Skip to content
AttackFeed by Joe Wagner | Cybersecurity News from Across the Internet

AttackFeed by Joe Wagner

Cybersecurity News from Across the Internet

  • Attack/News Feeds
  • Gov Alerts/ISAC Feeds
  • Vulnerability Alerts
  • Privacy/Governance Feeds
  • Fraud Feeds
  • iOS App
  • Android App
AttackFeed by Joe Wagner | Fake CAPTCHA IRSF Scam and 120 Keitaro Campaigns Drive Global SMS, Crypto Fraud  - The Hacker News
Attack Feeds
Fake CAPTCHA IRSF Scam and 120 Keitaro Campaigns Drive Global SMS, Crypto Fraud  – The Hacker News
April 27, 2026
AttackFeed by Joe Wagner | Pwn2Own Berlin 2026 - Day One Results  - Zero Day Initiative - Blog
Attack Feeds
Pwn2Own Berlin 2026 – Day One Results  – Zero Day Initiative – Blog
May 14, 2026
AttackFeed by Joe Wagner | Citizen Lab Finds Cellebrite Tool Used on Kenyan Activist’s Phone in Police Custody  - The Hacker News
Attack Feeds
Citizen Lab Finds Cellebrite Tool Used on Kenyan Activist’s Phone in Police Custody  – The Hacker News
February 18, 2026
AttackFeed by Joe Wagner | Fake Word Phishing Reveals Enterprise Blind Spot in Trusted Remote Access Tools  - Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds
Fake Word Phishing Reveals Enterprise Blind Spot in Trusted Remote Access Tools  – Hackread – Cybersecurity News, Data Breaches, AI and More
May 20, 2026
AttackFeed by Joe Wagner | New ClickFix attack Hides in Native Windows Tools to Reduce Detection Risk  - Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds
New ClickFix attack Hides in Native Windows Tools to Reduce Detection Risk  – Hackread – Cybersecurity News, Data Breaches, AI and More
April 24, 2026
AttackFeed by Joe Wagner | Masjesu Botnet Emerges as DDoS-for-Hire Service Targeting Global IoT Devices  - The Hacker News
Attack Feeds
Masjesu Botnet Emerges as DDoS-for-Hire Service Targeting Global IoT Devices  – The Hacker News
April 8, 2026

New DHL Phishing Scam Uses 11-Step Attack Chain to Steal Passwords  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 28, 2026 By Deeba Ahmed No Comments on New DHL Phishing Scam Uses 11-Step Attack Chain to Steal Passwords  – Hackread – Cybersecurity News, Data Breaches, AI and More
New DHL Phishing Scam Uses 11-Step Attack Chain to Steal Passwords  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Forcepoint’s X-Labs reports an 11-step DHL phishing scam that uses fake OTP codes and EmailJS to harvest user credentials and device telemetry.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Federal CIO cautious on Anthropic’s Mythos despite planned rollout  – CyberScoop

Posted on April 28, 2026 By Greg Otto No Comments on Federal CIO cautious on Anthropic’s Mythos despite planned rollout  – CyberScoop
Federal CIO cautious on Anthropic’s Mythos despite planned rollout  – CyberScoop
Attack Feeds

Federal Chief Information Officer Greg Barbaccia said Tuesday the government is approaching Anthropic’s Mythos model with measured expectations, acknowledging both its potential to strengthen federal cyber defenses and the significant uncertainties that remain about how it would perform in real-world conditions. Barbaccia said his direct exposure to Mythos has been limited to evaluations and benchmarking … Read More “Federal CIO cautious on Anthropic’s Mythos despite planned rollout  – CyberScoop” »

Oracle Quarterly Critical Patches Issued April 21, 2026  – Cyber Security Advisories – MS-ISAC

Posted on April 28, 2026 By Joe-W No Comments on Oracle Quarterly Critical Patches Issued April 21, 2026  – Cyber Security Advisories – MS-ISAC
Gov/ISAC Feeds

Multiple vulnerabilities have been discovered in Oracle products, the most severe of which could allow for remote code execution. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the logged-on user. Depending on the privileges associated with the user, an attacker could then install programs; … Read More “Oracle Quarterly Critical Patches Issued April 21, 2026  – Cyber Security Advisories – MS-ISAC” »

Multiple Vulnerabilities in Mozilla Products Could Allow for Arbitrary Code Execution  – Cyber Security Advisories – MS-ISAC

