactory Bug Just Days After Patch Release
- Breeze Comet: Financially Motivated Hackers Target Brazilian Payment Systems
- Malicious Packagist Packages Found Targeting Unpatched iPhones to Steal Crypto Wallet Data
- Fake Job Interviews, Real Malware: Iranian Hackers Target Windows, Mac and Linux Users
- Why Hackers Are Choosing Simplicity Over Sophistication: The Rise of 'ClickFix' Attacks
- AI Research Nonprofit METR Hit by API Key Theft, Racks Up $600,000 in Unauthorised AI Usage
- Russia-Linked Hackers Try to Trick AI Security Tools With Fake 'Nuclear Weapon' Prompt
- Critical Flaws in Langflow and Ruby on Rails Under Active Attack
- North Korean Fake Worker Scam Spreads Beyond IT Into Healthcare and Sales
- Weekly Threat Recap: Backdoored Routers, Rogue AI Agents, and Old Bugs Still Doing Damage
- Fake Wallpaper App Used to Sneak ValleyRAT Backdoor Past Antivirus
- Ransomware Gang Weaponises Popular AI Coding Tool in Fresh Attacks
- New Visibility Tools for AI Coding Assistants Highlight a Bigger Identity Problem
- China-Linked 'Fire Ant' Group Targets Cisco Routers to Steal Credentials and Cover Its Tracks
- DoJ Walks Back Claim of Chinese Hack, Clarifies Agencies Were Targeted, Not Breached
- New 'TerminalFix' Attack Tricks Users Into Hacking Their Own PCs via Fake CAPTCHAs
- Critical WordPress Plugin and Theme Bugs Put Sites at Risk of Takeover
- Berlin Government Refuses to Pay Ransom After State Network Data Theft
- Critical Flaw in Cosmos EVM Module Exploited to Drain Funds from Six Blockchains
- Urgent Patch Needed: PaperCut Print Software Flaws Let Hackers Take Over Without Login
- Android 17 to Encrypt Website Visit Data From Network Snoopers
- Critical ownCloud Flaw Exploited in Attack on Philippine Nuclear Research Agency
- 18 Chrome and 1 Edge Extension Caught Stealing Crypto Wallets
- Root-Level Flaws in Unitree G1 Robots Highlight Growing IoT Attack Surface
- Why 'Identity Fabric' Is Becoming a Must-Have for Business Security in 2026
- ServiceNow Patches Critical Flaws Rated Maximum Severity — Act Now if You're Self-Hosted
- Chinese-Made ZBT Routers Found With Hidden Backdoors Allowing Full Remote Takeover
- Critical cPanel Flaw Could Let a Single Hosting Customer Seize Full Server Control
- Urgent: PaperCut Print Software Under Active Attack — Patch Now
- New HOOKEDGE Backdoor Linked to Russian State Hackers Hits European Governments
- OpenAI Admits Its AI Models Exploited Flaws Due to 'Reward Hacking'
- Next.js Rushes Out Fixes for Two Critical Bugs Allowing Remote Takeover
- Weekly Threat Roundup: Massive IoT Botnet, Water System Attacks, and Fake Software Traps SMBs Should Know About
- Security Flaw Found in Amazon's AI Coding Tool Could Leak Sensitive Data
- AI Is Speeding Up Cyberattacks — Is Your Security Ready to Keep Pace?
