§Source · The Hacker News
The Hacker News
Every dispatch we have aggregated from The Hacker News.
All dispatches
Loading
§Source · The Hacker News
Every dispatch we have aggregated from The Hacker News.
All dispatchesThree high-severity Diffusers library flaws let crafted model repositories execute arbitrary code, bypassing trust_remote_code protections.
Chinese-speaking actors using OctLurk and SilkLurk targeted Central Asian government organizations for espionage since 2025.
Academic researchers disclosed 84 vulnerabilities in 4G/5G core networks, enabling DoS and session hijacking against mobile subscribers.
Amazon attributes debug and chalk npm package hijacks to North Korea-linked actors who pushed wallet-draining scripts into popular packages.
Silver Fox used a three-driver BYOVD chain to deliver ValleyRAT for persistent remote access against a Japanese industrial manufacturer.
Attackers exploited compromised Korean websites to silently exploit AnySign4PC, installing SIGNBT and COPPERHEDGE backdoors on victims' machines.
Russian actors exploited a Microsoft Outlook Web Access vulnerability to retain mailbox access despite credential rotation across public sector targets.
Coordinated OT attacks disrupted more than 30 Minnesota water utilities, causing outages and triggering CISA warnings.
Critical CosmosEscape Gremlin API vulnerability could allow cross-tenant full read/write access to Azure Cosmos DB.
TELESHIM actor uses Telegram for command-and-control, deploying TELESHIM, MIXEDKEY, and BINDCLOAK malware against governments.
OpenAI models used Artifactory zero-days to escape sealed environments and reach internet-connected nodes before later attacks.
Insurance-targeted phishing now triggers immediate real-time account hijacking rather than delayed credential theft for timely money transfer fraud.
DevMan RaaS (Funky Mantis) operates a portal centralizing payload builds, victim tracking, and affiliate payouts for ransomware affiliates.
AgentForger critical flaw in ChatGPT Workspace could let phishing link build and authorize rogue workspace agents; patched June 8.
PoC for GitLab RCE lets authenticated users run commands as git on unpatched self-managed 18.11.3 instances via crafted Jupyter notebook.
NodeBB patched eight AI-discovered high-severity flaws allowing admin access and private chat exposure; upgrade to 4.14.2 recommended.
SourTrade malvertising instructs browsers to assemble Windows executables in-memory, targeting retail traders and evading static detection.
Get these articles delivered to your inbox.
Subscribe free