HackMyIP

Cybersecurity News

Latest updates from top security sources

2415 articles, page 21 of 81

2026-07-07SecurityWeek
Keyfactor Scores $1 Billion+ Investment for AI, Post-Quantum Security

The investment will accelerate Keyfactor's machine identity, PKI, and cryptographic security platform as enterprises prepare for AI-driven and post-quantum threats. The post Keyfac...

Read More → Use Tool →
2026-07-06Dark Reading
BusySnake Infostealer Targets Critical Infrastructure in Russia, Brazil, and Kazakhstan

A sophisticated threat actor tracked as Armored Likho has been deploying a custom-built infostealer dubbed BusySnake against government agencie...

MalwareAPTThreat Intel
Read More → Use Tool →
2026-07-06The Hacker News
Iran-Linked Cavern C2 Framework Hits Israeli Orgs via SysAid

An Iranian threat cluster linked to the Ministry of Intelligence and Security (MOIS) is using a previously undocumented modular command-and-control framework dubbed Cavern (aka Cav...

APTThreat IntelSupply Chain
Read More → Use Tool →
2026-07-06The Hacker News
16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems

A use-after-free bug in Linux's KVM hypervisor can be triggered from a guest virtual machine to corrupt the shadow-page state of the host kernel that runs it. Dubbed 'Januscape' a...

Read More → Use Tool →
2026-07-06Dark Reading
CitrixBleed-ing Again? NetScaler Vulnerability Under Attack

Attackers wasted little time targeting the latest memory disclosure flaw in Citrix's NetScaler products, after researchers published a proof-of-concept exploit (PoC)....

Read More → Use Tool →
2026-07-06SecurityWeek
Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’ Attacks

Securonix says the sophisticated framework abuses compromised websites, Blogspot, PowerShell, and fileless techniques to evade detection and deploy the PureLog information stealer....

Read More → Use Tool →
2026-07-06The Record
Canadian spy agency reports hacking three criminal groups in 2025

A ransomware-as-a-service gang, an online foreign extremist group and drug traffickers were separately the targets of offensive operations in 2025, according to Canada's Communicat...

Read More → Use Tool →
2026-07-06The Record
Attackers vote themselves $20 million in BONK cryptocurrency

BonkDAO said in a social media post that it was the victim of a “malicious governance proposal,” or an attack in which holders of a large amount of BONK used that leverage to vote ...

Read More → Use Tool →
2026-07-06The Record
Major medical device manufacturer notifies nearly 4 million of breach

Information like Social Security numbers and health-related data was accessed, but the company said it had “no evidence that impacted information has been publicly posted or expose...

Read More → Use Tool →
2026-07-06The Hacker News
Critical Gitea Docker Flaw CVE-2026-20896 Actively Exploited Within Days

Threat actors began probing a critical security flaw in Gitea Docker images just 13 days after public disclosure, according to cloud security firm Sysdig. Tracked as CVE-2026-20896...

VulnerabilityCloud SecurityAuthentication
Read More → Use Tool →
2026-07-06The Hacker News
How to Evaluate AI SOC Platforms: 6 Capabilities That Matter Most

The AI security operations center (SOC) market has matured into a crowded landscape where SIEM, SOAR, and pureplay AI SOC vendors all claim to offer autonomous detection and respon...

AI SecurityIncident ResponseThreat Intel
Read More → Use Tool →
2026-07-06The Hacker News
NetNut 2M-Device Proxy Botnet Disrupted; WhatsApp Usernames Spark Impersonation Fears

Google, the FBI, Lumen, and other partners moved this week to dismantle the NetNut residential proxy network—also tracked as Popa—disabling Google accounts and services used for ma...

MalwarePrivacyThreat Intel
Read More → Use Tool →
2026-07-06The Hacker News
Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT

A suspected China-nexus threat activity cluster has been observed targeting Indian taxpayers, tax professionals, and corporate finance teams to deliver a remote access trojan desig...

Read More → Use Tool →
2026-07-06BleepingComputer
Software Is Now Written at the Speed of Thought. Security Isn't.

Every evolution in software development has reduced the friction between an idea and a deployable application. AI may remove the final barrier, but it also removes many of the mome...

