HackMyIP

Cybersecurity News

Latest updates from top security sources

1380 articles, page 39 of 46

2026-05-07BleepingComputer
ShinyHunters Exploits Zero‑Day to Deface Canvas Login Portals at 300+ Colleges

On March 12, 2025, the ShinyHunters ransomware group successfully compromised Instructure, the maker of the Canvas learning management system, by exploiting a previously unknown vu...

Zero-DayData BreachVulnerability
Read More → Use Tool →
2026-05-07BleepingComputer
TCLBanker Trojan Spreads via WhatsApp and Outlook, Hits 59 Financial Platforms

Security researchers have identified a new banking trojan, named TCLBanker, that is actively spreading through WhatsApp messages and Outlook emails. The campaign lures victims with...

MalwareSupply ChainPhishing
Read More → Use Tool →
2026-05-07BleepingComputer
PCPJack Worm Targets Cloud Infrastructure, Removes TeamPCP Infections

Security researchers have identified a new malware framework designated PCPJack that is actively targeting exposed cloud infrastructure environments. The threat operates as a crede...

MalwareCloud Security
Read More → Use Tool →
2026-05-07BleepingComputer
Australia Warns of ClickFix Attacks Spreading Vidar Stealer

The Australian Cyber Security Centre (ACSC) has issued a high‑priority advisory warning that a sophisticated malware campaign is actively using the ClickFix social‑engineering tech...

MalwarePhishingThreat Intel
Read More → Use Tool →
2026-05-07BleepingComputer
Ivanti EPMM Zero-Day Remote Code Execution Flaw Patched

Ivanti has released an emergency patch for a critical remote‑code‑execution (RCE) vulnerability in its Endpoint Manager Mobile (EPMM) product. Tracked as CVE‑2023‑XXXXX with a CVSS...

Zero-DayVulnerability
Read More → Use Tool →
2026-05-07BleepingComputer
How Browsers Bypass DLP: AI Prompts and Copy/Paste Create Data Leakage

Organizations investing heavily in data loss prevention (DLP) solutions are discovering a critical blind spot: the browser has become the primary vector for inadvertent data exfilt...

Data BreachAI SecurityPrivacy
Read More → Use Tool →
2026-05-07Dark Reading
PCPJack Malware Exploits Parquet Files to Steal Cloud Secrets

Security researchers at Unit 42 have uncovered a new cloud‑targeting malware family they are calling PCPJack, which has quietly replaced the earlier TeamPCP implant. PCPJack distin...

MalwareCloud SecurityThreat Intel
Read More → Use Tool →
2026-05-07Dark Reading
CISA Leadership: Tom Parker Rumored as Next Director

Industry insiders are buzzing after reports surfaced that Tom Parker, a seasoned executive known for his boardroom operational expertise, may be the frontrunner to assume the helm ...

Regulation
Read More → Use Tool →
2026-05-07Dark Reading
TrustFall Flaw Exposes Code Execution in Claude, Cursor, Gemini, CoPilot

Security researchers at the TrustFall convention have disclosed a critical vulnerability that allows malicious code repositories to trigger arbitrary code execution in several popu...

VulnerabilitySupply ChainLLM Security
Read More → Use Tool →
2026-05-07Dark Reading
AI-Driven Attack on Mexico Foiled by SCADA Login Shield

Security researchers at Dark Reading have disclosed the most sophisticated AI‑integrated cyber‑campaign observed to date, which targeted critical infrastructure in Mexico. The oper...

AI ThreatsIncident ResponseZero-Day
Read More → Use Tool →
2026-05-07BleepingComputer
US Sentenced for Laptop Farms Used by North Korean Remote IT Workers

Two U.S. nationals were sentenced to 18 months in federal prison each for managing laptop farms that facilitated North Korean IT workers in securing remote positions at nearly 70 A...

APTSupply ChainPrivacy
Read More → Use Tool →
2026-05-07BleepingComputer
California Man Gets 6.5 Years for $230M Crypto Heist, Money Laundering

Ethan J. Rivera, a 20‑year‑old from Los Angeles, California, was sentenced on Friday to 78 months (6.5 years) in federal prison for his role in a sophisticated criminal operation t...

Threat IntelPrivacyEncryption
Read More → Use Tool →
2026-05-07BleepingComputer
Modern Attacks Demand Security & Recovery: Webinar Insights

Modern cyber‑threats have evolved beyond the initial breach, with adversaries now targeting backup systems, encryption keys, and recovery pipelines to maximize impact. A new webina...

RansomwareIncident Response
Read More → Use Tool →
2026-05-07BleepingComputer
Critical Palo Alto Networks Zero-Day Exploited for Nearly a Month

Palo Alto Networks issued an urgent advisory warning customers that a critical‑severity zero‑day vulnerability in its PAN‑OS firewall software has been actively exploited by suspec...

Zero-DayAPTVulnerability
Read More → Use Tool →
2026-05-07BleepingComputer
Fake Claude AI Site Spreads Beagle Backdoor Malware on Windows

Security researchers have uncovered a phishing campaign that spoofs the official Anthropic Claude AI portal to distribute a new Windows backdoor dubbed “Beagle.” The fraudulent sit...

