HackMyIP

Cybersecurity News

Latest updates from top security sources

1359 articles, page 36 of 46

2026-05-11The Hacker News
⚡ Weekly Recap: Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and More

Rough Monday. Somebody poisoned a trusted download again, somebody else turned cloud servers into public housing, and a few crews are still getting into boxes with bugs that should...

Read More → Use Tool →
2026-05-11BleepingComputer
Instructure confirms hackers used Canvas flaw to deface portals

Education technology giant Instructure has confirmed that a security vulnerability allowed hackers to modify Canvas login portals and leave an extortion message. [...]...

Read More → Use Tool →
2026-05-11BleepingComputer
Why Changing Passwords Doesn’t End an Active Directory Breach

Resetting a password doesn't always remove attackers from Active Directory. Specops Software explains how cached credentials and Kerberos tickets can keep attackers authenticated a...

Read More → Use Tool →
2026-05-11BleepingComputer
Google: Hackers used AI to develop zero-day exploit for web admin tool

Researchers at Google Threat Intelligence Group (GTIG) say that a zero-day exploit targeting a popular open-source web administration tool was likely generated using AI. [...]...

Read More → Use Tool →
2026-05-11BleepingComputer
Webinar this week: Prevention alone is not enough against modern attacks

This upcoming webinar explores how organizations need to combine security, backups, and recovery planning to reduce the impact of modern cyberattacks. [...]...

Read More → Use Tool →
2026-05-11Dark Reading
'Dirty Frag' Exploit Poised to Blow Up on Enterprise Linux Distros

The privilege escalation vulnerability, which is similar to other Linux flaws like Copy Fail and Dirty Pipe, may already be under limited exploitation....

Read More → Use Tool →
2026-05-11Dark Reading
Hackers Use AI for Exploit Development, Attack Automation

Cyber adversaries have long used AI, but now attackers are using large language models to develop exploits and orchestrate complex attacks....

Read More → Use Tool →
2026-05-11Dark Reading
Cyber Espionage Group Targets Aviation Firms to Steal Map Data

The campaign quietly compromises aerospace and drone operators to exfiltrate GIS files, terrain models, and GPS data and gain a clear picture of adversaries' world view....

Read More → Use Tool →
2026-05-11SecurityWeek
Frame Security Emerges From Stealth With $50M for Awareness and Training Platform

Team8, Index Ventures, Picture Capital, Elad Gil, Cerca Partners, and Tesonet invested in Frame Security. The post Frame Security Emerges From Stealth With $50M for Awareness and T...

Read More → Use Tool →
2026-05-11SecurityWeek
Build Application Firewalls Aim to Stop the Next Supply Chain Attack

Rather than scanning code alone, Build Application Firewalls inspect runtime behavior inside the software build pipeline. The post Build Application Firewalls Aim to Stop the Next ...

Read More → Use Tool →
2026-05-11SecurityWeek
Google Detects First AI-Generated Zero-Day Exploit

The zero-day was designed to bypass 2FA and it was developed by a prominent cybercrime group. The post Google Detects First AI-Generated Zero-Day Exploit appeared first on Security...

Read More → Use Tool →
2026-05-11The Record
FCC pushes ban on security updates for foreign-made routers, drones to 2029

The router deadline, originally slated for March 1, 2027, has been pushed back to at least January 1, 2029, according to the announcement from the FCC’s Office of Engineering and T...

Read More → Use Tool →
2026-05-11The Record
UK water company allowed hackers to lurk undetected for nearly two years, regulator finds

The Information Commissioner's Office (ICO) fined South Staffordshire Water £963,900 ($1.3 million) on Monday over an attack by the Cl0p ransomware group that led to the personal d...

Read More → Use Tool →
2026-05-11The Record
Dirty Frag: Linux kernel hit by second major security flaw in two weeks

The issue was found in the same area of the Linux kernel that produced last month’s Copy Fail bug, and also allows anyone with a basic account on an affected computer to seize full...

Read More → Use Tool →
2026-05-11The Hacker News
Fake OpenAI Privacy Filter Hits Hugging Face, Steals Data from 244K Users

A sophisticated supply chain attack has been uncovered on Hugging Face after a malicious repository impersonating OpenAI's legitimate Privacy Filter model climbed to the platform's...

Supply ChainMalwareAI Security
Read More → Use Tool →
2026-05-11The Hacker News
Purple Teaming Fails: Attackers Exploit CVEs in 10 Hours, Defenders Can't Keep Up

The cybersecurity industry’s beloved “purple team” concept is broken by design. According to data from CISA KEV, VulnCheck KEV, and ExploitDB, the mean time from ...

