Skip to content
AttackFeed by Joe Wagner | Cybersecurity News from Across the Internet

AttackFeed by Joe Wagner

Cybersecurity News from Across the Internet

  • Attack/News Feeds
  • Gov Alerts/ISAC Feeds
  • Vulnerability Alerts
  • Privacy/Governance Feeds
  • Fraud Feeds
  • iOS App
  • Android App
AttackFeed by Joe Wagner | Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV  - The Hacker News
Attack Feeds
Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV  – The Hacker News
May 23, 2026
AttackFeed by Joe Wagner | Fake Windsurf IDE Extension Uses Solana Blockchain to Steal Developer Data  - Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds
Fake Windsurf IDE Extension Uses Solana Blockchain to Steal Developer Data  – Hackread – Cybersecurity News, Data Breaches, AI and More
March 19, 2026
AttackFeed by Joe Wagner | Researchers say credential-stealing campaign used AI to build evasion ‘at every stage’  - CyberScoop
Attack Feeds
Researchers say credential-stealing campaign used AI to build evasion ‘at every stage’  – CyberScoop
March 30, 2026
AttackFeed by Joe Wagner | GraphAlgo Scam: Lazarus Hackers Register Real US LLCs to Spread Malware  - Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds
GraphAlgo Scam: Lazarus Hackers Register Real US LLCs to Spread Malware  – Hackread – Cybersecurity News, Data Breaches, AI and More
April 10, 2026
AttackFeed by Joe Wagner | OpenAI Codex Security Scanned 1.2 Million Commits and Found 10,561 High-Severity Issues  - The Hacker News
Attack Feeds
OpenAI Codex Security Scanned 1.2 Million Commits and Found 10,561 High-Severity Issues  – The Hacker News
March 7, 2026
AttackFeed by Joe Wagner | Google and Amnesty International teamed up to make it harder for spyware vendors to hide  - CyberScoop
Attack Feeds
Google and Amnesty International teamed up to make it harder for spyware vendors to hide  – CyberScoop
May 12, 2026

AI Future: The Leading International AI and Web3 Forum to Take Place in April  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 3, 2026 By CyberNewswire No Comments on AI Future: The Leading International AI and Web3 Forum to Take Place in April  – Hackread – Cybersecurity News, Data Breaches, AI and More
AI Future: The Leading International AI and Web3 Forum to Take Place in April  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Moscow, Russia, 3rd April 2026, CyberNewswire  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

AI Firm Mercor Confirms Breach as Hackers Claim 4TB of Stolen Data  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 3, 2026 By Deeba Ahmed No Comments on AI Firm Mercor Confirms Breach as Hackers Claim 4TB of Stolen Data  – Hackread – Cybersecurity News, Data Breaches, AI and More
AI Firm Mercor Confirms Breach as Hackers Claim 4TB of Stolen Data  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

AI firm Mercor confirms a breach linked to a LiteLLM supply chain attack, as hackers claim to have stolen 4TB of sensitive data and internal systems.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Wyden warns Social Security chief: Trump’s voter database is ‘blatant voter suppression’  – CyberScoop

Posted on April 3, 2026 By djohnson No Comments on Wyden warns Social Security chief: Trump’s voter database is ‘blatant voter suppression’  – CyberScoop
Wyden warns Social Security chief: Trump’s voter database is ‘blatant voter suppression’  – CyberScoop
Attack Feeds

Sen. Ron Wyden, D-Ore., warned Social Security Administration chief Frank Bisignano that any follow-through on President Donald Trump’s executive order creating a new database of U.S. voters using agency data would be viewed by Democrats as a conscious choice on the part of SSA officials to participate in “blatant voter suppression.” “Facilitating Donald Trump’s directive … Read More “Wyden warns Social Security chief: Trump’s voter database is ‘blatant voter suppression’  – CyberScoop” »

Trump budget proposal would cut hundreds of millions more from CISA  – CyberScoop

Posted on April 3, 2026 By Tim Starks No Comments on Trump budget proposal would cut hundreds of millions more from CISA  – CyberScoop
Trump budget proposal would cut hundreds of millions more from CISA  – CyberScoop
Attack Feeds

