Skip to content
AttackFeed by Joe Wagner | Cybersecurity News from Across the Internet

AttackFeed by Joe Wagner

Cybersecurity News from Across the Internet

  • Attack/News Feeds
  • Gov Alerts/ISAC Feeds
  • Vulnerability Alerts
  • Privacy/Governance Feeds
  • Fraud Feeds
  • iOS App
  • Android App
AttackFeed by Joe Wagner | OpenClaw AI Agent Flaws Could Enable Prompt Injection and Data Exfiltration  - The Hacker News
Attack Feeds
OpenClaw AI Agent Flaws Could Enable Prompt Injection and Data Exfiltration  – The Hacker News
March 14, 2026
AttackFeed by Joe Wagner | Microsoft addresses 137 vulnerabilities in May’s Patch Tuesday, including 13 rated critical  - CyberScoop
Attack Feeds
Microsoft addresses 137 vulnerabilities in May’s Patch Tuesday, including 13 rated critical  – CyberScoop
May 12, 2026
AttackFeed by Joe Wagner | Google Says Hackers Used AI to Develop a Zero-Day Exploit  - Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds
Google Says Hackers Used AI to Develop a Zero-Day Exploit  – Hackread – Cybersecurity News, Data Breaches, AI and More
May 11, 2026
AttackFeed by Joe Wagner | Decoding Q1 2026’s $152.9 Billion Crypto Custody Concentration  - Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds
Decoding Q1 2026’s $152.9 Billion Crypto Custody Concentration  – Hackread – Cybersecurity News, Data Breaches, AI and More
April 28, 2026
AttackFeed by Joe Wagner | Critical defect in Java security engine poses serious downstream security risks  - CyberScoop
Attack Feeds
Critical defect in Java security engine poses serious downstream security risks  – CyberScoop
March 10, 2026
AttackFeed by Joe Wagner | Election threats are focused on campaign systems, not voting machines  - CyberScoop
Attack Feeds
Election threats are focused on campaign systems, not voting machines  – CyberScoop
June 1, 2026

wolfSSL Vulnerability Hits IoT, Routers and Military Systems, Update to 5.9.1 Now  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 14, 2026 By Deeba Ahmed No Comments on wolfSSL Vulnerability Hits IoT, Routers and Military Systems, Update to 5.9.1 Now  – Hackread – Cybersecurity News, Data Breaches, AI and More
wolfSSL Vulnerability Hits IoT, Routers and Military Systems, Update to 5.9.1 Now  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Critical wolfSSL flaw CVE-2026-5194 allows digital ID forgery across billions of devices, update to version 5.9.1 to fix the issue and reduce risk.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

The April 2026 Security Update Review  – Zero Day Initiative – Blog

Posted on April 14, 2026 By Dustin Childs No Comments on The April 2026 Security Update Review  – Zero Day Initiative – Blog
The April 2026 Security Update Review  – Zero Day Initiative – Blog
Attack Feeds

It’s time once again for Patch Tuesday, and this one is huge. We’ve also got multiple exploits in the wild, which adds another layer of urgency to this month’s release. Take a break from your regularly scheduled activities, and let’s take a look at the latest security patches from Adobe and Microsoft. If you’d rather … Read More “The April 2026 Security Update Review  – Zero Day Initiative – Blog” »

SEC Consult SA-20260414-0 :: Improper Enforcement of Locked Accounts in WebUI (SSO) in Kiuwan SAST on-premise (KOP) & cloud/SaaS  – Full Disclosure

Posted on April 14, 2026 By Joe-W No Comments on SEC Consult SA-20260414-0 :: Improper Enforcement of Locked Accounts in WebUI (SSO) in Kiuwan SAST on-premise (KOP) & cloud/SaaS  – Full Disclosure
SEC Consult SA-20260414-0 :: Improper Enforcement of Locked Accounts in WebUI (SSO) in Kiuwan SAST on-premise (KOP) & cloud/SaaS  – Full Disclosure
Alert Feeds

  Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Apr 14 SEC Consult Vulnerability Lab Security Advisory < 20260414-0 > ======================================================================= title: Improper Enforcement of Locked Accounts in WebUI (SSO)             product: Kiuwan SAST on-premise (KOP) & cloud/SaaS  vulnerable version: <2.8.2509.4       fixed version: 2.8.2509.4     … Read More “SEC Consult SA-20260414-0 :: Improper Enforcement of Locked Accounts in WebUI (SSO) in Kiuwan SAST on-premise (KOP) & cloud/SaaS  – Full Disclosure” »

