HackMyIP

Cybersecurity News

Latest updates from top security sources

2413 articles, page 11 of 81

2026-07-20SecurityWeek
Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software

Neo raised money across seed and Series A funding rounds from Andreessen Horowitz, Bessemer Venture Partners, and others. The post Neo Emerges From Stealth With $100M to Control an...

Read More → Use Tool →
2026-07-20SecurityWeek
SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch

The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533. The post SonicWall Zero-Days Exploited to Deliver Custom Malware fo...

Read More → Use Tool →
2026-07-20SecurityWeek
OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability

Attackers could send waves of malicious payloads to trigger buffer pre-allocations that are not freed, exhausting server memory. The post OpenSSL Silently Fixes ‘HollowByte&#...

Read More → Use Tool →
2026-07-20The Record
More than 1,000 domains illegally streaming World Cup games seized, DOJ says

Over the course of the World Cup tournament, the Department of Justice seized more than 1,000 domains for illegally streaming games....

Read More → Use Tool →
2026-07-20The Record
Hackers were inside South Korea's diplomat training system for 9 months

Unidentified hackers compromised an online education system used by South Korea's diplomatic academy, stealing personal information belonging to former and current employees of the...

Read More → Use Tool →
2026-07-20The Record
Romania races to restore land registry after cyberattack disrupts property market

Romania's land registry agency is still recovering from a cyberattack it called "the most serious technical incident in the institution's history."...

Read More → Use Tool →
2026-07-20The Record
Software provider to more than 2,000 US hospitals says hackers stole employee and customer data

Craneware, which is headquartered in Edinburgh and listed on London's AIM market, told investors it detected unauthorized access to a “subset” of its data environment and has since...

Read More → Use Tool →
2026-07-20The Hacker News
Russian Hacker Uses Gemini CLI AI to Control Dental Clinic Botnet

A Russian-speaking threat actor tracked as "bandcampro" has been observed weaponizing Google's open-source Gemini CLI artificial intelligence tool to operate a live, small-scale bo...

AI ThreatsMalwareThreat Intel
Read More → Use Tool →
2026-07-20SecurityWeek
HIH Index: New Tracker Catalogs Material Breaches Without Adding Up the Losses

Cybersecurity veteran Richard Bird has launched The Hacker in a Hoodie (HIH) Index, a public website that tracks disclosed material breaches pulled directly from SEC EDGAR 8-K fili...

Data BreachRegulation
Read More → Use Tool →
2026-07-20The Hacker News
7-Zip CVE-2026-14266: XZ Archive Flaw Allows Code Execution During Extraction

A newly disclosed vulnerability in the widely used 7-Zip archiver could allow attackers to execute arbitrary code when users open a maliciously crafted XZ archive. Tracked as CVE-2...

VulnerabilityZero-DayBug Bounty
Read More → Use Tool →
2026-07-20SecurityWeek
Ernst & Young Data Breach Affects Personal, Financial Information

Hackers stole names, addresses, Social Security numbers, credit/debit card numbers, and other information from a third-party management platform. The post Ernst & Young Data B...

Read More → Use Tool →
2026-07-20SecurityWeek
Watch on Demand: Cloud & Data Security Summit

Attendees will be able to interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments. The post Watch on Deman...

Read More → Use Tool →
2026-07-20SecurityWeek
Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool

The agentic security tool identifies potentially exploitable code flaws, traces attack paths, and recommends targeted remediations. The post Capital One Open Sources AI-Powered ‘Vu...

Read More → Use Tool →
2026-07-20SecurityWeek
Hugging Face Hacked in Autonomous AI Attack

Targeting production infrastructure, the attack compromised internal datasets and service credentials. The post Hugging Face Hacked in Autonomous AI Attack appeared first on Securi...

Read More → Use Tool →
2026-07-20SecurityWeek
Chrome 150 Update Patches Severe Memory Safety Bugs

The fresh security update resolves six critical and high-severity use-after-free vulnerabilities. The post Chrome 150 Update Patches Severe Memory Safety Bugs appeared first on Sec...

Read More → Use Tool →
2026-07-20The Hacker News
Autonomous AI Agent Hacks Hugging Face in Landmark Model Hub Breach

In a striking case of the defender becoming the target, Hugging Face, the world's largest open-source AI model repository, disclosed on July 20, 2026, that an autonomous AI agent s...

AI SecurityData BreachVulnerability
Read More → Use Tool →
2026-07-20The Hacker News
SleeperGem Attack Plants Backdoors in RubyGems to Hit Developer Machines

Cybersecurity researchers at StepSecurity have uncovered a new software supply chain campaign dubbed SleeperGem targeting the Ruby ecosystem through three malicious RubyGems packag...