Posted on April 28, 2026 By Joe-W No Comments on Multiple Vulnerabilities in Mozilla Products Could Allow for Arbitrary Code Execution  – Cyber Security Advisories – MS-ISAC
Gov/ISAC Feeds

Multiple vulnerabilities have been discovered in Mozilla products, the most severe of which could allow for arbitrary code execution.  Mozilla Firefox is a web browser used to access the Internet. Mozilla Firefox ESR is a version of the web browser intended to be deployed in large organizations. Mozilla Thunderbird is an email client. Mozilla Thunderbird … Read More “Multiple Vulnerabilities in Mozilla Products Could Allow for Arbitrary Code Execution  – Cyber Security Advisories – MS-ISAC” »

Researchers Discover Critical GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git Push  – The Hacker News

Posted on April 28, 2026 By [email protected] (The Hacker News) No Comments on Researchers Discover Critical GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git Push  – The Hacker News
Researchers Discover Critical GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git Push  – The Hacker News
Attack Feeds

Cybersecurity researchers have disclosed details of a critical security vulnerability impacting GitHub.com and GitHub Enterprise Server that could allow an authenticated user to obtain remote code execution with a single “git push” command. The flaw, tracked as CVE-2026-3854 (CVSS score: 8.7), is a case of command injection that could allow an attacker with push access … Read More “Researchers Discover Critical GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git Push  – The Hacker News” »

Pack2TheRoot: 12-Year-Old Linux PackageKit Flaw Enables Full Compromise  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 28, 2026 By Deeba Ahmed No Comments on Pack2TheRoot: 12-Year-Old Linux PackageKit Flaw Enables Full Compromise  – Hackread – Cybersecurity News, Data Breaches, AI and More
Pack2TheRoot: 12-Year-Old Linux PackageKit Flaw Enables Full Compromise  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Security experts have found a high-severity flaw named Pack2TheRoot in PackageKit that allows hackers to gain full root access on multiple Linux distributions.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Brazilian LofyGang Resurfaces After Three Years With Minecraft LofyStealer Campaign  – The Hacker News

Posted on April 28, 2026 By [email protected] (The Hacker News) No Comments on Brazilian LofyGang Resurfaces After Three Years With Minecraft LofyStealer Campaign  – The Hacker News
Brazilian LofyGang Resurfaces After Three Years With Minecraft LofyStealer Campaign  – The Hacker News
Attack Feeds

A cybercrime group of Brazilian origin has resurfaced after more than three years to orchestrate a campaign that targets Minecraft players with a new stealer called LofyStealer (aka GrabBot). “The malware disguises itself as a Minecraft hack called ‘Slinky,’” Brazil-based cybersecurity company ZenoX said in a technical report. “It uses the official game icon to … Read More “Brazilian LofyGang Resurfaces After Three Years With Minecraft LofyStealer Campaign  – The Hacker News” »

A Vulnerability in OpenSSH Could Allow for Authentication Bypass  – Cyber Security Advisories – MS-ISAC

Posted on April 28, 2026 By Joe-W No Comments on A Vulnerability in OpenSSH Could Allow for Authentication Bypass  – Cyber Security Advisories – MS-ISAC
Gov/ISAC Feeds

A vulnerability has been discovered in OpenSSH which could allow for authentication bypass. OpenSSH (Open Secdure Shell) is an open-source suite of secure networking utilities based on the SSH protocol. It provides encrypted communication sessions over unsecured networks in a client-server architecture, primarily used for remote login and secure file transfers. Successful exploitation of the vulnerability could … Read More “A Vulnerability in OpenSSH Could Allow for Authentication Bypass  – Cyber Security Advisories – MS-ISAC” »

Rep. Delia Ramirez takes over as top House cybersecurity Dem  – CyberScoop

Posted on April 28, 2026 By Tim Starks No Comments on Rep. Delia Ramirez takes over as top House cybersecurity Dem  – CyberScoop
Rep. Delia Ramirez takes over as top House cybersecurity Dem  – CyberScoop
Attack Feeds

Illinois Rep. Delia Ramirez is taking over as the top Democrat on the House Homeland Security panel’s cybersecurity subcommittee, replacing former Rep. Eric Swalwell after his resignation. Committee Democrats approved the change Tuesday at a meeting prior to a “shadow hearing” without the GOP majority, focused on protecting elections from Trump administration interference. Ramirez first … Read More “Rep. Delia Ramirez takes over as top House cybersecurity Dem  – CyberScoop” »