CyberDanube Security Research 20260408-0 | Remote Operation Denial of Service in Siemens SICAM A8000  – Full Disclosure

Posted on April 14, 2026 By Joe-W No Comments on CyberDanube Security Research 20260408-0 | Remote Operation Denial of Service in Siemens SICAM A8000  – Full Disclosure
CyberDanube Security Research 20260408-0 | Remote Operation Denial of Service in Siemens SICAM A8000  – Full Disclosure
Alert Feeds

  Posted by Thomas Weber | CyberDanube via Fulldisclosure on Apr 14 CyberDanube Security Research 20260408-0 ——————————————————————————- title| Remote Operation Denial of Service product| Siemens SICAM A8000 CP-8050/CP-8031/CP-8010/CP-8012 vulnerable version| <=V25.30 fixed version| V26.10 CVE number| CVE-2026-27663 impact| Medium homepage| https://siemens.com/… – Read More  – Full Disclosure 

CyberDanube Security Research 20260408-1 | Multiple Vulnerabilities in Siemens SICAM A8000  – Full Disclosure

Posted on April 14, 2026 By Joe-W No Comments on CyberDanube Security Research 20260408-1 | Multiple Vulnerabilities in Siemens SICAM A8000  – Full Disclosure
CyberDanube Security Research 20260408-1 | Multiple Vulnerabilities in Siemens SICAM A8000  – Full Disclosure
Alert Feeds

  Posted by Thomas Weber | CyberDanube via Fulldisclosure on Apr 14 CyberDanube Security Research 20260408-1 ——————————————————————————- title| Multiple Vulnerabilities product| Siemens SICAM A8000 CP-8050/CP-8031/CP-8010/CP-8012 vulnerable version| <=V25.30 fixed version| V26.10 CVE number| CVE-2026-27664 impact| High homepage| https://siemens.com/ found|… – Read More  – Full Disclosure 

New PHP Composer Flaws Enable Arbitrary Command Execution — Patches Released  – The Hacker News

Posted on April 14, 2026 By [email protected] (The Hacker News) No Comments on New PHP Composer Flaws Enable Arbitrary Command Execution — Patches Released  – The Hacker News
New PHP Composer Flaws Enable Arbitrary Command Execution — Patches Released  – The Hacker News
Attack Feeds

Two high-severity security vulnerabilities have been disclosed in Composer, a package manager for PHP, that, if successfully exploited, could result in arbitrary command execution. The vulnerabilities have been described as command injection flaws affecting the Perforce VCS (version control software) driver. Details of the two flaws are below – CVE-2026-40176 (CVSS  – Read More  – The Hacker News 

Kraken Exchange Faces Extortion After Insider Recorded System Footage  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 14, 2026 By Deeba Ahmed No Comments on Kraken Exchange Faces Extortion After Insider Recorded System Footage  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Kraken exchange faces extortion after a staff member misused access to record internal systems, about 2,000 accounts affected, no funds or systems breached.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Black Basta’s playbook lives on as former affiliates launch fast-scale intrusion campaign  – CyberScoop

Posted on April 14, 2026 By Matt Kapko No Comments on Black Basta’s playbook lives on as former affiliates launch fast-scale intrusion campaign  – CyberScoop
Black Basta’s playbook lives on as former affiliates launch fast-scale intrusion campaign  – CyberScoop
Attack Feeds

A small group of former Black Basta affiliates have targeted more than 100 employees across dozens of organizations to intrude network systems for potential data theft, ransomware deployment and extortion, according to ReliaQuest. The social engineering campaign, which involves mass email bombing and Microsoft Teams help desk impersonation, surged last month and dates back to … Read More “Black Basta’s playbook lives on as former affiliates launch fast-scale intrusion campaign  – CyberScoop” »

AI-Driven Pushpaganda Scam Exploits Google Discover to Spread Scareware and Ad Fraud  – The Hacker News

Posted on April 14, 2026 By [email protected] (The Hacker News) No Comments on AI-Driven Pushpaganda Scam Exploits Google Discover to Spread Scareware and Ad Fraud  – The Hacker News
AI-Driven Pushpaganda Scam Exploits Google Discover to Spread Scareware and Ad Fraud  – The Hacker News
Attack Feeds

Cybersecurity researchers have unmasked a novel ad fraud scheme that has been found to leverage search engine poisoning (SEO) techniques and artificial intelligence (AI)-generated content to push deceptive news stories into Google’s Discover feed and trick users into enabling persistent browser notifications that lead to scareware and financial scams. The campaign, which has been  – Read More  – … Read More “AI-Driven Pushpaganda Scam Exploits Google Discover to Spread Scareware and Ad Fraud  – The Hacker News” »

