HackMyIP

Cybersecurity News

Latest updates from top security sources

1595 articles, page 14 of 54

2026-08-26The Record
US DoJ Takedown Disables Chinese QScan and QTRouter Hacking Tools

The U.S. Department of Justice announced on Wednesday the takedown of two Chinese state-sponsored hacking platforms, "QScan" and "QTRouter," operated by Nanjing Xinjiuwei Network T...

APTMalwareIncident Response
Read More → Use Tool →
2026-08-26The Hacker News
Nimbus Manticore Deploys TWOSTROKE Backdoor and SSH Tunneler in Europe-Middle East Spying Campaign

Cybersecurity researchers at Group-IB have uncovered fresh infrastructure and previously undocumented malware tied to Nimbus Manticore, an Iranian state-sponsored APT group operati...

APTMalwareThreat Intel
Read More → Use Tool →
2026-08-26The Hacker News
Agentic AI Reshapes the SOC: From Alert Queues to Hypothesis-Driven Defense

For decades, the security operations center (SOC) has been defined by its alert queue—a backlog that, according to industry surveys, can balloon to thousands of tickets per day in ...

AI SecurityThreat IntelIncident Response
Read More → Use Tool →
2026-08-26SecurityWeek
CISA: 100+ US Water Systems Targeted in Iran-Linked Cyberattacks

The Cybersecurity and Infrastructure Security Agency (CISA) has disclosed that more than 100 internet-exposed water and wastewater systems were targeted in malicious cyber activity...

APTRegulationVulnerability
Read More → Use Tool →
2026-08-26The Hacker News
Claude Opus 4.6 Agent Autonomously Exploits Gym Booking IDOR

Aikido Security has recreated the Australian gym-booking incident first surfaced in chat logs shared with ABC News on August 10, confirming that Anthropic's Claude Opus 4.6 running...

AI SecurityLLM SecurityVulnerability
Read More → Use Tool →
2026-08-25Dark Reading
Hidden Prompts Trick AI Into False Email Summaries

With some simple HTML that's invisible to users, attackers can manipulate AI-powered email summarizers into producing malicious information....

Read More → Use Tool →
2026-08-25Dark Reading
Finding Nemo(Claw): Networking Issue Allows for LLM Poisoning in OpenClaw

Attackers can exploit a security bug in Nvidia's tool to gain unauthenticated access to the local model server through the Ollama API, paving the way for persistent AI agent corrup...

Read More → Use Tool →
2026-08-25Dark Reading
Is Cyber Facing an Affordability Crisis?

As breach costs reach record highs and defense spending nears $240 billion, small businesses are dangerously exposed, threatening supply chain security....

Read More → Use Tool →
2026-08-25The Hacker News
Mirage2FA Phishing Kit Hits 4,500 Companies, Bypasses Microsoft 365 MFA

A sweeping phishing-as-a-service operation known as Mirage2FA has compromised or targeted an estimated 4,532 unique corporate email domains across the United States and Europe betw...

PhishingAuthenticationCloud Security
Read More → Use Tool →
2026-08-25The Record
Paylogix Breach: Akira Ransomware Exposes 64K+ Employee Records

Paylogix, a New York-based benefits management platform serving employers and insurance firms, has disclosed that the Akira ransomware gang stole sensitive personal, financial, and...

RansomwareData BreachPrivacy
Read More → Use Tool →
2026-08-25The Hacker News
Hackers Abuse unpkg Mirrors via 24 npm Packages to Host Fake Cloudflare CAPTCHAs

Cybersecurity researchers at OX Security have uncovered a phishing campaign leveraging 24 malicious npm packages as free infrastructure to host fake Cloudflare CAPTCHA verification...

PhishingSupply ChainThreat Intel
Read More → Use Tool →
2026-08-25The Hacker News
U.S. Sanctions Iranian MOIS Hackers Behind Critical Infrastructure Attacks

The U.S. Department of the Treasury has imposed fresh sanctions on Iranian cyber actors as part of Operation Economic Outcast, an "unprecedented, whole-of-government, economic camp...

APTRegulationData Breach
Read More → Use Tool →
2026-08-25SecurityWeek
Alice Secures $140M to Harden AI Models Against Adversarial Attacks

AI trust and safety company Alice, formerly operating as ActiveFence, announced a $140 million funding round this week, bringing its total capital raised to $280 million. The round...

AI SecurityLLM SecurityThreat Intel
Read More → Use Tool →
2026-08-25The Record
Interpol Operation Jackal IV Nets 58 Arrests in Global Cybercrime Sweep

Interpol has concluded Operation Jackal IV, an eight-month coordinated effort that resulted in 58 arrests and the identification of hundreds of additional suspects across four cont...

