HackMyIP

Cybersecurity News

Latest updates from top security sources

2447 articles, page 60 of 82

2026-05-25SecurityWeek
DocketWise Data Breach Impacts 143,000

Hackers accessed names, addresses, Social Security numbers, financial information, and medical data from third-party partner repositories. The post DocketWise Data Breach Impacts 1...

Read More → Use Tool →
2026-05-25SecurityWeek
Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack

Fake automated commits injected GitHub Actions workflows containing payloads to steal credentials, CI secrets, keys, and tokens. The post Over 5,500 GitHub Repositories Infected in...

Read More → Use Tool →
2026-05-24BleepingComputer
Ghost CMS CVE-2026-26980 SQL Injection Powers ClickFix Campaign

A coordinated campaign is actively exploiting a critical SQL injection flaw (CVE-2026-26980) in Ghost CMS to inject malicious JavaScript that drives a ClickFix attack flow. Discove...

Zero-DayVulnerabilityMalware
Read More → Use Tool →
2026-05-23BleepingComputer
Laravel Lang Supply Chain Attack Deploys Credential-Stealing Malware

A sophisticated supply chain attack has compromised the Laravel Lang localization packages, affecting four repositories and potentially hundreds of historical versions. Security re...

Supply ChainMalwareData Breach
Read More → Use Tool →
2026-05-23The Hacker News
Anthropic's Claude Mythos Finds 10,000 High-Severity Flaws in Software

Anthropic's Project Glasswing initiative has uncovered more than 10,000 high- or critical-severity vulnerabilities across systemically important software globally since its launch ...

VulnerabilityAI SecurityZero-Day
Read More → Use Tool →
2026-05-23The Hacker News
npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks

GitHub has rolled out new controls for npm to improve the security of the software supply chain, giving maintainers the ability to explicitly approve a release prior to the package...

Read More → Use Tool →
2026-05-23The Hacker News
Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware

A new "coordinated" supply chain attack campaign has impacted eight packages on Packagist including malicious code designed to run a Linux binary retrieved from a GitHub Releases U...

Read More → Use Tool →
2026-05-23BleepingComputer
Italy disrupts CINEMAGOAL piracy app that stole streaming auth codes

Italian authorities have dismantled a piracy ecosystem centered around the CINEMAGOAL app that provided access to various streaming platforms, including Netflix, Disney+, and Spoti...

Read More → Use Tool →
2026-05-23The Hacker News
Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer

Cybersecurity researchers have flagged a fresh software supply chain attack campaign that has targeted multiple PHP packages belonging to Laravel-Lang to deliver a comprehensive c...

Read More → Use Tool →
2026-05-23The Hacker News
LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root

A maximum-severity security vulnerability impacting LiteSpeed User-End cPanel Plugin has come under active exploitation in the wild. The flaw, tracked as CVE-2026-48172 (CVSS scor...

Read More → Use Tool →
2026-05-23The Hacker News
Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a recently patched critical security flaw impacting Drupal Core to its Known Exploited Vulnerabilities (K...

Read More → Use Tool →
2026-05-23SecurityWeek
‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted Domains

The stealthy vulnerability impacts roughly 88 million domains and can be exploited to bypass DNS filtering and hide command-and-control traffic. The post ‘Underminr’ Vulnerability ...

Read More → Use Tool →
2026-05-23The Record
CISA Launches Form for Researchers to Report Exploited Vulnerabilities

The Cybersecurity and Infrastructure Security Agency (CISA) has unveiled a new nomination form enabling security researchers, vendors, and industry partners to submit vulnerabiliti...

VulnerabilityThreat IntelBug Bounty
Read More → Use Tool →
2026-05-22The Hacker News
Operation Saffron Takes Down First VPN Used by 25 Ransomware Groups

Authorities in Europe and North America have successfully dismantled First VPN, a criminal VPN service specifically designed to anonymize ransomware operations and other cyberattac...

RansomwareThreat IntelPrivacy
Read More → Use Tool →
2026-05-22The Record
FBI Warns of Kali365 Phishing Service Targeting Microsoft 365

The FBI has issued a critical advisory regarding Kali365, a Telegram-based Phishing-as-a-Service (PhaaS) platform that enables cybercriminals to compromise Microsoft 365 accounts b...