CISOs Urged to Innovate with Talent Retention as Job Satisfaction Declines –

Posted on April 14, 2026 By Joe-W No Comments on CISOs Urged to Innovate with Talent Retention as Job Satisfaction Declines –
CISOs Urged to Innovate with Talent Retention as Job Satisfaction Declines –
Privacy/Governance Feed

A new IANS report claims just 34% of cybersecurity professionals plan to stay put in the next 12 months – Read More  –  

Google Adds Rust-Based DNS Parser into Pixel 10 Modem to Enhance Security  – The Hacker News

Posted on April 14, 2026 By [email protected] (The Hacker News) No Comments on Google Adds Rust-Based DNS Parser into Pixel 10 Modem to Enhance Security  – The Hacker News
Google Adds Rust-Based DNS Parser into Pixel 10 Modem to Enhance Security  – The Hacker News
Attack Feeds

Google has announced the integration of a Rust-based Domain Name System (DNS) parser into the modem firmware as part of its ongoing efforts to beef up the security of Pixel devices and push memory-safe code at a more foundational level. “The new Rust-based DNS parser significantly reduces our security risk by mitigating an entire class of … Read More “Google Adds Rust-Based DNS Parser into Pixel 10 Modem to Enhance Security  – The Hacker News” »

Ransomware-Linked ViperTunnel Malware Hits UK and US Businesses  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 14, 2026 By Deeba Ahmed No Comments on Ransomware-Linked ViperTunnel Malware Hits UK and US Businesses  – Hackread – Cybersecurity News, Data Breaches, AI and More
Ransomware-Linked ViperTunnel Malware Hits UK and US Businesses  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

ViperTunnel is a Python-based backdoor linked to DragonForce ransomware that targets businesses using Windows servers across the US and the UK.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Booking.com Confirms Data Breach as Hackers Access Customer Details  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 14, 2026 By Waqas No Comments on Booking.com Confirms Data Breach as Hackers Access Customer Details  – Hackread – Cybersecurity News, Data Breaches, AI and More
Booking.com Confirms Data Breach as Hackers Access Customer Details  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Booking.com confirms a data breach exposing customer details to hackers. No payment data accessed, but users face risk of targeted phishing scams now!  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Mirax Android RAT Turns Devices into SOCKS5 Proxies, Reaching 220,000 via Meta Ads  – The Hacker News

Posted on April 14, 2026 By [email protected] (The Hacker News) No Comments on Mirax Android RAT Turns Devices into SOCKS5 Proxies, Reaching 220,000 via Meta Ads  – The Hacker News
Attack Feeds

A nascent Android remote access trojan called Mirax has been observed actively targeting Spanish-speaking countries, with campaigns reaching more than 220,000 accounts on Facebook, Instagram, Messenger, and Threads through advertisements on Meta. “Mirax integrates advanced Remote Access Trojan (RAT) capabilities, allowing threat actors to fully interact with compromised devices in real  – Read More  – The Hacker … Read More “Mirax Android RAT Turns Devices into SOCKS5 Proxies, Reaching 220,000 via Meta Ads  – The Hacker News” »

Mirax Android RAT Turns Devices into SOCKS5 Proxies, Reaching 220,000 via Meta Ads  – The Hacker News

Posted on April 14, 2026 By [email protected] (The Hacker News) No Comments on Mirax Android RAT Turns Devices into SOCKS5 Proxies, Reaching 220,000 via Meta Ads  – The Hacker News
Attack Feeds

A nascent Android remote access trojan called Mirax has been observed actively targeting Spanish-speaking countries, with campaigns reaching more than 220,000 accounts on Facebook, Instagram, Messenger, and Threads through advertisements on Meta. “Mirax integrates advanced Remote Access Trojan (RAT) capabilities, allowing threat actors to fully interact with compromised devices in real  – Read More  – The Hacker … Read More “Mirax Android RAT Turns Devices into SOCKS5 Proxies, Reaching 220,000 via Meta Ads  – The Hacker News” »

AI Security Institute Advocates Security Best Practices After Mythos Test –

Posted on April 14, 2026 By Joe-W No Comments on AI Security Institute Advocates Security Best Practices After Mythos Test –
AI Security Institute Advocates Security Best Practices After Mythos Test –
Privacy/Governance Feed

The AISI has issued its judgement on Anthropic’s Mythos Preview model – Read More  –  

Analysis of 216M Security Findings Shows a 4x Increase In Critical Risk (2026 Report)  – The Hacker News