President Donald Trump’s fiscal 2027 budget would slash the Cybersecurity and Infrastructure Security Agency’s total by $707 million, according to a summary released Friday, which would deeply chop down an agency that already took a big hit in Trump’s first year. Another budget document suggests a smaller — but still substantial — hit of $361 … Read More “Trump budget proposal would cut hundreds of millions more from CISA  – CyberScoop” »

Wyden warns Social Security chief: Trump’s voter database is ‘blatant voter suppression’  – CyberScoop

Posted on April 3, 2026 By djohnson No Comments on Wyden warns Social Security chief: Trump’s voter database is ‘blatant voter suppression’  – CyberScoop
Wyden warns Social Security chief: Trump’s voter database is ‘blatant voter suppression’  – CyberScoop
Attack Feeds

Sen. Ron Wyden, D-Ore., warned Social Security Administration chief Frank Bisignano that any follow-through on President Donald Trump’s executive order creating a new database of U.S. voters using agency data would be viewed by Democrats as a conscious choice on the part of SSA officials to participate in “blatant voter suppression.” “Facilitating Donald Trump’s directive … Read More “Wyden warns Social Security chief: Trump’s voter database is ‘blatant voter suppression’  – CyberScoop” »

New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs –

Posted on April 3, 2026 By Joe-W No Comments on New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs –
New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs –
Privacy/Governance Feed

A large-scale credential theft campaign targeting senior executives has been linked to a previously unknown automated phishing platform called Venom – Read More  –  

Why Third-Party Risk Is the Biggest Gap in Your Clients’ Security Posture  – The Hacker News

Posted on April 3, 2026 By [email protected] (The Hacker News) No Comments on Why Third-Party Risk Is the Biggest Gap in Your Clients’ Security Posture  – The Hacker News
Why Third-Party Risk Is the Biggest Gap in Your Clients’ Security Posture  – The Hacker News
Attack Feeds

The next major breach hitting your clients probably won’t come from inside their walls. It’ll come through a vendor they trust, a SaaS tool their finance team signed up for, or a subcontractor nobody in IT knows about. That’s the new attack surface, and most organizations are underprepared for it. Cynomi’s new guide, Securing the Modern Perimeter: The Rise of … Read More “Why Third-Party Risk Is the Biggest Gap in Your Clients’ Security Posture  – The Hacker News” »

UNC1069 Social Engineering of Axios Maintainer Led to npm Supply Chain Attack  – The Hacker News

Posted on April 3, 2026 By [email protected] (The Hacker News) No Comments on UNC1069 Social Engineering of Axios Maintainer Led to npm Supply Chain Attack  – The Hacker News
UNC1069 Social Engineering of Axios Maintainer Led to npm Supply Chain Attack  – The Hacker News
Attack Feeds

The maintainer of the Axios npm package has confirmed that the supply chain compromise was the result of a highly-targeted social engineering campaign orchestrated by North Korean threat actors tracked as UNC1069. Maintainer Jason Saayman said the attackers tailored their social engineering efforts “specifically to me” by first approaching him under the guise of the founder of … Read More “UNC1069 Social Engineering of Axios Maintainer Led to npm Supply Chain Attack  – The Hacker News” »

Nigerian romance scammer jailed after being caught out by fellow fraudster  – GRAHAM CLULEY

Posted on April 3, 2026 By Graham Cluley No Comments on Nigerian romance scammer jailed after being caught out by fellow fraudster  – GRAHAM CLULEY
Nigerian romance scammer jailed after being caught out by fellow fraudster  – GRAHAM CLULEY
Attack Feeds

A Nigerian fraudster spent years posing as a woman online, romancing unsuspecting American men out of their savings – until he accidentally tried the same trick on a fellow scammer, who told him to “learn how to do a clean job.” The recovered chat logs helped put him behind bars for 15 years. Read more … Read More “Nigerian romance scammer jailed after being caught out by fellow fraudster  – GRAHAM CLULEY” »

Drift Loses $285 Million in Durable Nonce Social Engineering Attack Linked to DPRK  – The Hacker News

Posted on April 3, 2026 By [email protected] (The Hacker News) No Comments on Drift Loses $285 Million in Durable Nonce Social Engineering Attack Linked to DPRK  – The Hacker News
Drift Loses $285 Million in Durable Nonce Social Engineering Attack Linked to DPRK  – The Hacker News
Attack Feeds

