Skip to content
AttackFeed by Joe Wagner | Cybersecurity News from Across the Internet

AttackFeed by Joe Wagner

Cybersecurity News from Across the Internet

  • Attack/News Feeds
  • Gov Alerts/ISAC Feeds
  • Vulnerability Alerts
  • Privacy/Governance Feeds
  • Fraud Feeds
  • iOS App
  • Android App
AttackFeed by Joe Wagner | Veeam Patches 7 Critical Backup & Replication Flaws Allowing Remote Code Execution  - The Hacker News
Attack Feeds
Veeam Patches 7 Critical Backup & Replication Flaws Allowing Remote Code Execution  – The Hacker News
March 13, 2026
AttackFeed by Joe Wagner | New TrickMo Variant Uses TON C2 and SOCKS5 to Create Android Network Pivots  - The Hacker News
Attack Feeds
New TrickMo Variant Uses TON C2 and SOCKS5 to Create Android Network Pivots  – The Hacker News
May 12, 2026
AttackFeed by Joe Wagner | GlassWorm Malware Uses Solana Dead Drops to Deliver RAT and Steal Browser, Crypto Data  - The Hacker News
Attack Feeds
GlassWorm Malware Uses Solana Dead Drops to Deliver RAT and Steal Browser, Crypto Data  – The Hacker News
March 25, 2026
AttackFeed by Joe Wagner | The Importance of Behavioral Analytics in AI-Enabled Cyber Attacks  - The Hacker News
Attack Feeds
The Importance of Behavioral Analytics in AI-Enabled Cyber Attacks  – The Hacker News
March 20, 2026
AttackFeed by Joe Wagner | Android Malware Spotted Subscribing Victims to Paid Services Without Consent  - Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds
Android Malware Spotted Subscribing Victims to Paid Services Without Consent  – Hackread – Cybersecurity News, Data Breaches, AI and More
May 21, 2026
AttackFeed by Joe Wagner | Acting CISA chief says DHS funding lapse would limit, halt some agency work  - CyberScoop
Attack Feeds
Acting CISA chief says DHS funding lapse would limit, halt some agency work  – CyberScoop
February 11, 2026

Iran-Linked Hackers Disrupt U.S. Critical Infrastructure by Targeting Internet-Exposed PLCs  – The Hacker News

Posted on April 8, 2026 By [email protected] (The Hacker News) No Comments on Iran-Linked Hackers Disrupt U.S. Critical Infrastructure by Targeting Internet-Exposed PLCs  – The Hacker News
Iran-Linked Hackers Disrupt U.S. Critical Infrastructure by Targeting Internet-Exposed PLCs  – The Hacker News
Attack Feeds

Iran-affiliated cyber actors are targeting internet-facing operational technology (OT) devices across critical infrastructures in the U.S., including programmable logic controllers (PLCs), cybersecurity and intelligence agencies warned Tuesday. “These attacks have led to diminished PLC functionality, manipulation of display data and, in some cases, operational disruption and financial  – Read More  – The Hacker News 

Feds quash widespread Russia-backed espionage network spanning 18,000 devices  – CyberScoop

Posted on April 7, 2026 By Matt Kapko No Comments on Feds quash widespread Russia-backed espionage network spanning 18,000 devices  – CyberScoop
Feds quash widespread Russia-backed espionage network spanning 18,000 devices  – CyberScoop
Attack Feeds

Russian state-sponsored attackers compromised more than 18,000 routers spread across more than 120 countries to gain deeper access to sensitive networks for a large-scale espionage campaign before it was recently neutralized, researchers and authorities said Tuesday. Forest Blizzard, also known as APT28 and Fancy Bear, exploited known vulnerabilities to steal credentials for thousands of TP-Link … Read More “Feds quash widespread Russia-backed espionage network spanning 18,000 devices  – CyberScoop” »

Multiple Vulnerabilities in Mozilla Products Could Allow for Arbitrary Code Execution  – Cyber Security Advisories – MS-ISAC

Posted on April 7, 2026 By Joe-W No Comments on Multiple Vulnerabilities in Mozilla Products Could Allow for Arbitrary Code Execution  – Cyber Security Advisories – MS-ISAC
Gov/ISAC Feeds

Multiple vulnerabilities have been discovered in Mozilla products, the most severe of which could allow for arbitrary code execution.   Mozilla Firefox is a web browser used to access the Internet. Mozilla Firefox ESR is a version of the web browser intended to be deployed in large organizations. Mozilla Thunderbird is an email client. Mozilla … Read More “Multiple Vulnerabilities in Mozilla Products Could Allow for Arbitrary Code Execution  – Cyber Security Advisories – MS-ISAC” »

