HackMyIP

Cybersecurity News

Latest updates from top security sources

1595 articles, page 9 of 54

2026-09-03The Hacker News
Thomson Reuters C-Track Breach Exposes SSNs and Sealed Court Data

Thomson Reuters disclosed on Wednesday that an unauthorized actor obtained files from C-Track, the court case management platform operated by its West Publishing Corporation subsid...

Data BreachPrivacySupply Chain
Read More → Use Tool →
2026-09-03The Hacker News
US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries

An RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be part of a broader campai...

Read More → Use Tool →
2026-09-03The Hacker News
Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means

In early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for credentials across 469 locations across developer environme...

Read More → Use Tool →
2026-09-03The Hacker News
Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone

The iPhone belonging to a member of Serbia's student protest movement was infected with NSO Group's Pegasus spyware, according to new findings from the Citizen Lab in collaboration...

Read More → Use Tool →
2026-09-03The Hacker News
Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon

The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a proof-of-concept (PoC...

Read More → Use Tool →
2026-09-03The Hacker News
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in a...

Read More → Use Tool →
2026-09-03Dark Reading
What We Missed: Did ShinyHunters 'Breach' ReliaQuest?

In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from the latest antics of ShinyHunters to new research about the preval...

Read More → Use Tool →
2026-09-03Dark Reading
'Breeze Comet' Tears Into Brazilian & Global Financial Systems

Brazil's most sophisticated threat group is making light work of the country's financial systems, putting money directly into its own pocket....

Read More → Use Tool →
2026-09-03SecurityWeek
HiddenLayer Raises $100 Million for AI Runtime Security

The Austin-based company will invest in agentic runtime security capabilities to secure AI coding agents. The post HiddenLayer Raises $100 Million for AI Runtime Security appeared ...

Read More → Use Tool →
2026-09-03SecurityWeek
153 Million Driver License Images Offered on Dark Web

Cybercriminals are offering digital scans of US and Canadian driver’s licenses, likely stolen from IDScan.net. The post 153 Million Driver License Images Offered on Dark Web appear...

Read More → Use Tool →
2026-09-03SecurityWeek
Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability

The high-severity SQL injection flaw (CVE-2026-19949) could allow unauthenticated attackers to achieve remote code execution. The post Over 3 Million WordPress Sites Affected by Mi...

Read More → Use Tool →
2026-09-03SecurityWeek
Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities

Publicly disclosed S/MIME flaws could expose encrypted email content, while critical IOS XR and Nexus bugs could enable remote code execution and authentication bypass. The post Ci...

Read More → Use Tool →
2026-09-03The Hacker News
Weekly Threat Roundup: Teams Phishing, Ransomware, OAuth Traps

Microsoft has warned of a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support and help desk personnel. Attackers socially...

PhishingRansomwareThreat Intel
Read More → Use Tool →
2026-09-03Dark Reading
Phantom Deal Scam Uses Fake M&A Lures to Dupe Enterprise Finance Staff

A sophisticated business email compromise (BEC) operation dubbed "Phantom Deal" is targeting midlevel employees at large enterprises, leveraging highly convincing fake merger and a...

PhishingThreat IntelAPT
Read More → Use Tool →
2026-09-03SecurityWeek
Capsule Security Launches AI Circuit Breaker to Stop Rogue Agents

Capsule Security, founded in 2025 by CEO Naor Paz and CTO Lidan Hazout, has unveiled what it calls the first dedicated runtime security layer for autonomous AI agents. Announced on...

AI SecurityAI ThreatsIncident Response
Read More → Use Tool →
2026-09-03The Record
Serbian Opposition Figures Hit by Pegasus and NoviSpy Spyware

At least 14 Serbian civil society figures—including a member of parliament, a local opposition politician, and student protesters—have been targeted with advanced mobile spyware si...

MalwarePrivacyAPT
Read More → Use Tool →
2026-09-03The Hacker News
Cisco Nexus 9000 Flaw Lets Attackers Run Code as Root via Exposed Ports

Cisco has disclosed a critical security vulnerability, tracked as CVE-2026-20212, affecting 10 Silicon One-based Nexus 9000 switches and carrying a maximum CVSS score of 9.8. The f...

VulnerabilityAuthentication
Read More → Use Tool →
2026-09-03Dark Reading
AI Agents Compress 2-Week Cyberattack Into 10-Hour Breach

A new report from Dark Reading reveals that frontier AI agents have compressed what traditionally takes human attackers roughly two weeks into a ten-hour automated breach, marki...

AI ThreatsAI SecurityThreat Intel
Read More → Use Tool →
2026-09-03SecurityWeek
Manchester Airports Breach Exposes 8.8M Users After Ransom Refusal

The Manchester Airports Group (MAG) has confirmed that approximately 8.8 million individuals had their personal data exposed after the FulcrumSec extortion gang published roughly 5...

Data BreachRansomware
Read More → Use Tool →
2026-09-03The Record
Thomson Reuters C-Track Breach Exposes Court Data Across 12 US States

Thomson Reuters disclosed a significant data breach on Wednesday affecting its C-Track court case management platform, compromising court records and sensitive personal data across...

Data BreachSupply ChainPrivacy
Read More → Use Tool →
2026-09-03The Hacker News
Node.js Runtime Weaponized for Stealth Malware Delivery in Targeted Attacks

Threat actors are increasingly abusing the trusted Node.js JavaScript runtime as a covert malware delivery mechanism, targeting government departments, technology firms, and hotels...

MalwareAPTThreat Intel
Read More → Use Tool →
2026-09-03SecurityWeek
AIR Security Raises $50M to Build Firewall for AI Agents

AIR Security has emerged from stealth with $50 million in funding to launch what it calls the first firewall purpose-built for AI agents. The round was led by Sequoia Capital and G...

AI SecurityAI ThreatsSupply Chain
Read More → Use Tool →
2026-09-02The Hacker News
Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages

A Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run by Brazilian government and educ...

Read More → Use Tool →
2026-09-02The Hacker News
BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access

Virtualizor said hackers used a Border Gateway Protocol (BGP) hijack to divert Softaculous traffic. The hackers then used the diverted update traffic to deliver a malicious Virtual...

Read More → Use Tool →
2026-09-02The Hacker News
Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control

Cybersecurity researchers have disclosed details of a new Android banking trojan called StreamRat that was promoted to Spanish-speaking users through a fake television-streaming ca...

Read More → Use Tool →
2026-09-02The Hacker News
How to Secure Enterprise AI: From Adoption to Incident Readiness

The debate about whether AI delivers business value is over. The challenge now is implementing it at scale and securely across every function while meeting board-level pressure to ...

Read More → Use Tool →
2026-09-02The Hacker News
GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many gover...

Read More → Use Tool →
2026-09-02The Hacker News
Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands

The U.S. Department of Justice (DoJ) has charged a Russian national, extradited from Cyprus on August 28, with using roughly 255 fake accounts on a freelance platform to send malwa...

Read More → Use Tool →
2026-09-02The Hacker News
Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another

Forescout Research - Vedere Labs said it used Anthropic's Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controlle...

Read More → Use Tool →
2026-09-02The Hacker News
Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnera...

Read More → Use Tool →