HackMyIP

Cybersecurity News

Latest updates from top security sources

1073 articles, page 3 of 36

2026-08-12The Hacker News
Cisco ASA and FTD Flaw (CVE-2026-20349) Actively Exploited for DoS

Cisco has confirmed that a high-severity vulnerability in Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software is being acti...

VulnerabilityThreat IntelIncident Response
Read More → Use Tool →
2026-08-12The Hacker News
ShieldBreak Zero-Day Bypasses Microsoft Defender Patch, Grants SYSTEM Access (PoC Released)

Security researcher Chaotic Eclipse has published a proof-of-concept exploit for a new Microsoft zero-day dubbed ShieldBreak, which the researcher claims fully bypasses the patch f...

Zero-DayVulnerability
Read More → Use Tool →
2026-08-12The Hacker News
SAP Patches Critical Commerce Cloud Flaw Enabling Remote Code Execution

SAP has rolled out emergency patches for a maximum-severity vulnerability in SAP Commerce Cloud (Data Hub Adapter) that could allow unauthenticated attackers to execute arbitrary c...

VulnerabilityCloud SecurityAuthentication
Read More → Use Tool →
2026-08-12The Hacker News
LiteLLM Supply Chain Attack Exposes 2,100+ Organizations via Malicious PyPI Releases

Two malicious LiteLLM releases, versions 1.82.7 and 1.82.8, were published to the Python Package Index (PyPI) on March 24 and remained available for roughly 40 minutes between 10:3...

Supply ChainData BreachAI Security
Read More → Use Tool →
2026-08-12Dark Reading
How Walmart Scaled Security Operations Through Trust and Innovation

Walmart, the world's largest retailer by revenue, has overhauled its security operations center (SOC) by leaning into a culture-first model that prioritizes psychological safety, t...

Incident ResponseThreat IntelCloud Security
Read More → Use Tool →
2026-08-12Dark Reading
Walmart's Purple Teaming: How Colocating Red and Blue Teams Strengthens Defenses

Walmart has adopted a 'trusted agent' model for purple teaming, physically colocating its offensive red team and defensive blue team to break down silos and accelerate the detectio...

Threat IntelIncident Response
Read More → Use Tool →
2026-08-12The Hacker News
VMware vCenter Flaw Actively Exploited for Persistent Remote Access

Threat actors are actively weaponizing a critical directory-traversal vulnerability in Broadcom VMware vCenter (CVE-2026-59310, CVSS 9.8) to establish persistent remote access on c...

APTVulnerabilityThreat Intel
Read More → Use Tool →
2026-08-12The Hacker News
Enterprise Defenses Strong at Perimeter, Weak Inside: Picus 2026

Enterprise defenses are having one of their strongest years on record at the network perimeter, but collapse almost entirely once an attacker is inside. According to Picus Labs' ne...

Threat IntelIncident ResponseVulnerability
Read More → Use Tool →
2026-08-12The Record
CISA Orders Fed Agencies to Patch Microsoft Winsock Bug Exploited by Lazarus

CISA has directed U.S. federal agencies to patch CVE-2026-68820, a Windows Winsock vulnerability actively exploited by North Korea's Lazarus Group, by August 25. The flaw, which ca...

Zero-DayVulnerabilityAPT
Read More → Use Tool →
2026-08-12The Hacker News
Hidden AI Reasoning Flaw Leaked API Keys and Passwords Across Major LLMs

Researchers have disclosed a critical design flaw in the reasoning APIs of OpenAI, Anthropic, and Google that allowed weaker AI models to decode the internal reasoning traces of st...

AI SecurityLLM SecurityVulnerability
Read More → Use Tool →
2026-08-12SecurityWeek
WhatsApp Scam Alert Uses On-Device AI to Detect Fraud Without Breaking Encryption

WhatsApp has begun a limited beta rollout of Scam Alert, an optional feature that uses an on-device machine learning model to flag suspicious messages sent by unknown contacts. The...

AI SecurityPrivacyEncryption
Read More → Use Tool →
2026-08-12The Record
Microsoft Patch Tuesday Fixes 419 Flaws as AI Accelerates Bug Discovery

Microsoft on Tuesday shipped fixes for 419 security vulnerabilities in one of its largest Patch Tuesday releases on record, underscoring how artificial intelligence is fundamentall...

VulnerabilityZero-DayAPT
Read More → Use Tool →
2026-08-12The Hacker News
Lazarus Group Exploits Windows Zero-Day to Deploy Troy Backdoor

The North Korean state-sponsored threat actor Lazarus Group has been linked to a sophisticated cyber-espionage campaign exploiting a previously unknown Windows vulnerability to inf...

APTZero-DayPhishing
Read More → Use Tool →
2026-08-12Dark Reading
City-Forum APT Campaign Steals Salesforce and ServiceNow Data Since March 2025

A long-running cyber-espionage operation dubbed "City-Forum" has been systematically exfiltrating sensitive data from enterprise Salesforce and ServiceNow instances since at least ...

APTData BreachThreat Intel
Read More → Use Tool →
2026-08-12SecurityWeek
AI Security Startup Mindgard Bags $30M to Red-Team Vulnerable Models

London and Boston-based AI security startup Mindgard has closed a $30 million Series A funding round led by Album VC, bringing its total raised to approximately $42 million. Existi...

