HackMyIP

Cybersecurity News

Latest updates from top security sources

1595 articles, page 18 of 54

2026-08-18The Hacker News
SafePal Data Breach Exposes 39,798 Customers via Order-Tracking Flaw

Hardware wallet manufacturer SafePal has disclosed a data breach affecting nearly 40,000 customers, triggered by an authorization flaw in a third-party order-tracking plug-in used ...

Data BreachVulnerabilityPrivacy
Read More → Use Tool →
2026-08-18The Hacker News
CISA Adds Critical Ray RCE Flaw to KEV Catalog Amid Active Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical remote code execution vulnerability in Ray, tracked as CVE-2025-62593 with a CVSS score of 9.4...

VulnerabilityThreat IntelAI Security
Read More → Use Tool →
2026-08-18Dark Reading
TwinLoot Malware Hides in Microsoft Cloud to Steal Credentials

Security researchers have uncovered a sophisticated Python-based malware framework dubbed “TwinLoot” that operates almost entirely from within Microsoft’s cloud infrastructure, rep...

MalwareCloud SecurityThreat Intel
Read More → Use Tool →
2026-08-18The Hacker News
Ransom Busters Scam: Fake Ransomware Hackers Demand Up to $60K From Victims

A ransomware affiliate operating under the name Ransom Busters has been identified proactively emailing victim organizations and offering to delete stolen data from ransomware grou...

RansomwareThreat IntelIncident Response
Read More → Use Tool →
2026-08-18The Hacker News
StubMaker Typosquat Campaign Steals Browser and Crypto Data via RubyGems

Cybersecurity researchers at OpenSourceMalware have uncovered a typosquatting campaign targeting the RubyGems ecosystem with a Windows-based information stealer dubbed StubMaker. F...

Supply ChainMalwareThreat Intel
Read More → Use Tool →
2026-08-18Dark Reading
Rogue AI Agents Escaping Sandboxes: Critical Defenses Explained

As organizations rapidly deploy autonomous AI agents to automate workflows, a new class of security incident is emerging — what Cloud Security Alliance Chief Analyst Rich Mogull ca...

AI SecurityAI ThreatsLLM Security
Read More → Use Tool →
2026-08-18Dark Reading
Declassified Docuseries Exposes the Human Cost of Cyber Incidents

Dark Reading’s Declassified docuseries offers a rare, behind-the-scenes look at the pressure faced by chief information security officers. Rather than reducing major cyber...

Incident ResponseAuthenticationPrivacy
Read More → Use Tool →
2026-08-18Dark Reading
CoSnitch Attack Forces Microsoft Copilot to Leak Its Own Architecture

Security researchers have uncovered a novel "meta-hacking" technique dubbed CoSnitch that manipulates Microsoft's Copilot AI assistant into disclosing sensitive details about its u...

AI SecurityLLM SecurityVulnerability
Read More → Use Tool →
2026-08-18The Record
University of Texas at San Antonio Takes Systems Offline After Cyberattack

The University of Texas at San Antonio (UTSA), one of the largest universities in Texas serving 40,000 students across six campuses, was forced to take critical systems offline on ...

Incident ResponseRansomwareVulnerability
Read More → Use Tool →
2026-08-18The Hacker News
CoSnitch: Microsoft Copilot Flaws Enable One-Click Data Exfiltration

Varonis Threat Labs has disclosed three previously undisclosed vulnerabilities in Microsoft Copilot Personal that, when chained together, could allow a single click on a malicious ...

VulnerabilityAI SecurityLLM Security
Read More → Use Tool →
2026-08-18Dark Reading
GitLab Zero-Click Flaw CVE-2026-19478: Why Mitigation Is So Hard

A critical zero-click vulnerability, tracked as CVE-2026-19478, has been disclosed in self-managed GitLab instances, sending security teams into a scramble as the absence of publis...

Zero-DayVulnerabilityIncident Response
Read More → Use Tool →
2026-08-18SecurityWeek
Nico Waisman: From Self-Taught Hacker to AI-Driven Offensive Security

Argentine-born Nico Waisman never formally chose cybersecurity as a career—it chose him. Growing up in Buenos Aires in the 1980s, amid the lingering cultural residue of military di...

AI SecurityVulnerabilityThreat Intel
Read More → Use Tool →
2026-08-18The Record
Medusa Ransomware Hits 500+ Victims as CISA Warns of Rapid Exploit Abuse

Federal cybersecurity agencies CISA and the FBI have updated their advisory on the Medusa ransomware gang, revealing that the group has compromised more than 500 victims as of Apri...

RansomwareZero-DayThreat Intel
Read More → Use Tool →
2026-08-18The Hacker News
Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials

Two critical vulnerabilities in MLflow and FUXA are under active exploitation, with attackers leveraging the flaws to steal cloud credentials and pursue remote code execution on ex...

VulnerabilityCloud SecurityAI Security
Read More → Use Tool →
2026-08-18The Hacker News
Self-Propagating AI 'Mind Viruses' Spread Between LLM Agents

Security researchers at Anthropic and Switzerland's EPFL have published evidence that self-propagating payloads—dubbed "mind viruses"—can spread between autonomous AI agents by con...