MalwarePhishingAI Security
Read More → Use Tool →
2026-05-07Dark Reading
AI-Driven Cyberattack Targets SCADA Systems, Foiled by Login Screen

Security researchers at Mandiant and Dragos have documented what they are calling the world's first fully AI-integrated cyberattack campaign targeting operational technology (OT) i...

AI ThreatsVulnerabilityThreat Intel
Read More → Use Tool →
2026-05-06The Hacker News
New Mirai Botnet 'xlabs_v1' Exploits ADB for IoT DDoS Attacks

Cybersecurity researchers have identified a new Mirai-variant botnet designated as xlabs_v1 that actively exploits the Android Debug Bridge (ADB) interface to compromise internet-c...

MalwareVulnerabilityThreat Intel
Read More → Use Tool →
2026-05-06The Hacker News
MuddyWater APT Uses Microsoft Teams in Credential Theft Attack

The Iranian state-sponsored threat actor MuddyWater, also tracked as Mango Sandstorm, Seedworm, and Static Kitten, has been linked to a sophisticated cyberattack that leveraged Mic...

APTPhishingRansomware
Read More → Use Tool →
2026-05-06The Hacker News
Hacker News Opens Cybersecurity Stars Awards 2026 Submissions

The Hacker News (THN) has officially opened the call for entries for the Cybersecurity Stars Awards 2026, an initiative designed to shine a spotlight on the behind‑the‑scenes work ...

Bug BountyThreat IntelIncident Response
Read More → Use Tool →
2026-05-06The Hacker News
AI Agents Outpacing Enterprise Governance: Security Teams Sound Alarm

According to Gartner's inaugural Market Guide for Guardian Agents, published in 2024, enterprise deployment of AI agents is accelerating at a pace that outstrips the development of...

AI SecurityAI ThreatsLLM Security
Read More → Use Tool →
2026-05-06The Hacker News
Google Expands Binary Transparency for Android to Block Supply Chain Attacks

Google has announced a significant expansion of its Binary Transparency initiative for Android, introducing a public verification mechanism designed to protect the ecosystem from s...

Supply ChainVulnerabilityEncryption
Read More → Use Tool →
2026-05-06The Hacker News
CloudZ RAT Exploits Windows Phone Link to Steal Credentials and OTPs

Security analysts have uncovered a sophisticated intrusion campaign leveraging the CloudZ remote access trojan (RAT) alongside a previously undocumented plugin called Pheno to targ...

MalwareAPTAuthentication
Read More → Use Tool →
2026-05-06The Hacker News
Palo Alto PAN-OS Flaw CVE-2026-0300 Under Active Exploitation

Palo Alto Networks has issued an urgent security advisory regarding a critical buffer overflow vulnerability, tracked as CVE-2026-0300, affecting multiple versions of PAN-OS softwa...

Zero-DayVulnerabilityIncident Response
Read More → Use Tool →
2026-05-06Dark Reading
VoidStealer Bypasses Chrome App-Bound Encryption: New Threat

Researchers at Cisco Talos have uncovered a new variant of the VoidStealer Trojan that successfully circumvents Google Chrome’s App‑Bound Encryption (ABE). The malware, tracked as ...

MalwareEncryptionZero-Day
Read More → Use Tool →
2026-05-06Dark Reading
Instructure Breach Exposes Canvas LMS Vendor Risks for Schools

A threat actor known as ShinyHunters has claimed responsibility for a cyberattack against Instructure, the company behind the widely deployed Canvas learning management system (LMS...

Data BreachSupply ChainVulnerability
Read More → Use Tool →
2026-05-06Dark Reading
From Stuxnet to ChatGPT: 20 Cyber Milestones

Over the past two decades, a succession of high‑impact incidents has reshaped the cyber risk landscape, forcing organizations to constantly recalibrate their defenses. From the rev...

MalwareAI SecurityZero-Day
Read More → Use Tool →
2026-05-06Dark Reading
CloudZ RAT and Pheno Plug-in Target Windows Phone Link for Text Theft

Security researchers have uncovered a sophisticated cyberattack campaign leveraging the Windows Phone Link application to steal text messages and circumvent two-factor authenticati...

MalwareAuthenticationPrivacy
Read More → Use Tool →
2026-05-06Dark Reading
UAE Cyberattacks Triple, Critical Infrastructure at Risk

As the conflict with Iran intensifies, cyber operatives have turned their focus on the United Arab Emirates, with breach attempts spiking threefold over the past few weeks. Securit...

APTVulnerability
Read More → Use Tool →
2026-05-06BleepingComputer
Google Ads Abused in GoDaddy ManageWP Login Phishing Scam

A sophisticated phishing campaign is leveraging Google’s sponsored search ads to mimic the login page of ManageWP, GoDaddy’s platform for centrally managing large fleets of WordPre...

PhishingAuthenticationThreat Intel
Read More → Use Tool →
2026-05-06Dark Reading
New VoidStealer Bypass Exposes Chrome App-Bound Encryption Flaw

Security researchers at Dark Reading have disclosed a novel technique that allows the VoidStealer Trojan to circumvent Google Chrome's App-Bound Encryption (ABE), a security mechan...

MalwareEncryptionZero-Day
Read More → Use Tool →