- Two Australians Charged Over Alleged TeamPCP Supply Chain Hacking Attacks
- AI Is Now a Daily Tool for Nearly Half of Security Teams, New Report Finds
- New Malware Campaign Disables Security Software Using a Trusted Driver
- New GoCaracal Malware Uses Ethereum Blockchain to Hide Its Command Servers
- GPUThor Attack Bypasses ECC Protection on NVIDIA Workstation GPUs
- US Cybersecurity Agency Flags Six Actively Exploited Vulnerabilities, Including Citrix NetScaler Flaw
- FBI Takes Down Chinese Hacking Infrastructure Targeting US Critical Networks
- Iranian State-Backed Hackers Add New Backdoor and Tunneling Tool to Arsenal
- New Phishing Toolkit 'NovaCookies' Hijacks Microsoft 365 Logins via Fake Docusign Alerts
- CISA Red Team Breaches Two Critical Infrastructure Firms — One Never Noticed
- Unpatched Flaws in Popular Video Player Software Could Let Hackers Steal Files and Run Code
- AI Is Rewriting the Rulebook for Security Operations Centres
- AI Agent 'Cheats' Booking Limits: What the Claude Gym-Booking Test Means for Your Business
- OpenAI Shuts Down Russian Influence Campaign Using ChatGPT
- INTERPOL Crackdown Nets 58 Arrests in Global Cyber Fraud Operation
- New 'SLEEPWALKER' Backdoor Hides Silently Until a Secret Signal Activates It
- Critical Gitea Flaw Under Active Attack — Patch Now Before It Drops Malware
- AI Voice Scam Targets Stolen iPhone Owners to Bypass Apple's Security Lock
- US Treasury Sanctions Iran-Linked Hackers Over Critical Infrastructure Attacks
- Security Flaw in NVIDIA's NemoClaw Could Let Hackers Hijack Local AI Models
- WhatsApp Now Supports Multiple Passkeys for Stronger, Phishing-Resistant Logins
- Security Flaw in Marimo Notebooks Allowed Malicious Commands to Run Automatically
- Phishing Kit 'Mirage2FA' Bypasses Two-Factor Authentication, Hits 4,500 Companies
- Fake npm Packages Used to Host Phishing CAPTCHA Scams
- New RATs Hide Commands Inside FTP Server Banners
- AI Is Reshaping Vulnerability Management for Businesses of All Sizes
- Hackers Actively Exploiting WordPress SAML Login Plugin Flaws
- Critical Oracle WebLogic Vulnerability Under Active Attack—Patch Now
- Fake Minecraft Downloads Used to Spread 'Weedhack' Malware
- Cybercriminals Get Smarter: AI, Trusted Tools and Old Vulnerabilities Fuel New Wave of Attacks
- New Malware Loaders WordlistLoader and SynkLoader Target Windows Users
- AI Coding Tools Are Boosting Productivity — But Also Piling Up Security Debt
- Critical Keycloak Flaw Lets Hackers Hijack Accounts Without a Password
- Chinese Hackers Use Fake Graduation Invites to Breach Myanmar Government Systems
- The Hidden Danger of AI 'Super-Users' in Your Business
- Chinese Cybercrime Group Uses AI to Supercharge Attacks on Web Servers
- TikTok to Pay $400 Million Over Child Privacy Violations
- AI-Powered Backdoor Hidden in Fake npm Packages Targets Linux Systems
- Microsoft Defender's Own Driver Can Be Turned Into a Security-Killing Tool
- New Android Malware Targets In-Car Entertainment Systems for Ad Fraud and Proxy Networks
- AI-Powered Security Tools Are Changing How Businesses Detect Cyber Threats
- Cisco Issues Urgent Patches for Nine Flaws, Five Rated Maximum Severity
- Critical GitLab Flaw Under Active Attack — Patch Immediately
- Critical Microsoft Entra ID Flaw Exploited in the Wild — But No Action Needed From Customers
- Malicious Code Found in Popular Rust Software Libraries Used by Millions
- Suspected Russian Hackers Exploit Google and WhatsApp Login Features to Hijack Accounts
- Trusted Tools, New Tricks: This Week's Cyber Threats Exploit What You Already Rely On
- US Warns of AI-Generated Malware Targeting Critical Infrastructure Systems