Russian GRU Exploiting Vulnerable Routers to Steal Sensitive Information  – IC3.gov News

Posted on April 7, 2026 By Joe-W No Comments on Russian GRU Exploiting Vulnerable Routers to Steal Sensitive Information  – IC3.gov News
Gov/ISAC Feeds

Post Content – Read More – IC3.gov News 

Hackers Pose as Non-Profit Developers to Deploy Monero Mining Malware  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 7, 2026 By Deeba Ahmed No Comments on Hackers Pose as Non-Profit Developers to Deploy Monero Mining Malware  – Hackread – Cybersecurity News, Data Breaches, AI and More
Hackers Pose as Non-Profit Developers to Deploy Monero Mining Malware  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

REF1695 hackers spread Monero mining malware via fake non-profit installers, using stealth tactics to evade detection and hijack systems for profit.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Iranian hackers launching disruptive attacks at U.S. energy, water targets, feds warn  – CyberScoop

Posted on April 7, 2026 By Tim Starks No Comments on Iranian hackers launching disruptive attacks at U.S. energy, water targets, feds warn  – CyberScoop
Iranian hackers launching disruptive attacks at U.S. energy, water targets, feds warn  – CyberScoop
Attack Feeds

Iranian government hackers are launching disruptive cyberattacks on American energy and water infrastructure, U.S. government agencies “urgently” warned Tuesday. The hackers are taking aim at devices and systems that control industrial processes, and have harmed victims in the last month following the onset of U.S.-Israel strikes against Iran, according to the joint alert from the … Read More “Iranian hackers launching disruptive attacks at U.S. energy, water targets, feds warn  – CyberScoop” »

Tech giants launch AI-powered ‘Project Glasswing’ to identify critical software vulnerabilities  – CyberScoop

Posted on April 7, 2026 By Greg Otto No Comments on Tech giants launch AI-powered ‘Project Glasswing’ to identify critical software vulnerabilities  – CyberScoop
Tech giants launch AI-powered ‘Project Glasswing’ to identify critical software vulnerabilities  – CyberScoop
Attack Feeds

Major technology companies have joined forces in an effort to use advanced artificial intelligence to identify and address security flaws in the world’s most critical software systems, marking a significant shift in how the industry approaches cybersecurity threats. Anthropic announced Project Glasswing on Tuesday, bringing together Amazon, Apple, Broadcom, Cisco, CrowdStrike, the Linux Foundation, Microsoft, … Read More “Tech giants launch AI-powered ‘Project Glasswing’ to identify critical software vulnerabilities  – CyberScoop” »

Cybercrime losses jumped 26% to $20.9 billion in 2025  – CyberScoop

Posted on April 7, 2026 By Matt Kapko No Comments on Cybercrime losses jumped 26% to $20.9 billion in 2025  – CyberScoop
Cybercrime losses jumped 26% to $20.9 billion in 2025  – CyberScoop
Attack Feeds

Cybercrime remains a booming business.  Annual cybercrime losses amounted to almost $20.9 billion last year, reflecting a 26% increase from 2024, the FBI’s Internet Crime Complaint Center (IC3) said in its annual report Tuesday. The comprehensive study exposes a worsening digital crime environment that is driving financial losses, with momentum moving in the wrong direction … Read More “Cybercrime losses jumped 26% to $20.9 billion in 2025  – CyberScoop” »

Russian State-Linked APT28 Exploits SOHO Routers in Global DNS Hijacking Campaign  – The Hacker News

Posted on April 7, 2026 By [email protected] (The Hacker News) No Comments on Russian State-Linked APT28 Exploits SOHO Routers in Global DNS Hijacking Campaign  – The Hacker News
Russian State-Linked APT28 Exploits SOHO Routers in Global DNS Hijacking Campaign  – The Hacker News
Attack Feeds

The Russia-linked threat actor known as APT28 (aka Forest Blizzard) has been linked to a new campaign that has compromised insecure MikroTik and TP-Link routers and modified their settings to turn them into malicious infrastructure under their control as part of a cyber espionage campaign since at least May 2025. The large-scale exploitation campaign has been codenamed   – … Read More “Russian State-Linked APT28 Exploits SOHO Routers in Global DNS Hijacking Campaign  – The Hacker News” »

Russia Hacked Routers to Steal Microsoft Office Tokens  – Krebs on Security

Posted on April 7, 2026 By BrianKrebs No Comments on Russia Hacked Routers to Steal Microsoft Office Tokens  – Krebs on Security
Russia Hacked Routers to Steal Microsoft Office Tokens  – Krebs on Security
Attack Feeds