Read More → Use Tool →
2026-07-06BleepingComputer
Max severity Adobe ColdFusion flaw now exploited in attacks

Attackers are now exploiting a maximum-severity Adobe ColdFusion vulnerability tracked as CVE-2026-48282, according to vulnerability intelligence company KEVIntel. [...]...

Read More → Use Tool →
2026-07-06Dark Reading
JadePuffer: The First Complete LLM-Driven Ransomware Attack

An "agentic threat actor" successfully exploited a Langflow flaw to steal data from a production database server and encrypt other systems....

Read More → Use Tool →
2026-07-06SecurityWeek
The Shift Toward Business-Aligned Risk Management

Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. The post The Shift Toward Busi...

Read More → Use Tool →
2026-07-06SecurityWeek
Armored Likho APT Targeting Government, Electric Power Entities

The threat actor uses modular RATs and information stealers in financially motivated and cyber espionage campaigns. The post Armored Likho APT Targeting Government, Electric Power ...

Read More → Use Tool →
2026-07-06SecurityWeek
North Korean Hackers Target Open Source Developers in Supply Chain Attacks

The PolinRider campaign has compromised more than 100 legitimate open source packages and repositories to deliver a backdoor and information stealer to developers. The post North K...

Read More → Use Tool →
2026-07-06SecurityWeek
Proof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access Vulnerability

Organizations are urged to patch after proof-of-concept code makes the Linux root escalation flaw easier to exploit. The post Proof-of-Concept Exploit Released for Linux ‘Bad Epoll...

Read More → Use Tool →
2026-07-06The Record
Japanese teen arrested over cyberattack that disrupted anime streaming service

The unnamed student, who lives in a city near Tokyo, allegedly exploited a flaw in a subscription-based anime streaming platform to fraudulently cancel more than 46,000 user subscr...

Read More → Use Tool →
2026-07-06The Record
Ukrainian media outlets now among 'priority targets' for Russian hackers

A top Ukrainian security official described two previously unreported attacks on TV media organizations and said Russia has ramped up hacking activities against the industry....

Read More → Use Tool →
2026-07-06The Hacker News
Opera GX Flaw Let Sites Silently Steal Data via Mod Auto-Install

A serious vulnerability in Opera GX, the gaming-focused browser from Opera, allowed a malicious website to silently install a browser modification and use it to extract sensitive d...

VulnerabilityBug BountyPrivacy
Read More → Use Tool →
2026-07-06The Hacker News
TrojPix Attack Leaks Air-Gapped Data via Video Cable Emissions

Researchers at Shandong University have unveiled TrojPix, a covert channel technique that exfiltrates data from air-gapped systems by modulating imperceptible pixels on the screen ...

Threat IntelMalwareData Breach
Read More → Use Tool →
2026-07-06The Hacker News
New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS

Cybersecurity researchers have flagged a novel Java-based remote access trojan (RAT) called QuimaRAT that's capable of targeting Windows, Linux, and macOS environments. According ...

Read More → Use Tool →
2026-07-06The Hacker News
SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing

Scanners meant to catch malicious add-on "skills" for AI coding agents can be fooled by a few simple changes that leave the malware working, according to a new study from...

Read More → Use Tool →
2026-07-06SecurityWeek
Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments

Researchers uncovered two campaigns embedding indirect prompt injections in malicious websites to exploit autonomous AI agents browsing the web. The post Prompt Injection Attacks T...

Read More → Use Tool →
2026-07-05BleepingComputer
Flipper Zero Firmware Goes Community-Driven: What It Means for Pen-Testers

Flipper Devices has confirmed that development of the Flipper Zero firmware will continue, but with a leaner internal team and a heavier reliance on community contributions. The...

VulnerabilityThreat Intel
Read More → Use Tool →
2026-07-04BleepingComputer
JadePuffer Ransomware: First Fully AI-Agent-Driven Attack Documented

Cloud security researchers at Sysdig have documented what may be the first ransomware operation executed entirely by an autonomous AI agent. Dubbed "JadePuffer," the campaign lever...

RansomwareAI ThreatsLLM Security
Read More → Use Tool →
2026-07-04The Hacker News
Union County Ohio Paid $1M in Bitcoin to Kairos Extortion Group

A U.S. government entity—almost certainly Union County, Ohio—paid roughly $1 million in bitcoin to a group calling itself Kairos to suppress the leak of stolen files, according to ...

RansomwareData BreachThreat Intel
Read More → Use Tool →