Posted on April 14, 2026 By [email protected] (The Hacker News) No Comments on Analysis of 216M Security Findings Shows a 4x Increase In Critical Risk (2026 Report)  – The Hacker News
Analysis of 216M Security Findings Shows a 4x Increase In Critical Risk (2026 Report)  – The Hacker News
Attack Feeds

OX Security recently analyzed 216 million security findings across 250 organizations over a 90-day period. The primary takeaway: while raw alert volume grew by 52% year-over-year, prioritized critical risk grew by nearly 400%. The surge in AI-assisted development is creating a “velocity gap” where the density of high-impact vulnerabilities is scaling faster than  – Read More  – The Hacker News 

Secretary Mullin must help finish the job: Urge the Senate to confirm Plankey  – CyberScoop

Posted on April 14, 2026 By Greg Otto No Comments on Secretary Mullin must help finish the job: Urge the Senate to confirm Plankey  – CyberScoop
Secretary Mullin must help finish the job: Urge the Senate to confirm Plankey  – CyberScoop
Attack Feeds

On March 23, the Senate confirmed Senator Markwayne Mullin as the next homeland security secretary, marking an important step in strengthening leadership during a critical moment for our nation’s security. But only half of the job is done. The Cybersecurity and Infrastructure Security Agency (CISA), the federal government’s main civilian cyber defense agency, still lacks … Read More “Secretary Mullin must help finish the job: Urge the Senate to confirm Plankey  – CyberScoop” »

108 Malicious Chrome Extensions Steal Google and Telegram Data, Affecting 20,000 Users  – The Hacker News

Posted on April 14, 2026 By [email protected] (The Hacker News) No Comments on 108 Malicious Chrome Extensions Steal Google and Telegram Data, Affecting 20,000 Users  – The Hacker News
108 Malicious Chrome Extensions Steal Google and Telegram Data, Affecting 20,000 Users  – The Hacker News
Attack Feeds

Cybersecurity researchers have discovered a new campaign in which a cluster of 108 Google Chrome extensions has been found to communicate with the same command-and-control (C2) infrastructure with the goal of collecting user data and enabling browser-level abuse by injecting ads and arbitrary JavaScript code into every web page visited. According to Socket, the extensions are … Read More “108 Malicious Chrome Extensions Steal Google and Telegram Data, Affecting 20,000 Users  – The Hacker News” »

Quantum Threats to PHI: Why Vault Now? – JISA Softech Pvt Ltd

Posted on April 14, 2026 By Aakash Chaudhary No Comments on Quantum Threats to PHI: Why Vault Now? – JISA Softech Pvt Ltd
Quantum Threats to PHI: Why Vault Now? – JISA Softech Pvt Ltd
Privacy/Governance Feed

The healthcare industry is facing a new age of cybersecurity threat, one that is not predetermined by the current… The post Quantum Threats to PHI: Why Vault Now? appeared first on JISA Softech Pvt Ltd.  – Read More  – JISA Softech Pvt Ltd 

CISA Adds 6 Known Exploited Flaws in Fortinet, Microsoft, and Adobe Software  – The Hacker News

Posted on April 14, 2026 By [email protected] (The Hacker News) No Comments on CISA Adds 6 Known Exploited Flaws in Fortinet, Microsoft, and Adobe Software  – The Hacker News
CISA Adds 6 Known Exploited Flaws in Fortinet, Microsoft, and Adobe Software  – The Hacker News
Attack Feeds

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added half a dozen security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The list of vulnerabilities is as follows – CVE-2026-21643 (CVSS score: 9.1) –  An SQL injection vulnerability in  Fortinet FortiClient EMS that could allow an unauthenticated attacker to  – Read … Read More “CISA Adds 6 Known Exploited Flaws in Fortinet, Microsoft, and Adobe Software  – The Hacker News” »

ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers  – The Hacker News

Posted on April 14, 2026 By [email protected] (The Hacker News) No Comments on ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers  – The Hacker News
ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers  – The Hacker News
Attack Feeds

A critical security vulnerability impacting ShowDoc, a document management and collaboration service popular in China, has come under active exploitation in the wild. The vulnerability in question is CVE-2025-0520 (aka CNVD-2020-26585), which carries a CVSS score of 9.4 out of 10.0. It relates to a case of unrestricted file upload that stems from improper validation of  – Read More  – … Read More “ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers  – The Hacker News” »

Here’s how cyber heavyweights in the US and UK are dealing with Claude Mythos  – CyberScoop