Solana-based decentralized exchange Drift has confirmed that attackers drained about $285 million from the platform during a security incident that took place on April 1, 2026. “Earlier today, a malicious actor gained unauthorized access to Drift Protocol through a novel attack involving durable nonces, resulting in a rapid takeover of Drift’s Security Council administrative powers,” the&  … Read More “Drift Loses $285 Million in Durable Nonce Social Engineering Attack Linked to DPRK  – The Hacker News” »

New SparkCat Variant in iOS, Android Apps Steals Crypto Wallet Recovery Phrase Images  – The Hacker News

Posted on April 3, 2026 By [email protected] (The Hacker News) No Comments on New SparkCat Variant in iOS, Android Apps Steals Crypto Wallet Recovery Phrase Images  – The Hacker News
New SparkCat Variant in iOS, Android Apps Steals Crypto Wallet Recovery Phrase Images  – The Hacker News
Attack Feeds

Cybersecurity researchers have discovered a new version of the SparkCat malware on the Apple App Store and Google Play Store, more than a year after the trojan was discovered targeting both the mobile operating systems. The malware has been found to conceal itself within seemingly benign apps, such as enterprise messengers and food delivery services, while  – Read More  – The Hacker … Read More “New SparkCat Variant in iOS, Android Apps Steals Crypto Wallet Recovery Phrase Images  – The Hacker News” »

[CVE-2026-33691] OWASP CRS whitespace padding bypass vulnerability  – Full Disclosure

Posted on April 3, 2026 By Joe-W No Comments on [CVE-2026-33691] OWASP CRS whitespace padding bypass vulnerability  – Full Disclosure
[CVE-2026-33691] OWASP CRS whitespace padding bypass	vulnerability  – Full Disclosure
Alert Feeds

  Posted by cyber security on Apr 02 A vulnerability was identified in OWASP CRS where whitespace padding in filenames can bypass file upload extension checks, allowing uploads of dangerous files such as .php, .phar, .jsp, and .jspx. This issue has been assigned CVE‑2026‑33691. Impact: Attackers may evade CRS protections and upload web shells disguised … Read More “[CVE-2026-33691] OWASP CRS whitespace padding bypass vulnerability  – Full Disclosure” »

[KIS-2026-06] MetInfo CMS

Posted on April 3, 2026 By Joe-W No Comments on [KIS-2026-06] MetInfo CMS
[KIS-2026-06] MetInfo CMS
Alert Feeds

  Posted by Egidio Romano on Apr 02 ————————————————————————— MetInfo CMS <= 8.1 (weixinreply.class.php) PHP Code Injection Vulnerability ————————————————————————— [-] Software Link: https://www.metinfo.cn [-] Affected Versions: Versions 7.9, 8.0, and 8.1. [-] Vulnerability Description: The vulnerable code is located into the… – Read More  – Full Disclosure 

Apple OHTTP Relay: 14 Third-Party Endpoints, 6 Countries, Zero User Visibility  – Full Disclosure

Posted on April 3, 2026 By Joe-W No Comments on Apple OHTTP Relay: 14 Third-Party Endpoints, 6 Countries, Zero User Visibility  – Full Disclosure
Apple OHTTP Relay: 14 Third-Party Endpoints, 6 Countries,	Zero User Visibility  – Full Disclosure
Alert Feeds

  Posted by Joseph Goydish II via Fulldisclosure on Apr 02 SUMMARY Apple’s Oblivious HTTP relay for Live Caller ID Lookup (iOS 18+) routes traffic through 14 third-party endpoints across six countries. These include an anonymous Delaware LLC sharing data with OpenAI, a Russian endpoint (Yandex), and a Swiss GmbH whose privacy policy names “The … Read More “Apple OHTTP Relay: 14 Third-Party Endpoints, 6 Countries, Zero User Visibility  – Full Disclosure” »

SEC Consult SA-20260326-0 :: Local Privilege Escalation in Vienna Assistant (MacOS) – Vienna Symphonic Library  – Full Disclosure

Posted on April 3, 2026 By Joe-W No Comments on SEC Consult SA-20260326-0 :: Local Privilege Escalation in Vienna Assistant (MacOS) – Vienna Symphonic Library  – Full Disclosure
SEC Consult SA-20260326-0 :: Local Privilege Escalation in Vienna Assistant (MacOS) – Vienna Symphonic Library  – Full Disclosure
Alert Feeds

  Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Apr 02 SEC Consult Vulnerability Lab Security Advisory < 20260326-0 > ======================================================================= title: Local Privilege Escalation product: Vienna Assistant (MacOS) – Vienna Symphonic Library  vulnerable version: 1.2.542 fixed version: – CVE number: CVE-2026-24068              impact: high homepage:https://www.vsl.co.at/       … Read More “SEC Consult SA-20260326-0 :: Local Privilege Escalation in Vienna Assistant (MacOS) – Vienna Symphonic Library  – Full Disclosure” »

SEC Consult SA-20260401-0 :: Broken Access Control in Open WebUI  – Full Disclosure

Posted on April 3, 2026 By Joe-W No Comments on SEC Consult SA-20260401-0 :: Broken Access Control in Open WebUI  – Full Disclosure
SEC Consult SA-20260401-0 :: Broken Access Control in Open	WebUI  – Full Disclosure
Alert Feeds

  Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Apr 02 SEC Consult Vulnerability Lab Security Advisory < 20260401-0 > ======================================================================= title: Broken Access Control             product: Open WebUI  vulnerable version: <v0.8.11       fixed version: v0.8.11 CVE number: CVE-2026-34222              impact: high … Read More “SEC Consult SA-20260401-0 :: Broken Access Control in Open WebUI  – Full Disclosure” »

Multiple Vulnerabilities in Cisco Products Could Allow for Arbitrary Code Execution  – Cyber Security Advisories – MS-ISAC

Posted on April 2, 2026 By Joe-W No Comments on Multiple Vulnerabilities in Cisco Products Could Allow for Arbitrary Code Execution  – Cyber Security Advisories – MS-ISAC
Gov/ISAC Feeds

Multiple vulnerabilities have been discovered in Cisco products, the most severe of which could allow for arbitrary code execution.  Cisco Smart Software Manager On‑Prem is a centralized Cisco tool used by organizations to manage software licenses, entitlements, and compliance for Cisco products within their own network environment. Cisco Integrated Management Controller (IMC) is embedded server … Read More “Multiple Vulnerabilities in Cisco Products Could Allow for Arbitrary Code Execution  – Cyber Security Advisories – MS-ISAC” »

Multiple Vulnerabilities in Progress ShareFile Could Allow for Remote Code Execution  – Cyber Security Advisories – MS-ISAC

Posted on April 2, 2026 By Joe-W No Comments on Multiple Vulnerabilities in Progress ShareFile Could Allow for Remote Code Execution  – Cyber Security Advisories – MS-ISAC
Gov/ISAC Feeds

Multiple vulnerabilities have been discovered in Progress ShareFile, which when chained together, could allow for remote code execution. Progress ShareFile is a secure, cloud-based content collaboration and file-sharing platform. It enables businesses to securely exchange documents, manage client workflows, and obtain electronic signatures, with a focus on compliance for industries like finance and healthcare. Successful … Read More “Multiple Vulnerabilities in Progress ShareFile Could Allow for Remote Code Execution  – Cyber Security Advisories – MS-ISAC” »

Hackers Exploit CVE-2025-55182 to Breach 766 Next.js Hosts, Steal Credentials  – The Hacker News

Posted on April 2, 2026 By [email protected] (The Hacker News) No Comments on Hackers Exploit CVE-2025-55182 to Breach 766 Next.js Hosts, Steal Credentials  – The Hacker News
Hackers Exploit CVE-2025-55182 to Breach 766 Next.js Hosts, Steal Credentials  – The Hacker News
Attack Feeds

A large-scale credential harvesting operation has been observed exploiting the React2Shell vulnerability as an initial infection vector to steal database credentials, SSH private keys, Amazon Web Services (AWS) secrets, shell command history, Stripe API keys, and GitHub tokens at scale. Cisco Talos has attributed the operation to a threat cluster it tracks as  – Read More  – The Hacker News 

ShinyHunters Hackers Claim Theft of 3M+ Cisco Records, Threaten Public Leak  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 2, 2026 By Waqas No Comments on ShinyHunters Hackers Claim Theft of 3M+ Cisco Records, Threaten Public Leak  – Hackread – Cybersecurity News, Data Breaches, AI and More
ShinyHunters Hackers Claim Theft of 3M+ Cisco Records, Threaten Public Leak  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

