HackMyIP

Cybersecurity News

Latest updates from top security sources

1333 articles, page 21 of 45

2026-05-27SecurityWeek
‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems

Malicious repositories and disguised symlinks can trick AI coding agents into silently installing attacker-controlled MCP servers capable of stealing secrets, compromising CI pipel...

Read More → Use Tool →
2026-05-27SecurityWeek
GlassWorm Botnet Disrupted

Security firms took down all four command-and-control (C&C) channels used by the GlassWorm malware. The post GlassWorm Botnet Disrupted appeared first on SecurityWeek....

Read More → Use Tool →
2026-05-27SecurityWeek
LA Metro Cyberattack Linked to Iranian State-Sponsored Hackers

The attack was claimed by a hacktivist group, but evidence showed it used infrastructure linked to Iranian government threat actors. The post LA Metro Cyberattack Linked to Iranian...

Read More → Use Tool →
2026-05-27SecurityWeek
FBI: Hackers Sending Operatives in Person to Insert USB Drives and Steal Data

The FBI has issued an alert warning of Silent Ransom Group attacks targeting law firms. The post FBI: Hackers Sending Operatives in Person to Insert USB Drives and Steal Data appea...

Read More → Use Tool →
2026-05-27SecurityWeek
CISA Urges Immediate Patching of Exploited LiteSpeed cPanel Plugin Zero-Day

Resolved last week, the vulnerability was exploited in the wild as a zero-day to execute scripts with root privileges. The post CISA Urges Immediate Patching of Exploited LiteSpeed...

Read More → Use Tool →
2026-05-27SecurityWeek
Anthropic Releases New Claude Sandbox, Security Guidance Plugin

The AI giant says the new plugin, which helps developers find vulnerabilities as they write code, has been used extensively internally. The post Anthropic Releases New Claude Sandb...

Read More → Use Tool →
2026-05-26Dark Reading
State Cyber Leaders Push Congress for More Funding, Support

A recent congressional hearing highlighted how states are reeling from federal cutbacks to important cybergrants and information-sharing initiatives amid damaging attacks to critic...

Read More → Use Tool →
2026-05-26Dark Reading
Shai-Hulud Hackers TeamPCP: Lucky or Skilled?

TeamPCP, the cybercrime group behind later waves of the Shai-Hulud worm, has done significant damage to the open source ecosystem. But it's not necessarily due to skill alone....

Read More → Use Tool →
2026-05-26Dark Reading
For Enterprises, Security Remains Agentic AI's Biggest Challenge

Every company needs an agentic AI strategy, but the tools to allow agentic AI frameworks to be safely and securely adopted are just starting to appear....

Read More → Use Tool →
2026-05-26Dark Reading
State Cyber Leaders Beg Congress for More Funding, Support

A recent congressional hearing highlighted how states are reeling from federal cutbacks to important cyber grants and information sharing initiatives amid damaging attacks to criti...

Read More → Use Tool →
2026-05-26BleepingComputer
KnowledgeDeliver flaw exploited as a zero-day to install web shells

Hackers exploited a critical zero-day vulnerability in a server running the KnowledgeDeliver learning management system (LMS) to deploy the Godzilla web shell. [...]...

Read More → Use Tool →
2026-05-26BleepingComputer
Charter confirms data breach after ShinyHunters extortion threat

U.S. telecommunications giant Charter Communications has confirmed it suffered a data breach after the ShinyHunters extortion group threatened to leak stolen data unless a ransom i...

Read More → Use Tool →
2026-05-26Dark Reading
Feeding Frenzy: 'Megalodon' Malware Infects Thousands of GitHub Repos

In just six hours, the campaign quietly pushed thousands of malicious commits to more than 5,500 GitHub repositories, stealing credentials, developer secrets, and more....

Read More → Use Tool →
2026-05-26Dark Reading
The Hackers Behind Shai-Hulud: Lucky or Skilled?

TeamPCP, the hackers behind the Shai-Hulud worm, has done significant damage to the open source ecosystem. But it's not necessarily due to skill alone....

Read More → Use Tool →
2026-05-26Dark Reading
Microsoft Issues Out-of-Band SharePoint Patch

SharePoint access often means access to the keys of the kingdom, something attackers and defenders understand all too well....

