HackMyIP

Cybersecurity News

Latest updates from top security sources

1387 articles, page 43 of 47

2026-04-30The Hacker News
DEEP#DOOR Python Backdoor Steals Browser and Cloud Credentials

Security researchers at SentinelOne and WithSecure have uncovered a sophisticated Python-based backdoor named DEEP#DOOR that leverages legitimate tunneling services to establish co...

MalwareCloud SecurityThreat Intel
Read More → Use Tool →
2026-04-30The Hacker News
EtherRAT Spoofs Admin Tools via GitHub in Supply Chain Attack

Atos Threat Research Center (TRC) uncovered in March 2026 a highly resilient malicious operation that distributes a remote‑access trojan called EtherRAT. The campaign abuses GitHub...

MalwareSupply ChainAPT
Read More → Use Tool →
2026-04-30KrebsOnSecurity
Brazilian Anti-DDoS Firm Exposed as Botnet Operator

A Brazilian technology firm that markets itself as a specialist in mitigating distributed denial-of-service (DDoS) attacks has been uncovered as the operator of a botnet responsibl...

Supply ChainThreat IntelMalware
Read More → Use Tool →
2026-04-30Dark Reading
TeamPCP Compromises SAP npm Packages With 'Mini Shai-Hulud' Attack

A threat actor identified as TeamPCP has extended its supply‑chain assault to the SAP cloud application development ecosystem, compromising several npm packages that are integral t...

Supply ChainMalwareVulnerability
Read More → Use Tool →
2026-04-30Dark Reading
AI-Powered Scan Uncovers 9-Year-Old Linux Kernel Bug, Patch Ready

Security researchers using an AI-driven static analysis engine called Sentinel have uncovered a nine‑year‑old flaw in the Linux kernel’s netfilter subsystem. The vulnerability, tra...

VulnerabilityAI Security
Read More → Use Tool →
2026-04-30Dark Reading
Anthropic's Mythos AI Redefines Cyber Threat Landscape

Anthropic has officially launched Mythos, its latest large language model designed with a reported 1.2 trillion parameters and native multimodal reasoning capabilities. According t...

AI SecurityAI ThreatsLLM Security
Read More → Use Tool →
2026-04-30Dark Reading
Oracle Red Bull Racing Powers Security with Automation

Oracle Red Bull Racing has launched a sweeping automation initiative aimed at embedding security directly into the team’s high‑velocity development pipelines. With the pit wall and...

Cloud SecurityIncident ResponseVulnerability
Read More → Use Tool →
2026-04-30Dark Reading
Japan Banks on Edge Over Anthropic's Superhacker AI Model

Japan’s financial services industry is on high alert after the release of Anthropic’s latest large language model, internally dubbed “Claude Mythos,” which early demonstrations sug...

AI SecurityAI ThreatsLLM Security
Read More → Use Tool →
2026-04-30The Hacker News
New Linux Copy Fail Flaw Grants Root Access on Major Distros

Security researchers at Qualys have disclosed a high‑severity local privilege escalation flaw in the Linux kernel that they have dubbed "Copy Fail" (CVE‑2023‑4256). The vulnerabili...

VulnerabilityZero-Day
Read More → Use Tool →
2026-04-30The Hacker News
Google Patches Critical Gemini CLI Flaw Enabling Remote Code Execution

Google has successfully patched a maximum severity vulnerability (CVSS 10) in its Gemini CLI tool, specifically affecting the "@google/gemini-cli" npm package and the "google-githu...

VulnerabilitySupply ChainLLM Security
Read More → Use Tool →
2026-04-30BleepingComputer
Bluekit Phishing Kit Offers AI Assistant, 40+ Templates

Security researchers have uncovered a new phishing-as-a-service platform called Bluekit that advertises more than 40 ready‑made templates targeting popular online services such as ...

PhishingAI ThreatsAI Security
Read More → Use Tool →
2026-04-29Dark Reading
AI Reverse Engineering Exposes Critical GitHub Vulnerability

Security researchers at Wiz have leveraged an AI‑powered reverse‑engineering engine to uncover a high‑severity flaw in GitHub’s continuous integration infrastructure that would hav...

AI SecurityVulnerabilityZero-Day
Read More → Use Tool →
2026-04-29Dark Reading
AI Finds 38 Security Flaws in OpenEMR, Threatening 100K Providers

Security researchers using an AI‑driven code analysis platform identified 38 distinct vulnerabilities in the OpenEMR electronic health record (EHR) system, including 12 rated criti...

VulnerabilityAI SecurityData Breach
Read More → Use Tool →
2026-04-29Dark Reading
Vect 2.0 Ransomware Wiper Flaw Exposes TeamPCP Supply Chain Risks

A newly identified ransomware strain named Vect 2.0 has been observed executing wiper‑style attacks against organizations compromised through the TeamPCP software supply chain. The...

RansomwareSupply ChainMalware
Read More → Use Tool →
2026-04-29Dark Reading
Lotus Wiper Malware Targets Venezuelan Energy and Utilities

A coordinated cyberattack leveraging a newly identified wiper malware, named Lotus Wiper, has struck several energy companies and utility providers in Venezuela, according to a rep...