Hackers linked to Russia’s military intelligence units are using known flaws in older Internet routers to mass harvest authentication tokens from Microsoft Office users, security experts warned today. The spying campaign allowed state-backed Russian hackers to quietly siphon authentication tokens from users on more than 18,000 networks without deploying any malicious software or code. Microsoft … Read More “Russia Hacked Routers to Steal Microsoft Office Tokens  – Krebs on Security” »

Docker CVE-2026-34040 Lets Attackers Bypass Authorization and Gain Host Access  – The Hacker News

Posted on April 7, 2026 By [email protected] (The Hacker News) No Comments on Docker CVE-2026-34040 Lets Attackers Bypass Authorization and Gain Host Access  – The Hacker News
Docker CVE-2026-34040 Lets Attackers Bypass Authorization and Gain Host Access  – The Hacker News
Attack Feeds

A high-severity security vulnerability has been disclosed in Docker Engine that could permit an attacker to bypass authorization plugins (AuthZ) under specific circumstances. The vulnerability, tracked as CVE-2026-34040 (CVSS score: 8.8), stems from an incomplete fix for CVE-2024-41110, a maximum-severity vulnerability in the same component that came to light in July 2024. ”  – Read More  – The Hacker … Read More “Docker CVE-2026-34040 Lets Attackers Bypass Authorization and Gain Host Access  – The Hacker News” »

GrafanaGhost Vulnerability Allows Data Theft via AI Injection  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 7, 2026 By Deeba Ahmed No Comments on GrafanaGhost Vulnerability Allows Data Theft via AI Injection  – Hackread – Cybersecurity News, Data Breaches, AI and More
GrafanaGhost Vulnerability Allows Data Theft via AI Injection  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

GrafanaGhost is a critical vulnerability in Grafana’s AI components that uses indirect prompt injection and protocol-relative URL bypasses to exfiltrate data.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns –

Posted on April 7, 2026 By Joe-W No Comments on Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns –
Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns –
Privacy/Governance Feed

Newly identified malicious campaigns are linked to virtual private servers modified by APT28 to operate as malicious DNS servers – Read More  –  

GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration –

Posted on April 7, 2026 By Joe-W No Comments on GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration –
GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration –
Privacy/Governance Feed

GrafanaGhost chains AI prompt injection and URL flaws to exfiltrate sensitive Grafana data – Read More  –  

‘GrafanaGhost’ bypasses Grafana’s AI defenses without leaving a trace  – CyberScoop

Posted on April 7, 2026 By Greg Otto No Comments on ‘GrafanaGhost’ bypasses Grafana’s AI defenses without leaving a trace  – CyberScoop
‘GrafanaGhost’ bypasses Grafana’s AI defenses without leaving a trace  – CyberScoop
Attack Feeds

Security researchers at Noma Security have disclosed a new vulnerability they are calling GrafanaGhost, an exploit capable of silently stealing sensitive data from Grafana environments by chaining multiple security bypasses, including a method that circumvents the platform’s AI model guardrails without requiring any user interaction. Grafana is widely deployed across enterprise organizations as a central … Read More “‘GrafanaGhost’ bypasses Grafana’s AI defenses without leaving a trace  – CyberScoop” »

AI Agents and Non-Human Identities Creating Critical Security Gaps, Report  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 7, 2026 By Deeba Ahmed No Comments on AI Agents and Non-Human Identities Creating Critical Security Gaps, Report  – Hackread – Cybersecurity News, Data Breaches, AI and More
AI Agents and Non-Human Identities Creating Critical Security Gaps, Report  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

New research from Keeper Security, reveals non-human identities and automated system-to-system interactions are becoming the top security risk for businesses in 2026.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Over 1,000 Exposed ComfyUI Instances Targeted in Cryptomining Botnet Campaign  – The Hacker News

Posted on April 7, 2026 By [email protected] (The Hacker News) No Comments on Over 1,000 Exposed ComfyUI Instances Targeted in Cryptomining Botnet Campaign  – The Hacker News
Over 1,000 Exposed ComfyUI Instances Targeted in Cryptomining Botnet Campaign  – The Hacker News
Attack Feeds

An active campaign has been observed targeting internet-exposed instances running ComfyUI, a popular stable diffusion platform, to enlist them into a cryptocurrency mining and proxy botnet. “A purpose-built Python scanner continuously sweeps major cloud IP ranges for vulnerable targets, automatically installing malicious nodes via ComfyUI-Manager if no exploitable node is already  – Read More  – The Hacker … Read More “Over 1,000 Exposed ComfyUI Instances Targeted in Cryptomining Botnet Campaign  – The Hacker News” »

