Triage is supposed to make things simpler. In a lot of teams, it does the opposite. When you can’t reach a confident verdict early, alerts turn into repeat checks, back-and-forth, and “just escalate it” calls. That cost doesn’t stay inside the SOC; it shows up as missed SLAs, higher cost per case, and more room … Read More “Top 5 Ways Broken Triage Increases Business Risk Instead of Reducing It – The Hacker News” »
Category: Attack Feeds
The notorious cybercrime collective known as Scattered LAPSUS$ Hunters (SLH) has been observed offering financial incentives to recruit women to pull off social engineering attacks. The idea is to hire them for voice phishing campaigns targeting IT help desks, Dataminr said in a new threat brief. The group is said to be offering anywhere between … Read More “SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks – The Hacker News” »
One Identity Appoints Michael Henricks as Chief Financial and Operating Officer – Hackread – Cybersecurity News, Data Breaches, AI and More
Alisa Viejo, CA, United States, 25th February 2026, CyberNewswire – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
Autonomous Endpoint Management Isn’t Just Efficiency, It’s a Security Imperative – Hackread – Cybersecurity News, Data Breaches, AI and More
Autonomous Endpoint Management cuts exposure time by matching patch speed to attacker breakout timelines, reducing risk, workload delays, and breach costs. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
Would-be attackers spent 2025 swimming in a sea of more than 40,000 newly published vulnerabilities, VulnCheck said in a report released Wednesday, but only 1% of those defects, just 422, were exploited in the wild. As the deluge of vulnerabilities grows every year, and CVSS ratings lose significance for vulnerability management prioritization, some defenders are … Read More “Vulnerabilities grew like weeds in 2025, but only 1% were weaponized in attacks – CyberScoop” »
Why automating sensitive data transfers is now a mission-critical priority More than half of national security organizations still rely on manual processes to transfer sensitive data, according to The CYBER360: Defending the Digital Battlespace report. This should alarm every defense and government leader because manual handling of sensitive data is not just inefficient, it is … Read More “Manual Processes Are Putting National Security at Risk – The Hacker News” »
$300 a Month Android Malware ‘Oblivion’ Uses Fake Updates to Hijack Phones – Hackread – Cybersecurity News, Data Breaches, AI and More
Cybersecurity researchers at Certo reveal Oblivion, a new Android Trojan targeting major brands like Samsung and Xiaomi. It bypasses security to steal passwords and bank codes. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
“Decimated.” “Amateur hour.” “Pretty much fallen apart.” “It’s really hard to find something positive to say right now.” It’s been a little more than one year into the second Trump administration, and there’s a large consensus, if not total unanimity, among those who have worked with and for the Cybersecurity and Infrastructure Security Agency: It … Read More “Across party lines and industry, the verdict is the same: CISA is in trouble – CyberScoop” »
A Chinese law enforcement official attempted to use ChatGPT to review its reports on cyber operations, subsequently revealing details of a worldwide online harassment and silencing campaign of China’s critics at home and abroad. In a new threat report released Wednesday, OpenAI said the activity concerned a single account that regularly used ChatGPT to review … Read More “Chinese group’s ChatGPT use reveals worldwide harassment campaign against critics – CyberScoop” »
$10,000 bounty offered if you can hack Ring cameras to stop them sharing your data with Amazon – GRAHAM CLULEY
Amid a privacy backlash, a US $10,000 reward has been offered for anyone who can find a way to run Ring doorbell cameras locally, cutting off the flow of video data to Amazon’s servers. Read more in my article on the Hot for Security blog. – Read More – GRAHAM CLULEY
A 39-year-old Australian national who was previously employed at U.S. defense contractor L3Harris has been sentenced to a little over seven years in prison for selling eight zero-day exploits to Russian exploit broker Operation Zero in exchange for millions of dollars. Peter Williams pleaded guilty to two counts of theft of trade secrets in October … Read More “Defense Contractor Employee Jailed for Selling 8 Zero-Days to Russian Broker – The Hacker News” »
SolarWinds has released updates to address four critical security flaws in its Serv-U file transfer software that, if successfully exploited, could result in remote code execution. The vulnerabilities, all rated 9.1 on the CVSS scoring system, are listed below – CVE-2025-40538 – A broken access control vulnerability that allows an attacker to create a system … Read More “SolarWinds Patches 4 Critical Serv-U 15.5 Flaws Allowing Root Code Execution – The Hacker News” »
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a recently disclosed vulnerability in FileZen to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-25108 (CVSS v4 score: 8.7), is a case of operating system (OS) command injection that could allow an authenticated user to execute … Read More “CISA Confirms Active Exploitation of FileZen CVE-2026-25108 Vulnerability – The Hacker News” »
