HackMyIP

Cybersecurity News

Latest updates from top security sources

2415 articles, page 22 of 81

2026-07-04The Hacker News
North Korean Hackers Push 108 Malicious Packages in PolinRider Campaign

North Korean threat actors tied to the Contagious Interview campaign have published 108 unique malicious packages and browser extensions across npm, Packagist, Go, and the Google C...

Supply ChainAPTMalware
Read More → Use Tool →
2026-07-03The Hacker News
Unpatched FatFs Flaws Expose Millions of IoT Devices to Code Execution

Security research firm runZero has disclosed seven previously unpatched vulnerabilities in FatFs, a lightweight FAT/exFAT filesystem library embedded in the fir...

VulnerabilitySupply Chain
Read More → Use Tool →
2026-07-03The Hacker News
Avalon Malware Framework Bundles Credential Theft with CrownX Ransomware

Blackpoint Cyber researchers Nevan Beal and Sam Decker have uncovered Avalon, a previously undocumented modular malware framework that consolidates credential harvesting, lateral m...

MalwareRansomwarePhishing
Read More → Use Tool →
2026-07-03The Hacker News
Bad Epoll Linux Flaw Lets Unprivileged Users Gain Root Access

A newly disclosed Linux kernel vulnerability dubbed "Bad Epoll" (CVE-2026-46242) enables unprivileged users to escalate privileges and gain root access on affected systems. The fla...

VulnerabilityZero-DayBug Bounty
Read More → Use Tool →
2026-07-03The Hacker News
North Korean Hackers Hide Malware in Fake Rollup npm Packages

Security researchers at JFrog have uncovered a new North Korea-linked software supply chain campaign targeting JavaScript developers through malicious npm packages disguised as leg...

Supply ChainAPTMalware
Read More → Use Tool →
2026-07-03BleepingComputer
NetNut Botnet Dismantled: 2 Million Infected Devices Cut Off

A coordinated law enforcement and industry operation has dismantled NetNut, one of the world's largest residential proxy networks, cutting off access to an estimated two million co...

MalwareIncident ResponseThreat Intel
Read More → Use Tool →
2026-07-03The Hacker News
Armored Likko APT Deploys BusySnake Stealer Against Government and Power Sector

A previously undocumented advanced persistent threat group dubbed Armored Likho has been conducting cyber-espionage and financially motivated intrusions against government agencies...

APTMalwarePhishing
Read More → Use Tool →
2026-07-03BleepingComputer
ARToken PhaaS Exposes EvilTokens Microsoft 365 Phishing Toolkit

Cisco Talos researchers have uncovered a phishing-as-a-service (PhaaS) platform named “ARToken” that operates as an affiliate of the EvilTokens ecosystem, exposing a sophisticated ...

PhishingThreat IntelAuthentication
Read More → Use Tool →
2026-07-03Dark Reading
Chinese LLMs Widen Attack-Defense Gap in Cybersecurity

Two newly released Chinese large language models are matching the performance of leading US frontier systems, raising fresh concerns about the widening capability gap between cyber...

AI SecurityAI ThreatsLLM Security
Read More → Use Tool →
2026-07-03SecurityWeek
Weekly Cybersecurity Roundup: KDDI Breach, Zero-Day Drops, PamStealer

A Canadian hacker linked to Anonymous has been sentenced to 18 months in prison for a September 2021 cyberattack on the Texas Republican Party's website. Aubrey Cottle, 39, of Osha...

Data BreachZero-DayMalware
Read More → Use Tool →
2026-07-03The Hacker News
EU Lawmaker Probing Pegasus Spyware Was Herself Hacked With Pegasus

A former Member of the European Parliament who served on a committee investigating commercial spyware abuse was herself repeatedly targeted with NSO Group's Pegasus spyware, accord...

MalwareZero-DayPrivacy
Read More → Use Tool →
2026-07-03The Hacker News
PamStealer macOS Malware Steals Login Passwords via Fake Maccy Sites

A new macOS information stealer dubbed PamStealer has been identified by Jamf Threat Labs, employing a multi-stage infection chain designed to harvest login credentials, browser da...

MalwareAuthenticationThreat Intel
Read More → Use Tool →
2026-07-03SecurityWeek
Agentic AI Used in Ransomware Attack via Langflow CVE-2025-3248

A threat actor tracked as JadePuffer has executed what cloud security firm Sysdig describes as the first fully agentic AI-driven ransomware campaign, exploiting a critical missing ...

RansomwareAI ThreatsVulnerability
Read More → Use Tool →
2026-07-03SecurityWeek
Medtronic Data Breach Impacts 3.8 Million People

In April, ShinyHunters accessed the company’s corporate IT systems and stole patients’ personal and medical information. The post Medtronic Data Breach Impacts 3.8 Million People a...

