HackMyIP

Cybersecurity News

Latest updates from top security sources

1595 articles, page 11 of 54

2026-09-01The Hacker News
Critical JFrog Artifactory Flaw Exploited for Admin Tokens

Threat actors began exploiting CVE-2026-82329, a critical JFrog Artifactory authentication-bypass vulnerability, just days after its public disclosure. The flaw carries a CVSS scor...

VulnerabilitySupply ChainAuthentication
Read More → Use Tool →
2026-09-01SecurityWeek
Palo Alto Networks Buys Console to Power AI Agent Workflows in Cortex

Palo Alto Networks (NASDAQ: PANW) announced on Tuesday that it has acquired Console, an AI-native platform built to help enterprises design agentic workflows and automate operation...

AI SecurityCloud Security
Read More → Use Tool →
2026-09-01The Record
China's Fire Ant APT Hijacks Cisco Routers for Network Intrusions

Cybersecurity firm Sygnia has detailed a sophisticated Chinese-linked hacking operation dubbed "Fire Ant" that compromised Cisco IOS XR routers to infiltrate organizations and pivo...

APTSupply ChainThreat Intel
Read More → Use Tool →
2026-09-01The Hacker News
Malicious Packagist Themes Exploit WebKit to Steal iPhone Crypto Wallets

Socket security researcher Kush Pandya has uncovered 13 malicious Composer theme packages on Packagist that target unpatched iPhones, ultimately stealing cryptocurrency wallet seed...

MalwareSupply ChainZero-Day
Read More → Use Tool →
2026-09-01SecurityWeek
AI Ports PLC Exploit in Hours, Costs Researchers $500 in API Fees

Researchers at Forescout's Vedere Labs successfully used Anthropic's Claude to port a remote code execution (RCE) exploit between two WAGO programmable logic controllers, but the e...

AI SecurityVulnerabilityThreat Intel
Read More → Use Tool →
2026-09-01The Record
Gentlemen Ransomware Gang Steals Patient Data in Nutex Healthcare Breach

Houston-based healthcare facilities operator Nutex confirmed in an 8-K filing with the Securities and Exchange Commission on Monday that cybercriminals breached its servers in Augu...

RansomwareData BreachIncident Response
Read More → Use Tool →
2026-09-01The Hacker News
Iranian Hackers Target Engineers With Cross-Platform RATs via Fake Coding Tests

The Iranian state-aligned threat group Nimbus Manticore, also tracked as "Iranian Dream Job," has been linked to two previously undocumented cross-platform remote access trojans ca...

APTMalwarePhishing
Read More → Use Tool →
2026-09-01The Hacker News
Why Threat Actors Prefer Repeatable Attacks Over Clever Ones

Last year, the most common way into a corporate network was simply asking. Microsoft's threat intelligence team reported that ClickFix — a social engineering technique that walks a...

Threat IntelMalwareVulnerability
Read More → Use Tool →
2026-09-01SecurityWeek
Five Venezuelans Plead Guilty to ATM Jackpotting Scheme in US

Five Venezuelan nationals pleaded guilty in a US federal court to conspiracy to commit bank larceny through an ATM jackpotting scheme targeting locations in Kansas. The defendants—...

MalwareThreat IntelIncident Response
Read More → Use Tool →
2026-09-01The Hacker News
METR API Key Stolen, $600K in AI Credits Consumed by Attackers

METR (Model Evaluation and Threat Research), a non-profit that evaluates frontier AI models for agentic task performance, disclosed two notable security incidents in which external...

AI SecurityVulnerabilityIncident Response
Read More → Use Tool →
2026-08-31Dark Reading
Anthropic Users Hit by Infostealer Attacks, Session Thefts

A threat actor used a variety of infostealers to collect session information and access Claude accounts belonging to an unknown number of users....

Read More → Use Tool →
2026-08-31Dark Reading
'TerminalFix' Campaign Weaponizes PowerShell for Enterprise Attacks

The ClickFix-style campaign features a sophisticated, multistage attack chain that includes reverse tunnels into victim organizations' networks....

Read More → Use Tool →
2026-08-31Dark Reading
The Guardrails Debate: Security Researcher Changes His Mind

While guardrails are critical, as evidenced by recent high-profile incidents, defenders need help staying ahead of attackers who do not play by the rules....

Read More → Use Tool →
2026-08-31Dark Reading
AI Model Rules Are Not Security Controls

OpenAI's Hugging Face attack postmortem shows agents don't care about rules — they need strong controls....

Read More → Use Tool →
2026-08-31The Record
McKesson Confirms Data Breach: ShinyHunters Hit Healthcare Giant

Pharmaceutical and healthcare technology distributor McKesson disclosed a cybersecurity incident on Friday, filing an 8-K with the Securities and Exchange Commission (SEC) and warn...

Data BreachThreat IntelIncident Response
Read More → Use Tool →
2026-08-31The Hacker News
Anthropic Compliance API Improves Claude Code Security Visibility

Anthropic has added local session transcript endpoints to its Compliance API, giving security teams a clearer audit trail for Claude Code activity. Unlike a conventional chatbot, C...

