HackMyIP

Cybersecurity News

Latest updates from top security sources

2415 articles, page 20 of 81

2026-07-08The Hacker News
UAT-7810 APT Expands ORB Network with New LONGLEASH Malware

Cisco Talos researchers have uncovered that a China-linked advanced persistent threat actor tracked as UAT-7810 is actively evolving its toolkit to grow its Operational Relay Box (...

APTMalwareThreat Intel
Read More → Use Tool →
2026-07-08The Hacker News
GhostLock Linux Kernel Flaw Grants Root Access on Most Distros

Nebula Security has disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel use-after-free vulnerability that lets any local user escalate to full root on unpatched system...

VulnerabilityCloud SecurityBug Bounty
Read More → Use Tool →
2026-07-08The Hacker News
CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of activ...

Read More → Use Tool →
2026-07-08Dark Reading
State IDs for AI Agents: Will Estonia Set a Precedent?

The world's digital testing ground plans to help people use AI agents for government purposes....

Read More → Use Tool →
2026-07-08SecurityWeek
CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws

Two newly disclosed critical vulnerabilities in Adobe ColdFusion and Langflow join two Joomla extension flaws in CISA's Known Exploited Vulnerabilities catalog, with federal agenci...

Read More → Use Tool →
2026-07-08SecurityWeek
Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection

Researchers show how attackers can use a crafted public GitHub Issue to trick AI-powered workflows into exposing data from private repositories without authentication. The post Cri...

Read More → Use Tool →
2026-07-07Dark Reading
Fake Big-Brand Job Listings Steal Google Logins from Marketers

A sophisticated phishing campaign is weaponizing the names of well-known consumer brands to lure marketing professionals into surrendering their Google Workspace credentials. Resea...

PhishingThreat IntelAuthentication
Read More → Use Tool →
2026-07-07Dark Reading
Google Dialogflow CX Rogue Agent Flaw Exposed Chatbot Data

Cybersecurity researchers at Varonis have disclosed a critical vulnerability in Google’s Dialogflow CX platform that could have allowed attackers to siphon sensitive data from ente...

AI SecurityVulnerabilityCloud Security
Read More → Use Tool →
2026-07-07The Hacker News
DEBULL Tooling Exploits Microsoft Device-Code Flow in M365 Phishing

A new Microsoft 365 device-code phishing campaign observed between late June and early July 2026 is leveraging a reusable attack framework dubbed DEBULL to hijack enterprise accoun...

PhishingAuthenticationThreat Intel
Read More → Use Tool →
2026-07-07The Hacker News
RedWing Android Malware Rented on Telegram Targets Banking Apps

A new Android malware-as-a-service operation dubbed RedWing is being advertised on Telegram as a turnkey bank-fraud kit, enabling low-skill criminals to hijack victim devices, harv...

MalwarePhishingThreat Intel
Read More → Use Tool →
2026-07-07The Hacker News
Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots

A critical flaw in Google's Dialogflow CX could have let an attacker with edit rights on one Code Block-enabled agent compromise other Code Block-enabled agents in the same Google ...

Read More → Use Tool →
2026-07-07The Hacker News
Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data

A public issue can trick GitHub Agentic Workflows into leaking the contents of an organization's private repositories, researchers at Noma Security have shown. The attacker needs ...

Read More → Use Tool →
2026-07-07The Hacker News
Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker

U.S. prosecutors linked an alleged Scattered Spider hacker to a break-in at a luxury jewelry retailer using a persistent Windows device ID, according to a newly unsealed federal co...

Read More → Use Tool →
2026-07-07The Hacker News
Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants

Cybersecurity researchers have disclosed details of a now-patched critical session isolation vulnerability in Writer, an enterprise generative artificial intelligence (AI) platform...

Read More → Use Tool →
2026-07-07The Hacker News
What Changes When Your Software Supply Chain Includes AI Writing Your Code?

Software supply chain security was hard enough. Then AI joined the build pipeline. For five years, "software supply chain security" meant one question: what's in your code? Which ...

