HackMyIP

Cybersecurity News

Latest updates from top security sources

2415 articles, page 34 of 81

2026-06-22SecurityWeek
New Exploit Bypasses Apple’s Boot Defenses, Affects Millions of iPhones

The vulnerability exploited by the Usbliter8 exploit cannot be patched and a PoC exploit has been released by researchers. The post New Exploit Bypasses Apple’s Boot Defenses...

Read More → Use Tool →
2026-06-22SecurityWeek
Fortinet Responds to FortiBleed Campaign

A database of over 86,000 confirmed working credentials was created during the credential-harvesting campaign. The post Fortinet Responds to FortiBleed Campaign appeared first on S...

Read More → Use Tool →
2026-06-22SecurityWeek
More Cybersecurity Firms Disclose Impact From Klue Hack

HackerOne, Huntress, Jamf, OneTrust, Recorded Future, Snyk, and Tanium are among the affected Klue customers. The post More Cybersecurity Firms Disclose Impact From Klue Hack appea...

Read More → Use Tool →
2026-06-22SecurityWeek
Texas Parks & Wildlife Data Breach Affects 3 Million Individuals

Hackers stole personal information after breaching the systems of a third-party license vendor serving TPWD. The post Texas Parks & Wildlife Data Breach Affects 3 Million Indi...

Read More → Use Tool →
2026-06-21BleepingComputer
AryStinger botnet infected thousands of D-Link routers worldwide

A previously undocumented malware botnet named AryStinger has compromised more than 4,000 outdated routers to turn them into proxies for malicious traffic. [...]...

Read More → Use Tool →
2026-06-20BleepingComputer
Prinz Eugen Ransomware Targets Recent Files First in Go-Based Attack

A newly identified ransomware operation dubbed ‘Prinz Eugen’ is turning heads in the cybersecurity community for an unusual encryption strategy: prioritizing recently modified file...

RansomwareMalwareEncryption
Read More → Use Tool →
2026-06-20BleepingComputer
North Korean Sapphire Sleet Behind Mastra AI npm Supply Chain Attack

Microsoft has attributed the recent Mastra AI supply chain attack—which compromised more than 140 npm packages—to Sapphire Sleet, a North Korean state-sponsored threat group also t...

Supply ChainAPTMalware
Read More → Use Tool →
2026-06-20The Hacker News
Hackers Exploit Gravity SMTP Flaw to Steal API Keys from WordPress Sites

Threat actors are actively exploiting a recently patched information disclosure vulnerability in the Gravity SMTP WordPress plugin, installed on roughly 100,000 websites. Tracked a...

VulnerabilityThreat IntelIncident Response
Read More → Use Tool →
2026-06-20SecurityWeek
French President Urges US to Share Cutting-Edge AI and Democracies to Cooperate on Regulation

French President Emmanuel Macron urged the world’s wealthy democracies to work together on regulating advanced AI systems. The post French President Urges US to Share Cutting-Edge ...

Read More → Use Tool →
2026-06-19The Hacker News
Unpatchable usbliter8 Exploit Breaks Apple A12 and A13 SecureROM

Security researchers at Paradigm Shift have published a working exploit, dubbed usbliter8, that achieves arbitrary code execution inside the SecureROM of Apple's A12 and A13 SoCs. ...

VulnerabilityZero-Day
Read More → Use Tool →
2026-06-19The Hacker News
The Gentlemen RaaS Deploys GentleKiller to Disable 400 EDR Processes

The Gentlemen ransomware-as-a-service (RaaS) operation has emerged as one of the most technically agile cybercrime crews since launching in March 2025, according to ESET researcher...

RansomwareMalware
Read More → Use Tool →
2026-06-19BleepingComputer
Icarus Hackers Claim Klue OAuth Breach Exposing Salesforce Data

Market intelligence platform Klue has confirmed a security incident in which attackers exploited a compromised legacy credential to steal OAuth tokens, gaining access to multiple c...

Data BreachSupply ChainAuthentication
Read More → Use Tool →
2026-06-19BleepingComputer
Hackers Exploit Gravity SMTP Flaw Exposing API Keys on 100K WordPress Sites

Threat actors are actively exploiting an unauthenticated information disclosure vulnerability in the Gravity SMTP WordPress plugin, which is installed on over 100,000 websites. Tra...

VulnerabilityThreat Intel
Read More → Use Tool →
2026-06-19The Hacker News
AutoJack Flaw Lets Malicious Web Pages Hijack AI Agents for Code Execution

Microsoft researchers have disclosed AutoJack, an exploit chain that weaponizes an AI browsing agent into a remote code execution vector. By luring a local agent to render an attac...