North Korean Lazarus Group Adopts Medusa Ransomware in Global Attacks – Hackread – Cybersecurity News, Data Breaches, AI and More
Lazarus Group is now using Medusa ransomware in attacks on healthcare and social services, signaling a move toward profit-focused cybercrime. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
Ex-L3Harris executive sentenced to 87 months in prison for selling zero-day exploits to Russian broker – CyberScoop
An ex-L3 Harris executive was sentenced to over seven years in prison Tuesday after pleading guilty to selling eight zero-day exploits to a Russian broker in exchange for millions of dollars. Williams, 39, admitted to two counts of theft of trade secrets in U.S. District Court in Washington, D.C., last year, acknowledging he took at … Read More “Ex-L3Harris executive sentenced to 87 months in prison for selling zero-day exploits to Russian broker – CyberScoop” »
A vulnerability in GitHub Codespaces could have been exploited by bad actors to seize control of repositories by injecting malicious Copilot instructions in a GitHub issue. The artificial intelligence (AI)-driven vulnerability has been codenamed RoguePilot by Orca Security. It has since been patched by Microsoft following responsible disclosure. “Attackers can craft hidden instructions inside a … Read More “RoguePilot Flaw in GitHub Codespaces Enabled Copilot to Leak GITHUB_TOKEN – The Hacker News” »
Anthropic Claims Chinese AI Firms ‘Distilled’ Claude to Train Their Models – Hackread – Cybersecurity News, Data Breaches, AI and More
Anthropic claims Chinese AI firms distilled Claude to train rival AI models, raising concerns about model extraction, security risks, and AI distillation abuse. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
UAC-0050 Targets European Financial Institution With Spoofed Domain and RMS Malware – The Hacker News
A Russia-aligned threat actor has been observed targeting a European financial institution as part of a social engineering attack to likely facilitate intelligence gathering or financial theft, signaling a possible expansion of the threat actor’s targeting beyond Ukraine and into entities supporting the war-torn nation. The activity, which targeted an unnamed entity involved in regional … Read More “UAC-0050 Targets European Financial Institution With Spoofed Domain and RMS Malware – The Hacker News” »
Amazon: Low-Skill Hacker Used AI Tools to Breach FortiGate Devices Globally – Hackread – Cybersecurity News, Data Breaches, AI and More
Amazon says a Russian speaking low-skill hacker used AI tools to breach hundreds of FortiGate devices worldwide, showing how AI can scale cyberattacks with basic methods. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
How to Strengthen App Performance Without Slowing Innovation – Hackread – Cybersecurity News, Data Breaches, AI and More
Learn how to strengthen app performance without slowing innovation using metrics, observability, scalability planning, and disciplined release strategies. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
How to Maximize DDoS Readiness with Proactive Protection Strategies – Hackread – Cybersecurity News, Data Breaches, AI and More
Strengthen DDoS Readiness with proactive protection strategies, risk assessments, traffic monitoring, scalable defenses, and rapid response planning. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
Sendmarc Releases DMARCbis Fireside Chat Featuring Co-Editor Todd Herr – Hackread – Cybersecurity News, Data Breaches, AI and More
Wilmington, North America, 24th February 2026, CyberNewswire – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
Romanian Hacker Extradited to US Admits Hacking Oregon State Network – Hackread – Cybersecurity News, Data Breaches, AI and More
Catalin Dragomir admits to hacking an Oregon government office and selling network access. Read more on the $250k fraud case and his 2026 sentencing. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
New ZeroDayRAT Malware Claims Full Monitoring of Android and iOS Devices – Hackread – Cybersecurity News, Data Breaches, AI and More
Meet ZeroDayRAT, a newly advertised malware targeting Android and iOS devices with surveillance, location tracking, and crypto theft tools sold via Telegram as a MaaS service. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
The North Korea-linked Lazarus Group (aka Diamond Sleet and Pompilus) has been observed using Medusa ransomware in an attack targeting an unnamed entity in the Middle East, according to a new report by the Symantec and Carbon Black Threat Hunter Team. Broadcom’s threat intelligence division said it also identified the same threat actors mounting an … Read More “Lazarus Group Uses Medusa Ransomware in Middle East and U.S. Healthcare Attacks – The Hacker News” »
Most identity programs still prioritize work the way they prioritize IT tickets: by volume, loudness, or “what failed a control check.” That approach breaks the moment your environment stops being mostly-human and mostly-onboarded. In modern enterprises, identity risk is created by a compound of factors: control posture, hygiene, business context, and intent. Any one of … Read More “Identity Prioritization isn’t a Backlog Problem – It’s a Risk Math Problem – The Hacker News” »
