HackMyIP

Cybersecurity News

Latest updates from top security sources

1589 articles, page 7 of 53

2026-09-08The Record
Cyberattack encrypts systems at Bavarian municipal utility

A municipal utility in Bavaria is recovering from a cyberattack that encrypted its internal IT systems but did not affect water and electricity services....

Read More → Use Tool →
2026-09-08The Hacker News
Critical FreeIPA Flaw Chain Lets Attackers Forge Admin Credentials

A pair of chained vulnerabilities in FreeIPA and the 389 Directory Server can allow an anonymous, never-logged-in client to manufacture a Kerberos identity of its choosing and land...

VulnerabilityAuthentication
Read More → Use Tool →
2026-09-08The Hacker News
Adobe Patches Critical Magento Zero-Day StyleSmuggler Under Active Attack

Adobe has shipped emergency security updates for a maximum-severity vulnerability, tracked as CVE-2026-75650 (CVSS 10.0), affecting Adobe Commerce, Magento Open Source, and Adobe C...

Zero-DayVulnerabilityMalware
Read More → Use Tool →
2026-09-08The Hacker News
BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams

Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams...

Read More → Use Tool →
2026-09-08The Hacker News
Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing

Online dating app Grindr has opted to pay £26 million ($35.1 million) to settle a lawsuit in the U.K. over allegations that it shared users' personal information, including their H...

Read More → Use Tool →
2026-09-07The Hacker News
PEEP Malware Turns Chrome and Edge Into Host-Level Backdoors

SOCRadar researchers have disclosed details on PEEP, a sophisticated post-exploitation toolkit that transforms Chromium-based browsers into covert backdoors for host-level command ...

MalwareThreat IntelAPT
Read More → Use Tool →
2026-09-07The Hacker News
Fake IT Help Desk Calls Used to Steal Microsoft 365 Data from Executives

Threat hunters at Arctic Wolf have uncovered a widespread data theft and extortion campaign, tracked as PREY-0058, that targets Microsoft 365 and other SaaS platforms by impersonat...

PhishingData BreachThreat Intel
Read More → Use Tool →
2026-09-07The Hacker News
Weekly Recap: Chrome 0-Day Exploited, N-Central RCE Flaws, Supply Chain Hit

Google has shipped an emergency patch for a high-severity Chrome vulnerability tracked as CVE-2026-85046 (CVSS 8.8), a type confusion bug in the V8 JavaScript and WebAssembly engin...

Zero-DayVulnerabilitySupply Chain
Read More → Use Tool →
2026-09-07The Hacker News
Cloud Misconfigurations Differ Wildly Across AWS, Azure, and GCP

New research from Intruder's 2026 Cloud Security Index reveals that cloud security risk profiles vary dramatically across providers, undermining the assumption that a single cloud ...

Cloud SecurityVulnerabilityAuthentication
Read More → Use Tool →
2026-09-07The Hacker News
ScreenConnect Abuse Spreads Four-Stage VBScript Chain to New Hosts

Cybersecurity researchers at Huntress have uncovered worm-like activity abusing ConnectWise ScreenConnect to deliver a four-stage Visual Basic Script (VBScript) payload to newly co...

MalwarePhishingThreat Intel
Read More → Use Tool →
2026-09-07The Hacker News
Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specifi...

Read More → Use Tool →
2026-09-07SecurityWeek
Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits

The proof-of-concept (PoC) exploits lead to privilege escalation, spawning a shell with System privileges. The post Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Expl...

Read More → Use Tool →
2026-09-07SecurityWeek
North Korean Hackers Deploy New Linux Espionage Toolkit

The stealthy toolkit embeds a backdoor in HAProxy and targets automotive and media organizations in South Korea for long-term surveillance. The post North Korean Hackers Deploy New...

Read More → Use Tool →
2026-09-07SecurityWeek
OpenAI Agents Hijack Another Victim Website

OpenAI agents made 15,000–18,000 autonomous edits to a German wiki over three months, evading moderation and echoing tactics seen in the Hugging Face breach. The post OpenAI Agents...

Read More → Use Tool →
2026-09-07The Record
Berlin investigates new data leak after hackers publish stolen login credentials

Another trove of data from Berlin's government has appeared online, authorities said. Germany's information security agency separately warned about the Rhysida cybercrime group....

Read More → Use Tool →
2026-09-07The Hacker News
N-able N-central Hotfix 4 Patches Critical 10.0 RCE Zero-Day

N-able has shipped its fourth hotfix in five weeks for the on-premises N-central remote monitoring and management (RMM) platform, addressing a maximum-severity vulnerability that e...