UK exposes Russian military intelligence hijacking vulnerable routers for cyber attacks  – All Feed

Posted on April 7, 2026 By Joe-W No Comments on UK exposes Russian military intelligence hijacking vulnerable routers for cyber attacks  – All Feed
Gov/ISAC Feeds

New advisory warns cyber threat group APT28 have exploited vulnerable edge devices to support malicious operations. – Read More – All Feed 

APT28 exploit routers to enable DNS hijacking operations  – All Feed

Posted on April 7, 2026 By Joe-W No Comments on APT28 exploit routers to enable DNS hijacking operations  – All Feed
Gov/ISAC Feeds

Russian cyber actor APT28 exploit vulnerable routers to hijack DNS, enabling adversary‑in‑the‑middle attacks and theft of passwords and authentication tokens. – Read More – All Feed 

Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI –

Posted on April 7, 2026 By Joe-W No Comments on Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI –
Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI –
Privacy/Governance Feed

Cryptocurrency scams alone cost victims over $7 billion, while AI-enabled fraud threats are on the rise, says FBI – Read More  –  

The Hidden Cost of Recurring Credential Incidents  – The Hacker News

Posted on April 7, 2026 By [email protected] (The Hacker News) No Comments on The Hidden Cost of Recurring Credential Incidents  – The Hacker News
The Hidden Cost of Recurring Credential Incidents  – The Hacker News
Attack Feeds

When talking about credential security, the focus usually lands on breach prevention. This makes sense when IBM’s 2025 Cost of a Data Breach Report puts the average cost of a breach at $4.4 million. Avoiding even one major incident is enough to justify most security investments, but that headline figure obscures the more persistent problems caused by recurring credential  … Read More “The Hidden Cost of Recurring Credential Incidents  – The Hacker News” »

[Webinar] How to Close Identity Gaps in 2026 Before AI Exploits Enterprise Risk  – The Hacker News

Posted on April 7, 2026 By [email protected] (The Hacker News) No Comments on [Webinar] How to Close Identity Gaps in 2026 Before AI Exploits Enterprise Risk  – The Hacker News
[Webinar] How to Close Identity Gaps in 2026 Before AI Exploits Enterprise Risk  – The Hacker News
Attack Feeds

In the rapid evolution of the 2026 threat landscape, a frustrating paradox has emerged for CISOs and security leaders: Identity programs are maturing, yet the risk is actually increasing. According to new research from the Ponemon Institute, hundreds of applications within the typical enterprise remain disconnected from centralized identity systems. These “dark  – Read More  – The Hacker News 

DPRK-Linked Hackers Use GitHub as C2 in Multi-Stage Attacks Targeting South Korea  – The Hacker News

Posted on April 7, 2026 By [email protected] (The Hacker News) No Comments on DPRK-Linked Hackers Use GitHub as C2 in Multi-Stage Attacks Targeting South Korea  – The Hacker News
DPRK-Linked Hackers Use GitHub as C2 in Multi-Stage Attacks Targeting South Korea  – The Hacker News
Attack Feeds

Threat actors likely associated with the Democratic People’s Republic of Korea (DPRK) have been observed using GitHub as command-and-control (C2) infrastructure in multi-stage attacks targeting organizations in South Korea. The attack chain, per Fortinet FortiGuard Labs, involves obfuscated Windows shortcut (LNK) files acting as the starting point to drop a decoy PDF  – Read More  – The Hacker News 

Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks –

Posted on April 7, 2026 By Joe-W No Comments on Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks –
Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks –
Privacy/Governance Feed

Microsoft has released a new report about the Storm-1175 group and its connection to Medusa ransomware – Read More  –  

Building secure AI data pipelines with CryptoBind – JISA Softech Pvt Ltd

Posted on April 7, 2026 By Aakash Chaudhary No Comments on Building secure AI data pipelines with CryptoBind – JISA Softech Pvt Ltd
Building secure AI data pipelines with CryptoBind – JISA Softech Pvt Ltd
Privacy/Governance Feed

Artificial Intelligence (AI) is as reliable as the data that it ingests. With enterprises broadening their use of AI… The post Building secure AI data pipelines with CryptoBind appeared first on JISA Softech Pvt Ltd.  – Read More  – JISA Softech Pvt Ltd 

New GPUBreach Attack Enables Full CPU Privilege Escalation via GDDR6 Bit-Flips  – The Hacker News