Medtronic Confirms Data Breach After ShinyHunters Claims –

Posted on April 28, 2026 By Joe-W No Comments on Medtronic Confirms Data Breach After ShinyHunters Claims –
Medtronic Confirms Data Breach After ShinyHunters Claims –
Privacy/Governance Feed

Medtronic confirms IT breach as ShinyHunters claims millions of records accesseda – Read More  –  

Stablecoins: Always-On Money Needs Always-On Controls  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 28, 2026 By Ido Sofer No Comments on Stablecoins: Always-On Money Needs Always-On Controls  – Hackread – Cybersecurity News, Data Breaches, AI and More
Stablecoins: Always-On Money Needs Always-On Controls  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Stablecoins are becoming the money layer for the always-on economy.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

VECT 2.0 Ransomware Irreversibly Destroys Files Over 131KB on Windows, Linux, ESXi  – The Hacker News

Posted on April 28, 2026 By [email protected] (The Hacker News) No Comments on VECT 2.0 Ransomware Irreversibly Destroys Files Over 131KB on Windows, Linux, ESXi  – The Hacker News
VECT 2.0 Ransomware Irreversibly Destroys Files Over 131KB on Windows, Linux, ESXi  – The Hacker News
Attack Feeds

Threat hunters are warning that the cybercriminal operation known as VECT 2.0 acts more like a wiper than a ransomware due to a critical flaw in its encryption implementation across Windows, Linux, and ESXi variants that renders recovery impossible even for the threat actors. The fact that VECT’s locker permanently destroys large files rather than … Read More “VECT 2.0 Ransomware Irreversibly Destroys Files Over 131KB on Windows, Linux, ESXi  – The Hacker News” »

Why Secure Data Movement Is the Zero Trust Bottleneck Nobody Talks About  – The Hacker News

Posted on April 28, 2026 By [email protected] (The Hacker News) No Comments on Why Secure Data Movement Is the Zero Trust Bottleneck Nobody Talks About  – The Hacker News
Why Secure Data Movement Is the Zero Trust Bottleneck Nobody Talks About  – The Hacker News
Attack Feeds

Every security program is betting on the same assumption: once a system is connected, the problem is solved. Open a ticket, stand up a gateway, push the data through. Done. That assumption is wrong. It is also a major reason Zero Trust programs stall. New research my team just published puts numbers on it. The … Read More “Why Secure Data Movement Is the Zero Trust Bottleneck Nobody Talks About  – The Hacker News” »

Ransomware Turf War as 0APT and KryBit Groups Trade Blows –

Posted on April 28, 2026 By Joe-W No Comments on Ransomware Turf War as 0APT and KryBit Groups Trade Blows –
Ransomware Turf War as 0APT and KryBit Groups Trade Blows –
Privacy/Governance Feed

Ransomware groups 0APT and KryBit have doxxed each other online – Read More  –  

Chinese National Extradited Over Silk Typhoon Cyber Campaign –

Posted on April 28, 2026 By Joe-W No Comments on Chinese National Extradited Over Silk Typhoon Cyber Campaign –
Chinese National Extradited Over Silk Typhoon Cyber Campaign –
Privacy/Governance Feed

Extradition links alleged MSS-directed hacker to Silk Typhoon and COVID-19 espionage – Read More  –  

The Role of Aggregated Liquidity in Modern Crypto Markets  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 28, 2026 By Owais Sultan No Comments on The Role of Aggregated Liquidity in Modern Crypto Markets  – Hackread – Cybersecurity News, Data Breaches, AI and More
The Role of Aggregated Liquidity in Modern Crypto Markets  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Aggregated liquidity improves crypto trading by combining multiple sources, offering better rates, deeper markets, and more reliable execution across assets.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Why Unofficial Download Sources Are Still a Security Risk in 2026  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 28, 2026 By Owais Sultan No Comments on Why Unofficial Download Sources Are Still a Security Risk in 2026  – Hackread – Cybersecurity News, Data Breaches, AI and More
Why Unofficial Download Sources Are Still a Security Risk in 2026  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Security Risk in 2026: why unofficial download sources still put users at risk, and how to verify safe, official install paths before installing software.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Critical Unpatched Flaw Leaves Hugging Face LeRobot Open to Unauthenticated RCE  – The Hacker News

