The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. The vulnerability, CVE-2024-21182 (CVSS score: 7.5), allows an unauthenticated attacker with network access to take control of susceptible servers. It was – Read … Read More “Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation – The Hacker News” »
Category: Attack Feeds
The Russian hacking group known as Gamaredon has been attributed to the continued exploitation of a WinRAR vulnerability to deliver multiple malware families aimed at data theft and propagation. Per Sekoia, the activity involves the weaponization of CVE-2025-8088, a path traversal flaw in WinRAR, to launch an HTML Application payload dubbed GammaPhish, which is then … Read More “Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine – The Hacker News” »
The Trump administration issued a revised executive order Tuesday focused on artificial intelligence, offering a significantly pared-back vision for the federal government’s role vetting AI systems compared to a draft version that was spiked weeks ago. The order keeps in place the administration’s largely voluntary framework for companies to engage with the federal government around … Read More “Trump administration releases scaled-back AI executive order – CyberScoop” »
The Pentagon is focusing on integrating cyber into all its operations, and wants to make sure it integrates security into artificial intelligence usage from the outset, the Defense Department’s top cyber policy official said Tuesday. Recent conflicts have made clear how important cyber is, said Katherine Sutton, assistant secretary for cyber policy and principal cyber … Read More “DOD wants to integrate cyber in all operations, and integrate security into AI – CyberScoop” »
The Trump administration issued a revised executive order Tuesday focused on artificial intelligence, offering a significantly pared-back vision for the federal government’s role vetting AI systems compared to a draft version that was spiked weeks ago. The order keeps in place the administration’s largely voluntary framework for companies to engage with the federal government around … Read More “Trump administration releases scaled-back AI executive order – CyberScoop” »
Hackers Abused Meta’s AI Support Bot to Hijack Major Instagram Accounts – Hackread – Cybersecurity News, Data Breaches, AI and More
Hackers abused Meta’s AI support bot to hijack major Instagram accounts, bypassing security checks as videos showed the flaw before Meta fixed the issue. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
Anthropic is broadening access to its Project Glasswing program, adding approximately 150 organizations in 15 countries, the company announced Tuesday, as its restricted Claude Mythos Preview model has already surfaced more than 10,000 high- or critical-severity software vulnerabilities since the program launched in early April. The expansion follows an initial cohort of roughly 50 partners … Read More “Anthropic expanding access to Project Glasswing – CyberScoop” »
New WordPress Malware Uses Steam Profile Comments to Hide C2 Instructions – Hackread – Cybersecurity News, Data Breaches, AI and More
GoDaddy researchers found WordPress malware using Steam Community profile comments to hide encoded command and control data, with nearly 1,980 sites affected. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
AI-Driven Exploitation is Destroying Vulnerability Management. Here’s How to Handle It. – The Hacker News
AI-driven exploitation timelines are rapidly shrinking, and they are not going to stop shrinking. Vulnerabilities are being discovered, reproduced, and weaponized faster than ever in the history of enterprise security. As a result, the window between a vulnerability being disclosed and indiscriminate exploitation observed across the internet is now measured in hours, not days. The … Read More “AI-Driven Exploitation is Destroying Vulnerability Management. Here’s How to Handle It. – The Hacker News” »
Halo Security Honored with 2026 MSP Today Product of the Year Award – Hackread – Cybersecurity News, Data Breaches, AI and More
Miami Beach, FL, USA, 2nd June 2026, CyberNewswire – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
Most organizations now recognize that endpoint protection alone is no longer sufficient. That’s why adoption of endpoint detection and response (EDR) has accelerated rapidly in recent years. Organizations understand that modern attacks move faster, evade traditional prevention controls, and require continuous visibility into suspicious activity across the environment. But owning EDR – Read More – … Read More “How Leading Organizations Are Turning EDR Into Operational Resilience – The Hacker News” »
Most organizations now recognize that endpoint protection alone is no longer sufficient. That’s why adoption of endpoint detection and response (EDR) has accelerated rapidly in recent years. Organizations understand that modern attacks move faster, evade traditional prevention controls, and require continuous visibility into suspicious activity across the environment. But owning EDR – Read More – … Read More “How Leading Organizations Are Turning EDR Into Operational Resilience – The Hacker News” »
Cybersecurity researchers have disclosed details of a spear-phishing campaign likely undertaken by the Pakistan-aligned SideCopy group targeting Afghanistan’s Ministry of Finance with an open-source remote access trojan called Xeno RAT. “The campaign opens with a spear phishing delivery – a ZIP archive containing a malicious LNK file bearing a carefully crafted Pashto-language filename,” – Read … Read More “Pakistan-Linked SideCopy Targets Afghanistan Finance Ministry with Xeno RAT – The Hacker News” »
