HackMyIP

Cybersecurity News

Latest updates from top security sources

1595 articles, page 15 of 54

2026-08-24The Hacker News
Operation QUICSILVER: China-Linked QUICAgent Backdoor Targets Myanmar

Cybersecurity researchers at Seqrite Labs have identified a China-nexus cyber espionage campaign, codenamed Operation QUICSILVER, targeting Myanmar's government and information tec...

APTMalwareThreat Intel
Read More → Use Tool →
2026-08-24The Hacker News
AI Code Generation Creates Growing Remediation Debt for Enterprise Security Teams

Enterprise security teams are quietly accumulating what researchers call "remediation debt" as AI coding assistants accelerate development cycles and flood software stacks with new...

AI SecuritySupply ChainVulnerability
Read More → Use Tool →
2026-08-24Dark Reading
CISA Sets 3-Day Deadline to Patch Actively Exploited Zimbra Flaw CVE-2026-73570

CISA has added a critical Zimbra Collaboration Suite vulnerability—tracked as CVE-2026-73570—to its Known Exploited Vulnerabilities (KEV) catalog, ordering federal agencies to appl...

VulnerabilityIncident ResponseThreat Intel
Read More → Use Tool →
2026-08-24SecurityWeek
CISOs Hired for Tech Skills But Judged on Business Results

Industry surveys consistently show CISO tenure falling short of other C-suite roles, and a persistent double standard is largely to blame. During recruitment, boards prioritize tec...

RegulationPrivacy
Read More → Use Tool →
2026-08-24The Record
US Sanctions Iranian Cyber Actors Over Critical Infrastructure Attacks

The U.S. Treasury Department announced sanctions on Monday against several Iranian nationals tied to state-sponsored cyber operations targeting American critical infrastructure, ju...

APTRegulationThreat Intel
Read More → Use Tool →
2026-08-24The Hacker News
Weedhack Malware Targets Minecraft Players via Fake Clients and SEO Poisoning

Cybersecurity researchers at McAfee Labs have uncovered an ongoing campaign in which the Weedhack malware family is being distributed to gamers through fraudulent Minecraft client ...

MalwareThreat IntelPhishing
Read More → Use Tool →
2026-08-24The Hacker News
AI-Powered PLC Attacks, GitLab Exploit & npm Backdoors: Weekly Recap

A wave of AI-driven attacks and supply-chain compromises dominated this week's cybersecurity headlines, underscoring how quickly threat actors are weaponizing automation and truste...

AI ThreatsSupply ChainVulnerability
Read More → Use Tool →
2026-08-24SecurityWeek
ReliaQuest Confirms ShinyHunters Phishing Attack, Says Impact Limited

Cybersecurity firm ReliaQuest has confirmed it was targeted by hackers affiliated with the ShinyHunters group in a social engineering campaign, though the company maintains that th...

PhishingAuthenticationIncident Response
Read More → Use Tool →
2026-08-24The Record
Hackers Turn Android Car Head Units Into Proxy Botnet

Kaspersky researchers have uncovered what appears to be the first documented malware campaign designed specifically to compromise Android-based car head units, targeting devices ma...

MalwareSupply ChainThreat Intel
Read More → Use Tool →
2026-08-24The Hacker News
WordlistLoader Drops Amatera Stealer via ClickFix; SynkLoader Phishes Windows

Cybersecurity researchers at Gen Digital have identified two newly tracked malware families—WordlistLoader and SynkLoader—being deployed to harvest Windows credentials and stage ne...

MalwarePhishingThreat Intel
Read More → Use Tool →
2026-08-24The Hacker News
UAT-10147 Hackers Use AI to Scale Attacks, Deploy SPECTRE Malware

Researchers at Cisco Talos have exposed a Chinese-speaking cybercrime operation dubbed UAT-10147 that is weaponizing artificial intelligence to automate large-scale intrusions agai...

AI ThreatsMalwareThreat Intel
Read More → Use Tool →
2026-08-24SecurityWeek
Broadcom Patches 91 Spring Framework Vulnerabilities, Including Critical RCE Flaws

Broadcom has rolled out a sweeping security update for its Spring application development framework, addressing 91 vulnerabilities in a single release cycle. The patch batch spans ...

VulnerabilitySupply ChainAI Security
Read More → Use Tool →
2026-08-24SecurityWeek
Venezuelan National Gets Record 8-Year Sentence for ATM Jackpotting Scheme

A 27-year-old Venezuelan national has been sentenced to 96 months in federal prison for his role in an ATM jackpotting operation that caused more than $3.5 million in losses, the U...

MalwareAPTThreat Intel
Read More → Use Tool →
2026-08-24SecurityWeek
Apollo Global Breach Exposes SSNs in BlackFile Vishing Campaign

Apollo Global Management has disclosed a data breach that exposed sensitive personal information following a social engineering attack. According to a breach notice sent to affecte...

Data BreachPhishingThreat Intel
Read More → Use Tool →
2026-08-22The Hacker News
TikTok to Pay $400M in Child Privacy Settlement with U.S. DOJ

The U.S. Department of Justice announced on Friday that ByteDance-owned TikTok has agreed to pay $400 million to settle a 2024 lawsuit accusing the social media platform of violati...