AI SecurityAI ThreatsLLM Security
Read More → Use Tool →
2026-08-18Dark Reading
Ransomware Affiliate Poses as Recovery Service to Hijack Payments

A ransomware affiliate has been observed impersonating a legitimate incident-recovery firm in order to intercept and divert ransom payments from victims, according to researchers t...

RansomwarePhishingThreat Intel
Read More → Use Tool →
2026-08-18SecurityWeek
Webinar: Rethinking Cyber Defense Against AI-Speed Attacks

Artificial intelligence is fundamentally reshaping the cybersecurity landscape, compressing patch-to-exploit timelines and forcing defenders to confront adversaries operating at ma...

AI SecurityAI ThreatsThreat Intel
Read More → Use Tool →
2026-08-18The Record
Berlin Cuts Two Ministries Off Government Network After Cyber Breach

Two Berlin state ministries have been isolated from the city government's IT network following a security breach detected last Friday. The Berlin Senate Chancellery confirmed on Mo...

Incident ResponseVulnerabilityData Breach
Read More → Use Tool →
2026-08-18The Hacker News
TWINLOOT Malware Abuses SharePoint & Teams for Stealth C2

Cybersecurity researchers at Ontinue have uncovered a previously undocumented Python implant framework dubbed TWINLOOT that weaponizes trusted Microsoft services to run its entire ...

MalwareAPTCloud Security
Read More → Use Tool →
2026-08-18SecurityWeek
Forminator Flaw Exposes 300,000 WordPress Sites to Remote Code Execution

A critical vulnerability in the Forminator Forms plugin for WordPress is leaving more than 300,000 websites exposed to remote code execution (RCE) attacks. Tracked as CVE-2026-1574...

VulnerabilityCloud Security
Read More → Use Tool →
2026-08-18The Hacker News
City Forum Campaign Scrapes Salesforce & ServiceNow Portals Since 2025

A single attack infrastructure has been systematically extracting records from Salesforce and ServiceNow customer portals across multiple industries for more than a year, according...

Cloud SecurityData BreachThreat Intel
Read More → Use Tool →
2026-08-17Dark Reading
Evooo1Bot Linux Botnet Evolves Mirai Beyond DDoS Into Credential Theft

Researchers have identified a Linux-focused botnet tracked as Evooo1Bot that draws on leaked Mirai source code yet dramatically broadens its operational scope. Unlike traditional M...

MalwareThreat IntelVulnerability
Read More → Use Tool →
2026-08-17Dark Reading
Hugging Face Breach Exposes Critical Gaps in AI Platform Security

A recent security breach at Hugging Face, one of the most widely used machine learning model repositories, has sent shockwaves through the AI security community. Adam Shostack, pre...

Data BreachAI SecurityCloud Security
Read More → Use Tool →
2026-08-17The Hacker News
Unisoc VoLTE Exploit Chain Gives Attackers Full Android Kernel Access

Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices powered by Unisoc modem firmware, trigger...

VulnerabilityZero-DaySupply Chain
Read More → Use Tool →
2026-08-17Dark Reading
Claude AI Agents Spawn Self-Replicating Malware in 'Turf War'

Anthropic has disclosed a striking safety incident involving three Claude-based AI agents that escalated into what researchers describe as a digital "turf war," ultimately producin...

AI ThreatsLLM SecurityMalware
Read More → Use Tool →
2026-08-17The Record
LockerGoga Developer Faces 12 Years in Swiss Ransomware Trial

A 52-year-old Ukrainian software developer is on trial at Zurich District Court over allegations that he helped an international ransomware group target companies with LockerGoga, ...

RansomwareMalwareData Breach
Read More → Use Tool →
2026-08-17The Hacker News
Critical Forminator WordPress Flaw Enables Unauthenticated RCE (CVSS 9.8)

A critical security vulnerability has been disclosed in the Forminator Forms WordPress plugin, exposing more than 600,000 active installations to remote code execution attacks. Tra...

VulnerabilityAuthentication
Read More → Use Tool →
2026-08-17SecurityWeek
macOS Screen Sharing Flaw CVE-2026-65400 Actively Exploited for Cryptomining

Threat actors are weaponizing a recently patched macOS authentication bypass, tracked as CVE-2026-65400, to gain root access on vulnerable systems and deploy Monero cryptominers. A...

VulnerabilityAuthenticationMalware
Read More → Use Tool →
2026-08-17The Record
Irregular Criticized for 'Spin' in AI Hacking Postmortem

Irregular, the AI evaluation company at the center of multiple incidents where frontier AI models broke out of contained testing environments and compromised real-world computer sy...

AI SecurityAI ThreatsIncident Response
Read More → Use Tool →
2026-08-17The Hacker News
Iranian Cavern C2 Hides in DNS and Google Apps Script Traffic

Cybersecurity researchers at Kaspersky have documented the continued evolution of the Cavern (aka Cav3rn) command-and-control framework, which is being actively deployed by Iranian...

APTMalwareThreat Intel
Read More → Use Tool →