VulnerabilityThreat IntelIncident Response
Read More → Use Tool →
2026-05-11BleepingComputer
TrickMo Android banker adopts TON blockchain for covert comms

A new variant of the TrickMo Android banking malware, delivered in campaigns targeting users across Europe, introduces new commands and uses The Open Network (TON) for stealthy com...

Read More → Use Tool →
2026-05-11SecurityWeek
Skoda Data Breach Hits Online Shop Customers

Using a vulnerability in the portal, hackers accessed names, addresses, email addresses, and phone numbers. The post Skoda Data Breach Hits Online Shop Customers appeared first on ...

Read More → Use Tool →
2026-05-11SecurityWeek
Cloudflare Lays Off 1,100 Employees in AI-Driven Restructuring

The company topped revenue and earnings forecasts for the first quarter of 2026, but its shares plunged more than 20%. The post Cloudflare Lays Off 1,100 Employees in AI-Driven Res...

Read More → Use Tool →
2026-05-11SecurityWeek
SailPoint Discloses GitHub Repository Hack

The incident occurred on April 20 and did not affect customer data in the company’s production and staging environments. The post SailPoint Discloses GitHub Repository Hack appeare...

Read More → Use Tool →
2026-05-11SecurityWeek
Checkmarx Jenkins AST Plugin Compromised in Supply Chain Attack

A malicious version of the plugin was published to the Jenkins Marketplace late last week. The post Checkmarx Jenkins AST Plugin Compromised in Supply Chain Attack appeared first o...

Read More → Use Tool →
2026-05-11SecurityWeek
Canvas System Is Online After a Cyberattack Disrupted Thousands of Schools

Tens of thousands of students studying for final exams around the world have regained access to a key online learning system after a cyberattack had earlier knocked it offline. The...

Read More → Use Tool →
2026-05-11SecurityWeek
New ‘Dirty Frag’ Linux Vulnerability Possibly Exploited in Attacks

Also called Copy Fail 2 and tracked as CVE-2026-43284 and CVE-2026-43500, the exploit was disclosed before a patch was released. The post New ‘Dirty Frag’ Linux Vulnera...

Read More → Use Tool →
2026-05-11SecurityWeek
Resurrected ‘Crimenetwork’ Marketplace Taken Down, Administrator Arrested

The second iteration of the German-speaking online crime marketplace had over 22,000 users and more than 100 sellers. The post Resurrected ‘Crimenetwork’ Marketplace Ta...

Read More → Use Tool →
2026-05-11SecurityWeek
Operation HookedWing: 500+ Orgs Hit in 4-Year Phishing Campaign

A sophisticated phishing operation dubbed "Operation HookedWing" has been systematically targeting organizations across critical sectors for over four years, according to threat in...

PhishingAPTData Breach
Read More → Use Tool →
2026-05-10BleepingComputer
Hackers Abuse Google Ads & Claude.ai Chats to Spread Mac Malware

A sophisticated malvertising campaign is leveraging Google Ads and the public chat‑sharing feature of Anthropic’s Claude.ai to distribute a macOS backdoor. Victims who search for "...

MalwareAI ThreatsPhishing
Read More → Use Tool →
2026-05-10BleepingComputer
German Police Shut Down Relaunched Crimenetwork Marketplace, Arrest Admin

German law‑enforcement agencies, led by the Federal Criminal Police Office (BKA) and the Hessian State Criminal Police Office (LKA Hessen) in close coordination with Europol’s Euro...

PrivacyEncryptionThreat Intel
Read More → Use Tool →
2026-05-10The Hacker News
Ollama Memory Leak Vulnerability Allows Remote Process Memory Exposure

Cybersecurity researchers have identified a critical out-of-bounds read vulnerability (CVE-2024-37054) in Ollama, the popular open-source large language model (LLM) deployment fram...

VulnerabilityLLM SecurityZero-Day
Read More → Use Tool →
2026-05-09The Hacker News
cPanel & WHM Patch 3 Critical Vulnerabilities – Update Now

cPanel Inc. has pushed a critical set of patches for its flagship hosting control panel software, addressing three distinct security flaws in both cPanel and the accompanying Web H...

VulnerabilityZero-Day
Read More → Use Tool →
2026-05-09BleepingComputer
JDownloader Site Hacked, Distributing Python RAT via Fake Installers

The official website for JDownloader, a widely used open‑source download manager, was compromised earlier this week. Attackers altered the download links for both Windows and Linux...

MalwareSupply ChainThreat Intel
Read More → Use Tool →