Posted on April 7, 2026 By [email protected] (The Hacker News) No Comments on New GPUBreach Attack Enables Full CPU Privilege Escalation via GDDR6 Bit-Flips  – The Hacker News
New GPUBreach Attack Enables Full CPU Privilege Escalation via GDDR6 Bit-Flips  – The Hacker News
Attack Feeds

New academic research has identified multiple RowHammer attacks against high-performance graphics processing units (GPUs) that could be exploited to escalate privileges and, in some cases, even take full control of a host. The efforts have been codenamed GPUBreach, GDDRHammer, and GeForge. GPUBreach goes a step further than GPUHammer, demonstrating for the first time that  – Read More  – The … Read More “New GPUBreach Attack Enables Full CPU Privilege Escalation via GDDR6 Bit-Flips  – The Hacker News” »

Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited –

Posted on April 7, 2026 By Joe-W No Comments on Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited –
Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited –
Privacy/Governance Feed

Fortinet has updated its FortiClient EMS product after zero-day attacks surfaced – Read More  –  

Life imprisonment for Cambodian scam compound operators – but will it make a difference?  – GRAHAM CLULEY

Posted on April 7, 2026 By Graham Cluley No Comments on Life imprisonment for Cambodian scam compound operators – but will it make a difference?  – GRAHAM CLULEY
Life imprisonment for Cambodian scam compound operators – but will it make a difference?  – GRAHAM CLULEY
Attack Feeds

Cambodia has taken a dramatic step in its fight against scam compounds that have imprisoned innocent people, and forced them to work as virtual slaves defrauding victims via the internet around the world with romance scams and dodgy investment schemes. Read more in my article on the Hot for Security blog.  – Read More  – … Read More “Life imprisonment for Cambodian scam compound operators – but will it make a difference?  – GRAHAM CLULEY” »

China-Linked Storm-1175 Exploits Zero-Days to Rapidly Deploy Medusa Ransomware  – The Hacker News

Posted on April 7, 2026 By [email protected] (The Hacker News) No Comments on China-Linked Storm-1175 Exploits Zero-Days to Rapidly Deploy Medusa Ransomware  – The Hacker News
China-Linked Storm-1175 Exploits Zero-Days to Rapidly Deploy Medusa Ransomware  – The Hacker News
Attack Feeds

A China-based threat actor known for deploying Medusa ransomware has been linked to the weaponization of a combination of zero-day and N-day vulnerabilities to orchestrate “high-velocity” attacks and break into susceptible internet-facing systems. “The threat actor’s high operational tempo and proficiency in identifying exposed perimeter assets have proven successful, with recent  – Read More  – The Hacker … Read More “China-Linked Storm-1175 Exploits Zero-Days to Rapidly Deploy Medusa Ransomware  – The Hacker News” »

Flowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation; 12,000+ Instances Exposed  – The Hacker News

Posted on April 7, 2026 By [email protected] (The Hacker News) No Comments on Flowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation; 12,000+ Instances Exposed  – The Hacker News
Flowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation; 12,000+ Instances Exposed  – The Hacker News
Attack Feeds

Threat actors are exploiting a maximum-severity security flaw in Flowise, an open-source artificial intelligence (AI) platform, according to new findings from VulnCheck. The vulnerability in question is CVE-2025-59528 (CVSS score: 10.0), a code injection vulnerability that could result in remote code execution. “The CustomMCP node allows users to input configuration settings for connecting  – Read More  … Read More “Flowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation; 12,000+ Instances Exposed  – The Hacker News” »

Fortinet customers confront actively exploited zero-day, with a full patch still pending  – CyberScoop

Posted on April 6, 2026 By Matt Kapko No Comments on Fortinet customers confront actively exploited zero-day, with a full patch still pending  – CyberScoop
Fortinet customers confront actively exploited zero-day, with a full patch still pending  – CyberScoop
Attack Feeds

Fortinet released an emergency software update over the weekend to address an actively exploited vulnerability in FortiClient EMS, an endpoint management tool for customer devices. The zero-day vulnerability — CVE-2026-35616 — has a CVSS rating of 9.8 and was added to the Cybersecurity and Infrastructure Security Agency’s known exploited vulnerability catalog Monday.  Fortinet said in … Read More “Fortinet customers confront actively exploited zero-day, with a full patch still pending  – CyberScoop” »

Iran-Linked Password-Spraying Campaign Targets 300+ Israeli Microsoft 365 Organizations  – The Hacker News

Posted on April 6, 2026 By [email protected] (The Hacker News) No Comments on Iran-Linked Password-Spraying Campaign Targets 300+ Israeli Microsoft 365 Organizations  – The Hacker News
Iran-Linked Password-Spraying Campaign Targets 300+ Israeli Microsoft 365 Organizations  – The Hacker News
Attack Feeds