UnsolicitedBooker Targets Central Asian Telecoms With LuciDoor and MarsSnake Backdoors – The Hacker News
The threat activity cluster known as UnsolicitedBooker has been observed targeting telecommunications companies in Kyrgyzstan and Tajikistan, marking a shift from prior attacks aimed at Saudi Arabian entities. The attacks involve the deployment of two distinct backdoors codenamed LuciDoor and MarsSnake, according to a report published by Positive Technologies last week. “The group used several … Read More “UnsolicitedBooker Targets Central Asian Telecoms With LuciDoor and MarsSnake Backdoors – The Hacker News” »
Cyberattacks reached victims faster and came from a wider range of threat groups than ever last year, CrowdStrike said in its annual global threat report released Tuesday, adding that cybercriminals and nation-states increasingly relied on predictable tactics to evade detection by exploiting trusted systems. The average breakout time — how long it took financially-motivated attackers … Read More “CrowdStrike says attackers are moving through networks in under 30 minutes – CyberScoop” »
Anthropic on Monday said it identified “industrial-scale campaigns” mounted by three artificial intelligence (AI) companies, DeepSeek, Moonshot AI, and MiniMax, to illegally extract Claude’s capabilities to improve their own models. The distillation attacks generated over 16 million exchanges with its large language model (LLM) through about 24,000 fraudulent accounts in violation of its terms – … Read More “Anthropic Says Chinese AI Firms Used 16 Million Claude Queries to Copy Model – The Hacker News” »
Data Breaches in 2026: What’s old, what’s new? – Hackread – Cybersecurity News, Data Breaches, AI and More
Data breaches in 2026 explained, new cyber threats, AI driven attacks, common breach causes, and practical security strategies for individuals and businesses – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
The Russia-linked state-sponsored threat actor tracked as APT28 has been attributed to a new campaign targeting specific entities in Western and Central Europe. The activity, per S2 Grupo’s LAB52 threat intelligence team, was active between September 2025 and January 2026. It has been codenamed Operation MacroMaze. “The campaign relies on basic tooling and the exploitation … Read More “APT28 Targeted European Entities Using Webhook-Based Macro Malware – The Hacker News” »
Anthropic on Monday accused three Chinese artificial intelligence laboratories of stealthily trying to siphon Claude’s capabilities for their own models, potentially in a way that could fuel offensive cyber operations. The U.S. AI startup said the three labs, DeepSeek, Moonshot and MiniMax, ran “industrial-scale campaigns” with a tactic known as “distillation.” It involves sending bulk … Read More “Anthropic accuses Chinese labs of trying to illicitly take Claude’s capabilities – CyberScoop” »
Multiple Zero-Day Flaws in PDF Platforms Enable XSS and One-Click Attacks – Hackread – Cybersecurity News, Data Breaches, AI and More
16 zero-day security flaws found in Foxit and Apryse PDF platforms could lead to account takeover and RCE. Learn how AI identified these risks. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
Cybersecurity researchers have disclosed details of a new cryptojacking campaign that uses pirated software bundles as lures to deploy a bespoke XMRig miner program on compromised hosts. “Analysis of the recovered dropper, persistence triggers, and mining payload reveals a sophisticated, multi-stage infection prioritizing maximum cryptocurrency mining hashrate, often destabilizing the victim – Read More – … Read More “Wormable XMRig Campaign Uses BYOVD Exploit and Time-Based Logic Bomb – The Hacker News” »
PayPal Confirms Six-Month Data Exposure Linked to Loan System Error – Hackread – Cybersecurity News, Data Breaches, AI and More
PayPal has confirmed a data leak in its Working Capital loan system that exposed names, dates of birth, and Social Security numbers for six months. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
Top Technology Stacks for MVP Development in 2026 – Hackread – Cybersecurity News, Data Breaches, AI and More
Top technology stacks for MVP development in 2026, best tools for fast launch, scalability, cost efficiency, and proven frameworks for startups building products. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
Hackers Use Excel Exploit to Hide XWorm 7.2 in JPEG Files, Hijack PCs – Hackread – Cybersecurity News, Data Breaches, AI and More
A new phishing campaign is spreading XWorm 7.2 via malicious Excel files, hiding the malware in Windows processes, and using AES encryption to steal passwords and Wi-Fi keys. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
⚡ Weekly Recap: Double-Tap Skimmers, PromptSpy AI, 30Tbps DDoS, Docker Malware & More – The Hacker News
Security news rarely moves in a straight line. This week, it feels more like a series of sharp turns, some happening quietly in the background, others playing out in public view. The details are different, but the pressure points are familiar. Across devices, cloud services, research labs, and even everyday apps, the line between normal … Read More “⚡ Weekly Recap: Double-Tap Skimmers, PromptSpy AI, 30Tbps DDoS, Docker Malware & More – The Hacker News” »
