HackMyIP

Cybersecurity News

Latest updates from top security sources

2415 articles, page 32 of 81

2026-06-23BleepingComputer
New macOS ClickFix attack silently mounts DMGs to push infostealer

A new macOS ClickFix campaign is using Terminal commands to silently download, mount, and launch info-stealing malware from malicious disk image (DMG) files. [...]...

Read More → Use Tool →
2026-06-23Dark Reading
Scope of Salesforce Attacks Expands as Icarus Leaks Data

More victims have emerged after attackers breached application vendor Klue and used its OAuth tokens to steal customers' Salesforce data....

Read More → Use Tool →
2026-06-23Dark Reading
'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows

The CI/CD workflow weakness affects Microsoft's Azure Sentinel, Google's AI Agent Development Kit, Apache's Doris analytics database, Cloudflare's Workers SDK, and Python Software ...

Read More → Use Tool →
2026-06-23The Record
Five Eyes agencies sound alarm about AI’s threat to cybersecurity

"The timeline is not years, it is months,” the nations of the Five Eyes intelligence alliance said in a joint alert about the cybersecurity concerns of artificial intelligence....

Read More → Use Tool →
2026-06-23The Record
Feds seize alleged cyber-scam infrastructure connected to Southeast Asian company

The Department of Justice announced the “seizure of a cloud computing account” used by subsidiaries of the Huione Group, a conglomerate severed from the U.S. financial system last ...

Read More → Use Tool →
2026-06-23The Hacker News
Fake AI Agent Skill Bypasses Scanners, Hits 26,000 Agents

Security researchers at AIR have demonstrated a stark gap in AI agent supply chain defenses by publishing a malicious-looking skill that sailed past every scanner it was tested aga...

AI SecuritySupply ChainAI Threats
Read More → Use Tool →
2026-06-23The Hacker News
Trump Executive Order Mandates Post-Quantum Crypto Migration by 2030

President Trump signed Executive Order 14409 on June 22, establishing firm deadlines for federal agencies to migrate high-value assets and high-impact systems to post-quantum crypt...

EncryptionRegulationVulnerability
Read More → Use Tool →
2026-06-23The Hacker News
GitHub Updates actions/checkout to Block Common Pwn Request Attack Patterns

GitHub is moving to strengthen software supply chain security by updating "actions/checkout" to block pwn request attacks that exploit the risky use of the "pull_request_target wor...

Read More → Use Tool →
2026-06-23The Hacker News
Agentic AI: The Weapon That No Longer Needs a Warrior

Every weapon begins as an extension of the hand that holds it. The spear lengthened the reach of the arm. The bow sent the point flying without the throw. The rifle placed a man's ...

Read More → Use Tool →
2026-06-23BleepingComputer
Scattered Spider members plead guilty to hacking Transport for London

Two members of the 'Scattered Spider' cybercrime group pleaded guilty to hacking the Transport for London (TfL) systems in 2024. [...]...

Read More → Use Tool →
2026-06-23BleepingComputer
The Exploit Doesn't Exist. You Can Still Prove It Works Against You

Attackers can now weaponize newly disclosed vulnerabilities far faster than most organizations can patch them. Picus Security explains how security teams can validate exploitabilit...

Read More → Use Tool →
2026-06-23BleepingComputer
LastPass confirms data breach in Klue supply chain attack

LastPass announced that hackers accessed customer data from its Salesforce environment after stealing the company's OAuth tokens in the Klue supply chain attack earlier this month....

Read More → Use Tool →
2026-06-23BleepingComputer
Webinar: Why email security teams are drowning in alerts

Phishing, BEC, and account takeover attacks continue to overwhelm security teams with alerts and investigations. This webinar explores how behavioral AI can help automate detection...

Read More → Use Tool →
2026-06-23KrebsOnSecurity
Scattered Spider Hackers Plead Guilty on Day 1 of Trial

Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for t...

Read More → Use Tool →
2026-06-23Dark Reading
SocGholish Takedown Highlights Malicious TDS Threats

SocGholish uses traffic distribution systems (TDSs) to provide initial access into victims' networks for cybercrime groups such as the notorious Evil Corp....

Read More → Use Tool →
2026-06-23Dark Reading
FortiBleed Attackers Turn Firewalls Into Credential Stealers as Heists Persist

The threat actors engineered a Golang-based sniffer to target 430,000 FortiGate firewalls and identify 110 million credentials in the ongoing global campaign....