Read More → Use Tool →
2026-07-07Dark Reading
'GitLost' Flaw Leaks Private Data From GitHub's Agentic Workflows

The flaw allows an unauthenticated attacker to craft a GitHub Issue in an org's public repository and then silently pull data from its private repos, too....

Read More → Use Tool →
2026-07-07SecurityWeek
County Government Reportedly Paid $1 Million to Cyber Extortion Group

The alleged victim, believed to be a small Ohio county, reportedly paid the extortion group to prevent the public release of sensitive stolen data. The post County Government Repor...

Read More → Use Tool →
2026-07-07SecurityWeek
Critical Gitea Flaw Under Active Exploitation, Researchers Warn

Attackers are exploiting the critical Gitea vulnerability CVE-2026-20896 to bypass authentication with a single HTTP header and access vulnerable repositories and secrets. The post...

Read More → Use Tool →
2026-07-07SecurityWeek
CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws

The audits are reportedly being spearheaded by CISA’s Attack Surface Evaluation team, a specialized unit tasked with conducting digital defense assessments and simulated hacking ex...

Read More → Use Tool →
2026-07-07SecurityWeek
Critical Adobe ColdFusion Vulnerability Exploited in Attacks

Hackers are exploiting a recently patched critical vulnerability (CVE-2026-48282) in Adobe ColdFusion that carries a CVSS score of 10/10. The post Critical Adobe ColdFusion Vulnera...

Read More → Use Tool →
2026-07-07SecurityWeek
Iran-Linked Hackers Using Modular C&C Framework in Cyberattacks

Researchers say the Iran-linked threat actor used an adaptable modular malware framework and compromised IT service providers to reach high-value targets in Israel. The post Iran-L...

Read More → Use Tool →
2026-07-07The Record
Supreme Court allows Texas app law requiring age verification to take effect

A student advocacy organization and tech trade group had appealed to the high court to stay the Texas App Store Accountability Act on an emergency basis until the lower court rules...

Read More → Use Tool →
2026-07-07The Record
Britain plans to build autonomous AI 'Cyber Shield' to defend nation

The capability, called Cyber Shield, is designed to counter a threat the National Cyber Security Centre (NCSC) said could see attackers “move at machine speed and greater scale, re...

Read More → Use Tool →
2026-07-07The Record
Major Japanese telco says cyberattack exposed 12 million emails

The company said the breach affected an email system used to manage customer email accounts, webmail services and email storage for five Japanese internet service providers....

Read More → Use Tool →
2026-07-07The Record
UK cyber pledge draws only a handful of top firms despite ministerial appeal

Those that did sign include large firms such as Aviva, the London Stock Exchange Group and Marks & Spencer, which lost hundreds of millions of pounds in a cyberattack last year, as...

Read More → Use Tool →
2026-07-07The Hacker News
BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support, PRA

BeyondTrust has rolled out security updates to remediate four critical vulnerabilities in its Remote Support (RS) and Privileged Remote Access (PRA) appliances, two of which carry ...

VulnerabilityAuthenticationAI Security
Read More → Use Tool →
2026-07-07The Hacker News
China-Aligned Hackers Exploit Roundcube Flaws to Target Universities

A suspected China-aligned threat cluster, tracked by Proofpoint as UNK_MassTraction, has been exploiting patched vulnerabilities in Roundcube webmail to compromise physics and engi...

APTPhishingVulnerability
Read More → Use Tool →
2026-07-07The Hacker News
CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware

Several versions of firmware released by Chinese network device manufacturer Tenda have been found to embed an undocumented authentication backdoor that enables administrative acce...

Read More → Use Tool →
2026-07-07SecurityWeek
CISO Conversations: Tarah Wheeler, Cybersecurity Leader, Thought Leader and Original Thinker

Tarah Wheeler is CISO at TPO Group, a firm that provides cybersecurity consultancy for high-stakes organizations. But despite this elevated position, her journey was far from typic...

Read More → Use Tool →
2026-07-07SecurityWeek
Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems

The 16-year-old Januscape flaw affects Linux's KVM hypervisor, allowing attackers to escape virtual machines and potentially execute code on the underlying host. The post Linux Ker...

Read More → Use Tool →