Posted on April 13, 2026 By djohnson No Comments on Here’s how cyber heavyweights in the US and UK are dealing with Claude Mythos  – CyberScoop
Here’s how cyber heavyweights in the US and UK are dealing with Claude Mythos  – CyberScoop
Attack Feeds

A joint report from the Cloud Security Alliance (CSA), the SANS Institute and the Open Worldwide Application Security Project (OWASP) concludes that in the near term, organizations are “likely to be overwhelmed” by threat actors using AI to find and exploit vulnerabilities faster than defenders can patch them. While those organizations can use AI tools … Read More “Here’s how cyber heavyweights in the US and UK are dealing with Claude Mythos  – CyberScoop” »

OpenAI Rotates macOS Certificates Following Axios Supply Chain Breach  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 13, 2026 By Deeba Ahmed No Comments on OpenAI Rotates macOS Certificates Following Axios Supply Chain Breach  – Hackread – Cybersecurity News, Data Breaches, AI and More
OpenAI Rotates macOS Certificates Following Axios Supply Chain Breach  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

OpenAI rotates macOS certificates after downloading a compromised Axios version, urging users to update apps before revoked certificates are blocked in May 2026.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

OpenAI’s Mac apps need updates thanks to the Axios hack  – CyberScoop

Posted on April 13, 2026 By Matt Kapko No Comments on OpenAI’s Mac apps need updates thanks to the Axios hack  – CyberScoop
OpenAI’s Mac apps need updates thanks to the Axios hack  – CyberScoop
Attack Feeds

OpenAI updated its security certificates and is requiring all macOS users to update to the latest versions after determining its products, along with many others, were impacted by a widespread supply-chain attack that briefly infected a popular open-source library in late March, the company said in a blog post Friday. The artificial intelligence vendor said … Read More “OpenAI’s Mac apps need updates thanks to the Axios hack  – CyberScoop” »

JanelaRAT Malware Targets Latin American Banks with 14,739 Attacks in Brazil in 2025  – The Hacker News

Posted on April 13, 2026 By [email protected] (The Hacker News) No Comments on JanelaRAT Malware Targets Latin American Banks with 14,739 Attacks in Brazil in 2025  – The Hacker News
JanelaRAT Malware Targets Latin American Banks with 14,739 Attacks in Brazil in 2025  – The Hacker News
Attack Feeds

Banks and financial institutions in Latin American countries like Brazil and Mexico have continued to be the target of a malware family called JanelaRAT. A modified version of BX RAT, JanelaRAT is known to steal financial and cryptocurrency data associated with specific financial entities, as well as track mouse inputs, log keystrokes, take screenshots, and … Read More “JanelaRAT Malware Targets Latin American Banks with 14,739 Attacks in Brazil in 2025  – The Hacker News” »

FBI and Indonesian Police Dismantle W3LL Phishing Network Behind $20M Fraud Attempts  – The Hacker News

Posted on April 13, 2026 By [email protected] (The Hacker News) No Comments on FBI and Indonesian Police Dismantle W3LL Phishing Network Behind $20M Fraud Attempts  – The Hacker News
FBI and Indonesian Police Dismantle W3LL Phishing Network Behind $20M Fraud Attempts  – The Hacker News
Attack Feeds

The U.S. Federal Bureau of Investigation (FBI), in partnership with the Indonesian National Police, has dismantled the infrastructure associated with a global phishing operation that leveraged an off-the-shelf toolkit called W3LL to steal thousands of victims’ account credentials and attempt more than $20 million in fraud. In tandem, authorities detained the alleged developer, who has&  – Read … Read More “FBI and Indonesian Police Dismantle W3LL Phishing Network Behind $20M Fraud Attempts  – The Hacker News” »

BITTER APT Uses Signal, Google, and Zoom Lures to Spread ProSpy Spyware  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 13, 2026 By Deeba Ahmed No Comments on BITTER APT Uses Signal, Google, and Zoom Lures to Spread ProSpy Spyware  – Hackread – Cybersecurity News, Data Breaches, AI and More
BITTER APT Uses Signal, Google, and Zoom Lures to Spread ProSpy Spyware  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

BITTER APT spreads ProSpy and ToSpy via Signal, Google, and Zoom lures, targeting journalists through LinkedIn and iMessage spearphishing.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Mirax Android Trojan Turns Devices Into Residential Proxy Nodes –

Posted on April 13, 2026 By Joe-W No Comments on Mirax Android Trojan Turns Devices Into Residential Proxy Nodes –
Mirax Android Trojan Turns Devices Into Residential Proxy Nodes –
Privacy/Governance Feed