Read More → Use Tool →
2026-05-26The Hacker News
MuddyWater APT Targets 9 Countries in DLL Side-Loading Espionage Campaign

The Iranian threat actor MuddyWater has been linked to a sophisticated cyber espionage campaign that compromised at least nine organizations across nine countries on four continent...

APTThreat IntelMalware
Read More → Use Tool →
2026-05-26The Hacker News
[THN Webinar] New AI DDoS Attacks Are Smarter. Learn How to Fight Back

Every single day, hackers are finding new ways to crash websites and steal data. But right now, something has changed. Hackers are no longer working alone. They are now using powe...

Read More → Use Tool →
2026-05-26The Hacker News
CERT-In Recommends 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks

The Indian Computer Emergency Response Team (CERT-In) has issued new guidelines requiring organizations to patch critical security vulnerabilities in internet-exposed systems withi...

Read More → Use Tool →
2026-05-26BleepingComputer
How Varonis Atlas integrates Claude Compliance API for AI governance

AI governance requires visibility into how AI tools interact with enterprise data. Varonis explains how its Atlas platform uses Claude Compliance API data to help monitor usage, in...

Read More → Use Tool →
2026-05-26BleepingComputer
Microsoft Defender can now automatically isolate hacked endpoints

Microsoft is testing a new Defender for Endpoint capability that will automatically isolate compromised endpoints to thwart attackers' attempts to move laterally across the network...

Read More → Use Tool →
2026-05-26BleepingComputer
Webinar: Too many tools are slowing network incident response

IT teams often need to jump between monitoring dashboards, infrastructure tools, ticketing systems, and communication platforms during network incidents. This webinar explores how ...

Read More → Use Tool →
2026-05-26SecurityWeek
AppOmni’s Marlin AI Brings Autonomous Investigation to SaaS Security

Marlin AI automatically analyzes SaaS misconfigurations, investigates related activity across enterprise environments, and recommends remediation steps — while stopping short of fu...

Read More → Use Tool →
2026-05-26SecurityWeek
Iranian APT Targets Aviation, Software Companies With Updated Tools

Nimbus Manticore has continued its operations during and after the US military campaign against Iran. The post Iranian APT Targets Aviation, Software Companies With Updated Tools a...

Read More → Use Tool →
2026-05-26The Record
Lithuania investigates theft of 600,000 state registry records by foreign actor

The Lithuanian Prosecutor General’s Office said Friday that attackers gained unauthorized access to more than 600,000 records managed by the Centre of Registers, the state agency r...

Read More → Use Tool →
2026-05-26The Hacker News
Microsoft Patches Critical SharePoint RCE Flaw CVE-2026-45659

Microsoft has released security updates addressing a critical remote code execution vulnerability, tracked as CVE-2026-45659, affecting Microsoft SharePoint Server across multiple ...

Vulnerability
Read More → Use Tool →
2026-05-26The Hacker News
MFA Prompt Bombing: Push-Based 2FA Exploitation Explained

Multi-factor authentication (MFA) was designed to close a critical gap in identity security by requiring a second factor beyond passwords. However, attackers have developed a techn...

AuthenticationPhishingThreat Intel
Read More → Use Tool →
2026-05-26The Hacker News
New AI DDoS Attacks Are Smarter. Learn How to Fight Back in This Webinar

Every single day, hackers are finding new ways to crash websites and steal data. But right now, something has changed. Hackers are no longer working alone. They are now using powe...

Read More → Use Tool →
2026-05-26The Hacker News
CERT-In Mandates 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks

The Indian Computer Emergency Response Team (CERT-In) has issued new guidelines requiring organizations to patch critical security vulnerabilities in internet-exposed systems withi...

Read More → Use Tool →
2026-05-26The Hacker News
Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO Poisoning

The Iranian state-sponsored threat actor known as Nimbus Manticore (aka Screening Serpens and UNC1549) has been attributed to a fresh campaign using lures impersonating organizatio...

Read More → Use Tool →
2026-05-26BleepingComputer
CISA orders feds to patch actively exploited Drupal vulnerability

CISA has given U.S. government agencies until Wednesday evening to secure their servers against an SQL injection vulnerability in the Drupal content management system (CMS) that it...

Read More → Use Tool →