VulnerabilityZero-DayIncident Response
Read More → Use Tool →
2026-09-07The Hacker News
JSCeal Malware Bypasses Google Auth Using Stolen Session Cookies

Cybersecurity researchers at Check Point Research have published a deep-dive analysis of JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware engineered for credential harv...

MalwareThreat IntelAuthentication
Read More → Use Tool →
2026-09-07SecurityWeek
Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

The StyleSmuggler zero-day allows attackers to execute code and deploy a stealthy backdoor on Adobe Commerce and Magento stores. The post Adobe Commerce Zero-Day Exploited to Backd...

Read More → Use Tool →
2026-09-07SecurityWeek
Modified ScreenConnect Clients Used in Worm-Like Campaign

The attacks rely on backdoored ScreenConnect instances to transfer and execute payloads to newly connected clients. The post Modified ScreenConnect Clients Used in Worm-Like Campai...

Read More → Use Tool →
2026-09-06The Hacker News
Critical MikroTik Router Flaw Lets Attackers Gain Admin Access Without Password

Attackers are actively exploiting a critical vulnerability in MikroTik routers to seize full administrative control without any authentication, according to an advisory published S...

VulnerabilityAuthenticationIncident Response
Read More → Use Tool →
2026-09-06The Hacker News
REVSTEALER Modules Disable Windows Defender to Run Crypto Miner

Elastic Security Labs has published research on four previously undocumented Windows programs linked to REVSTEALER, a commercial information stealer that has circulated on cybercri...

MalwareThreat IntelVulnerability
Read More → Use Tool →
2026-09-05The Hacker News
Magento StyleSmuggler Zero-Day Actively Exploited to Backdoor Stores

A new unauthenticated remote code execution vulnerability in Magento Open Source and Adobe Commerce is being actively exploited in the wild, Dutch e-commerce security firm Sansec d...

Zero-DayVulnerabilityIncident Response
Read More → Use Tool →
2026-09-05The Hacker News
JetBrains Cadence Breached via TeamCity Flaw, AWS Credentials Exposed

JetBrains has confirmed that attackers breached its Cadence cloud computing environment last month by exploiting a critical, recently patched vulnerability in TeamCity, gaining acc...

Data BreachVulnerabilityCloud Security
Read More → Use Tool →
2026-09-05The Hacker News
Trezor Discloses 67,000 Customers Exposed in ShipMonk Supply Chain Breach

Hardware wallet manufacturer Trezor revealed on Friday that 67,000 additional U.S. customers had their personal data exposed in a breach at its third-party fulfillment partner Ship...

Data BreachSupply ChainZero-Day
Read More → Use Tool →
2026-09-05The Hacker News
Critical VMware VM Escape Flaws Let Guests Execute Host Code

Broadcom has rolled out emergency security patches for two serious vulnerabilities in VMware Workstation and VMware Fusion, both capable of breaking the virtual machine boundary an...

VulnerabilityCloud Security
Read More → Use Tool →
2026-09-05SecurityWeek
Critical Elementor Pro Flaw Exploited for Unauthenticated Site Takeover

A critical-severity vulnerability in the Elementor Pro WordPress plugin is being actively exploited by threat actors to compromise websites, according to WordPress security firm De...

VulnerabilityIncident Response
Read More → Use Tool →
2026-09-05The Hacker News
OpenAI Agents Used Abandoned Wiki to Coordinate and Bypass Sandboxes

The Nightingale Collective, an AI safety nonprofit, has revealed that approximately 18,000 autonomous AI agents identifying themselves as OpenAI systems flooded a dormant German wi...

AI SecurityAI ThreatsLLM Security
Read More → Use Tool →
2026-09-05The Hacker News
PaperCut Flaws Exploited to Steal Credentials From Schools, Universities

Threat actors are actively exploiting two newly disclosed PaperCut vulnerabilities—CVE-2026-81578 (authentication bypass) and CVE-2026-82078 (remote code execution)—to steal creden...

VulnerabilityThreat IntelAuthentication
Read More → Use Tool →
2026-09-04Dark Reading
Insurers Race to Cover Rogue AI Risks as Cyber Claims Surge

As enterprise deployments of autonomous AI agents accelerate, insurers and corporate security leaders are scrambling to quantify — and contain — the financial fallout from unintend...

AI SecurityAI ThreatsRegulation
Read More → Use Tool →
2026-09-04The Record
US Offers $10M Bounty for Iranian Cyber Commander Behind Critical Infrastructure Attacks

The U.S. State Department has announced a $10 million reward for information leading to the location or identification of Amir Yaryab, a senior Iranian official accused of leading ...

APTThreat IntelRegulation
Read More → Use Tool →