HackMyIP

Cybersecurity News

Latest updates from top security sources

2415 articles, page 35 of 81

2026-06-19SecurityWeek
CryptoBandits Malware Doubles as a Backdoor, Abuses Tor

CryptoBandits uses a local SOCKS5 proxy for traffic routing, blending data theft with remote code execution. The post CryptoBandits Malware Doubles as a Backdoor, Abuses Tor appear...

Read More → Use Tool →
2026-06-19SecurityWeek
FortiBleed: 86,000 Fortinet Device Credentials Compromised

The large-scale credential theft campaign hit roughly half of the internet-accessible Fortinet firewalls and VPNs. The post FortiBleed: 86,000 Fortinet Device Credentials Compromis...

Read More → Use Tool →
2026-06-19SecurityWeek
Cybersecurity Firms Impacted by Klue Supply Chain Attack

The hackers exfiltrated data from Salesforce instances of Klue customers, such as Huntress and Recorded Future. The post Cybersecurity Firms Impacted by Klue Supply Chain Attack ap...

Read More → Use Tool →
2026-06-19SecurityWeek
Cisco to Acquire WideField Security to Boost Splunk’s Agentic SOC

WideField will accelerate Agentic SOC capabilities by expanding the lens on threat investigation to include identity, credentials, sessions, and blast radius. The post Cisco to Acq...

Read More → Use Tool →
2026-06-19SecurityWeek
15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown

Law enforcement and private partners took down 106 SocGholish C&C servers and domains as part of Operation Endgame. The post 15,000 WordPress Websites Cleaned Up in SocGholish...

Read More → Use Tool →
2026-06-19The Record
UK's information commissioner resigns over ‘inappropriate humour’

Writing on LinkedIn, Edwards said that while he has not agreed with how the investigation into him has been conducted, he has come to accept that his position “has become untenable...

Read More → Use Tool →
2026-06-19SecurityWeek
Critical Splunk Enterprise CVE-2026-20253 Actively Exploited - Patch Now

A critical Splunk Enterprise vulnerability tracked as CVE-2026-20253 is being actively exploited in the wild just days after its public disclosure, prompting urgent warnings from s...

VulnerabilityZero-DayIncident Response
Read More → Use Tool →
2026-06-18Dark Reading
Novo Nordisk Breach Highlights Software Development Pipeline Risk

A leaked GitHub token underscores what most organizations get wrong: Treating secrets management as a tooling problem rather than an identity problem....

Read More → Use Tool →
2026-06-18The Hacker News
F5 Patches Two Critical NGINX RCE Flaws: CVE-2026-42530 & CVE-2026-42055

F5 has released emergency security updates to address two critical vulnerabilities in NGINX Open Source, both carrying a CVSS v4 score of 9.2, that could allow remote unauthenticat...

VulnerabilityCloud Security
Read More → Use Tool →
2026-06-18BleepingComputer
Gentlemen Ransomware Uses 8 EDR Killer Variants to Disable Defenses

The Gentlemen ransomware-as-a-service (RaaS) operation is actively maintaining a sophisticated suite of endpoint detection and response (EDR) killers to help its affiliates evade d...

RansomwareMalwareThreat Intel
Read More → Use Tool →
2026-06-18BleepingComputer
Nintendo Confirms TinyPulse Data Breach as Shadowbyt3$ Demands $2M Ransom

Nintendo of America has confirmed that threat actors stole internal survey data from TinyPulse, a third-party employee engagement platform owned by WebMD Health Services, but stres...

Data BreachSupply ChainRansomware
Read More → Use Tool →
2026-06-18Dark Reading
Novo Nordisk Breach Exposes Software Development Pipeline Risk

A leaked GitHub token underscores what most organizations get wrong: Treating secrets management as a tooling problem rather than an identity problem....

Read More → Use Tool →
2026-06-18Dark Reading
Operation Escaneo Signals Shift in LatAm Threat Landscape

The threat group's curious business model may combine opportunistic monetization alongside intel collection, without much coordination between the two....

Read More → Use Tool →
2026-06-18Dark Reading
FIFA Bug Exposes World Cup Streams to Remote Takeover

A hacker could have "Rickrolled" the World Cup — or worse — thanks to FIFA's unenforced Entra access controls....