Posted on April 28, 2026 By [email protected] (The Hacker News) No Comments on Critical Unpatched Flaw Leaves Hugging Face LeRobot Open to Unauthenticated RCE  – The Hacker News
Critical Unpatched Flaw Leaves Hugging Face LeRobot Open to Unauthenticated RCE  – The Hacker News
Attack Feeds

Cybersecurity researchers have disclosed details of a critical security flaw impacting LeRobot, Hugging Face’s open-source robotics platform with nearly 24,000 GitHub stars, that could be exploited to achieve remote code execution. The vulnerability in question is CVE-2026-25874 (CVSS score: 9.3), which has been described as a case of untrusted data deserialization stemming from the use … Read More “Critical Unpatched Flaw Leaves Hugging Face LeRobot Open to Unauthenticated RCE  – The Hacker News” »

New Linux FIRESTARTER Backdoor Targets Cisco Firepower Devices  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 28, 2026 By Deeba Ahmed No Comments on New Linux FIRESTARTER Backdoor Targets Cisco Firepower Devices  – Hackread – Cybersecurity News, Data Breaches, AI and More
New Linux FIRESTARTER Backdoor Targets Cisco Firepower Devices  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

CISA and NCSC warn that FIRESTARTER, a Linux-based backdoor, targets Cisco Firepower devices, evades patches, and enables persistent access even after firmware updates.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

After Mythos: New Playbooks For a Zero-Window Era  – The Hacker News

Posted on April 28, 2026 By [email protected] (The Hacker News) No Comments on After Mythos: New Playbooks For a Zero-Window Era  – The Hacker News
After Mythos: New Playbooks For a Zero-Window Era  – The Hacker News
Attack Feeds

When patching isn’t fast enough, NDR helps contain the next era of threats. If you’ve been tracking advancements in AI, you know the exploit window, the short buffer that organizations relied on to patch and protect after a vulnerability disclosure, is closing fast. Anthropic’s new model, Claude Mythos, and its Project Glasswing, showed that finding … Read More “After Mythos: New Playbooks For a Zero-Window Era  – The Hacker News” »

Chinese Silk Typhoon Hacker Extradited to U.S. Over COVID Research Cyberattacks  – The Hacker News

Posted on April 28, 2026 By [email protected] (The Hacker News) No Comments on Chinese Silk Typhoon Hacker Extradited to U.S. Over COVID Research Cyberattacks  – The Hacker News
Chinese Silk Typhoon Hacker Extradited to U.S. Over COVID Research Cyberattacks  – The Hacker News
Attack Feeds

A Chinese national accused of being a member of the Silk Typhoon hacking group has been extradited to the U.S. from Italy.  Xu Zewei, 34, was arrested in July 2025 by Italian authorities for his alleged links to the Chinese state-sponsored threat group and for orchestrating cyber attacks against American organizations and government agencies between … Read More “Chinese Silk Typhoon Hacker Extradited to U.S. Over COVID Research Cyberattacks  – The Hacker News” »

French police arrest 21-year-old “HexDex” hacker over 100 alleged data breaches  – GRAHAM CLULEY

Posted on April 28, 2026 By Graham Cluley No Comments on French police arrest 21-year-old “HexDex” hacker over 100 alleged data breaches  – GRAHAM CLULEY
French police arrest 21-year-old “HexDex” hacker over 100 alleged data breaches  – GRAHAM CLULEY
Attack Feeds

A 21-year-old man suspected of conducting approximately 100 data breaches since late 2025 – including a hack of the French Ministry of National Education that exposed records on almost a quarter of a million employees – has been arrested at his home in western France. Read more in my article on the Hot for Security … Read More “French police arrest 21-year-old “HexDex” hacker over 100 alleged data breaches  – GRAHAM CLULEY” »

North Korean Hackers Target Crypto Firms with ClickFix and AI-Made Zoom Lures –

Posted on April 28, 2026 By Joe-W No Comments on North Korean Hackers Target Crypto Firms with ClickFix and AI-Made Zoom Lures –
North Korean Hackers Target Crypto Firms with ClickFix and AI-Made Zoom Lures –
Privacy/Governance Feed

Arctic Wolf attributed this large-scale spear-phishing campaign to BlueNoroff, a financially motivated subgroup of the Lazarus Group – Read More  –  