- Researchers Find Way to Trick Grok Chatbot Into Leaking Private Chat Data
- Critical Flaw Found in Popular JavaScript Sandbox Tool 'isolated-vm'
- Citrix Patches Critical Authentication Bypass Flaw in NetScaler Products
- Unpatched Zimbra Servers Under Active Attack: What SMBs Need to Know
- ‘Zombie Card’ Attack Shows Expired Visa Cards Can Be Tricked Into Working Again
- 'Shady AI' Emerges as a Major Governance Risk for Businesses
- New 'CDN Tsunami' Attack Method Could Massively Amplify Website Outages
- New 'Manic' Android Malware Blends Banking Fraud with Spyware Tactics
- Critical Flaws Found in NASA Spacecraft Control Software Could Allow Unauthorized Commands
- New ToxicPanda 2.0 Android Malware Escalates Banking Fraud Threats Worldwide
- 40 Fake Firefox Extensions Found Stealing Cryptocurrency Wallet Data
- Critical Elementor Pro Flaw Lets Hackers Take Over WordPress Sites Without Logging In
- Researchers Demonstrate Data-Leaking Attack on Cloudflare Workers
- OpenAI Pauses AI Training to Strengthen Safety Monitoring
- New Espionage Campaign 'SilkParasite' Deploys Five Undocumented Hacking Tools
- Over 14,500 Dahua Cameras Hacked in Global Attack Campaign
- Phishing 3.0: When AI Attackers Meet AI Defenders
- Nearly 2,000 Hacked WordPress Sites Turned Into Malware Distribution Network
- CISA Flags Four Critical Flaws Under Active Attack — Patch Now
- Microsoft Uncovers 30+ Domains Linked to New Mac-Targeting Malware
- Hackers Deploy Custom Web Shell to Steal Engineering Data via PTC Windchill Flaw
- One Click, Data Gone: Flaws Found in Microsoft Copilot Personal
- Hackers Actively Exploiting AI and Industrial Software Flaws to Steal Cloud Credentials
- New Scam Alert: 'Ransom Busters' Preys on Ransomware Victims with Fake Recovery Offers
- Researchers Warn AI Coding Agents Can Catch and Spread 'Mind Viruses'
- New Malware 'TWINLOOT' Hides Inside Microsoft SharePoint and Teams to Steal Passwords
- Fake RubyGems Packages Caught Stealing Browser Data and Crypto Wallets
- One Attacker's Server Has Been Quietly Scraping Salesforce and ServiceNow Data for Over a Year
- SafePal Data Exposure Hits Nearly 40,000 Customers Due to Order-Tracking Flaw
- US Cybersecurity Agency Warns of Actively Exploited Flaw in AI Framework 'Ray'
- Critical GitLab Flaw Could Let Hackers Delete Projects Without Logging In
- GitHub Workflow Flaw in Snowflake Repo Shows Risk of Automated Issue Handling
- Critical WordPress Plugin Flaw Puts 600,000+ Sites at Risk of Takeover
- Iranian Hackers Refine 'Cavern' Malware to Hide Inside Everyday Web Traffic
- Weekly Threat Recap: Old Bugs, Exposed Services and Browser Hijacks Keep Costing Businesses
- AI Assistants Could Be Leaking Your Business Secrets Without You Knowing
- Unresolved Unisoc Modem Flaw Lets Attackers Take Over Android Devices via Video Call
- New Linux Botnet 'Evooo1Bot' Hijacks Vulnerable Devices for Proxy Networks
- Suspected China-Linked Hackers Exploit Critical VMware vCenter Flaw to Deploy Ransomware
- Critical SAP Commerce Cloud Flaw Under Active Attack — Patch Immediately
- Critical macOS Screen Sharing Bug Actively Exploited to Install Crypto Miners
- Cybercriminals Spend Millions Buying Expired Domains to Spread Scams and Malware
- Why Identity and Access Management Is Now a Compliance Must-Have
- Chinese Hacking Group Adds Stealth Rootkit to Evade Detection
- New Attack Technique Lets Hackers Hijack Your Logged-In Browser Sessions
- Fake Job Interview Pages Used to Steal Google and Facebook Logins in Global Phishing Campaign
- Apple Alerts Users in 110 Countries to Possible Spyware Targeting
- Hackers Actively Targeting SharePoint Flaw After Exploit Code Goes Public