Supply ChainMalwareThreat Intel
Read More → Use Tool →
2026-07-20SecurityWeek
Critical WP2Shell WordPress Flaws Actively Exploited in the Wild

Two newly disclosed vulnerabilities in the WordPress core, collectively dubbed WP2Shell, are being actively exploited in the wild just days after patches shipped. Tracked as CVE-20...

VulnerabilityZero-DayAI Threats
Read More → Use Tool →
2026-07-19The Hacker News
NGINX CVE-2026-42533: Critical Heap Overflow Bug Could Enable RCE

F5 has released patches for a critical vulnerability in the NGINX web server, tracked as CVE-2026-42533, that allows remote unauthenticated attackers to trigger a heap buffer overf...

VulnerabilityCloud Security
Read More → Use Tool →
2026-07-19The Hacker News
UAC-0145 Uses ClickFix CAPTCHAs to Deploy Malware in Ukraine

Russian state-sponsored threat actor UAC-0145, a sub-cluster within the GRU-linked Sandworm advanced hacking unit, has been observed weaponizing the ClickFix social engineering str...

APTMalwarePhishing
Read More → Use Tool →
2026-07-19The Hacker News
SonicWall SMA Zero-Days Exploited by UTA0533 for Root Access Before Patch

An unattributed threat actor tracked as UTA0533 exploited two previously unknown vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000-series VPN appliances as zero-days beg...

Zero-DayAPTThreat Intel
Read More → Use Tool →
2026-07-17The Hacker News
OpenSSL HollowByte Flaw Lets 11-Byte TLS Request Freeze Server Memory

A recently disclosed OpenSSL vulnerability dubbed “HollowByte” allows attackers to permanently fragment server memory using nothing more than an 11-byte TLS handshake message, forc...

VulnerabilityIncident Response
Read More → Use Tool →
2026-07-17The Hacker News
7 Malicious Vite npm Packages Use Blockchain C2 to Deploy RAT

Cybersecurity researchers at Checkmarx have uncovered a software supply chain attack targeting the Vite frontend tooling ecosystem, with seven malicious npm packages collectively d...

Supply ChainMalwareThreat Intel
Read More → Use Tool →
2026-07-17The Hacker News
wp2shell WordPress Flaw Enables Unauthenticated Remote Code Execution

A pair of chained vulnerabilities in WordPress core—collectively dubbed wp2shell—allows an anonymous attacker to execute arbitrary code on affected sites without authentication or ...

VulnerabilityZero-DayBug Bounty
Read More → Use Tool →
2026-07-17Dark Reading
Inc Ransomware Exploits SonicWall SMA Zero-Days for Root Access

The Inc Ransomware group has been observed weaponizing two previously undisclosed zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) appliances, chaining the flaws to...

RansomwareZero-DayVulnerability
Read More → Use Tool →
2026-07-17The Hacker News
NadMesh Botnet Pivots to Cloud Credential Theft via Exposed AI Services

Researchers at QiAnXin's XLab have documented a new Go-language botnet called NadMesh that emerged in early July 2026 and is actively scanning the public internet for exposed AI in...

MalwareAI SecurityCloud Security
Read More → Use Tool →
2026-07-17The Hacker News
GoldenEyeDog Subgroup Steals DigiCert Code-Signing Certificates

Cybersecurity researchers at Expel have attributed the April 2026 DigiCert security incident to a threat activity cluster tracked as CylindricalCanine, a sub-group of the Chinese c...

APTData BreachThreat Intel
Read More → Use Tool →
2026-07-17The Hacker News
North Korean Hackers Hide OtterCookie Malware in SVG Flag Images via Fake Coding Tests

Threat actors linked to North Korea's Contagious Interview campaign have weaponized steganography inside SVG image files to deliver a four-stage malware payload aligned with OtterC...

MalwareAPTPhishing
Read More → Use Tool →
2026-07-17Dark Reading
Blind Trust in AI Agents Is the Next Cybersecurity Blind Spot

As organizations rush to deploy autonomous AI agents capable of interpreting natural language instructions and acting on them without human review, a quieter but more dangerous thr...

AI ThreatsAI SecurityLLM Security
Read More → Use Tool →
2026-07-17Dark Reading
Gold Eagle: White House's AI Vulnerability Plan Raises Implementation Questions

The White House has launched Gold Eagle, a new clearinghouse initiative designed to coordinate vulnerability disclosure and response across government and private sectors as artifi...

VulnerabilityAI SecurityRegulation
Read More → Use Tool →