An Iran-nexus threat actor is suspected to be behind a password-spraying campaign targeting Microsoft 365 environments in Israel and the U.A.E. amid ongoing conflict in the Middle East. The activity, assessed to be ongoing, was carried out in three distinct attack waves that took place on March 3, March 13, and March 23, 2026, per Check Point. “The campaign is … Read More “Iran-Linked Password-Spraying Campaign Targets 300+ Israeli Microsoft 365 Organizations  – The Hacker News” »

pcTattleTale stalkerware maker sentence includes fine, supervised release  – CyberScoop

Posted on April 6, 2026 By Tim Starks No Comments on pcTattleTale stalkerware maker sentence includes fine, supervised release  – CyberScoop
pcTattleTale stalkerware maker sentence includes fine, supervised release  – CyberScoop
Attack Feeds

A federal judge has sentenced the maker of stalkerware pcTattleTale, which went out of business after a data breach, to supervised release and a $5,000 fine. Bryan Fleming pleaded guilty in January to a charge of intentionally manufacturing, possessing or selling a device with the knowledge that it would be primarily used for surreptitious interception … Read More “pcTattleTale stalkerware maker sentence includes fine, supervised release  – CyberScoop” »

Missile Alert Phishing Exploits Iran-US-Israel Conflict for Microsoft Logins  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 6, 2026 By Deeba Ahmed No Comments on Missile Alert Phishing Exploits Iran-US-Israel Conflict for Microsoft Logins  – Hackread – Cybersecurity News, Data Breaches, AI and More
Missile Alert Phishing Exploits Iran-US-Israel Conflict for Microsoft Logins  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

New Phishing scam uses fake missile alerts and the ongoing conflict involving Iran to target users with QR codes and fake government emails to steal Microsoft passwords.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

⚡ Weekly Recap: Axios Hack, Chrome 0-Day, Fortinet Exploits, Paragon Spyware and More  – The Hacker News

Posted on April 6, 2026 By [email protected] (The Hacker News) No Comments on ⚡ Weekly Recap: Axios Hack, Chrome 0-Day, Fortinet Exploits, Paragon Spyware and More  – The Hacker News
⚡ Weekly Recap: Axios Hack, Chrome 0-Day, Fortinet Exploits, Paragon Spyware and More  – The Hacker News
Attack Feeds

This week had real hits. The key software got tampered with. Active bugs showed up in the tools people use every day. Some attacks didn’t even need much effort because the path was already there. One weak spot now spreads wider than before. What starts small can reach a lot of systems fast. New bugs, faster use, less time to react. That’s this … Read More “⚡ Weekly Recap: Axios Hack, Chrome 0-Day, Fortinet Exploits, Paragon Spyware and More  – The Hacker News” »

Multi-OS Cyberattacks: How SOCs Close a Critical Risk in 3 Steps  – The Hacker News

Posted on April 6, 2026 By [email protected] (The Hacker News) No Comments on Multi-OS Cyberattacks: How SOCs Close a Critical Risk in 3 Steps  – The Hacker News
Multi-OS Cyberattacks: How SOCs Close a Critical Risk in 3 Steps  – The Hacker News
Attack Feeds

Your attack surface no longer lives on one operating system, and neither do the campaigns targeting it. In enterprise environments, attackers move across Windows endpoints, executive MacBooks, Linux infrastructure, and mobile devices, taking advantage of the fact that many SOC workflows are still fragmented by platform.  For security leaders, this creates a  – Read More  – The Hacker News 

Why Security Researchers and Red Teams Are Turning to Workflow Automation  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 6, 2026 By Owais Sultan No Comments on Why Security Researchers and Red Teams Are Turning to Workflow Automation  – Hackread – Cybersecurity News, Data Breaches, AI and More
Why Security Researchers and Red Teams Are Turning to Workflow Automation  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Security researchers and red teams adopt workflow automation to cut alert fatigue, enrich data, and scale operations across SOC, intel and recon tasks.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Cloudflare Targets WordPress With New AI-Powered EmDash CMS  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 6, 2026 By Deeba Ahmed No Comments on Cloudflare Targets WordPress With New AI-Powered EmDash CMS  – Hackread – Cybersecurity News, Data Breaches, AI and More
Cloudflare Targets WordPress With New AI-Powered EmDash CMS  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Cloudflare launches EmDash CMS, an AI-powered platform built to fix WordPress security flaws with sandboxed plugins, serverless scaling, and passkey auth.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