Security researchers warn of Mirax, an emerging Android banking trojan using MaaS, remote access and residential proxies to target European users – Read More  –  

Mailbox Rule Abuse Emerges as Stealthy Post-Compromise Threat –

Posted on April 13, 2026 By Joe-W No Comments on Mailbox Rule Abuse Emerges as Stealthy Post-Compromise Threat –
Mailbox Rule Abuse Emerges as Stealthy Post-Compromise Threat –
Privacy/Governance Feed

Attackers are abusing Microsoft 365 mailbox rules to hide activity, exfiltrate data and retain access after account compromise, researchers warn – Read More  –  

OpenSSF Flags Malware Campaign on Slack Posing as Linux Foundation Figures  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 13, 2026 By Deeba Ahmed No Comments on OpenSSF Flags Malware Campaign on Slack Posing as Linux Foundation Figures  – Hackread – Cybersecurity News, Data Breaches, AI and More
OpenSSF Flags Malware Campaign on Slack Posing as Linux Foundation Figures  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

OpenSSF warns hackers impersonate Linux Foundation leaders on Slack, tricking developers into installing malware that can compromise entire systems.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and More  – The Hacker News

Posted on April 13, 2026 By [email protected] (The Hacker News) No Comments on ⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and More  – The Hacker News
⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and More  – The Hacker News
Attack Feeds

Monday is back, and the weekend’s backlog of chaos is officially hitting the fan. We are tracking a critical zero-day that has been quietly living in your PDFs for months, plus some aggressive state-sponsored meddling in infrastructure that is finally coming to light. It is one of those mornings where the gap between a quiet shift and a … Read More “⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and More  – The Hacker News” »

Your MTTD Looks Great. Your Post-Alert Gap Doesn’t  – The Hacker News

Posted on April 13, 2026 By [email protected] (The Hacker News) No Comments on Your MTTD Looks Great. Your Post-Alert Gap Doesn’t  – The Hacker News
Your MTTD Looks Great. Your Post-Alert Gap Doesn’t  – The Hacker News
Attack Feeds

Anthropic restricted its Mythos Preview model last week after it autonomously found and exploited zero-day vulnerabilities in every major operating system and browser. Palo Alto Networks’ Wendi Whitmorewarned that similar capabilities are weeks or months from proliferation. CrowdStrike’s 2026 Global Threat Report puts average eCrime breakout time at 29 minutes. Mandiant’s M-Trends 2026  – Read More  – … Read More “Your MTTD Looks Great. Your Post-Alert Gap Doesn’t  – The Hacker News” »

Alleged German DDoS-for-Hire Kingpin Behind Fluxstress Caught in Thailand  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 13, 2026 By Deeba Ahmed No Comments on Alleged German DDoS-for-Hire Kingpin Behind Fluxstress Caught in Thailand  – Hackread – Cybersecurity News, Data Breaches, AI and More
Alleged German DDoS-for-Hire Kingpin Behind Fluxstress Caught in Thailand  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Alleged German cybercrime figure behind Fluxstress and Neldowner arrested in Thailand after years running global DDoS-for-hire services across countries.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Why Your Deprecated Endpoints Are an Attacker’s Best Friend: The Rise of Ghost APIs  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 13, 2026 By Arunkumar Mathiyazhagan No Comments on Why Your Deprecated Endpoints Are an Attacker’s Best Friend: The Rise of Ghost APIs  – Hackread – Cybersecurity News, Data Breaches, AI and More
Why Your Deprecated Endpoints Are an Attacker’s Best Friend: The Rise of Ghost APIs  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Ghost APIs are deprecated endpoints left active, exposing systems to attack. Learn how they differ from shadow APIs and why they create hidden security risks  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

FBI Dismantles $20m Phishing Operation W3LL –

Posted on April 13, 2026 By Joe-W No Comments on FBI Dismantles $20m Phishing Operation W3LL –
FBI Dismantles $20m Phishing Operation W3LL –
Privacy/Governance Feed

The W3LL phishing kit has been associated with fraud attempts totaling $20m – Read More  –  

Booking.com warns customers of hack that exposed their data  – Data and computer security | The Guardian

Posted on April 13, 2026 By Lauren Almeida No Comments on Booking.com warns customers of hack that exposed their data  – Data and computer security | The Guardian
Booking.com warns customers of hack that exposed their data  – Data and computer security | The Guardian
Attack Feeds

