HackMyIP

Cybersecurity News

Latest updates from top security sources

2415 articles, page 31 of 81

2026-06-24The Hacker News
Cordyceps Flaws Expose 300+ GitHub Repos to CI/CD Supply-Chain Attacks

Cybersecurity researchers at Novee Security have identified a critical class of CI/CD workflow misconfiguration dubbed "Cordyceps" that exposes more than 300 high-impact GitHub rep...

Supply ChainVulnerabilityCloud Security
Read More → Use Tool →
2026-06-24The Hacker News
Dawn of the Apex Agentic Adversary

We are standing at the end of an era we never thought to mourn: the era of human-speed threats. For years, cybersecurity moved to a rhythm organizations could follow. A researcher...

Read More → Use Tool →
2026-06-24BleepingComputer
CISA warns of max severity Ubiquiti flaws exploited in attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of hackers actively exploiting flaws in Ubiquity UniFi OS and Lantronix serial-to-ethernet servers. [......

Read More → Use Tool →
2026-06-24BleepingComputer
Amadey, StealC malware operations disrupted in Operation Endgame action

Microsoft, Europol, and international partners have disrupted infrastructure used by the Amadey and StealC malware operations as part of Operation Endgame, which targets cybercrimi...

Read More → Use Tool →
2026-06-24BleepingComputer
Securing the service desk: Why social engineering attacks keep succeeding

Service desks have become a favored target for attackers seeking password resets, MFA changes, and access to corporate accounts. Specops Software breaks down how service desk socia...

Read More → Use Tool →
2026-06-24Dark Reading
More Malicious OpenClaw Skills Threaten AI Supply Chain

OpenClaw removed five packages from ClawHub, its skills marketplace, that bypassed security checks even though they included infostealers and other threats....

Read More → Use Tool →
2026-06-24SecurityWeek
When Information Becomes the Attack Surface – Understanding AI Agent Traps

From hidden content injections to cognitive state poisoning, attackers are turning trusted data sources into traps for autonomous AI. The post When Information Becomes the Attack S...

Read More → Use Tool →
2026-06-24SecurityWeek
Microsoft and Allies Smash Shared Infrastructure of Amadey and StealC Malware

Hundreds of C&C servers were disrupted in an operation involving law enforcement and several cybersecurity companies. The post Microsoft and Allies Smash Shared Infrastructure...

Read More → Use Tool →
2026-06-24SecurityWeek
Exclusive: Meet AIVEX, a New Triage Model Built to Reduce Supply Chain Threat and Risk

The new framework seeks to help security teams identify which software supply chain vulnerabilities pose the greatest operational, safety, and business risks in AI-driven environme...

Read More → Use Tool →
2026-06-24SecurityWeek
macOS Weaknesses Chained to Silently Disable Endpoint Security Agents

A standard non-admin account is sufficient to conduct an attack that exploits legitimate OS behavior rather than software vulnerabilities. The post macOS Weaknesses Chained to Sile...

Read More → Use Tool →
2026-06-24SecurityWeek
Third DraftKings Hacker Sentenced to 18 Months in Prison

Nathan Austad has been ordered to pay roughly $1.8 million in forfeiture and restitution, and the sentence also includes 3 years of supervised release.  The post Third DraftKings H...

Read More → Use Tool →
2026-06-24SecurityWeek
Critical Ubiquiti Vulnerabilities in Attackers’ Crosshairs

The flaws allow remote, unauthenticated attackers to make system changes, access underlying accounts, and inject commands. The post Critical Ubiquiti Vulnerabilities in Attackers&#...

Read More → Use Tool →
2026-06-24The Record
German rail services resume after wireless communications outage

Deutsche Bahn said a nationwide disruption of railway services was tied to a malfunction in its 2G-based GSM-R communications system....

Read More → Use Tool →
2026-06-24The Record
Indian auto giant Bajaj Auto hit by ransomware incident

The company said in a regulatory filing that it became aware of the incident on Tuesday morning and had taken precautionary measures to contain its impact....

Read More → Use Tool →
2026-06-24The Hacker News
DoJ Seizes Huione Cloud Account in Cyber Scam Laundering Crackdown

The U.S. Department of Justice announced on Tuesday the seizure of a cloud computing account operated by subsidiaries of Cambodia-based conglomerate HuiOne Group, a network accused...

