HackMyIP

Cybersecurity News

Latest updates from top security sources

1349 articles, page 29 of 45

2026-05-18KrebsOnSecurity
CISA Admin Leaked AWS GovCloud Keys on Github

Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several h...

Read More → Use Tool →
2026-05-18Dark Reading
Microsoft Exchange Zero-Day Under Attack, No Patch Available

CVE-2026-42897 stems from a cross-site scripting (XSS) vulnerability and can allow an attacker to compromise Outlook Web Access (OWA) mailboxes....

Read More → Use Tool →
2026-05-18Dark Reading
'Claw Chain' Vulnerabilities Threaten OpenClaw Deployments

The now patched vulnerabilities in the rapidly growing AI agent framework allow attackers to steal credentials, escalate privileges, and maintain persistence....

Read More → Use Tool →
2026-05-18Dark Reading
Shai-Hulud Worm Clones Spread After Code Release

The release of Shai-Hulud source code spells trouble for software developers as researchers worry the self-replicating worm could scale....

Read More → Use Tool →
2026-05-18Dark Reading
Boulevard of Broken Dreams: 2 Decades of Cyber Fails

From the MGM and Caesars fiasco and MOVEit's patch nightmare to epic business blunders and the jaded reality of living in a post-breach world, Dark Reading looks back at the mistak...

Read More → Use Tool →
2026-05-18The Record
More than 200 arrested in cyber raids aimed at Middle East scam networks

Investigators found hundreds of compromised devices that were used as part of the cybercriminal operation and notified device owners as part of the raids....

Read More → Use Tool →
2026-05-18The Hacker News
INTERPOL Operation Ramz: 201 Arrests in MENA Cybercrime Crackdown

INTERPOL's Operation Ramz has concluded with a significant blow to cybercriminal operations across the Middle East and North Africa (MENA) region. The coordinated crackdown, spanni...

PhishingThreat IntelIncident Response
Read More → Use Tool →
2026-05-18The Hacker News
Reduce Phishing Exposure Before Business Disruption Hits

Phishing attacks continue to evolve beyond simple credential harvesting, creating multi-stage risks that can compromise email systems, SaaS applications, cloud platforms, and inter...

PhishingThreat IntelIncident Response
Read More → Use Tool →
2026-05-18The Hacker News
⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More

Monday opens with a trust problem. A mail server flaw is under active use. A network control system was targeted. Trusted packages were poisoned. A fake model page pushed a stealer...

Read More → Use Tool →
2026-05-18BleepingComputer
Leaked Shai-Hulud malware fuels new npm infostealer campaign

The Shai-Hulud malware leaked last week is now used in new attacks on the Node Package Manager (npm) index, as infected packages emerged over the weekend. [...]...

Read More → Use Tool →
2026-05-18BleepingComputer
Grafana says stolen GitHub token let hackers steal codebase

Grafana Labs disclosed that hackers have downloaded its source code after breaching its GitHub environment using a stolen access token. [...]...

Read More → Use Tool →
2026-05-18Dark Reading
Fuel Tank Breaches Expand Scope of Iran's Cyber Offensive

Security experts have long warned that insecure automatic tank gauge (ATG) systems exposed on the Internet can be tampered with by threat actors....

Read More → Use Tool →
2026-05-18SecurityWeek
Millions Impacted Across Several US Healthcare Data Breaches

Several healthcare data breaches impacting hundreds of thousands and even millions were added to the HHS tracker. The post Millions Impacted Across Several US Healthcare Data Breac...

Read More → Use Tool →
2026-05-18SecurityWeek
‘Claw Chain’ OpenClaw Flaws Allow Sandbox Escape, Backdoor Delivery

Four vulnerabilities in OpenClaw can be chained together to steal credentials, escape the sandbox, and plant persistent backdoors. The post ‘Claw Chain’ OpenClaw Flaws ...

Read More → Use Tool →
2026-05-18The Record
Grafana refuses to pay ransom after codebase theft

On Saturday night, the company released a statement confirming the incident and outlining their decision not to pay a ransom issued by the hackers behind the attack....

Read More → Use Tool →
2026-05-18The Record
Experts warn of privacy risks as AI firms looks to connect to financial accounts

OpenAI announced Friday that it is rolling out a new ChatGPT feature allowing users to connect all of their financial accounts to the chatbot for personal finance advice....