No Metrics Are Better Than Bad Metrics in the SOC, Says NCSC –

Posted on April 28, 2026 By Joe-W No Comments on No Metrics Are Better Than Bad Metrics in the SOC, Says NCSC –
No Metrics Are Better Than Bad Metrics in the SOC, Says NCSC –
Privacy/Governance Feed

The National Cyber Security Centre has warned against measuring SOCs with ticket-based metrics – Read More  –  

Microsoft Confirms Active Exploitation of Windows Shell CVE-2026-32202  – The Hacker News

Posted on April 28, 2026 By [email protected] (The Hacker News) No Comments on Microsoft Confirms Active Exploitation of Windows Shell CVE-2026-32202  – The Hacker News
Microsoft Confirms Active Exploitation of Windows Shell CVE-2026-32202  – The Hacker News
Attack Feeds

Microsoft on Monday revised its advisory for a now-patched, high-severity security flaw impacting Windows Shell to acknowledge that it has been actively exploited in the wild. The vulnerability in question is CVE-2026-32202 (CVSS score: 4.3), a spoofing vulnerability that could allow an attacker to access sensitive information. It was addressed as part of its Patch … Read More “Microsoft Confirms Active Exploitation of Windows Shell CVE-2026-32202  – The Hacker News” »

Microsoft Patches Entra ID Role Flaw That Enabled Service Principal Takeover  – The Hacker News

Posted on April 28, 2026 By [email protected] (The Hacker News) No Comments on Microsoft Patches Entra ID Role Flaw That Enabled Service Principal Takeover  – The Hacker News
Microsoft Patches Entra ID Role Flaw That Enabled Service Principal Takeover  – The Hacker News
Attack Feeds

An administrative role meant for artificial intelligence (AI) agents within Microsoft Entra ID could enable privilege escalation and identity takeover attacks, according to new findings from Silverfort. Agent ID Administrator is a privileged built-in role introduced by Microsoft as part of its agent identity platform to handle all aspects of an AI agent’s identity lifecycle … Read More “Microsoft Patches Entra ID Role Flaw That Enabled Service Principal Takeover  – The Hacker News” »

U.S. companies hit with record fines for privacy in 2025  – CyberScoop

Posted on April 28, 2026 By djohnson No Comments on U.S. companies hit with record fines for privacy in 2025  – CyberScoop
U.S. companies hit with record fines for privacy in 2025  – CyberScoop
Attack Feeds

U.S. states issued $3.45 billion in privacy-related fines to companies in 2025, a total larger  than the last five years combined, according to research and advisory firm Gartner. The increase is partly driven in part by stronger, more established privacy laws in states like California, new interstate partnerships built around enforcing laws across state lines, … Read More “U.S. companies hit with record fines for privacy in 2025  – CyberScoop” »

Post-Quantum HSM: protect keys now – JISA Softech Pvt Ltd

Posted on April 28, 2026 By Aakash Chaudhary No Comments on Post-Quantum HSM: protect keys now – JISA Softech Pvt Ltd
Post-Quantum HSM: protect keys now – JISA Softech Pvt Ltd
Privacy/Governance Feed

The cybersecurity landscape is approaching a structural shift. Encryption has traditionally been based on computational infeasible mathematical problems that… The post Post-Quantum HSM: protect keys now appeared first on JISA Softech Pvt Ltd.  – Read More  – JISA Softech Pvt Ltd 

Chinese national extradited to US for pandemic-era Silk Typhoon attacks  – CyberScoop

Posted on April 27, 2026 By Matt Kapko No Comments on Chinese national extradited to US for pandemic-era Silk Typhoon attacks  – CyberScoop
Chinese national extradited to US for pandemic-era Silk Typhoon attacks  – CyberScoop
Attack Feeds

A Chinese national allegedly involved in a massive, pandemic-era attack spree that compromised nearly 13,000 U.S. organizations was extradited from Italy to the United States and formally charged in federal court, the Justice Department said Monday. Xu Zewei and his co-conspirators are accused of exploiting a string of zero-day vulnerabilities in Microsoft Exchange Server to … Read More “Chinese national extradited to US for pandemic-era Silk Typhoon attacks  – CyberScoop” »

Supreme Court justices skeptically question both sides in geofence surveillance case  – CyberScoop

Posted on April 27, 2026 By Tim Starks No Comments on Supreme Court justices skeptically question both sides in geofence surveillance case  – CyberScoop
Supreme Court justices skeptically question both sides in geofence surveillance case  – CyberScoop
Attack Feeds