AI SecurityVulnerabilitySupply Chain
Read More → Use Tool →
2026-06-19The Hacker News
Operation Endgame Disrupts SocGholish: 106 Servers Down, 15K WordPress Sites Cleaned

In a significant blow against one of the web's most persistent malware distribution networks, Dutch law enforcement, working alongside the FBI, the Royal Canadian Mounted Police, a...

MalwareThreat IntelIncident Response
Read More → Use Tool →
2026-06-19The Hacker News
CISA Warns: FortiBleed Campaign Hits 86,644 FortiGate Devices Globally

CISA has issued an urgent advisory urging Fortinet customers to secure their FortiGate appliances against an ongoing malicious campaign dubbed FortiBleed, which has already comprom...

Data BreachAuthenticationThreat Intel
Read More → Use Tool →
2026-06-19The Hacker News
From Assistive to Agentic: How AI Is Redefining Enterprise Threat Management

The average enterprise security team juggles 40 or more security tools, generating massive amounts of internal telemetry and asset data. Yet these tools operate in silos, producing...

AI SecurityThreat IntelIncident Response
Read More → Use Tool →
2026-06-19BleepingComputer
Texas Vendor Breach Exposes 3M Driver's Licenses in TPWD Hack

The Texas Parks and Wildlife Department (TPWD) disclosed a data breach at its external license system vendor on June 19, 2026, compromising the personal information of more than 3 ...

Data BreachSupply ChainPrivacy
Read More → Use Tool →
2026-06-19BleepingComputer
Every AI Agent Is an Identity. Most Organizations Don't Treat Them That Way

AI agents can access data, trigger workflows, deploy code, and interact with critical business systems, often with little oversight. Token Security breaks down why AI agents are be...

Read More → Use Tool →
2026-06-19BleepingComputer
Webinar: How attackers bypass MFA and how defenders can respond

Modern phishing attacks, including Device Code phishing, can undermine MFA protections and grant attackers access to corporate accounts without stealing passwords. This webinar exp...

Read More → Use Tool →
2026-06-19Dark Reading
Stressors, AI Forcing Changes to Cybersecurity Teams

As threats proliferate and AI complicates cybersecurity, CISOs say the job is getting harder, but more companies still want cybersecurity expertise, if even on a part-time basis....

Read More → Use Tool →
2026-06-19SecurityWeek
In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum

Other noteworthy stories that might have slipped under the radar: Android TV botnet Popa linked to Israeli firm, Velvet Ant maintained decade-long stealth, unpatched GCP Config Con...

Read More → Use Tool →
2026-06-19The Record
Police raid malware network tied to Russia's Evil Corp hacker group

An international operation targeted the SocGholish botnet, which has been linked to the Russia-based cybercrime group Evil Corp....

Read More → Use Tool →
2026-06-19The Hacker News
Apple Patches Beats Studio Buds Bluetooth Spy Flaw as Unpatchable A12/A13 Exploit Emerges

Apple has released a firmware update for its Beats Studio Buds wireless earbuds to remediate a high-severity Bluetooth vulnerability, tracked as CVE-2025-20701, that allowed nearby...

VulnerabilityZero-DayPrivacy
Read More → Use Tool →
2026-06-19The Hacker News
Shadow AI: Why Access Control, Not Data Leakage, Is the Real Enterprise Threat

The enterprise AI risk landscape has fundamentally shifted. Security teams initially focused on employees pasting sensitive data into public AI tools, responding with usage policie...

AI SecurityAI ThreatsCloud Security
Read More → Use Tool →
2026-06-19The Hacker News
Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data

Salesforce has revealed that it disabled the Klue Battlecards app integration within its platform in response to a security incident impacting the competitive intelligence company ...

Read More → Use Tool →
2026-06-19BleepingComputer
Microsoft: June 2026 Windows updates break Recycle Bin prompts

Microsoft has confirmed a confusing Windows bug that causes different filenames to appear in the confirmation dialog when deleting a file from the Recycle Bin. [...]...

Read More → Use Tool →
2026-06-19BleepingComputer
CISA: Splunk Enterprise flaw actively exploited, patch by Sunday

CISA has urged U.S. federal agencies to secure their systems by Sunday against a critical Splunk Enterprise vulnerability that is being exploited in attacks. [...]...

Read More → Use Tool →
2026-06-19BleepingComputer
NY man charged after harassing college student with AI-generated nudes

A New York man faces cyberstalking charges after allegedly sharing AI-generated nude images and fabricated racist messages using fake social media profiles to harass a Georgia coll...

Read More → Use Tool →
2026-06-19BleepingComputer
CISA warns Fortinet users to secure devices after FortiBleed leak

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) urged Fortinet customers to secure their devices after nearly 74,000 firewall and VPN credentials were exposed in a...

Read More → Use Tool →