PrivacyRegulation
Read More → Use Tool →
2026-08-22SecurityWeek
Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 Target Global Users

Three major banking trojan families—Manic, Grandoreiro, and an updated ToxicPanda variant—are actively targeting financial institutions and end users across multiple continents, ac...

MalwareThreat IntelPhishing
Read More → Use Tool →
2026-08-21Dark Reading
Unprotected TSN Protocols Open OT Networks to Physical Attack

Time-Sensitive Networking (TSN), a family of IEEE 802.1 standards originally designed to deliver deterministic Ethernet for audio, video, and automotive applications, is rapidly ga...

VulnerabilityThreat Intel
Read More → Use Tool →
2026-08-21SecurityWeek
CISA: Head Mare Hacktivists Actively Exploiting TrueConf Server Flaws

Federal agencies were put on alert this week after the US Cybersecurity and Infrastructure Security Agency (CISA) added two critical vulnerabilities in TrueConf Server to its Known...

VulnerabilityAPTMalware
Read More → Use Tool →
2026-08-21SecurityWeek
Microsoft Patches Exploited Entra ID Zero-Day and 21 Other Flaws

Microsoft on Thursday released 22 security updates addressing severe vulnerabilities across its product portfolio, headlined by an actively exploited zero-day in Entra ID. Tracked ...

Zero-DayVulnerabilityCloud Security
Read More → Use Tool →
2026-08-21Dark Reading
Hardware Makers Race to Deploy Post-Quantum Cryptography Before Q-Day Arrives

Major hardware manufacturers are accelerating the rollout of post-quantum cryptography (PQC) as the cybersecurity community braces for "Q-Day"—the moment when cryptographically rel...

EncryptionVulnerabilityRegulation
Read More → Use Tool →
2026-08-21SecurityWeek
Defense Contractors' CMMC Confidence Outpaces Their Ability to Prove Compliance

Two new industry surveys reveal a widening gap between perception and reality across the defense industrial base: defense contractors are reporting record confidence in their cyber...

RegulationSupply Chain
Read More → Use Tool →
2026-08-21SecurityWeek
Critical isolated-vm Flaw Enables Remote Code Execution on Host

A critical-severity type confusion vulnerability in the isolated-vm Node.js library could allow threat actors to achieve remote code execution (RCE) on the underlying host system, ...

VulnerabilityZero-Day
Read More → Use Tool →
2026-08-21SecurityWeek
iAuthFlow V2 Phishing Kit Uses Passkeys to Survive Password Resets

A sophisticated phishing toolkit dubbed iAuthFlow V2 is raising alarm across the cybersecurity community for its ability to maintain persistent access to compromised Gmail accounts...

PhishingAuthenticationMalware
Read More → Use Tool →
2026-08-21The Record
Microolap Confirms Cyberattack as Pro-Ukraine Hackers Claim Russian Data Theft

Russian network monitoring software developer Microolap confirmed that hackers compromised several of its systems this week, but pushed back against claims by a pro-Ukraine hacking...

Data BreachAPTIncident Response
Read More → Use Tool →
2026-08-21The Hacker News
Critical GitLab CVE-2026-19478 Exploited Within Days — Patch Now

A critical code injection vulnerability in GitLab, tracked as CVE-2026-19478 with a CVSS score of 9.4, has come under active in-the-wild exploitation just days after public disclos...

VulnerabilityZero-DayAI Threats
Read More → Use Tool →
2026-08-21SecurityWeek
Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini

Researchers at Adversa AI have identified a novel attack technique dubbed Cryptographic Context Injection that successfully circumvents safety guardrails in major AI platforms, inc...

AI SecurityAI ThreatsLLM Security
Read More → Use Tool →
2026-08-21The Record
SickKids Hospital Breached Again: Employee Data Stolen via Third-Party App

Canada's largest pediatric health center, the Hospital for Sick Children (SickKids), has disclosed a second major cybersecurity incident in three years, with attackers stealing per...

Data BreachPrivacySupply Chain
Read More → Use Tool →
2026-08-21The Hacker News
Microsoft Patches Critical Entra ID RCE Flaw (CVSS 10.0)

Microsoft has patched a maximum-severity vulnerability in its Entra ID cloud identity service that could allow remote code execution over a network. Tracked as CVE-2026-69836 with ...

VulnerabilityCloud SecurityThreat Intel
Read More → Use Tool →
2026-08-21The Hacker News
Trojanized npm Packages Deliver RedC2 4.0 Linux Backdoor in Supply Chain Attack

Cybersecurity researchers at TrendAI, the enterprise security arm of Trend Micro, have uncovered 14 trojanized npm packages that masquerade as legitimate calendar, streak-tracking,...

Supply ChainMalwareAI Threats
Read More → Use Tool →
2026-08-21Dark Reading
OpenAI Rolls Out Security Controls After Hugging Face Model Leak

OpenAI has introduced a suite of new security controls for its platform, a move that industry observers say is overdue following last month's disclosure that an internal Hugging Fa...

AI SecurityLLM SecurityIncident Response
Read More → Use Tool →