Supreme Court justices lobbed sharp questions at both sides about the constitutionality of geofence warrants during oral arguments Monday in a case that could have broader implications for law enforcement collection of Americans’ data. Chatrie v. The United States stems from the 2019 conviction of Okello Chatrie in a bank robbery, where authorities obtained location … Read More “Supreme Court justices skeptically question both sides in geofence surveillance case  – CyberScoop” »

82 Chrome Extensions Found Selling User Data, 6.5 Million Users Affected  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 27, 2026 By Waqas No Comments on 82 Chrome Extensions Found Selling User Data, 6.5 Million Users Affected  – Hackread – Cybersecurity News, Data Breaches, AI and More
82 Chrome Extensions Found Selling User Data, 6.5 Million Users Affected  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

LayerX research finds 82 Chrome extensions collecting and selling user data, affecting at least 6.5 million users through disclosed but concerning practices.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

ShinyHunters Leaks Data of Udemy, Zara, 7-Eleven in Salesforce Linked Breach  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 27, 2026 By Waqas No Comments on ShinyHunters Leaks Data of Udemy, Zara, 7-Eleven in Salesforce Linked Breach  – Hackread – Cybersecurity News, Data Breaches, AI and More
ShinyHunters Leaks Data of Udemy, Zara, 7-Eleven in Salesforce Linked Breach  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

ShinyHunters has leaked data linked to Udemy, Zara, and 7-Eleven, with claims of exposed Salesforce records and cloud-based systems.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Senators seek answers about hackers obtaining sensitive student data from ostensibly anonymous tip line  – CyberScoop

Posted on April 27, 2026 By Tim Starks No Comments on Senators seek answers about hackers obtaining sensitive student data from ostensibly anonymous tip line  – CyberScoop
Senators seek answers about hackers obtaining sensitive student data from ostensibly anonymous tip line  – CyberScoop
Attack Feeds

A bipartisan pair of senators want a company that operates a tip line for anonymously reporting school safety concerns to answer questions about hackers compromising sensitive student information. Sens. Maggie Hassan, D-N.H., and Jim Banks, R-Ind., announced on Monday they’d sent a letter to the firm, Navigate360, about last month’s incident. “We write to express … Read More “Senators seek answers about hackers obtaining sensitive student data from ostensibly anonymous tip line  – CyberScoop” »

⚡ Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More  – The Hacker News

Posted on April 27, 2026 By [email protected] (The Hacker News) No Comments on ⚡ Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More  – The Hacker News
⚡ Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More  – The Hacker News
Attack Feeds

Everything is dumb again. This week feels broken in a very familiar way. Old tricks are back. New tools are doing shady crap. Supply chains got hit. Fake help desks worked. Weird research showed how easy some attacks still are. Most of it feels like stuff we should have fixed years ago. Bad extensions. Stolen … Read More “⚡ Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More  – The Hacker News” »

Checkmarx Confirms GitHub Repository Data Posted on Dark Web After March 23 Attack  – The Hacker News

Posted on April 27, 2026 By [email protected] (The Hacker News) No Comments on Checkmarx Confirms GitHub Repository Data Posted on Dark Web After March 23 Attack  – The Hacker News
Checkmarx Confirms GitHub Repository Data Posted on Dark Web After March 23 Attack  – The Hacker News
Attack Feeds

Checkmarx has disclosed that its ongoing investigation tied to the supply chain security incident has revealed that a cybercriminal group published data related to the company on the dark web. “Based on current evidence, we believe this data originated from Checkmarx’s GitHub repository, and that access to that repository was facilitated through the initial supply … Read More “Checkmarx Confirms GitHub Repository Data Posted on Dark Web After March 23 Attack  – The Hacker News” »

US Sanctions Target Cambodian Scam Network Leaders –

Posted on April 27, 2026 By Joe-W No Comments on US Sanctions Target Cambodian Scam Network Leaders –
US Sanctions Target Cambodian Scam Network Leaders –
Privacy/Governance Feed

US sanctions target Cambodian scam networks tied to crypto fraud and trafficking – Read More  –  

UNC6692 Hackers Exploit Microsoft Teams to Deploy SNOW Malware  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 27, 2026 By Deeba Ahmed No Comments on UNC6692 Hackers Exploit Microsoft Teams to Deploy SNOW Malware  – Hackread – Cybersecurity News, Data Breaches, AI and More
UNC6692 Hackers Exploit Microsoft Teams to Deploy SNOW Malware  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