Dashlane Discloses Brute-Force Attack, Encrypted Vaults of Fewer Than 20 Users Downloaded – The Hacker News
Password manager Dashlane has disclosed that “fewer than” 20 users on the personal subscription plan had their encrypted vaults downloaded following a brute-force attack launched by an unknown party. On May 31, 2026, the company said an “external” threat actor launched a brute-force attack against certain Dashlane user accounts with the aim of breaking two-factor … Read More “Dashlane Discloses Brute-Force Attack, Encrypted Vaults of Fewer Than 20 Users Downloaded – The Hacker News” »
Why Encrypted File Sharing Is Essential for Modern Businesses – Hackread – Cybersecurity News, Data Breaches, AI and More
Consider the history of any recent corporate scandal, and it is quite possible to guess what the story… – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
Researchers and threat hunters are scrambling to respond to an actively exploited authentication-bypass vulnerability affecting Palo Alto Networks customers’ firewalls. The company initially tagged CVE-2026-0257 with a medium-severity rating when it disclosed the defect May 13, but quickly reassessed it as critical after Rapid7 observed and confirmed active exploitation in the wild. The Cybersecurity and … Read More “Attackers are exploiting Palo Alto Networks defect that initially flew under the radar – CyberScoop” »
What One Predator Case Can Reveal About an Online Platform’s Safety Gaps – Hackread – Cybersecurity News, Data Breaches, AI and More
When a predator contacts a child through an online platform, the details of how it happened often expose… – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
Tina Peters, convicted in election-security breach, emerges defiant and vows legal fight – CyberScoop
Former Mesa County, Colorado election clerk Tina Peters remained unapologetic in her first public interview since her prison sentence was commuted, reiterating many of the same conspiratorial beliefs about elections while vowing to recover her health and fight on in court to have her criminal record expunged. In an interview with former Trump campaign manager … Read More “Tina Peters, convicted in election-security breach, emerges defiant and vows legal fight – CyberScoop” »
Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm – The Hacker News
A new Mini Shai-Hulud supply chain attack campaign, codenamed Miasma, has compromised @redhat-cloud-services packages to steal credentials and secrets from developer machines and deliver a self-propagating worm. “This is effectively a Mini Shai-Hulud campaign: it uses the same core tactics of install-time execution, credential harvesting, CI/CD targeting, encrypted exfiltration, and potential – Read More – … Read More “Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm – The Hacker News” »
The U.S. Postal Service is moving forward with mail-in ballot restrictions, following a court’s rejection of a request by voting rights groups to immediately block an executive order from President Donald Trump ordering the changes. A new regulation proposed last Friday seeks to apply “uniform standards for the mailing of absentee ballots to and from … Read More “USPS moving forward with mail-in ballot changes as courts weigh Trump’s election order – CyberScoop” »
The Instagram accounts for the Obama White House and the Chief Master Sergeant of the U.S. Space Force were briefly defaced with pro-Iranian images and messages over the weekend, after instructions began circulating on Telegram showing how to trick Meta’s “AI support assistant” bot into resetting account passwords. A screenshot from a video released on … Read More “Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts – Krebs on Security” »
RaccoonLine Publishes 2026 dVPN Buyer’s Guide for Privacy-Focused Users – Hackread – Cybersecurity News, Data Breaches, AI and More
Roma, Італія, 1st June 2026, CyberNewswire – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
A new cyber espionage campaign codenamed Operation Dragon Weave has been observed targeting officials and citizens in the Czech Republic and Taiwan to deliver an AdaptixC2 agent. According to Seqrite Labs, targets of the campaign include government, research, academic, technology, and financial services sectors. The activity entails distributing spear-phishing emails containing ZIP attachments – Read … Read More “China-Aligned Groups Ramp Up Attacks: Dragon Weave Hits Czech Republic & Taiwan – The Hacker News” »
Zero-Click pretalx XSS Flaw Lets Hackers Hijack Conference Organizer Accounts – Hackread – Cybersecurity News, Data Breaches, AI and More
pretalx XSS flaw lets attackers hijack conference organizer accounts, steal sessions, auto-accept talks, and demote admins. Patched in v2026.1.0. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
How to Get a Reddit API Key in 2026: Step-by-Step Guide – Hackread – Cybersecurity News, Data Breaches, AI and More
Getting a Reddit API key starts with creating an application through Reddit’s developer portal and understanding how its… – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More – The Hacker News