North Korean Hackers Pose as Trading Firm to Steal $285M from Drift  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 6, 2026 By Deeba Ahmed No Comments on North Korean Hackers Pose as Trading Firm to Steal $285M from Drift  – Hackread – Cybersecurity News, Data Breaches, AI and More
North Korean Hackers Pose as Trading Firm to Steal $285M from Drift  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

North Korean hackers (UNC4736) posed as a trading firm for six months to infiltrate Drift Protocol, using social engineering tactics to steal $285M without suspicion.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

How LiteLLM Turned Developer Machines Into Credential Vaults for Attackers  – The Hacker News

Posted on April 6, 2026 By [email protected] (The Hacker News) No Comments on How LiteLLM Turned Developer Machines Into Credential Vaults for Attackers  – The Hacker News
How LiteLLM Turned Developer Machines Into Credential Vaults for Attackers  – The Hacker News
Attack Feeds

The most active piece of enterprise infrastructure in the company is the developer workstation. That laptop is where credentials are created, tested, cached, copied, and reused across services, bots, build tools, and now local AI agents. In March 2026, the TeamPCP threat actor proved just how valuable developer machines are. Their supply chain attack on  – Read More  – The Hacker News 

Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools  – The Hacker News

Posted on April 6, 2026 By [email protected] (The Hacker News) No Comments on Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools  – The Hacker News
Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools  – The Hacker News
Attack Feeds

Threat actors associated with Qilin and Warlock ransomware operations have been observed using the bring your own vulnerable driver (BYOVD) technique to silence security tools running on compromised hosts, according to findings from Cisco Talos and Trend Micro. Qilin attacks analyzed by Talos have been found to deploy a malicious DLL named “msimg32.dll,”  – Read More  – The Hacker News 

BKA Identifies REvil Leaders Behind 130 German Ransomware Attacks  – The Hacker News

Posted on April 6, 2026 By [email protected] (The Hacker News) No Comments on BKA Identifies REvil Leaders Behind 130 German Ransomware Attacks  – The Hacker News
BKA Identifies REvil Leaders Behind 130 German Ransomware Attacks  – The Hacker News
Attack Feeds

Germany’s Federal Criminal Police Office (aka BKA or the Bundeskriminalamt) has unmasked the real identity of the main threat actors associated with the now-defunct REvil (aka Sodinokibi) ransomware-as-a-service (RaaS) operation. The threat actor, who went by the alias UNKN, functioned as a representative of the group, advertising the ransomware in June 2019 on the XSS … Read More “BKA Identifies REvil Leaders Behind 130 German Ransomware Attacks  – The Hacker News” »

Germany Doxes “UNKN,” Head of RU Ransomware Gangs REvil, GandCrab  – Krebs on Security

Posted on April 5, 2026 By BrianKrebs No Comments on Germany Doxes “UNKN,” Head of RU Ransomware Gangs REvil, GandCrab  – Krebs on Security
Germany Doxes “UNKN,” Head of RU Ransomware Gangs REvil, GandCrab  – Krebs on Security
Attack Feeds

An elusive hacker who went by the handle “UNKN” and ran the early Russian ransomware groups GandCrab and REvil now has a name and a face. Authorities in Germany say 31-year-old Russian Daniil Maksimovich Shchukin headed both cybercrime gangs and helped carry out at least 130 acts of computer sabotage and extortion against victims across … Read More “Germany Doxes “UNKN,” Head of RU Ransomware Gangs REvil, GandCrab  – Krebs on Security” »

$285 Million Drift Hack Traced to Six-Month DPRK Social Engineering Operation  – The Hacker News

Posted on April 5, 2026 By [email protected] (The Hacker News) No Comments on $285 Million Drift Hack Traced to Six-Month DPRK Social Engineering Operation  – The Hacker News
$285 Million Drift Hack Traced to Six-Month DPRK Social Engineering Operation  – The Hacker News
Attack Feeds

Drift has revealed that the April 1, 2026, attack that led to the theft of $285 million was the culmination of a months-long targeted and meticulously planned social engineering operation undertaken by the Democratic People’s Republic of Korea (DPRK) that began in the fall of 2025. The Solana-based decentralized exchange described it as “an attack six months in the  – … Read More “$285 Million Drift Hack Traced to Six-Month DPRK Social Engineering Operation  – The Hacker News” »

Microsoft Details Cookie-Controlled PHP Web Shells Persisting via Cron on Linux Servers  – The Hacker News

Posted on April 5, 2026 By [email protected] (The Hacker News) No Comments on Microsoft Details Cookie-Controlled PHP Web Shells Persisting via Cron on Linux Servers  – The Hacker News
Microsoft Details Cookie-Controlled PHP Web Shells Persisting via Cron on Linux Servers  – The Hacker News
Attack Feeds

