HackMyIP

Cybersecurity News

Latest updates from top security sources

2415 articles, page 15 of 81

2026-07-14Dark Reading
Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakes

Three of the 622 CVEs for which Microsoft issued patches this week are zero-days; there are more than 60 critical vulnerabilities....

Read More → Use Tool →
2026-07-14Dark Reading
6 GHz Wi-Fi Flaws Could Disrupt Critical Systems

Automated Frequency Coordination systems by default trust client-side data, which could lead to location spoofing and other attacks that disrupt traffic....

Read More → Use Tool →
2026-07-14Dark Reading
Manage Vendor Risk in a Few Practical Steps

Risk tolerance, exposure visibility, board oversight — handling third-party risk is complicated but achievable with disciplined, precise governance....

Read More → Use Tool →
2026-07-14SecurityWeek
Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days

Two flaws in Active Directory and SharePoint Server have been exploited as zero-days, and a BitLocker bug was publicly disclosed. The post Microsoft Patches Record 622 Vulnerabilit...

Read More → Use Tool →
2026-07-14SecurityWeek
Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims

The D1R cybercrime group claimed to have stolen valuable data from Synopsys and Bosch, threatening to leak it unless a ransom is paid.  The post Synopsys Finds No Evidence of Data ...

Read More → Use Tool →
2026-07-14The Record
US unseals indictment against alleged operators of Russian bulletproof hosting service

The Russians face multiple charges for allegedly providing cybercriminals with infrastructure and tech support through the St. Petersburg-based business Media Land and a sister com...

Read More → Use Tool →
2026-07-14The Hacker News
11 Vulnerable UEFI Shims Expose Systems to Secure Boot Bypass

ESET researcher Martin Smolár has uncovered 11 outdated, Microsoft-signed Unified Extensible Firmware Interface (UEFI) shim bootloaders that can be weaponized to bypass Secure Boot...

VulnerabilitySupply ChainThreat Intel
Read More → Use Tool →
2026-07-14The Hacker News
LabubaRAT: New Rust-Based Trojan Impersonates NVIDIA Software on Windows

Cybersecurity researchers at Blackpoint Cyber have uncovered a previously undocumented Rust-based remote access trojan dubbed LabubaRAT that masquerades as legitimate NVIDIA softwa...

MalwareThreat Intel
Read More → Use Tool →
2026-07-14The Hacker News
RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata

Cybersecurity researchers have disclosed details of two access control-related flaws impacting the RabbitMQ message broker service that could allow attackers to leak OAuth client s...

Read More → Use Tool →
2026-07-14The Hacker News
Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks

Researchers at KU Leuven tested 85 of the most popular crypto wallets that run as browser extensions and found that the wallets themselves leak enough to link and track the people ...

Read More → Use Tool →
2026-07-14The Hacker News
How Pentera Turns AI Security Workflows into Validation Engines

AI security agents are starting to influence real security decisions. They summarize findings, prioritize remediation, recommend next steps, and help teams move faster. But most st...

Read More → Use Tool →
2026-07-14The Hacker News
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials

At least two distinct threat actors are weaponizing a novel evasion technique called OAuth client ID spoofing in cloud campaigns, while slipping past telemetry. The activity allow...

Read More → Use Tool →
2026-07-14Dark Reading
Frontier AI: The Genie's Out of the Bottle, but Where's the Rulebook?

Cutting-edge artificial intelligence models are deploying with more independence and less human oversight. Several state governments are trying to legislate transparency in their u...

Read More → Use Tool →
2026-07-14Dark Reading
ClickFix's Mushrooming Ecosystem Demands New Defense Tactics

The attack vector is available for rent at scale, and evades AV and EDR, leaving YARA analysis as the best detection option....

Read More → Use Tool →
2026-07-14Dark Reading
Cursor IDE Auto-Executes Malicious Code in Poisoned Repos

Researchers reported the vulnerability to Cursor in December, but it still remains in the popular AI coding platform and can be exploited in poisoned repository attacks....

Read More → Use Tool →
2026-07-14SecurityWeek
Adobe Patches Critical ColdFusion Vulnerabilities

The ColdFusion security defects could allow attackers to execute arbitrary code or elevate their privileges. The post Adobe Patches Critical ColdFusion Vulnerabilities appeared fir...

Read More → Use Tool →
2026-07-14SecurityWeek
7 Severe Vulnerabilities Patched in VMware Avi Load Balancer

The flaws can be exploited for authentication bypass, remote code execution, privilege escalation, and directory traversal. The post 7 Severe Vulnerabilities Patched in VMware Avi ...

Read More → Use Tool →
2026-07-14SecurityWeek
Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar

A ClaudeBleed-linked vulnerability reportedly persists across eight patches, exposing potentially sensitive data to other extensions.  The post Unpatched Claude for Chrome Flaw Let...

Read More → Use Tool →
2026-07-14The Record
Finland issues wanted notice for hacker behind massive psychotherapy data breach

The defendant's lawyer told Finnish media that he does not know where his client is but believes Kivimäki is outside Finland....

Read More → Use Tool →
2026-07-14The Record
NATO logistics, Ukrainian troops are top subjects of Russian camera hacks, advisory says

Dutch intelligence officials report that at least one Russian agency is compromising internet-connected cameras across Europe to spy on military logistics and Ukrainian personnel....

Read More → Use Tool →
2026-07-14The Hacker News
Grok Build Secretly Uploads Entire Git Repositories to xAI Cloud

A security researcher publishing as cereblab has uncovered that xAI's Grok Build coding CLI was uploading entire Git repositories—including full commit history—to a Google Cloud St...

AI SecurityPrivacyData Breach
Read More → Use Tool →
2026-07-14The Hacker News
U.S. Sanctions First VPN and Cryptor Seller for Aiding Ransomware

The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) has imposed sanctions on two individuals and a VPN service provider for facilitating ransomware operations an...

RansomwareRegulationMalware
Read More → Use Tool →
2026-07-14The Hacker News
148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet

A campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a distributed denial-of-service botnet for roughly two weeks in May, according to new...

Read More → Use Tool →
2026-07-14The Hacker News
Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity

Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a si...

Read More → Use Tool →
2026-07-14SecurityWeek
SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud

The flaws could allow attackers to access and modify data, and cause system unavailability and request-response desynchronization. The post SAP Patches Critical Vulnerabilities in ...

Read More → Use Tool →
2026-07-14SecurityWeek
US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers

Multiple state-sponsored APTs are compromising poorly secured devices across critical infrastructure sector networks. The post US, Allies Warn of Russian Cyberattacks Targeting Cri...

Read More → Use Tool →
2026-07-14SecurityWeek
Valarian Raises $50 Million for Sovereign Infrastructure Control Layer

UK-based cybersecurity firm Valarian has raised a total of $70 million for its ACRA technology. The post Valarian Raises $50 Million for Sovereign Infrastructure Control Layer appe...

Read More → Use Tool →
2026-07-14SecurityWeek
Multiple Jscrambler Packages Impacted by Supply Chain Attack

A threat actor poisoned several Jscrambler NPM package versions to drop a cross-platform credential stealer. The post Multiple Jscrambler Packages Impacted by Supply Chain Attack a...

Read More → Use Tool →
2026-07-14SecurityWeek
Pentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity Rules

A new CMMC review and reform task force will conduct a comprehensive review of the program. The post Pentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity Rules ap...

Read More → Use Tool →
2026-07-13The Record
Hackers steal Lidl customer data from external service provider

The retailer said the incident did not affect its online shopping platform itself but involved a separately stored customer database maintained by a third-party provider. According...

Read More → Use Tool →