HackMyIP

Cybersecurity News

Latest updates from top security sources

1589 articles, page 1 of 53

2026-09-15The Hacker News
Iranian MOIS Deploys HEAVYGRAM Malware to Spy on Dissidents via Telegram

A joint advisory from the FBI, the U.K.'s National Cyber Security Centre (NCSC), and the Netherlands' AIVD has exposed a Windows malware strain dubbed HEAVYGRAM (also tracked as CH...

MalwareAPTPrivacy
Read More → Use Tool →
2026-09-15The Hacker News
BambooToken Malware Exploits MQTT Protocol to Target Windows and Linux

Security researchers at Lumen Black Lotus Labs have uncovered a sophisticated multi-platform malware campaign dubbed BambooToken, which leverages the lightweight Message Queueing T...

MalwareAPTThreat Intel
Read More → Use Tool →
2026-09-15The Hacker News
Marimo RCE Exploited: Human Attacker Reaches SSH Bastion in 8 Seconds

A new report from Sysdig's Threat Research Team reveals that skilled human attackers can match machine-speed exploitation without any AI assistance. In one documented attack chain,...

VulnerabilityCloud SecurityThreat Intel
Read More → Use Tool →
2026-09-15The Hacker News
Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point

Introduction Security teams have gotten pretty good at testing against what can hurt them. Can this EDR agent catch this payload? Will my organization fail the phishing simulation...

Read More → Use Tool →
2026-09-15The Hacker News
Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers

Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data. The first is an automated effort aimed at in...

Read More → Use Tool →
2026-09-15Dark Reading
VectraRAT Can Hack Windows Enterprises for $250 per Month

The full-service malware-as-a-service (MaaS) platform offers a Windows implant, command-and-control (C2) infrastructure, and an operator panel for comprehensive remote access....

Read More → Use Tool →
2026-09-15SecurityWeek
$1 Million Sandbox Challenge Uncovers Linux Kernel Flaws

AI-assisted researchers flooded Vercel with reports, forcing the company to automate vulnerability triage. The post $1 Million Sandbox Challenge Uncovers Linux Kernel Flaws appeare...

Read More → Use Tool →
2026-09-15SecurityWeek
Exein Secures $270M at $1.7B Valuation for Physical AI Security

The cybersecurity startup is building a proprietary foundation model and plans to accelerate global expansion. The post Exein Secures $270M at $1.7B Valuation for Physical AI Secur...

Read More → Use Tool →
2026-09-15SecurityWeek
Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data

A hacker claims to have stolen 7.5 million customer records after breaching the company’s systems. The post Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data...

Read More → Use Tool →
2026-09-15SecurityWeek
Thai Broadband Provider Hacked via Fortinet Vulnerability

The hackers staged numerous scripts for reconnaissance and CVE probing, along with brute-force utilities and privilege escalation tools. The post Thai Broadband Provider Hacked via...

Read More → Use Tool →
2026-09-15SecurityWeek
OpenAI Investigates Report Linking AI Agents to RubyGems Attack

The incident occurred in May, when RubyGems maintainers suspended new account registrations due to what appeared like malicious activity. The post OpenAI Investigates Report Linkin...

Read More → Use Tool →
2026-09-15The Record
Iranian cyber spies used fake MRI scan results to hack ‘enemy of regime’

According to the United Kingdom’s National Cyber Security Centre (NCSC), Iran has used this and similar cyber activity to “support the repression of individuals who are seen as a t...

Read More → Use Tool →
2026-09-15The Record
Zelensky appoints former police chief to lead Ukraine’s cyber coordination center

Ihor Klymenko, who has experience in law enforcement and as interior minister, will run Ukraine's National Cybersecurity Coordination Center....

Read More → Use Tool →
2026-09-15The Record
Electric and gas utility CenterPoint Energy warns of data breach after dark web post

Houston-based CenterPoint Energy notified federal regulators about an incident that exposed some customer data on the dark web....

Read More → Use Tool →
2026-09-15The Record
China spy chief points at US AI models in cyber threat warning

China's spy chief identified Anthropic’s Claude Mythos and OpenAI’s GPT-5.5-Cyber as signs of what he called a “disruptive upgrade” in cyber capabilities, increasing the speed and ...

Read More → Use Tool →
2026-09-15The Record
Manhattan DA takes down 12 AI deepfake porn sites

Manhattan District Attorney Alvin Bragg held a press conference on Monday touting the takedown of the sites, which hosted AI-generated videos of more than 1,200 people. The sites a...