Read More → Use Tool →
2026-07-03SecurityWeek
Alleged Scattered Spider Hacker Extradited to US

Prosecutors say 19-year-old Peter Stokes was a member of Scattered Spider, the hacking group linked to more than 100 network intrusions and over $100 million in ransom payments. Th...

Read More → Use Tool →
2026-07-03SecurityWeek
Google, FBI Disrupt NetNut Residential Proxy Network Powered by Millions of Devices

NetNut rented access to millions of compromised devices, allowing cybercriminals and nation-state actors to mask their identities during attacks. The post Google, FBI Disrupt NetNu...

Read More → Use Tool →
2026-07-03SecurityWeek
Critical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code Execution

The DuneSlide vulnerabilities enable zero-click prompt injection attacks that escape Cursor's sandbox and execute arbitrary code on the underlying operating system. The post Critic...

Read More → Use Tool →
2026-07-03BleepingComputer
Anthropic Clarifies: Claude Fable 5 Not Permanently Leaving Subscriptions

Anthropic has moved to reassure Claude users that its most powerful model, Fable 5, will not be a permanent pay-to-play exclusion from standard subscription tiers. Following the re...

AI SecurityLLM SecurityRegulation
Read More → Use Tool →
2026-07-03The Record
Pegasus Spyware Found on EU Parliament Member Probing Its Misuse

A phone belonging to former Greek Member of the European Parliament Stelios Kouloglou was infected with Pegasus spyware on at least two occasions during his tenure on the PEGA C...

PrivacyMalwareAPT
Read More → Use Tool →
2026-07-03BleepingComputer
Claude Fable Relaunch Frustrates Users as Safety Guardrails Trigger Excessive Fallbacks

Anthropic has released Claude Fable to all subscribers following the lifting of a Department of Commerce export ban, but the restored model is drawing sharp criticism from develope...

AI SecurityLLM Security
Read More → Use Tool →
2026-07-02The Hacker News
Google Disrupts NetNut Proxy Network Spanning 2 Million Hacked Home Devices

Google has significantly disrupted NetNut, one of the largest residential proxy networks in operation, in a coordinated takedown with the FBI, Lumen's Black Lotus Labs, and acad...

MalwareThreat IntelPrivacy
Read More → Use Tool →
2026-07-02KrebsOnSecurity
FBI Seizes NetNut Proxy Network and Popa Botnet Tied to 2M Infected Devices

The FBI and IRS Criminal Investigation have seized hundreds of domains associated with NetNut, a sprawling residential proxy service operated by publicly-traded Israeli company Ala...

MalwareThreat IntelIncident Response
Read More → Use Tool →
2026-07-02The Hacker News
Anubis Ransomware Exploits Citrix Bleed 2 in Credential-Based Attacks

Threat actors tied to the Anubis ransomware-as-a-service (RaaS) operation have been actively exploiting Citrix Bleed 2 (CVE-2025-5777), a critical authentication-bypass flaw in Cit...

RansomwareVulnerabilitySupply Chain
Read More → Use Tool →
2026-07-02Dark Reading
Aussies Face Reduced Cybercrime Risk, as Pressure Shifts to SMBs

Improved institutional safeguards and stricter regulations have pushed the burdens of protection and risk reduction on to Australian businesses....

Read More → Use Tool →
2026-07-02Dark Reading
Apple Reverses Age-Old Patch Policy to Keep Up With AI

Expect more compressed patching cycles from Apple going forward, as attackers leverage artificial intelligence to reduce time to exploit....

Read More → Use Tool →
2026-07-02Dark Reading
FortiBleed Actors Collaborating With Inc, Lynx Ransomware Gangs

After gaining a foothold in thousands of Fortinet firewalls, the attackers are starting to monetize that access, and are also piling on a Nextcloud zero-day bug....

Read More → Use Tool →
2026-07-02Dark Reading
Ransomware Thugs Masquerade as Interpol to Entice Small Biz

The ransomware campaign relies on basic social engineering and stretches across multiple regions, including the US, Europe, Middle East, and elsewhere....

Read More → Use Tool →
2026-07-02The Record
Launch of UK's National Cyber Action Plan delayed amid Labour leadership crisis

The plan had been due for publication on Monday, the sources said. It has been postponed amid the uncertainty over the governing Labour Party’s leadership contest, which opens July...

Read More → Use Tool →
2026-07-02The Hacker News
ToddyCat's Umbrij Malware Exploits OAuth Tokens to Hijack Gmail Sessions

Kaspersky researchers have uncovered a sophisticated new malware dubbed Umbrij, attributed to the advanced persistent threat group ToddyCat, which leverages the Google API and OAut...

APTMalwareAuthentication
Read More → Use Tool →
2026-07-02The Hacker News
Why Traditional Identity Lifecycle Management Breaks Down for AI Agents

Enterprise identity lifecycle management was architected around a human employee with an HR record, a reporting manager, and a defined departure date. AI agents possess none of the...

AI SecurityAuthenticationRegulation
Read More → Use Tool →