AI SecurityLLM SecurityCloud Security
Read More → Use Tool →
2026-08-31The Record
Fraudsters Steal $6M from Tectonic Crypto Platform via Token Price Manipulation

At least $6 million was drained from decentralized lending platform Tectonic over the weekend after an attacker exploited the protocol's thinly traded Tonic token by artificially i...

Incident ResponseVulnerability
Read More → Use Tool →
2026-08-31The Hacker News
Silver Fox Hides ValleyRAT Backdoor in Signed Chinese Adware to Bypass Antivirus

Threat actor Silver Fox has been spotted distributing the ValleyRAT backdoor (also tracked as Winos 4.0) disguised as QN Wallpaper, a legitimate but ad-supported Chinese desktop wa...

MalwareThreat IntelAPT
Read More → Use Tool →
2026-08-31The Record
Five Plead Guilty in $58M ATM Jackpotting Scheme Using Ploutus Malware

Five Venezuelan nationals have pleaded guilty to conspiracy to commit bank larceny in a federal Kansas court after prosecutors accused them of being part of a coordinated group tha...

MalwareThreat IntelIncident Response
Read More → Use Tool →
2026-08-31The Hacker News
Aurora Ransomware Group Uses AI Coding Assistant to Hit 10 Targets

Threat actors linked to the Aurora (Aur0ra) ransomware operation have been leveraging Cursor, an AI-powered coding assistant originally developed by SpaceX, to plan and execute int...

RansomwareAI SecurityThreat Intel
Read More → Use Tool →
2026-08-31The Hacker News
North Korean Job Fraud Expands to Healthcare and Finance Sectors

North Korean threat actors have broadened their fraudulent employment scheme beyond the IT sector, with new investigations revealing operatives embedded in healthcare, sales, and f...

APTThreat IntelAuthentication
Read More → Use Tool →
2026-08-31SecurityWeek
HardBreacher: Nightmare Eclipse Drops Kaspersky Endpoint Security Exploit

The independent researcher known as Nightmare Eclipse (also called Chaotic Eclipse) has publicly released a proof-of-concept exploit dubbed HardBreacher targeting a privilege escal...

Zero-DayVulnerability
Read More → Use Tool →
2026-08-31The Record
Berlin Refuses Ransom After Rhysida Ransomware Steals 5.79TB of Government Data

Berlin's Governing Mayor Kai Wegner confirmed on Friday that the state government will not comply with an extortion demand from the Rhysida ransomware group, which claimed responsi...

RansomwareData BreachIncident Response
Read More → Use Tool →
2026-08-31The Hacker News
FBI Disrupts Chinese Spy Proxy as AI Agents Hack Themselves

The U.S. Federal Bureau of Investigation has dismantled infrastructure tied to QTYF, a Chinese technical quartermaster that sold reconnaissance, proxy management, and operational r...

APTAI SecurityPhishing
Read More → Use Tool →
2026-08-31The Hacker News
Fire Ant APT Hijacks Cisco Routers to Steal Credentials and Blind Security Logs

A China-nexus cyber espionage group tracked as Fire Ant has expanded beyond VMware hypervisors to compromise Cisco IOS XR routers, TACACS servers, and Linux management hosts used t...

APTThreat IntelAuthentication
Read More → Use Tool →
2026-08-31The Hacker News
DoJ: U.S. Agencies Targeted by Chinese QTFY Hackers — Not Confirmed Breached

The U.S. Department of Justice issued a correction to a previous press statement, clarifying that several federal agencies were "targets" — not confirmed "victims" — of intrusions ...

APTThreat IntelMalware
Read More → Use Tool →
2026-08-30The Hacker News
TerminalFix ClickFix Variant Hides Reverse-Tunnel Backdoor Behind Fake Captchas

Microsoft has shed light on a sophisticated new ClickFix variant dubbed TerminalFix that tricks users into running malicious PowerShell commands through fake Cloudflare CAPTCHA ver...

MalwarePhishingThreat Intel
Read More → Use Tool →
2026-08-29The Hacker News
Five Critical WordPress Plugin Flaws Enable Site Takeover and RCE

Security researchers have disclosed five critical vulnerabilities across popular WordPress plugins and themes that collectively expose millions of websites to authentication bypass...

VulnerabilityAuthentication
Read More → Use Tool →
2026-08-29Dark Reading
Building a Secure AI Strategy for the Enterprise: Key Takeaways

Enterprise adoption of generative AI and large language models has accelerated faster than most governance frameworks can handle, making secure AI strategy a board-level priority. ...

AI SecurityRegulationCloud Security
Read More → Use Tool →
2026-08-29Dark Reading
Securing Cloud Assets in the AI Era: What Enterprises Must Know

As organizations accelerate AI adoption, the security perimeter around cloud environments is shifting faster than most governance frameworks can keep up. Dark Reading is hosting a ...

Cloud SecurityAI Security
Read More → Use Tool →