As more organizations run their own Large Language Models (LLMs), they are also deploying more internal services and Application Programming Interfaces (APIs) to support those models. Modern security risks are being introduced less from the models themselves and more from the infrastructure that serves, connects and automates the model. Each new LLM endpoint expands the … Read More “How Exposed Endpoints Increase Risk Across LLM Infrastructure – The Hacker News” »
Cybersecurity researchers have disclosed what they say is an active “Shai-Hulud-like” supply chain worm campaign that has leveraged a cluster of at least 19 malicious npm packages to enable credential harvesting and cryptocurrency key theft. The campaign has been codenamed SANDWORM_MODE by supply chain security company Socket. As with prior Shai-Hulud attack waves, the malicious … Read More “Malicious npm Packages Harvest Crypto Keys, CI Secrets, and API Tokens – The Hacker News” »
The Iranian hacking group known as MuddyWater (aka Earth Vetala, Mango Sandstorm, and MUDDYCOAST) has targeted several organizations and individuals mainly located across the Middle East and North Africa (MENA) region as part of a new campaign codenamed Operation Olalampo. The activity, first observed on January 26, 2026, has resulted in the deployment of new … Read More “MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP – The Hacker News” »
Researchers Demonstrate 27 Attacks Against Major Password Managers – Hackread – Cybersecurity News, Data Breaches, AI and More
Researchers demonstrate multiple attacks against major password managers, showing how compromised servers and design flaws can expose encrypted vault data. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
Hackers Hide Pulsar RAT Inside PNG Images in New NPM Supply Chain Attack – Hackread – Cybersecurity News, Data Breaches, AI and More
Cybersecurity researchers at Veracode reveal a typosquatting attack that disguises Pulsar RAT as images to bypass Windows security and antivirus programs. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
New ClickFix Attack Targets Crypto Wallets and 25+ Browsers with Infostealer – Hackread – Cybersecurity News, Data Breaches, AI and More
Researchers at CyberProof have identified a new fake captcha campaign linked to the ClickFix operation. This stealthy infostealer targets over 25 browsers, cryptocurrency wallets like MetaMask, and gaming accounts by tricking users into executing malicious PowerShell commands. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
A Russian-speaking, financially motivated threat actor has been observed taking advantage of commercial generative artificial intelligence (AI) services to compromise over 600 FortiGate devices located in 55 countries. That’s according to new findings from Amazon Threat Intelligence, which said it observed the activity between January 11 and February 18, 2026. “No exploitation of FortiGate – … Read More “AI-Assisted Threat Actor Compromises 600+ FortiGate Devices in 55 Countries – The Hacker News” »
EC-Council Expands AI Certification Portfolio to Strengthen U.S. AI Workforce Readiness and Security – The Hacker News
With $5.5 trillion in global AI risk exposure and 700,000 U.S. workers needing reskilling, four new AI certifications and Certified CISO v4 help close the gap between AI adoption and workforce readiness. EC-Council, creator of the world-renowned Certified Ethical Hacker (CEH) credential and a global leader in applied cybersecurity education, today launched its Enterprise AI … Read More “EC-Council Expands AI Certification Portfolio to Strengthen U.S. AI Workforce Readiness and Security – The Hacker News” »
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Roundcube webmail software to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities in question are listed below – CVE-2025-49113 (CVSS score: 9.9) – A deserialization of untrusted data vulnerability that allows remote code – Read … Read More “CISA Adds Two Actively Exploited Roundcube Flaws to KEV Catalog – The Hacker News” »
Artificial intelligence (AI) company Anthropic has begun to roll out a new security feature for Claude Code that can scan a user’s software codebase for vulnerabilities and suggest patches. The capability, called Claude Code Security, is currently available in a limited research preview to Enterprise and Team customers. “It scans codebases for security vulnerabilities and … Read More “Anthropic Launches Claude Code Security for AI-Powered Vulnerability Scanning – The Hacker News” »
Spanish police say they have arrested hacker who booked luxury hotel rooms for just one cent – GRAHAM CLULEY
Spain’s police force has announced that it has arrested a 20-year-old man who they claim managed to book luxury hotel rooms worth up to €1,000 a night for just one euro cent. Read more in my article on the Hot for Security blog. – Read More – GRAHAM CLULEY
Anthropic is rolling out a new security feature for Claude Code that can scan a user’s software codebases for vulnerabilities and suggest patching solutions. The company announced Friday that Claude Code Security will initially be available to a limited number of enterprise and team customers for testing. That follows more than a year of stress-testing … Read More “Anthropic rolls out embedded security scanning for Claude – CyberScoop” »