Read More → Use Tool →
2026-06-23SecurityWeek
Dragos Unveils AI for OT Security

Named EmberAI, the new capability is built on Dragos’ massive operational technology cybersecurity dataset. The post Dragos Unveils AI for OT Security  appeared first on SecurityWe...

Read More → Use Tool →
2026-06-23SecurityWeek
Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps

Attackers could abuse Dify's multi-tenant cloud service to read private chats, preview other tenants' documents, and reach internal APIs. The post Data Exposure Flaws Threaten Dify...

Read More → Use Tool →
2026-06-23SecurityWeek
Eight-Year-Old Samsung KNOX Flaw Exposed Millions of Galaxy Devices to Kernel Attacks

The high-severity use-after-free vulnerability in Samsung's KNOX security framework affected Android-powered Galaxy devices from the S9 through S25. The post Eight-Year-Old Samsung...

Read More → Use Tool →
2026-06-23SecurityWeek
CISO Conversations: Carl Froggett – Combining CISO and CIO at Deep Instinct

Carl Froggett combines CISO and CIO. He currently occupies both positions at Deep Instinct. Before then, he was CISO at Citi for almost 17 years. The post CISO Conversations: Carl ...

Read More → Use Tool →
2026-06-23SecurityWeek
Algerian Man Extradited to US for Running Cybercrime Marketplaces

26-year-old Abdellah Belmili faces up to 30 years in prison for allegedly operating the marketplaces Market0Day and Spoxy. The post Algerian Man Extradited to US for Running Cyberc...

Read More → Use Tool →
2026-06-23The Record
Trump directs federal agencies to protect US data from quantum threats

An executive order signed Monday aims to accelerate the government's transition to post-quantum cryptography (PQC), a new generation of encryption designed to protect data from the...

Read More → Use Tool →
2026-06-23The Record
Compromise kids online safety bill unveiled by House leaders, with key omission

The so-called duty of care provision that was excluded would have mandated that online platforms take reasonable measures to prevent specific harms such as suicidal ideation, eatin...

Read More → Use Tool →
2026-06-23The Record
Two Scattered Spider members plead guilty over cyberattack that crippled London transit

A 20-year-old and an 18-year-old admitted to infiltrating the network of Transport for London in 2024, disrupting public transportation services for months....

Read More → Use Tool →
2026-06-23The Record
Tata Electronics confirms cyberattack after alleged Apple, Tesla documents appear online

Indian manufacturer Tata Electronics said a recent cybersecurity incident had "no impact" on operations. A cybercrime group had said it stolen confidential documents from the compa...

Read More → Use Tool →
2026-06-23The Hacker News
Malicious npm Packages Impersonate PostCSS Tools to Deploy Windows RAT

Cybersecurity researchers at JFrog have uncovered three malicious npm packages designed to deliver a Windows-based remote access trojan (RAT) to developers who install them. Publis...

Supply ChainMalwareThreat Intel
Read More → Use Tool →
2026-06-23The Hacker News
WhatsApp VBScript Campaign Drops ManageEngine RMM via Fake Documents

Security researchers at Kaspersky have uncovered an active social engineering campaign abusing WhatsApp Direct Messages to distribute heavily obfuscated VBScript files disguised as...

MalwarePhishingThreat Intel
Read More → Use Tool →
2026-06-23SecurityWeek
FFmpeg PixelSmash Flaw Allows RCE on Video Players, Media Servers, NAS Appliances

Attackers can send crafted media files to execute code in any application that uses FFmpeg’s libavcodec library. The post FFmpeg PixelSmash Flaw Allows RCE on Video Players, Media ...

Read More → Use Tool →
2026-06-23SecurityWeek
OpenAI Refocuses Cybersecurity Efforts on Patching Over Discovery

OpenAI has expanded its Daybreak cybersecurity initiative with a new suite of tools and partnerships. The post OpenAI Refocuses Cybersecurity Efforts on Patching Over Discovery app...

Read More → Use Tool →
2026-06-23SecurityWeek
Russian Initial Access Broker Behind FortiBleed Campaign

Using a custom sniffer, the threat actor has captured over 110 million credentials since at least February 2026. The post Russian Initial Access Broker Behind FortiBleed Campaign a...

Read More → Use Tool →