RegulationCloud SecurityThreat Intel
Read More → Use Tool →
2026-06-24BleepingComputer
Mistic Backdoor: New Stealth Malware Linked to KongTuke Access Broker

Symantec researchers have uncovered a new stealthy backdoor dubbed "Mistic" being deployed by KongTuke (also tracked as Woodgnat), a financially motivated initial access broker act...

MalwareRansomwareThreat Intel
Read More → Use Tool →
2026-06-24The Hacker News
Cisco Unified CM CVE-2026-20230 Actively Exploited — Patch Now

Threat actors are actively exploiting a critical vulnerability in Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition, tracked as CVE-2026-2...

VulnerabilityZero-DayIncident Response
Read More → Use Tool →
2026-06-24Dark Reading
Apple's MacOS Gap Lets Users Disable Security Tools

Attackers can exploit the issue to disable security and integrated browser tools without needing administrator privileges or kernel exploits....

Read More → Use Tool →
2026-06-24SecurityWeek
Agentic AI Security: Wrong Context, Wrong Decisions at Machine Speed

Context is the central plank of AI in general, and agentic AI in particular. If an AI system doesn’t have the correct context, it cannot make the correct decisions. The post Agenti...

Read More → Use Tool →
2026-06-24SecurityWeek
New ‘Mistic’ RAT Opens Door to Several Ransomware Families

Mistic is used by Woodgnat, an initial access broker working with Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta. The post New ‘Mistic’ RAT Opens Door to Seve...

Read More → Use Tool →
2026-06-24SecurityWeek
Exploitable CI/CD Vulnerabilities Expose Millions of Repositories to Hijacking

The security defects allow unauthenticated users to take control of the open source software supply chain. The post Exploitable CI/CD Vulnerabilities Expose Millions of Repositorie...

Read More → Use Tool →
2026-06-24SecurityWeek
BeyondTrust, LastPass Impacted by Klue-Salesforce Incident

Over a dozen Klue customers have confirmed that hackers stole data from their Salesforce instances. The post BeyondTrust, LastPass Impacted by Klue-Salesforce Incident appeared fir...

Read More → Use Tool →
2026-06-24SecurityWeek
Webinar Today: Modern Exposure Validation in the AI Era

The exploit timeline collapsed. Make sure your validation didn't. The post Webinar Today: Modern Exposure Validation in the AI Era appeared first on SecurityWeek....

Read More → Use Tool →
2026-06-24SecurityWeek
Cisco Unified CM Flaw CVE-2026-20230 Actively Exploited in the Wild

A critical vulnerability in Cisco's Unified Communications Manager (Unified CM) is being actively exploited in the wild, according to exploit intelligence firm Defused. The flaw, t...

VulnerabilityZero-DayThreat Intel
Read More → Use Tool →
2026-06-24SecurityWeek
Anthropic Mythos AI Uncovers Flaws in Classified US Government Systems

A senior U.S. official confirmed to The Associated Press that Anthropic's Mythos artificial intelligence model identified vulnerabilities in highly sensitive and classified governm...

AI SecurityAI ThreatsVulnerability
Read More → Use Tool →
2026-06-23The Hacker News
FortiBleed: 110M Credentials Stolen from 430K FortiGate Firewalls

A Russian-speaking initial access broker (IAB) has been linked to a massive credential-harvesting campaign called FortiBleed, which has compromised over 430,000 FortiGate firewalls...

Threat IntelVulnerabilityAuthentication
Read More → Use Tool →
2026-06-23BleepingComputer
Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks

A high-severity SSRF vulnerability, tracked as CVE-2026-20230, in Cisco Unified Communications Manager Server is now being exploited in attacks. [...]...

Read More → Use Tool →
2026-06-23BleepingComputer
Tata Electronics confirms cyberattack as hackers leak data

Tata Electronics has confirmed in a statement to BleepingComputer that it was the target of a cyberattack that impacted parts of its IT infrastructure. [...]...

Read More → Use Tool →
2026-06-23BleepingComputer
Windows 11 KB5095093 update rolls out new Point-in-Time restore feature

​​Microsoft has released the KB5095093 preview cumulative update for Windows 11 24H2 and 25H2, which fixes numerous bugs and begins rolling out new features, including the new Poin...

Read More → Use Tool →
2026-06-23BleepingComputer
Healthtech firm Xolis suffers data breach impacting 1.4 million people

Healthcare technology company Xsolis says that sensitive data belonging to nearly 1.4 million individuals was compromised in a phishing attack that gave attackers access to its net...

Read More → Use Tool →