Read More → Use Tool →
2026-05-18The Hacker News
Developer Workstations Now Critical Supply Chain Attack Targets

In a concentrated 48-hour window, threat actors launched coordinated attacks against npm, PyPI, and Docker Hub, marking a significant escalation in software supply chain aggression...

Supply ChainThreat IntelAuthentication
Read More → Use Tool →
2026-05-18The Hacker News
Ivanti, Fortinet, SAP, VMware Patch Critical RCE, SQL Injection, Privilege Escalation

Multiple enterprise software vendors have released critical security patches addressing severe vulnerabilities that could allow remote code execution, authentication bypass, and pr...

VulnerabilityZero-DayAuthentication
Read More → Use Tool →
2026-05-18The Hacker News
MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems

Chaotic Eclipse, the security researcher behind the recently disclosed Windows flaws, YellowKey and GreenPlasma, has released a proof-of-concept (PoC) for a Windows privilege escal...

Read More → Use Tool →
2026-05-18The Hacker News
Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware

Cybersecurity researchers have discovered four new npm packages containing information-stealing malware, one of which is a clone of the Shai-Hulud worm open-sourced by TeamPCP. The...

Read More → Use Tool →
2026-05-18The Hacker News
Pre-Stuxnet Fast16 Malware Tampered with Nuclear Weapons Simulations

A new analysis of the Lua-based fast16 malware has confirmed that it was a cyber sabotage tool designed to tamper with nuclear weapons testing simulations. According to Broadcom-ow...

Read More → Use Tool →
2026-05-18BleepingComputer
Microsoft testing adjustable taskbar, Start menu in Windows 11

Microsoft has finally brought back the resizable taskbar and Start menu to Windows 11 in the latest preview version rolling out to Insiders in the Experimental channel. [...]...

Read More → Use Tool →
2026-05-18BleepingComputer
Microsoft confirms Windows 11 security update install issues

Microsoft has confirmed that the May 2026 Windows 11 security update (KB5089549) fails to install on some systems and triggers 0x800f0922 errors. [...]...

Read More → Use Tool →
2026-05-18BleepingComputer
Exploit available for new DirtyDecrypt Linux root escalation flaw

A recently patched local privilege escalation vulnerability in the Linux kernel's rxgk module now has a proof-of-concept exploit that allows attackers to gain root access on some L...

Read More → Use Tool →
2026-05-18SecurityWeek
7-Eleven Data Breach Confirmed After ShinyHunters Ransom Demand

The hackers claimed to have stolen more than 600,000 Salesforce records, including personal information and corporate data.  The post 7-Eleven Data Breach Confirmed After ShinyHunt...

Read More → Use Tool →
2026-05-18SecurityWeek
Researcher Drops MiniPlasma Windows Exploit for Unpatched 2020 CVE

The researcher dropped the MiniPlasma exploit that uses the original proof-of-concept (PoC) code targeting the bug. The post Researcher Drops MiniPlasma Windows Exploit for Unpatch...

Read More → Use Tool →
2026-05-18SecurityWeek
First Shai-Hulud Worm Clones Emerge

At least one threat actor has adopted the recently released malware source code in attacks against NPM developers. The post First Shai-Hulud Worm Clones Emerge appeared first on Se...

Read More → Use Tool →
2026-05-18SecurityWeek
Grafana Confirms Breach After Hackers Claim They Stole Data

Grafana appears to have been targeted by Coinbase Cartel, a cybercrime group linked to ShinyHunters, Scattered Spider, and Lapsus$. The post Grafana Confirms Breach After Hackers C...

Read More → Use Tool →
2026-05-18SecurityWeek
Exploitation of Critical NGINX Vulnerability Begins

The flaw leads to denial-of-service on default configurations and to remote code execution if ASLR is disabled. The post Exploitation of Critical NGINX Vulnerability Begins appeare...

Read More → Use Tool →
2026-05-18BleepingComputer
Hackers earn $1,298,250 for 47 zero-days at Pwn2Own Berlin 2026

The Pwn2Own Berlin 2026 hacking contest has concluded, with security researchers collecting $1,298,250 in rewards after exploiting 47 zero-day flaws. [...]...

Read More → Use Tool →