AI SecurityVulnerabilityZero-Day
Read More → Use Tool →
2026-08-12The Record
UK Criminal Records Office Breached 3 Times in 2 Years Over Unpatched CMS

Britain's ACRO Criminal Records Office has been formally reprimanded by the Information Commissioner's Office (ICO) after suffering three separate cyber intrusions between July 202...

Data BreachVulnerabilityIncident Response
Read More → Use Tool →
2026-08-12The Hacker News
737 Malicious Chrome VPN Extensions Caught Routing Traffic Through Proxies

Security researchers at Socket have uncovered a sprawling campaign involving 737 malicious Chrome VPN and proxy extensions that impersonate 66 well-known privacy brands to intercep...

PrivacySupply ChainMalware
Read More → Use Tool →
2026-08-12Dark Reading
Ransomware Hits Colombia Justice Ministry Before Transition

Colombia’s Ministry of Justice and Law was hit by a ransomware attack only days before the country’s presidential transition, according to Dark Reading. The incident disrupted the ...

RansomwareIncident ResponseThreat Intel
Read More → Use Tool →
2026-08-12SecurityWeek
SharePoint Auth Bypass CVE-2026-55040 Exploited After Rapid7 PoC Release

Microsoft's July Patch Tuesday addressed CVE-2026-55040, a SharePoint vulnerability rooted in weak authentication that allows remote, unauthenticated attackers to bypass securit...

VulnerabilityAuthenticationThreat Intel
Read More → Use Tool →
2026-08-12The Record
FBI Warns: Hackers Use Social Engineering to Hijack Accounts and Steal Explicit Content

The FBI has issued a new public alert warning that threat actors are increasingly using social engineering and cyber intrusion techniques to compromise social media accounts belong...

PhishingAuthenticationPrivacy
Read More → Use Tool →
2026-08-12The Hacker News
Adobe Fixes Three CVSS 10.0 Flaws in ColdFusion & Campaign Classic

Adobe has rolled out emergency patches addressing multiple critical security vulnerabilities across ColdFusion, Commerce, and Campaign Classic that could allow attackers to execute...

VulnerabilityCloud SecurityAuthentication
Read More → Use Tool →
2026-08-12SecurityWeek
Ceva Logistics Cyberattack Disrupts European Warehouses, Exposes Customer Data

Global shipping and logistics provider Ceva Logistics, a subsidiary of France-based CMA CGM Group, suffered a cyberattack on July 29 that disrupted operations across eight European...

Data BreachSupply ChainIncident Response
Read More → Use Tool →
2026-08-12SecurityWeek
Cisco Patches Firewall Zero-Day CVE-2026-20349 Exploited for DoS Attacks

Cisco released emergency patches on Tuesday for a zero-day vulnerability, tracked as CVE-2026-20349, affecting firewalls running Secure Firewall Adaptive Security Appliance (ASA) a...

Zero-DayVulnerability
Read More → Use Tool →
2026-08-11The Hacker News
Windows 11 USB Plug and Play Flaw Lets Attackers Chain to SYSTEM Takeover

Security researchers Alejandro Hernando and Borja Martinez have demonstrated how Windows 11's Plug and Play (PnP) auto-installation can be weaponized into a SYSTEM-level compromise...

VulnerabilityIncident Response
Read More → Use Tool →
2026-08-11The Hacker News
Hackers Hit Polish Power Plant via Private Cellular Network, Shut Turbine

Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power (CHP) plant serving roughly 50,000 residents by pivoting through a pr...

VulnerabilityAuthenticationIncident Response
Read More → Use Tool →
2026-08-11The Hacker News
BdThemes Supply Chain Attack Poisons JSON to Spawn Rogue WordPress Admins

Cybersecurity researchers at Wordfence have disclosed a sophisticated supply chain attack targeting WordPress plugin vendor BdThemes, prompting the WordPress.org plugins team to...

Supply ChainVulnerability
Read More → Use Tool →
2026-08-11The Hacker News
GhostSplice Attack Splits MCP Instructions to Steal Secrets from AI Coding Agents

Security researchers have demonstrated a new technique that allows a malicious Model Context Protocol (MCP) server to exfiltrate SSH keys, environment secrets, proprietary sourc...

AI SecurityAI ThreatsLLM Security
Read More → Use Tool →
2026-08-11The Hacker News
Gunra Ransomware Exploits Fortinet Flaws in Attacks on Critical Sectors

A joint cybersecurity advisory from U.S. and South Korean agencies has warned that Gunra ransomware is actively targeting critical infrastructure sectors worldwide, including healt...

RansomwareThreat IntelVulnerability
Read More → Use Tool →
2026-08-11The Hacker News
Mozilla Revokes Firefox Linux Signing Key After Private Repo Exposure

Mozilla has revoked the cryptographic signing key used to authenticate Firefox and Thunderbird downloads for Linux after an unencrypted copy was accidentally committed to one of th...

Supply ChainEncryptionIncident Response
Read More → Use Tool →
2026-08-11The Hacker News
North Korean IT Workers Caught in Fake Crypto Startup Sting

Security researchers from BCA LTD, NorthScan, and ANY.RUN ran a deliberate insider-threat experiment in 2026, posing as a cryptocurrency startup called Ballena Azul and recruiting ...

APTThreat IntelPrivacy
Read More → Use Tool →