Read More → Use Tool →
2026-09-15The Hacker News
LiteSpeed Enterprise Flaw Allows Root Access on Shared Hosting Servers

A critical vulnerability in LiteSpeed Web Server Enterprise could allow a low-privilege hosting account to escalate to root access on a shared-hosting server, cPanel warned in an a...

VulnerabilityZero-DayCloud Security
Read More → Use Tool →
2026-09-15The Hacker News
Cisco Secure Email Gateway CVE-2026-76461 Actively Exploited — Patch Now

Cisco has disclosed that a critical vulnerability in AsyncOS Software for Cisco Secure Email Gateway is being actively exploited in the wild, enabling unauthenticated remote attack...

VulnerabilityThreat IntelIncident Response
Read More → Use Tool →
2026-09-15The Hacker News
Chinese APT Exploits Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

A China-linked threat actor tracked as UTA0560 has been observed weaponizing a recently patched zero-day exploit chain dubbed "BlueMoon" to compromise multiple non-governmental org...

Zero-DayAPTPhishing
Read More → Use Tool →
2026-09-15SecurityWeek
Japan Digital Agency Breach Exposes 240,000 via VPN Vulnerability

Japan's Digital Agency has disclosed a major data breach affecting approximately 240,000 individuals, with hackers exploiting a known VPN vulnerability to infiltrate its Government...

Data BreachVulnerabilityIncident Response
Read More → Use Tool →
2026-09-15SecurityWeek
Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases

The updates resolve kernel vulnerabilities that could lead to memory corruption, privilege escalation, system termination, and information leaks. The post Apple Patches 200 Vulnera...

Read More → Use Tool →
2026-09-15SecurityWeek
Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints

The Humanist AI Code of Conduct draws a line between defensive cyber research and operational attack capability. The post Microsoft AI Code of Conduct Sets Cyberattack Boundaries, ...

Read More → Use Tool →
2026-09-15SecurityWeek
Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack

Ads led to a ClickFix page designed to trick macOS and Windows users into installing malware. The post Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack a...

Read More → Use Tool →
2026-09-15SecurityWeek
Cisco Secure Email Gateway Zero-Day CVE-2026-76461 Exploited for Root RCE

Cisco has issued an urgent warning about a critical zero-day vulnerability, tracked as CVE-2026-76461, affecting its Secure Email Gateway (SEG) appliances. The flaw carries a CVSS ...

Zero-DayVulnerabilityAPT
Read More → Use Tool →
2026-09-14The Hacker News
Thai ISP 3BB Hit by MeshCentral Backdoor Targeting Subscriber Credentials

Threat intelligence firm Hunt.io has uncovered a sophisticated intrusion inside the network of 3BB, one of Thailand's largest broadband providers, where an attacker maintained pers...

Data BreachAPTThreat Intel
Read More → Use Tool →
2026-09-14The Hacker News
Telegram Desktop Flaw Let Hidden JavaScript Steal Exported Chat Data

Security researchers Denis Rostilov and Aleksander Rostilov of ExPatch disclosed a high-severity vulnerability in Telegram Desktop that allowed attackers to embed hidden JavaScript...

VulnerabilityPrivacyData Breach
Read More → Use Tool →
2026-09-14Dark Reading
Russian Sandworm APT Chains Cisco Flaws to Deploy Cyclops Blink Malware

Russian state-sponsored threat group Sandworm has been observed chaining vulnerabilities in Cisco devices to deploy Cyclops Blink, an upgraded iteration of the botnet malware that ...

MalwareAPTVulnerability
Read More → Use Tool →
2026-09-14Dark Reading
GitLab CVE-2026-85706: CVSS 10.0 Path Traversal Threatens Supply Chains

A maximum-severity vulnerability in GitLab is putting software supply chains worldwide at imminent risk. Tracked as CVE-2026-85706, the flaw is a path traversal vulnerability carry...

VulnerabilitySupply Chain
Read More → Use Tool →
2026-09-14The Record
Black Axe Members Extradited to U.S. to Face Romance Scam Charges

Five alleged members of the Nigerian-organized Black Axe cybercrime group have been extradited from South Africa to face federal charges in the United States. Perry Osagiede, Frank...

PhishingThreat IntelIncident Response
Read More → Use Tool →
2026-09-14The Hacker News
DDRop Attack Breaks Confidential Computing on Intel TDX and AMD SEV-SNP

Researchers from KU Leuven, ETH Zurich, Durham University, and Google have disclosed DDRop, a new active hardware attack that defeats the memory integrity guarantees of Intel TDX, ...

VulnerabilityCloud SecurityEncryption
Read More → Use Tool →