Undisclosed number of names, contact and reservation details are accessed in latest cybercrime attempt Business live – latest updates The accommodation reservation website Booking.com has suffered a data breach with “unauthorised parties” gaining access to customers’ details. The platform said it “noticed some suspicious activity involving unauthorised third parties being able to access some of … Read More “Booking.com warns customers of hack that exposed their data  – Data and computer security | The Guardian” »

North Korea’s APT37 Uses Facebook Social Engineering to Deliver RokRAT Malware  – The Hacker News

Posted on April 13, 2026 By [email protected] (The Hacker News) No Comments on North Korea’s APT37 Uses Facebook Social Engineering to Deliver RokRAT Malware  – The Hacker News
North Korea’s APT37 Uses Facebook Social Engineering to Deliver RokRAT Malware  – The Hacker News
Attack Feeds

The North Korean hacking group tracked as APT37 (aka ScarCruft) has been attributed to a fresh multi-stage, social engineering campaign in which threat actors approached targets on Facebook and added them as friends on the social media platform, turning the trust-building exercise into a delivery channel for a remote access trojan called RokRAT. “The threat actor used … Read More “North Korea’s APT37 Uses Facebook Social Engineering to Deliver RokRAT Malware  – The Hacker News” »

UK Cyber Security Council Launches Associate Cyber Security Professional Title –

Posted on April 13, 2026 By Joe-W No Comments on UK Cyber Security Council Launches Associate Cyber Security Professional Title –
Privacy/Governance Feed

The UK Cyber Security Council has unveiled a new Associate Cyber Security Professional title aimed at supporting early‑career cybersecurity professionals – Read More  –  

OpenAI Revokes macOS App Certificate After Malicious Axios Supply Chain Incident  – The Hacker News

Posted on April 13, 2026 By [email protected] (The Hacker News) No Comments on OpenAI Revokes macOS App Certificate After Malicious Axios Supply Chain Incident  – The Hacker News
OpenAI Revokes macOS App Certificate After Malicious Axios Supply Chain Incident  – The Hacker News
Attack Feeds

OpenAI revealed a GitHub Actions workflow used to sign its macOS apps, which downloaded the malicious Axios library on March 31, but noted that no user data or internal system was compromised. “Out of an abundance of caution, we are taking steps to protect the process that certifies our macOS applications are legitimate OpenAI apps,” OpenAI said in a … Read More “OpenAI Revokes macOS App Certificate After Malicious Axios Supply Chain Incident  – The Hacker News” »

Operation Atlantic Seizes $12m in Crypto Losses –

Posted on April 13, 2026 By Joe-W No Comments on Operation Atlantic Seizes $12m in Crypto Losses –
Operation Atlantic Seizes $12m in Crypto Losses –
Privacy/Governance Feed

UK, US and Canadian authorities have identified over 20,000 victims of approval phishing scams that trick users into handing over full crypto wallet access – Read More  –  

Hacker Used Claude Code, GPT-4.1 to Exfiltrate Hundreds of Millions of Mexican Records  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 12, 2026 By Deeba Ahmed No Comments on Hacker Used Claude Code, GPT-4.1 to Exfiltrate Hundreds of Millions of Mexican Records  – Hackread – Cybersecurity News, Data Breaches, AI and More
Hacker Used Claude Code, GPT-4.1 to Exfiltrate Hundreds of Millions of Mexican Records  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

A lone hacker used Claude Code and GPT-4.1 to exfiltrate hundreds of millions of Mexican citizen records from 9 government agencies.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

FBI Atlanta and Indonesian National Police Take Down W3LLSTORE Phishing Marketplace  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 12, 2026 By Waqas No Comments on FBI Atlanta and Indonesian National Police Take Down W3LLSTORE Phishing Marketplace  – Hackread – Cybersecurity News, Data Breaches, AI and More
FBI Atlanta and Indonesian National Police Take Down W3LLSTORE Phishing Marketplace  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

FBI Atlanta and Indonesian National Police dismantle W3LLSTORE phishing market linked to $20M fraud, seizing domains and detaining developer.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Adobe Patches Actively Exploited Acrobat Reader Flaw CVE-2026-34621  – The Hacker News

Posted on April 12, 2026 By [email protected] (The Hacker News) No Comments on Adobe Patches Actively Exploited Acrobat Reader Flaw CVE-2026-34621  – The Hacker News
Adobe Patches Actively Exploited Acrobat Reader Flaw CVE-2026-34621  – The Hacker News
Attack Feeds