PhishingCloud SecurityAuthentication
Read More → Use Tool →
2026-05-22The Record
Meta settles school district lawsuit claiming addictive design harmed students' mental health

The bellwether lawsuit was the first of at least 1,200 to be brought by a school district against Meta, Snap, YouTube and TikTok for similar alleged harms. The other cases have not...

Read More → Use Tool →
2026-05-22The Hacker News
Ghostwriter APT Targets Ukraine Gov with Prometheus Phishing Malware

The Belarus-aligned threat actor Ghostwriter, also tracked as UAC-0057 and UNC1151, has been observed conducting sophisticated phishing campaigns against Ukrainian government entit...

APTPhishingMalware
Read More → Use Tool →
2026-05-22The Hacker News
Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows

Cybersecurity researchers have disclosed details of a new automated campaign called Megalodon that has pushed 5,718 malicious commits to 5,561 GitHub repositories within a six-hour...

Read More → Use Tool →
2026-05-22The Hacker News
Making Vulnerable Drivers Exploitable Without Hardware - The BYOVD Perspective

1 Introduction This article provides a technical analysis of how many Windows kernel mode drivers can be interacted with from user mode without the hardware they were developed fo...

Read More → Use Tool →
2026-05-22BleepingComputer
Netherlands seizes 800 servers of hosting firm enabling cyberattacks

Financial crime investigators in the Netherlands (FIOD) arrested two men and seized 800 servers linked to a web hosting company that enabled cyberattacks, interference operations, ...

Read More → Use Tool →
2026-05-22BleepingComputer
Former US execs plead guilty to aiding tech support scammers

Two former executives of a call-tracking and analytics company pleaded guilty to concealing a years-long tech support fraud scheme that victimized individuals worldwide. [...]...

Read More → Use Tool →
2026-05-22BleepingComputer
Trend Micro warns of Apex One zero-day exploited in the wild

Japanese cybersecurity software company Trend Micro has addressed an Apex One zero-day vulnerability exploited in attacks targeting Windows systems. [...]...

Read More → Use Tool →
2026-05-22BleepingComputer
Drupal: Critical SQL injection flaw now targeted in attacks

Drupal is warning that hackers are attempting to exploit a "highly critical" SQL injection vulnerability announced earlier this week. [...]...

Read More → Use Tool →
2026-05-22BleepingComputer
Why Chargebacks are Just One Piece of the Fraud Puzzle

Fraud losses don't stop at chargebacks. False declines, account takeovers, and abuse also damage revenue and trust. IPQS breaks down why fraud teams need broader visibility into ri...

Read More → Use Tool →
2026-05-22BleepingComputer
Ubiquiti patches three max severity UniFi OS vulnerabilities

Ubiquiti has released security updates to patch three maximum severity vulnerabilities in UniFi OS that can be exploited by remote attackers without privileges. [...]...

Read More → Use Tool →
2026-05-22KrebsOnSecurity
Lawmakers Demand Answers as CISA Tries to Contain Data Leak

Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a ...

Read More → Use Tool →
2026-05-22Dark Reading
Akamai Joins Growing Chorus of Vendors Betting Big on Secure Enterprise Browsers

When Akamai announced its LayerX acquisition, the company joined a growing list of vendors adding secure enterprise browsers to their product portfolios....

Read More → Use Tool →
2026-05-22Dark Reading
Verizon DBIR: Healthcare Fends Off Increased Social Engineering Attacks

Ransomware and vendor breaches persist, but the 2026 Data Breach Investigations Report (DBIR) highlights how evolving social engineering tactics make the sector more vulnerable....

Read More → Use Tool →
2026-05-22Dark Reading
China's Webworm Uses Discord, Microsoft Graphs to Hack EU Governments

The advanced persistent threat group also relied on SOCKS proxies like SoftEther VPN, tunneling tools that act as a middleman between victim and attacker....

Read More → Use Tool →
2026-05-22SecurityWeek
Drupal Vulnerability in Hacker Crosshairs Shortly After Disclosure

Drupal is warning users that it has already seen attempts to exploit CVE-2026-9082 and security firms are seeing attacks against thousands of websites. The post Drupal Vulnerabilit...

Read More → Use Tool →