- North Korean Hackers Exploited Windows Zero-Day to Plant New Backdoor
- 737 Fake VPN Extensions Found Hijacking Browser Traffic in Chrome Web Store
- Flaw in Major AI Providers' APIs Exposed Hidden Reasoning Data, Including Secrets
- Businesses Getting Better at Blocking Attacks – But Attackers Are Slipping Through the Cracks Anyway
- Adobe Issues Urgent Patches for Critical ColdFusion and Campaign Classic Vulnerabilities
- Critical VMware vCenter Flaw Now Under Active Attack, Giving Hackers Persistent Access
- Brief but Dangerous: Malicious LiteLLM Package May Have Hit 2,100+ Organisations
- Critical SAP Commerce Cloud Flaw Rated Maximum Severity — Patch Now
- New 'ShieldBreak' Exploit Bypasses Windows Defender Patch, Grants Full System Access
- Cisco Firewall Flaw Being Actively Exploited to Crash Devices
- Microsoft's Latest Patch Tuesday Fixes 398 Bugs — One Already Under Attack
- New Kimwolf v7 Botnet Disguises DDoS Attacks as Normal Web Traffic
- Zoom's Drawing Tool Had a Dangerous Flaw — Update Now
- Fake Job Interviews Used to Trick IT Workers Into Installing Malicious VPN Software
- AI-Discovered Flaw Lets Attackers Break Into Microsoft SharePoint Without a Password
- DeadLock Ransomware Gang Uses Blockchain Tech to Dodge Takedowns
- OpenAI Releases Cybersecurity-Focused AI Model with Fewer Safety Restrictions
- Malicious SIM Cards Can Hijack IoT Devices Like EV Chargers and Industrial Routers
- Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Accidental Exposure
- Fake Crypto Startup Sting Exposes North Korean Fake IT Workers
- Fake USB Devices Can Trick Windows 11 Into Handing Over Full Control
- AI Coding Assistants Tricked Into Leaking Secrets via 'Split Instruction' Attacks
- Gunra Ransomware Targets Fortinet and Schneider Electric Vulnerabilities to Infiltrate Networks
- Hackers Shut Down Turbine at Polish Power Plant via Private Cellular Network
- WordPress Plugin Vendor BdThemes Hit by Supply Chain Attack, Creating Rogue Admin Accounts
- New China-Linked Ransomware 'StormEncryptor' Signals Evolving Threat to Businesses
- Weekly Threat Recap: AI Risks, a Metabase Zero-Day, and Router Backdoors Highlight Basic Security Gaps
- North Korean Hackers Go Offline with Custom AI to Supercharge Cyberattacks
- Passkeys Aren't Bulletproof: New Research Shows Ways Attackers Can Bypass Them
- AI Is Supercharging Software Development — Is Your Security Keeping Pace?
- Hackers Exploit Unpatched TrueConf Servers to Deliver Malicious Installers
- Fake VS Code Extension 'Solidity Pro' Caught Stealing Crypto Wallets and Credentials
- OpenAI Hits Pause on New AI Model After It Shows Alarming Cybersecurity Skills
- Atlassian's AI Assistant Rovo Could Be Tricked Into Leaking Jira and Confluence Data
- Hidden CSS Tricks in Emails Can Steal Passwords Across Major Webmail Platforms
- Critical Metabase Flaw Being Actively Exploited — Patch Immediately
- N-able Rushes Second Hotfix as Hackers Continue Targeting N-central RMM Tool
- Critical Flaw in Progress Kemp LoadMaster Added to US Government's Actively Exploited Vulnerabilities List
- Nearly 800 Fake npm Packages Caught Spreading Malware Across Windows, Mac and Linux
- New Mac Malware Uses Fake 'Fix It' Prompts to Steal Crypto and Passwords
- Fake IT Help Desk Calls Used to Steal Corporate Cloud Data, Researchers Warn
- Critical WordPress Flaw Could Let Hackers Take Over Your Website — Update Now
- Open Source Software Is Growing Up: What That Means for Small Businesses
- Decades-Old Linux Kernel Flaw Lets Attackers Escape Containers and Seize Root Access
- Phishing Attack Hijacks Microsoft 365 Accounts to Spy on Payroll and Finance Emails
