§Source · The Hacker News
The Hacker News
Every dispatch we have aggregated from The Hacker News.
All dispatches
Loading
§Source · The Hacker News
Every dispatch we have aggregated from The Hacker News.
All dispatchesCISA added a critical Ray vulnerability to its Known Exploited Vulnerabilities catalog due to observed active exploitation.
Malicious LiteLLM PyPI releases contained credential-stealing code that may have exposed secrets for 2,100+ organizations.
Zoom annotation vulnerabilities could allow meeting participants to take control of other attendees' clients without interaction.
BdThemes supply-chain compromise poisoned JSON feeds to create rogue WordPress admin accounts, backdooring sites without modifying plugin files.
China-linked Storm-1175 deploys StormEncryptor ransomware, likely exploiting an N-able N-central vulnerability to gain initial access.
Windows Plug and Play abuse can fetch signed vendor software and escalate to SYSTEM on fully updated Windows 11 via USB emulation.
Malicious SIM cards can run attacker code on cellular modems inside EV chargers, industrial routers, and telematics units, enabling device takeover.
Attackers used a private cellular network to intrude on a Polish heat-and-power plant, shutting a steam turbine and disrupting treatment systems.
Malware running in a signed Windows session can quietly use Windows Hello for Business keys to authenticate to Entra ID and persist.
Flaws in Claude Code and Google's Gemini CLI let an unprivileged GitHub issue execute code on CI runners and expose secrets.
Analysis links TeamPCP to Redis attacks from 2020 and to later supply-chain campaigns via overlapping infrastructure and domains.
Campaign published nearly 800 malicious npm packages delivering a cross-platform RAT and infostealer for Windows, macOS and Linux.
Active AitM phishing campaign hijacks Microsoft 365 accounts to collect payroll and finance emails using residential proxies.
N-able released hotfixes after active exploitation of N-central enabled persistent attacker access to managed systems.
QuickFox supply-chain compromise trojanized Windows installer to deliver FDMTP backdoor in deployments since at least August 2025.
Attackers used SQL injection to compile khunt toolkit inside Oracle DBs, executing post-exploitation tasks without writing executables to disk.
Agent infrastructure flaws at AWS, Google, and Vercel allow forged instructions to invoke agent tools without model authorization, bypassing guardrails.
Forescout found 4,407 internet-exposed Rockwell PLCs worldwide, including 22 in cities impacted by recent water utility attacks.
Researchers disclosed factory-installed backdoor in Zbtlink routers enabling unauthenticated root shells and persistent beaconing.
Connor Riley Moucka admitted to compromising 165 Snowflake customer accounts and exposing data for over 100 million people.
Get these articles delivered to your inbox.
Subscribe free