MalwareAPT
Read More → Use Tool →
2026-04-29The Hacker News
SAP npm Packages Compromised in Credential-Stealing Supply Chain Attack

Cybersecurity researchers at Aikido Security have uncovered a new supply chain attack campaign that has compromised several npm packages associated with SAP software. The malicious...

Supply ChainMalwareThreat Intel
Read More → Use Tool →
2026-04-29The Hacker News
North Korean Hackers Deploy AI-Embedded npm Malware & RATs

Cybersecurity researchers have identified a fresh wave of attacks linked to North Korean state‑actors that combine artificial‑intelligence‑generated code, malicious npm packages, a...

Supply ChainMalwareAPT
Read More → Use Tool →
2026-04-29The Hacker News
AI-Powered Kill Chain Automation Shifts Threat Landscape in 2026

In February 2026, a joint research team from SentinelLabs and the University of Calgary published a report revealing a paradigm shift in cyber‑attack tradecraft. The analysts, led ...

AI ThreatsAI SecurityThreat Intel
Read More → Use Tool →
2026-04-29The Hacker News
Exposure Management Platforms: Key Features and Common Pitfalls

Security teams across industries are increasingly discovering that traditional vulnerability management approaches fail to accurately represent organizational risk. Despite closing...

VulnerabilityThreat IntelCloud Security
Read More → Use Tool →
2026-04-29The Hacker News
Critical cPanel Authentication Vulnerability: Patch Now

cPanel and its WebHost Manager (WHM) product line contain a critical authentication flaw that could allow a remote attacker to bypass login controls and gain full control of the ho...

VulnerabilityAuthenticationZero-Day
Read More → Use Tool →
2026-04-29The Hacker News
CISA Adds Actively Exploited ConnectWise and Windows Flaws to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical security flaws—one affecting ConnectWise ScreenConnect and the other targeting Microsoft Win...

VulnerabilityZero-DayThreat Intel
Read More → Use Tool →
2026-04-29The Hacker News
Critical LiteLLM SQL Injection CVE-2026-42208 Exploited Within 36 Hours

Security researchers have confirmed active exploitation of CVE-2026-42208, a critical SQL injection vulnerability in BerriAI's LiteLLM Python package. The flaw, which was disclosed...

Zero-DayVulnerabilityLLM Security
Read More → Use Tool →
2026-04-28Dark Reading
BlueNoroff Leverages Fake Zoom Calls, Deepfakes to Target Crypto Execs

BlueNoroff, the North Korean threat group tracked as an advanced persistent threat (APT), has refined its attack playbook by weaponizing fake Zoom calls to snare cryptocurrency exe...

APTDeepfakeAI Threats
Read More → Use Tool →
2026-04-28Dark Reading
Chris Inglis Reflects on NSA Failures 13 Years After Snowden Leaks

Chris Inglis, who served as NSA Deputy Director from 2011 to 2014 under Director Keith Alexander, has broken his silence on the agency's missteps during the Edward Snowden affair, ...

PrivacyThreat IntelRegulation
Read More → Use Tool →
2026-04-28Dark Reading
Feuding Ransomware Groups 0APT and KryBit Expose Each Other's Operations

The ransomware ecosystem was rocked in early 2026 when two prominent ransomware‑as‑a‑service (RaaS) operations, 0APT and KryBit, turned on each other, spilling a treasure trove of ...

RansomwareAPTThreat Intel
Read More → Use Tool →
2026-04-28Dark Reading
Vidar Infostealer Dominates Market After Law Enforcement Takedowns

Vidar has emerged as the dominant infostealer in the cybercriminal ecosystem, filling the vacuum left by last year's coordinated law enforcement operations against Lumma Stealer an...

MalwareThreat IntelData Breach
Read More → Use Tool →
2026-04-28Dark Reading
GlassWorm VS Code Extensions Spread Self-Propagating Malware via Open VSX

Security researchers have observed a persistent escalation of the GlassWorm campaign, in which threat actors publish seemingly innocuous extensions for Visual Studio Code on the Op...

MalwareSupply ChainVulnerability
Read More → Use Tool →
2026-04-28The Hacker News
Critical GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Push

Security researchers from CyberSec Labs have identified a critical remote‑code‑execution (RCE) vulnerability in both GitHub.com and GitHub Enterprise Server. Tracked as CVE‑2026‑38...

Zero-DayVulnerabilitySupply Chain
Read More → Use Tool →
2026-04-28The Hacker News
Brazilian LofyGang Returns with Minecraft LofyStealer Campaign

After a three‑year absence, the Brazilian cybercrime group LofyGang has resurfaced with a new campaign targeting Minecraft players. The outfit is deploying a freshly coded stealer ...

MalwareThreat Intel
Read More → Use Tool →
2026-04-28The Hacker News
VECT 2.0 Ransomware Wipes Files Over 131KB on Windows, Linux, ESXi

The cyber‑crime group behind the VECT 2.0 ransomware has been observed deploying a strain that behaves more like a data‑wiper than conventional ransomware. In recent incidents targ...

RansomwareMalwareVulnerability
Read More → Use Tool →