- AI Research Tool Uncovers New Web Attack Techniques, Including Apache Zero-Day
- NatJack Attacks Exploit NAT Tables to Hijack Connections and Spoof DNS
- Windows Hello for Business Flaw Lets Malware Hijack Cloud Logins
- GitHub Issues Used to Hijack AI Coding Assistants' CI Pipelines
- Hacking Group 'TeamPCP' Has Been Quietly Attacking Servers Since 2020, Researchers Find
- New 'Zapscape' Flaw Could Let Attackers Break Out of Virtual Machines
- Cisco Fixes 12 Security Flaws in SD-WAN and IOS XE Software, Three Rated Critical
- Researchers Find New Way to Sneak Past Intel and AMD's Spectre Chip Defenses
- ThreatsDay Roundup: RCE Flaws, One-Click Exploits, and Trusted Tools Turned Against You
- Thousands of Rockwell Industrial Controllers Found Exposed Online, Including Near Water Utility Attacks
- Weak Random Number Bug in Popular Crypto Library Linked to $5.7 Million in Wallet Thefts
- Apple's iCloud Private Relay Can Leak Your Real IP Address, Researchers Warn
- 'Ask AI' Buttons Could Be Quietly Manipulating Your AI Assistant
- Hackers Exploit SQL Injection to Hijack Oracle Databases and Gain Full System Control
- Security Gaps in AWS, Google and Vercel AI Agent Tools Could Let Attackers Bypass Safety Checks
- Chinese Router Maker Zbtlink Caught Shipping Devices With Built-In Backdoor
- Ransomware-as-a-Service Kingpin Sentenced to 16 Years in Landmark US Case
- US Cybersecurity Agency Warns of Active Attacks on JetBrains TeamCity Servers
- Hacker Pleads Guilty in Massive Data Breach Affecting 100 Million People
- Fake 'ClickFix' Sites Now Screen Visitors Before Delivering Mac Malware
- OpenAI Shuts Down Cambodia-Based Scam Network Abusing ChatGPT
- Warning: Discounted 'Claude' AI Access Sold on Cybercrime Forums Puts User Data at Risk
- Security Flaws in Paperclip AI Agent Platform Could Let Attackers Run Malicious Commands
- Critical Flaws Patched in Veeam, HashiCorp Terraform MCP, and Django - Update Now
- Hackers Hide Malicious Server Addresses Inside Fake Ethereum Transactions
- Linux Kernel Flaw Lets Local Users Seize Full Control of Systems
- New Phishing Kit 'Kali365' Tricks Users Into Approving Attacker Logins on Real Microsoft Pages
- Critical Gitea Vulnerability Lets Attackers Steal Server Files Without Logging In
- Exposed n8n API Tokens Put Automation Workflows at Risk
- 77 Fake Extensions Caught Stealing Developer Data from Open VSX Marketplace
- AI Agent Caught Trying to Sneak Malware Into Open-Source Software — Then Covered Its Tracks
- US Cyber Agency Warns of Active Attacks on Langflow, Tomcat, and N-central Software
- Supply Chain Attack Hits QuickFox VPN Users with Hidden Backdoor
- Popular Phishing Toolkit Now Bypasses MFA Using a New Trick
- Massive npm Supply Chain Attack Hits Hundreds of Packages via Keyv Worm
- Beware Fake Adobe and Zoom Update Pop-Ups Hiding Remote Access Malware
- AI 'Vibe Hacking': How Cybercriminals Are Using AI as a Built-In Hacking Assistant
- Google Pulls AI Agent Workflows After Researchers Expose Prompt-Injection Flaw
- cPanel Fixes Critical Flaw Allowing Hosting Customers to Run SQL as Database Root
- New Russian 'DOUBLECUP' Malware Service Hides Malicious Code in Cached Images
- CISA Warns: N-able N-central Flaw Actively Exploited, Patch Now
- Malicious npm Packages Target Alibaba Developer Tool Users With Hidden Remote Access Trojan
- Malware Could Bypass Passkey Security in Google Password Manager, Researchers Warn
- INC Ransomware Gang Ramping Up Attacks on SonicWall VPN Flaws
- This Week in Cyber: AI Overreach, an $88M Crypto Heist, and the Danger of Forgotten Digital Access
- AI Tools Are Reshaping Security Operations—But Where They Fit Matters Most