Threat actors are increasingly using HTTP cookies as a control channel for PHP-based web shells on Linux servers and to achieve remote code execution, according to findings from the Microsoft Defender Security Research Team. “Instead of exposing command execution through URL parameters or request bodies, these web shells rely on threat actor-supplied cookie values to gate execution,  … Read More “Microsoft Details Cookie-Controlled PHP Web Shells Persisting via Cron on Linux Servers  – The Hacker News” »

BrowserGate: LinkedIn Tracks 6,000+ Browser Extensions on Users’ PCs  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 5, 2026 By Deeba Ahmed No Comments on BrowserGate: LinkedIn Tracks 6,000+ Browser Extensions on Users’ PCs  – Hackread – Cybersecurity News, Data Breaches, AI and More
BrowserGate: LinkedIn Tracks 6,000+ Browser Extensions on Users’ PCs  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

LinkedIn is accused in the BrowserGate report of tracking 6,000+ browser extensions on users’ PCs, raising concerns over privacy and data collection practices.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Fortinet Patches Actively Exploited CVE-2026-35616 in FortiClient EMS  – The Hacker News

Posted on April 5, 2026 By [email protected] (The Hacker News) No Comments on Fortinet Patches Actively Exploited CVE-2026-35616 in FortiClient EMS  – The Hacker News
Fortinet Patches Actively Exploited CVE-2026-35616 in FortiClient EMS  – The Hacker News
Attack Feeds

Fortinet has released out-of-band patches for a critical security flaw impacting FortiClient EMS that it said has been exploited in the wild. The vulnerability, tracked as CVE-2026-35616 (CVSS score: 9.1), has been described as a pre-authentication API access bypass leading to privilege escalation. “An improper access control vulnerability [CWE-284] in FortiClient EMS may allow an  – Read More  … Read More “Fortinet Patches Actively Exploited CVE-2026-35616 in FortiClient EMS  – The Hacker News” »

36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants  – The Hacker News

Posted on April 5, 2026 By [email protected] (The Hacker News) No Comments on 36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants  – The Hacker News
36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants  – The Hacker News
Attack Feeds

Cybersecurity researchers have discovered 36 malicious packages in the npm registry that are disguised as Strapi CMS plugins but come with different payloads to facilitate Redis and PostgreSQL exploitation, deploy reverse shells, harvest credentials, and drop a persistent implant. “Every package contains three files (package.json, index.js, postinstall.js), has no description, repository,  – Read More  – The … Read More “36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants  – The Hacker News” »

UNC1069 Targets Node.js Maintainers via Fake LinkedIn, Slack Profiles  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 4, 2026 By Deeba Ahmed No Comments on UNC1069 Targets Node.js Maintainers via Fake LinkedIn, Slack Profiles  – Hackread – Cybersecurity News, Data Breaches, AI and More
UNC1069 Targets Node.js Maintainers via Fake LinkedIn, Slack Profiles  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

North Korean group UNC1069 targets Node.js maintainers using fake LinkedIn and Slack profiles to spread malware and compromise open source packages.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

A Vulnerability in Fortinet FortiClientEMS Could Allow for Arbitrary Code Execution  – Cyber Security Advisories – MS-ISAC

Posted on April 4, 2026 By Joe-W No Comments on A Vulnerability in Fortinet FortiClientEMS Could Allow for Arbitrary Code Execution  – Cyber Security Advisories – MS-ISAC
Gov/ISAC Feeds

A Vulnerability has been discovered in Fortinet FortiClientEMS that could allow for arbitrary code execution. FortiClientEMS is a centralized management platform for deploying, configuring, monitoring, and enforcing security policies across numerous endpoints (computers) running the FortiClient agent. Successful exploitation of this vulnerability could allow for arbitrary code execution in the context of the affected service account. Depending … Read More “A Vulnerability in Fortinet FortiClientEMS Could Allow for Arbitrary Code Execution  – Cyber Security Advisories – MS-ISAC” »

Posts pagination

Previous 1 … 19 20 21 … 40 Next
  • Attack Feeds
  • Privacy/Governance Feed
  • Gov/ISAC Feeds
  • Alert Feeds
  • Privacy Policy
  • Wagner Cybersecurity

Copyright © 2026 AttackFeed by Joe Wagner.

Theme: Oceanly News Dark by ScriptsTown

We are using cookies for analytics purposes only.  We do not store, track or sell user information.

You can find out more about which cookies we are using or switch them off in .

AttackFeed by Joe Wagner
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.