Threat IntelIncident ResponseRegulation
Read More → Use Tool →
2026-08-25The Hacker News
Marimo Notebook RCE Flaw Lets Attackers Run MCP Commands Before Cells Execute

Marimo has patched a high-severity code injection vulnerability in its open-source notebook platform that allows a specially crafted notebook to execute attacker-supplied Model Con...

VulnerabilityAI Security
Read More → Use Tool →
2026-08-25The Hacker News
NVIDIA NemoClaw Flaw Lets Malicious Webpage Hijack Local Ollama AI Models

Researchers at Oasis Security have disclosed a serious vulnerability in NVIDIA's NemoClaw reference stack that allows an attacker-controlled webpage to seize control of a local Oll...

VulnerabilityAI SecurityLLM Security
Read More → Use Tool →
2026-08-25SecurityWeek
Linux Foundation Takes Governance of TRACE Open Standard for AI Runtime Attestation

The Linux Foundation announced Tuesday that it will assume governance of TRACE (Trust, Runtime Attestation and Compliance Evidence), a new open specification designed to produce ve...

AI SecurityCloud SecurityRegulation
Read More → Use Tool →
2026-08-25The Record
Ukraine to Share Battlefield AI Data with UK in Defense Pact

Ukraine has agreed to grant the United Kingdom access to a massive trove of battlefield intelligence collected during its war with Russia, enabling British companies and researcher...

AI SecurityRegulationAPT
Read More → Use Tool →
2026-08-25The Hacker News
WhatsApp Adds Multi-Passkey Support & Full Password 2FA Across iOS and Android

Meta announced a suite of WhatsApp account security enhancements on Tuesday, headlined by support for multiple passkeys on a single account, enabling users on both iOS and Android ...

AuthenticationPhishingPrivacy
Read More → Use Tool →
2026-08-25The Hacker News
miniOrange SAML Flaws Exploited to Hijack WordPress Admin Accounts

Attackers are actively scanning for WordPress sites running vulnerable versions of the Xecurify miniOrange SAML 2.0 Single Sign-On plugin, exploiting two unauthenticated authentica...

VulnerabilityAuthenticationThreat Intel
Read More → Use Tool →
2026-08-25SecurityWeek
First Car Head Unit Malware Linked to BadBox Botnet Discovered

Security researchers at Kaspersky have identified what they believe is the first malware strain built specifically to target automotive head units, and it carries strong links to t...

MalwareVulnerabilityThreat Intel
Read More → Use Tool →
2026-08-25The Record
Major DDoS Attack Disrupts Norwegian Government ID Services for 30+ Hours

Norway's public digital infrastructure faced severe disruption this week after a large-scale distributed denial-of-service (DDoS) attack knocked government services offline for mor...

Incident ResponseAuthenticationCloud Security
Read More → Use Tool →
2026-08-25The Hacker News
CVE-2026-21962: Oracle WebLogic Flaw Exploited in the Wild

CISA has added the Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in vulnerability CVE-2026-21962 to its Known Exploited Vulnerabilities catalog after evidence of active ...

VulnerabilityIncident ResponseThreat Intel
Read More → Use Tool →
2026-08-24Dark Reading
Foul Language: WordlistLoader Disguises Malware as Ordinary Text

ClickFix-style threat campaigns are using a new trick to evade detection and deliver Amatera, an increasingly prevalent infostealer....

Read More → Use Tool →
2026-08-24Dark Reading
Tricky 'SynkLoader' Multitool May Herald Ransomware

An advanced, multilingual malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along with a slew of novel features....

Read More → Use Tool →
2026-08-24Dark Reading
ToxicPanda Banking Trojan Matures Into Enterprise Threat

The latest version of the Android malware has new features that expand its global reach and put more than users' financial applications at risk....

Read More → Use Tool →
2026-08-24Dark Reading
The Vulnerability Gap: Why Discovery Is Outrunning Repair

The combination of AI both discovering more vulnerabilities at a faster pace and the tightening regulatory environment is making this an all-hands-on-deck moment for the cybersecur...

Read More → Use Tool →
2026-08-24The Hacker News
Critical Keycloak Flaw (CVE-2026-18963) Enables Full Account Takeover via Password Reset

Red Hat and the Keycloak project have shipped urgent patches for a flaw in the open-source identity and access management platform that allows unauthenticated remote attackers to t...

VulnerabilityAuthentication
Read More → Use Tool →
2026-08-24SecurityWeek
Uber Hit With $964M GDPR Fine Over Automated Driver Account Suspensions

The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) has fined Uber 825 million euros (approximately $964 million) for violating the EU's General Data Protection Regul...

RegulationPrivacyAI Security
Read More → Use Tool →
2026-08-24The Record
New Zealand to Ban Under-16s From Social Media, Fine Platforms 10% of Revenue

New Zealand Prime Minister Christopher Luxon announced Monday that his government plans to introduce legislation banning children under 16 from accessing major social media platfor...

RegulationPrivacyAI Security
Read More → Use Tool →