Adobe has released emergency updates to fix a critical security flaw in Acrobat Reader that has come under active exploitation in the wild. The vulnerability, assigned the CVE identifier CVE-2026-34621, carries a CVSS score of 8.6 out of 10.0. Successful exploitation of the flaw could allow an attacker to run malicious code on affected installations. It has been described … Read More “Adobe Patches Actively Exploited Acrobat Reader Flaw CVE-2026-34621  – The Hacker News” »

CPUID Breach Distributes STX RAT via Trojanized CPU-Z and HWMonitor Downloads  – The Hacker News

Posted on April 12, 2026 By [email protected] (The Hacker News) No Comments on CPUID Breach Distributes STX RAT via Trojanized CPU-Z and HWMonitor Downloads  – The Hacker News
CPUID Breach Distributes STX RAT via Trojanized CPU-Z and HWMonitor Downloads  – The Hacker News
Attack Feeds

Unknown threat actors compromised CPUID (“cpuid[.]com”), a website that hosts popular hardware monitoring tools like CPU-Z, HWMonitor, HWMonitor Pro, and PerfMonitor, for less than 24 hours to serve malicious executables for the software and deploy a remote access trojan called STX RAT. The incident lasted from approximately April 9, 15:00 UTC, to about April 10, 10:00 UTC, with  … Read More “CPUID Breach Distributes STX RAT via Trojanized CPU-Z and HWMonitor Downloads  – The Hacker News” »

FBI Recovers Deleted Signal Messages Through iPhone Notifications  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 11, 2026 By Deeba Ahmed No Comments on FBI Recovers Deleted Signal Messages Through iPhone Notifications  – Hackread – Cybersecurity News, Data Breaches, AI and More
FBI Recovers Deleted Signal Messages Through iPhone Notifications  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Signal messages may persist in iPhone notification data, enabling FBI access even after deletion, a court case reveals.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

AI and cryptocurrency scams are costing Americans billions, FBI reports  – GRAHAM CLULEY

Posted on April 11, 2026 By Graham Cluley No Comments on AI and cryptocurrency scams are costing Americans billions, FBI reports  – GRAHAM CLULEY
Attack Feeds

The fraud landscape has been changed by AI and cryptocurrency in a way that should concern organisations and individuals alike. Read more in my article on the Fortra blog.  – Read More  – GRAHAM CLULEY 

Google Chrome Update Disrupts Infostealer Cookie Theft  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 11, 2026 By Deeba Ahmed No Comments on Google Chrome Update Disrupts Infostealer Cookie Theft  – Hackread – Cybersecurity News, Data Breaches, AI and More
Google Chrome Update Disrupts Infostealer Cookie Theft  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Google adds Device Bound Session Credentials (DBSC) to Chrome 146, using hardware keys to block infostealer use of stolen session cookies on Windows.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Citizen Lab: Law Enforcement Used Webloc to Track 500 Million Devices via Ad Data  – The Hacker News

Posted on April 11, 2026 By [email protected] (The Hacker News) No Comments on Citizen Lab: Law Enforcement Used Webloc to Track 500 Million Devices via Ad Data  – The Hacker News
Citizen Lab: Law Enforcement Used Webloc to Track 500 Million Devices via Ad Data  – The Hacker News
Attack Feeds

Hungarian domestic intelligence, the national police in El Salvador, and several U.S. law enforcement and police departments have been attributed to the use of an advertising-based global geolocation surveillance system called Webloc. The tool was developed by Israeli company Cobwebs Technologies and is now sold by its successor Penlink after the two firms merged in July 2023  – Read … Read More “Citizen Lab: Law Enforcement Used Webloc to Track 500 Million Devices via Ad Data  – The Hacker News” »

ShinyHunters Claims Rockstar Games Snowflake Breach via Anodot  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 10, 2026 By Waqas No Comments on ShinyHunters Claims Rockstar Games Snowflake Breach via Anodot  – Hackread – Cybersecurity News, Data Breaches, AI and More
ShinyHunters Claims Rockstar Games Snowflake Breach via Anodot  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

ShinyHunters claims access to Rockstar Games Snowflake data via Anodot breach, threatening a data leak on April 14 if ransom demands are not met.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Posts pagination

Previous 1 … 17 18 19 … 40 Next
  • Attack Feeds
  • Privacy/Governance Feed
  • Gov/ISAC Feeds
  • Alert Feeds
  • Privacy Policy
  • Wagner Cybersecurity

Copyright © 2026 AttackFeed by Joe Wagner.

Theme: Oceanly News Dark by ScriptsTown

We are using cookies for analytics purposes only.  We do not store, track or sell user information.

You can find out more about which cookies we are using or switch them off in .

AttackFeed by Joe Wagner
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.