Read More → Use Tool →
2026-06-18The Record
Bulgaria allowed surveillance tech firm to sell products to repressive regimes, report says

The nonprofit Human Rights Watch obtained export licensing records covering 2018 through 2023, which show the Bulgarian government allowed the surveillance firm Circles to peddle t...

Read More → Use Tool →
2026-06-18The Hacker News
Orphaned AI Agents: Hidden Access Risks in Enterprise Networks

When an autonomous AI agent interacts with a company's core intellectual property, most security teams cannot instantly name the person who authorized it. The rush to deploy intern...

AI SecurityAuthenticationCloud Security
Read More → Use Tool →
2026-06-18The Hacker News
SearchJack Chrome Extensions Hit 758K Users as macOS ClickFix Spreads RAT

A cluster of 23 deceptive Chrome browser extensions has been uncovered routing user searches through monetization middleware before delivering results, exposing roughly 758,000 aff...

Threat IntelMalwarePhishingPrivacyCloud Security
Read More → Use Tool →
2026-06-18The Hacker News
Microsoft Uncovers Windows Clipper Malware Using USB LNK Worm and Tor C2

Microsoft's Defender Security Research Team has disclosed details of a sophisticated Windows-based cryptocurrency clipper campaign that has been active since February 2026. The mal...

MalwareThreat Intel
Read More → Use Tool →
2026-06-18The Hacker News
INC Ransomware Hits 830+ Victims Since 2023 — RaaS Giant Reshapes Cybercrime

INC Ransomware has cemented its position as one of the most prolific ransomware-as-a-service (RaaS) operations in 2026, claiming more than 830 victims since its emergence in August...

RansomwareMalwareThreat Intel
Read More → Use Tool →
2026-06-18The Hacker News
DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic

Threat actors associated with the DragonForce ransomware have been observed using a custom Go-based remote access trojan (RAT) called Backdoor.Turn to conceal command-and-control (...

Read More → Use Tool →
2026-06-18BleepingComputer
USB worm spreads crypto-stealing malware via Windows shortcut files

Threat actors targeting cryptocurrency wallets have been distributing clipboard-stealing malware with self-spreading capabilities and using the Tor network to conceal communication...

Read More → Use Tool →
2026-06-18BleepingComputer
Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks

Market intelligence platform Klue suffered a OAuth breach that enabled the "Icarus" threat actors to steal Salesforce CRM data from multiple organizations in an ongoing extortion c...

Read More → Use Tool →
2026-06-18BleepingComputer
5 reasons Microsoft 365 backup isn’t enough for business data protection

Microsoft 365 helps keep services running, but protecting and recovering business data remains your responsibility. Acronis breaks down five gaps organizations should consider when...

Read More → Use Tool →
2026-06-18BleepingComputer
Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp

International law enforcement agencies cleaned nearly 15,000 malware-infected WordPress websites and took down more than 100 servers linked to the SocGholish botnet and the Evil Co...

Read More → Use Tool →
2026-06-18BleepingComputer
ShapedPlugin update flow hacked to infect WordPress sites

Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack that distributed infected releases to paying customers via the vendor's official update syste...

Read More → Use Tool →
2026-06-18BleepingComputer
Apple fixes Beats Studio Buds flaw that let hackers spy on conversations

Apple has released security updates to patch a high-severity flaw affecting the Beats Studio Buds wireless earbuds that could allow attackers in Bluetooth range to spy on users' co...

Read More → Use Tool →
2026-06-18BleepingComputer
Telegram admits it couldn't police exam-leak channels, India tells court

India's government has told the Delhi High Court that Telegram was warned about two weeks before it was blocked, and that the platform admitted it could not proactively detect the ...

Read More → Use Tool →
2026-06-18KrebsOnSecurity
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeov...

Read More → Use Tool →
2026-06-18Dark Reading
Salesforce Data Thefts Continue via Klue App Compromise

Klue's Battlecards is now the third integrated application that has been compromised to steal customers' Salesforce data, and victims include Huntress, the cybersecurity vendor....

Read More → Use Tool →
2026-06-18Dark Reading
Get Out of Security Debt by Tackling the Exposure Problem

Teams digging out of security debt need to answer only two simple questions: Which vulnerabilities in our systems are exposed, and how long should they stay that way?...

Read More → Use Tool →