UNC6692 hackers exploit Microsoft Teams with fake IT alerts to deploy SNOW malware, steal credentials, and breach corporate networks in advanced attacks.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

BlackFile actively extorting data-theft victims in retail and hospitality sector  – CyberScoop

Posted on April 27, 2026 By Matt Kapko No Comments on BlackFile actively extorting data-theft victims in retail and hospitality sector  – CyberScoop
BlackFile actively extorting data-theft victims in retail and hospitality sector  – CyberScoop
Attack Feeds

Researchers warn that BlackFile, an extortion group likely associated with The Com, continues to impersonate IT support in voice-phishing and social engineering attacks that have impacted organizations in multiple industries, including healthcare, technology, transportation, logistics, wholesale and retail. Attackers have been actively targeting organizations in the retail and hospitality industry since February, according to Unit … Read More “BlackFile actively extorting data-theft victims in retail and hospitality sector  – CyberScoop” »

Widely Used Browser Extensions Selling User Data –

Posted on April 27, 2026 By Joe-W No Comments on Widely Used Browser Extensions Selling User Data –
Widely Used Browser Extensions Selling User Data –
Privacy/Governance Feed

Dozens of browser extensions openly sell user data via privacy policy disclosures – Read More  –  

Utilities Tech Supplier Itron Discloses Cyber-Attack, Operations Unaffected –

Posted on April 27, 2026 By Joe-W No Comments on Utilities Tech Supplier Itron Discloses Cyber-Attack, Operations Unaffected –
Utilities Tech Supplier Itron Discloses Cyber-Attack, Operations Unaffected –
Privacy/Governance Feed

Itron confirmed a cyber incident but does not believe it is likely to have a material impact on the company – Read More  –  

Researchers Uncover 73 Fake VS Code Extensions Delivering GlassWorm v2 Malware  – The Hacker News

Posted on April 27, 2026 By [email protected] (The Hacker News) No Comments on Researchers Uncover 73 Fake VS Code Extensions Delivering GlassWorm v2 Malware  – The Hacker News
Researchers Uncover 73 Fake VS Code Extensions Delivering GlassWorm v2 Malware  – The Hacker News
Attack Feeds

Cybersecurity researchers have flagged dozens of Microsoft Visual Studio Code (VS Code) extensions on the Open VSX repository that are linked to a persistent information-stealing campaign dubbed GlassWorm. The cluster of 73 extensions has been identified as cloned versions of their legitimate counterparts. Of these, six have been confirmed to be malicious, with the remaining … Read More “Researchers Uncover 73 Fake VS Code Extensions Delivering GlassWorm v2 Malware  – The Hacker News” »

PhantomCore Exploits TrueConf Vulnerabilities to Breach Russian Networks  – The Hacker News

Posted on April 27, 2026 By [email protected] (The Hacker News) No Comments on PhantomCore Exploits TrueConf Vulnerabilities to Breach Russian Networks  – The Hacker News
PhantomCore Exploits TrueConf Vulnerabilities to Breach Russian Networks  – The Hacker News
Attack Feeds

A pro-Ukrainian hacktivist group called PhantomCore has been attributed to attacks actively targeting servers running TrueConf video conferencing software in Russia since September 2025. That’s according to a report published by Positive Technologies, which found the threat actors to be leveraging an exploit chain comprising three vulnerabilities to execute commands remotely on susceptible  – Read … Read More “PhantomCore Exploits TrueConf Vulnerabilities to Breach Russian Networks  – The Hacker News” »

Mythos Changed the Math on Vulnerability Discovery. Most Teams Aren’t Ready for the Remediation Side  – The Hacker News

Posted on April 27, 2026 By [email protected] (The Hacker News) No Comments on Mythos Changed the Math on Vulnerability Discovery. Most Teams Aren’t Ready for the Remediation Side  – The Hacker News
Mythos Changed the Math on Vulnerability Discovery. Most Teams Aren’t Ready for the Remediation Side  – The Hacker News
Attack Feeds

Anthropic’s Claude Mythos Preview has dominated security discussions since its April 7 announcement. Early reporting describes a powerful cybersecurity-focused AI system capable of identifying vulnerabilities at scale and raising serious questions about how quickly organizations can validate, prioritize, and remediate what it finds. The debate that followed has mostly focused on the right  – Read … Read More “Mythos Changed the Math on Vulnerability Discovery. Most Teams Aren’t Ready for the Remediation Side  – The Hacker News” »