Monday hit like a cron job with anger issues. A busted auth path here, a repo-side faceplant there, some “patched-ish” thing already getting chewed on in the wild, and then the usual bonus round: poisoned dev tools, sketchy forum chatter, phishing kits pretending to be productivity, and AI lowering the bar for people who already … Read More “⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More – The Hacker News” »
Fake Purchase Order Emails Spread Fileless PureLogs Malware via RAR Archives – Hackread – Cybersecurity News, Data Breaches, AI and More
Hackers are using fake purchase order emails and process hollowing to deploy fileless PureLogs malware to steal Windows users’ browser, crypto, and Discord data. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
Three years ago, the practical question for an MSP building a cybersecurity practice was which “vCISO platform” to buy. The term was good shorthand for the work at the time: assessments, advisory, reporting, maybe a compliance module bolted on the side. The work has since outgrown the descriptor. A Security Growth Platform is the more … Read More “The Security Growth Platform: Why MSPs Are Moving Beyond vCISO Tools – The Hacker News” »
How to Get the Most From Your Explainer Video Production Services – Hackread – Cybersecurity News, Data Breaches, AI and More
Video can simplify a hard offer, shorten sales conversations, and improve recall. Those gains depend on disciplined planning… – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack – The Hacker News
Cybersecurity researchers have disclosed details of a new malicious supply chain campaign that’s targeting developers using OpenAI Codex through a legitimate-looking remote web UI. The tool, named codexui-android, is advertised on GitHub and npm as a remote web UI for OpenAI Codex, attracting over 29,000 weekly downloads. The package is still available for download from … Read More “OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack – The Hacker News” »
An unknown threat actor has been observed using a large language model (LLM) agent to conduct post-compromise actions after obtaining initial access following the exploitation of a publicly-accessible Marimo network using a recently disclosed vulnerability. “The attacker compromised an internet-reachable Marimo notebook via CVE-2026-39987, extracted two cloud credentials from the compromised – Read More – … Read More “Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit – The Hacker News” »
Threat actors are attempting to actively exploit a critical security flaw impacting WP Maps Pro, a WordPress plugin that has had over 15,000 sales on the Envato Market, to create malicious administrator accounts on susceptible sites. WP Maps Pro allows site owners to embed customizable Google Maps and OpenStreetMap with markers, listings, and advanced location … Read More “Critical WP Maps Pro Flaw Actively Exploited to Create Admin Accounts – The Hacker News” »
Cybersecurity threats to the 2026 midterm elections are targeting the accounts and platforms that campaigns, donors and voters use to communicate, according to a security report released Monday by Check Point Software Technologies. So far in this election cycle, threats are not aimed at voting machines or ballot-counting systems. Instead, threat actors are going after … Read More “Election threats are focused on campaign systems, not voting machines – CyberScoop” »
27,000-Download Codex UI Tool Secretly Stole OpenAI Refresh Tokens – Hackread – Cybersecurity News, Data Breaches, AI and More
A malicious Codex UI npm package with 27,000 weekly downloads was caught exfiltrating OpenAI refresh tokens, exposing developers to account takeover risks. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
Dutch authorities have announced the takedown of a botnet that enslaved millions of infected devices, including computers, tablets, smartphones, and IoT devices, to carry out malicious attacks. The bot network, per the Dutch Politie and the National Cyber Security Center (NCSC), consisted of at least 17 million infected devices. More than 200 servers located in … Read More “Dutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices – The Hacker News” »
Fake Anthropic Sites Deliver Fileless Infostealer to Claude Code Users – Hackread – Cybersecurity News, Data Breaches, AI and More
Fake Anthropic websites are being used to target Claude Code users with a fileless infostealer campaign that steals browser credentials and evades detection. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation – The Hacker News
Palo Alto Networks has warned that a recently disclosed medium-severity security flaw impacting PAN-OS and Prisma Access has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-0257 (CVSS score: 7.8), refers to a case of authentication bypass that could be exploited by bad actors to set up VPN connections. “Authentication bypass vulnerabilities … Read More “PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation – The Hacker News” »
Cybersecurity researchers have disclosed details of a vulnerability in OpenAI ChatGPT that leverages the artificial intelligence (AI) assistant’s implicit trust in Markdown links and images to trigger prompt injections and open the door to phishing attacks. The technique has been codenamed ChatGPhish by Permiso Security. “The chatgpt.com response renderer trusts Markdown links and Markdown – … Read More “ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface – The Hacker News” »
Tennessee man linked to 764 accused of series of crimes against children dating back to 2022 – CyberScoop
