HackMyIP

Cybersecurity News

Latest updates from top security sources

2026-07-17The Hacker News
wp2shell WordPress Flaw Enables Unauthenticated Remote Code Execution

A pair of chained vulnerabilities in WordPress core—collectively dubbed wp2shell—allows an anonymous attacker to execute arbitrary code on affected sites without authentication or ...

VulnerabilityZero-DayBug Bounty
Read More → Use Tool →
2026-07-16The Hacker News
AI Accelerates Bug Discovery, But Human Validation Still Decides What Counts

Artificial intelligence is reshaping offensive security by giving practitioners the ability to read codebases, map attack surfaces, generate payloads, explain unfamiliar APIs, and ...

AI SecurityVulnerabilityBug Bounty
Read More → Use Tool →
2026-07-08The Hacker News
GhostLock Linux Kernel Flaw Grants Root Access on Most Distros

Nebula Security has disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel use-after-free vulnerability that lets any local user escalate to full root on unpatched system...

VulnerabilityCloud SecurityBug Bounty
Read More → Use Tool →
2026-07-06The Hacker News
Opera GX Flaw Let Sites Silently Steal Data via Mod Auto-Install

A serious vulnerability in Opera GX, the gaming-focused browser from Opera, allowed a malicious website to silently install a browser modification and use it to extract sensitive d...

VulnerabilityBug BountyPrivacy
Read More → Use Tool →
2026-07-03The Hacker News
Bad Epoll Linux Flaw Lets Unprivileged Users Gain Root Access

A newly disclosed Linux kernel vulnerability dubbed "Bad Epoll" (CVE-2026-46242) enables unprivileged users to escalate privileges and gain root access on affected systems. The fla...

VulnerabilityZero-DayBug Bounty
Read More → Use Tool →
2026-07-02The Hacker News
ChocoPoC RAT Infects Vulnerability Researchers via Fake GitHub PoC Exploits

A new remote access trojan dubbed ChocoPoC is targeting vulnerability researchers and bug bounty hunters through weaponized proof-of-concept (PoC) repositories on GitHub. Discovere...

MalwareSupply ChainBug Bounty
Read More → Use Tool →
2026-06-30The Hacker News
Researchers Uncover 6 Flaws in AirDrop and Quick Share Wireless Sharing

Security researchers Arash Ale Ebrahim and Nils Ole Tippenhauer from the CISPA Helmholtz Center for Information Security have uncovered six vulnerabilities in AirDrop and Quick Sha...

VulnerabilityZero-DayBug Bounty
Read More → Use Tool →
2026-06-30SecurityWeek
Daktronics Controller Flaws Let Hackers Hijack Highway Signs

Critical and high-severity vulnerabilities in Daktronics controllers could allow remote attackers to tamper with highway signs, electronic scoreboards, and digital billboards world...

VulnerabilityAuthenticationBug Bounty
Read More → Use Tool →
2026-06-12BleepingComputer
Critical phpBB Auth Bypass Flaw Unpatched for 10 Years Exposes Admin Accounts

Security researchers at application security firm Aikido have disclosed a severe authentication bypass vulnerability in phpBB, the widely used open-source forum platform, that h...

AuthenticationVulnerabilityBug Bounty
Read More → Use Tool →
2026-06-09SecurityWeek
Google Patches 5th Chrome Zero-Day of 2026: CVE-2026-11645

Google on Monday rolled out Chrome 149, a critical security update that patches 74 vulnerabilities, including a high-severity zero-day flaw actively exploited in the wild. The vuln...

Zero-DayVulnerabilityBug Bounty
Read More → Use Tool →
2026-05-28The Hacker News
Microsoft Condemns Public Zero-Day Disclosures After GitHub Takedown

Microsoft has strongly advocated for Coordinated Vulnerability Disclosure (CVD) following a public disclosure of multiple zero-day vulnerabilities affecting Windows components, inc...

Zero-DayVulnerabilityBug Bounty
Read More → Use Tool →
2026-05-23The Record
CISA Launches Form for Researchers to Report Exploited Vulnerabilities

The Cybersecurity and Infrastructure Security Agency (CISA) has unveiled a new nomination form enabling security researchers, vendors, and industry partners to submit vulnerabiliti...

VulnerabilityThreat IntelBug Bounty
Read More → Use Tool →
2026-05-21BleepingComputer
Google Leaks Unfixed Chromium Flaw Enabling Silent JS Botnet

Google inadvertently exposed technical details of an unfixed Chromium vulnerability that allows JavaScript to persist in the background after the browser is closed, effectively giv...

VulnerabilityZero-DayBug Bounty
Read More → Use Tool →
2026-05-06The Hacker News
Hacker News Opens Cybersecurity Stars Awards 2026 Submissions

The Hacker News (THN) has officially opened the call for entries for the Cybersecurity Stars Awards 2026, an initiative designed to shine a spotlight on the behind‑the‑scenes work ...

Bug BountyThreat IntelIncident Response
Read More → Use Tool →
2026-05-05Dark Reading
How Security Leadership Shapes Penetration Test Success

When Alex Rivera, "CISO of Globex Systems", commissioned a penetration test in Q3 2023, his first decision was to define a precise scope that included internal VLAN segmentation, c...

VulnerabilityIncident ResponseBug Bounty
Read More → Use Tool →
2026-05-05BleepingComputer
Google Ups Android Exploit Bounties to $1.5M

Google announced a major overhaul of its Android and Chrome vulnerability reward programs, raising the maximum payout to $1.5 million for the most sophisticated exploit chains targ...

Bug BountyZero-Day
Read More → Use Tool →