Most Cybersecurity Professionals Feel Undervalued and Underpaid –

Posted on April 27, 2026 By Joe-W No Comments on Most Cybersecurity Professionals Feel Undervalued and Underpaid –
Most Cybersecurity  Professionals Feel Undervalued and Underpaid –
Privacy/Governance Feed

A new report by global technology recruitment firm, Harvey Nash, found that three quarters of cybersecurity staff are pessimistic on pay and half are looking for a new job – Read More  –  

Vidar Infostealer Spreads via Fake CAPTCHAs, Hides in JPEG and TXT Files  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 27, 2026 By Deeba Ahmed No Comments on Vidar Infostealer Spreads via Fake CAPTCHAs, Hides in JPEG and TXT Files  – Hackread – Cybersecurity News, Data Breaches, AI and More
Vidar Infostealer Spreads via Fake CAPTCHAs, Hides in JPEG and TXT Files  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

New version of Vidar infostealer spreads via fake CAPTCHAs, hides in JPEG and TXT files, uses fileless attacks and steals browser, crypto wallet data.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Fake CAPTCHA IRSF Scam and 120 Keitaro Campaigns Drive Global SMS, Crypto Fraud  – The Hacker News

Posted on April 27, 2026 By [email protected] (The Hacker News) No Comments on Fake CAPTCHA IRSF Scam and 120 Keitaro Campaigns Drive Global SMS, Crypto Fraud  – The Hacker News
Fake CAPTCHA IRSF Scam and 120 Keitaro Campaigns Drive Global SMS, Crypto Fraud  – The Hacker News
Attack Feeds

Cybersecurity researchers have disclosed details of a telecommunications fraud campaign that uses fake CAPTCHA verification tricks to dupe unsuspecting users into sending international text messages that incur charges on their mobile bills, generating illicit revenue for the threat actors who lease the phone numbers. According to a new report published by Infoblox, the operation is … Read More “Fake CAPTCHA IRSF Scam and 120 Keitaro Campaigns Drive Global SMS, Crypto Fraud  – The Hacker News” »

BlackFile Group Targets Retail and Hospitality with Vishing Attacks –

Posted on April 27, 2026 By Joe-W No Comments on BlackFile Group Targets Retail and Hospitality with Vishing Attacks –
BlackFile Group Targets Retail and Hospitality with Vishing Attacks –
Privacy/Governance Feed

Researchers uncover a new data theft and extortion group dubbed “BlackFile” – Read More  –  

Researchers Identify Fast16 Sabotage Malware That Pre-Dates Stuxnet –

Posted on April 27, 2026 By Joe-W No Comments on Researchers Identify Fast16 Sabotage Malware That Pre-Dates Stuxnet –
Researchers Identify Fast16 Sabotage Malware That Pre-Dates Stuxnet –
Privacy/Governance Feed

The “fast16” malware may have been used to target Iran’s nuclear program prior to Stuxnet – Read More  –  

Could your choice of metrics be harming your SOC?  – All Feed

Posted on April 27, 2026 By Joe-W No Comments on Could your choice of metrics be harming your SOC?  – All Feed
Gov/ISAC Feeds

Poor metrics can render a well-intentioned security operation centre entirely ineffective. – Read More – All Feed 

Microsoft Entra Agent ID Flaw Enabled Tenant Takeover via Privilege Escalation  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 26, 2026 By Deeba Ahmed No Comments on Microsoft Entra Agent ID Flaw Enabled Tenant Takeover via Privilege Escalation  – Hackread – Cybersecurity News, Data Breaches, AI and More
Microsoft Entra Agent ID Flaw Enabled Tenant Takeover via Privilege Escalation  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Microsoft Entra Agent ID flaw allowed privilege escalation and tenant takeover via Service Principal abuse, now fully patched by Microsoft.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Posts pagination

Previous 1 … 12 13 14 … 41 Next
  • Attack Feeds
  • Privacy/Governance Feed
  • Gov/ISAC Feeds
  • Alert Feeds
  • Privacy Policy
  • Wagner Cybersecurity

Copyright © 2026 AttackFeed by Joe Wagner.

Theme: Oceanly News Dark by ScriptsTown

We are using cookies for analytics purposes only.  We do not store, track or sell user information.

You can find out more about which cookies we are using or switch them off in .

AttackFeed by Joe Wagner
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.