A Tennessee man accused of abusing and sexually exploiting children while actively participating in 764, a sprawling online nihilistic violent extremist collective affiliated with The Com, pleaded not guilty Thursday to a series of charges that could keep him locked up for 50 years. Zachary Sweeney has allegedly victimized multiple children, on numerous occasions grooming … Read More “Tennessee man linked to 764 accused of series of crimes against children dating back to 2022 – CyberScoop” »
A Department of Commerce inspector general report released Thursday found that the National Institute of Standards and Technology has mismanaged a critical cybersecurity vulnerability database through poor planning, inefficient operations, duplicate federal programs, and failure to communicate with users. The National Vulnerability Database, maintained by NIST since 2005, collects information about computer security flaws and … Read More “Federal audit reveals NIST’s NVD is plagued by poor planning and duplication – CyberScoop” »
The Deliverability Problem: How New Platforms Are Solving Inbox Placement – Hackread – Cybersecurity News, Data Breaches, AI and More
Email still reaches more people than any other digital channel. Getting it to actually land in the inbox… – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
A previously undocumented threat actor dubbed GREYVIBE has been attributed to ongoing and persistent attacks targeting Ukraine and Ukraine-related entities since at least August 2025. GREYVIBE, per WithSecure, is assessed to be a Russian-speaking group operating broadly in the Russian time zone, with the activities aligning with Kremlin state interests, specifically when it comes to … Read More “New Russian-Linked GREYVIBE Targets Ukraine with AI-Powered Cyberattacks – The Hacker News” »
Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal – The Hacker News
Microsoft has come out strongly in favor of Coordinated Vulnerability Disclosure (CVD), urging the research community to share their findings and give affected vendors an opportunity to better understand the impact and address them before they are publicly disclosed. The development comes after a researcher named Chaotic Eclipse (aka Nightmare-Eclipse) disclosed details of multiple zero-day … Read More “Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal – The Hacker News” »
What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks – The Hacker News
Shadow AI used to mean employees pasting things they shouldn’t into ChatGPT. It now means something bigger: employees building full applications with AI, wiring them into production systems, and publishing them on the open internet. Without Security or IT in the loop. The artifact moved from a prompt to a product. The risk surface moved … Read More “What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks – The Hacker News” »
Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets – The Hacker News
Cybersecurity researchers have discovered a malicious NuGet package that masquerades as a C# software development kit for Sicoob, one of Brazil’s largest cooperative financial systems, to siphon client IDs and PFX certificates. According to Socket, versions 2.0.0 through 2.0.4 of “Sicoob.Sdk” contain functionality to exfiltrate sensitive information, including PFX certificates that are used to – … Read More “Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets – The Hacker News” »
Dutch police have arrested a 35-year-old man suspected of hacking into the computer systems of Amsterdam football giant Ajax, after the personal data of hundreds of thousands of supporters was put at risk. Read more in my article on the Hot for Security blog. – Read More – GRAHAM CLULEY
The North Korean state-sponsored threat actor known as Kimsuky (aka Velvet Chollima) has been attributed to a fresh set of cyber attacks targeting South Korean military and corporate entities through March and April 2026. “Kimsuky employed a range of tailored social engineering tactics, such as spoofing security software installation pages and crafting a fake Webex … Read More “Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels – The Hacker News” »
The CISO Whisperer’s Watch List For The Gartner Security & Risk Management Summit 2026 – Hackread – Cybersecurity News, Data Breaches, AI and More
New York, USA, 28th May 2026, CyberNewswire – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
Google security engineer accused of turning confidential search trends into $1.2M win on Polymarket – CyberScoop
A Google security engineer was arrested in New York and charged with crimes related to bets he allegedly placed on Polymarket using confidential information he pulled from Google systems, the Justice Department said Wednesday. Michele Spagnuolo, a 36-year-old Italian citizen who lives in Switzerland, is accused of placing multiple trades on the prediction marketplace last … Read More “Google security engineer accused of turning confidential search trends into $1.2M win on Polymarket – CyberScoop” »
A House subcommittee will hold an open hearing next week on how frontier artificial intelligence models are shaping the cybersecurity landscape, for good and for ill. The June 4 hearing will be the second the Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection has held that was focused at least in part on the subject, … Read More “House panel poised to hold hearing centered on AI impact on cyber – CyberScoop” »