ShinyHunters hackers claim they stole 3 million+ Cisco records via Salesforce and AWS, warning of a public leak if demands are not met by April 3, 2026.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

House Dems decry confirmed ICE usage of Paragon spyware  – CyberScoop

Posted on April 2, 2026 By Tim Starks No Comments on House Dems decry confirmed ICE usage of Paragon spyware  – CyberScoop
House Dems decry confirmed ICE usage of Paragon spyware  – CyberScoop
Attack Feeds

Immigration and Customs Enforcement has confirmed it is using Paragon spyware, prompting outrage Thursday from a trio of House Democrats. In response to a letter from the lawmakers inquiring about Paragon’s use, acting ICE Director Todd Lyons wrote that he had authorized the use of “cutting-edge technological tools” to help the Homeland Security Investigations division … Read More “House Dems decry confirmed ICE usage of Paragon spyware  – CyberScoop” »

Cisco Patches 9.8 CVSS IMC and SSM Flaws Allowing Remote System Compromise  – The Hacker News

Posted on April 2, 2026 By [email protected] (The Hacker News) No Comments on Cisco Patches 9.8 CVSS IMC and SSM Flaws Allowing Remote System Compromise  – The Hacker News
Cisco Patches 9.8 CVSS IMC and SSM Flaws Allowing Remote System Compromise  – The Hacker News
Attack Feeds

Cisco has released updates to address a critical security flaw in the Integrated Management Controller (IMC) that, if successfully exploited, could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system with elevated privileges. The vulnerability, tracked as CVE-2026-20093, carries a CVSS score of 9.8 out of a maximum of 10.0. “This  – Read More  … Read More “Cisco Patches 9.8 CVSS IMC and SSM Flaws Allowing Remote System Compromise  – The Hacker News” »

Microsoft Warns of WhatsApp Attachments Spreading Backdoor on Windows PCs  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 2, 2026 By Deeba Ahmed No Comments on Microsoft Warns of WhatsApp Attachments Spreading Backdoor on Windows PCs  – Hackread – Cybersecurity News, Data Breaches, AI and More
Microsoft Warns of WhatsApp Attachments Spreading Backdoor on Windows PCs  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Microsoft warns of a WhatsApp attachments spreading VBS malware that installs backdoors on Windows PCs, giving hackers remote access and control systems.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Lawmakers renew push for Labor Department-backed cyber apprenticeship grants  – CyberScoop

Posted on April 2, 2026 By mbracken No Comments on Lawmakers renew push for Labor Department-backed cyber apprenticeship grants  – CyberScoop
Lawmakers renew push for Labor Department-backed cyber apprenticeship grants  – CyberScoop
Attack Feeds

With the country’s cybersecurity workforce still experiencing major shortages, a bipartisan, bicameral group of lawmakers is pushing to enlist the Department of Labor to help tackle the problem. The Cyber Ready Workforce Act would direct the DOL to establish a grant program that supports the “creation, implementation, and expansion of registered apprenticeship programs in cybersecurity,” … Read More “Lawmakers renew push for Labor Department-backed cyber apprenticeship grants  – CyberScoop” »

Akira ransomware group can achieve initial access to data encryption in less than an hour  – CyberScoop

Posted on April 2, 2026 By djohnson No Comments on Akira ransomware group can achieve initial access to data encryption in less than an hour  – CyberScoop
Akira ransomware group can achieve initial access to data encryption in less than an hour  – CyberScoop
Attack Feeds

The Akira ransomware group has compromised hundreds of victims over the past year with a well-honed attack lifecycle that has whittled down the time from initial access to encryption of data in less than four hours, according to cybersecurity firm Halcyon. Akira has been active since 2023, racking up at least $245 million in ransom … Read More “Akira ransomware group can achieve initial access to data encryption in less than an hour  – CyberScoop” »

Medtech giant Stryker says it’s back up after Iranian cyberattack  – CyberScoop

Posted on April 2, 2026 By Tim Starks No Comments on Medtech giant Stryker says it’s back up after Iranian cyberattack  – CyberScoop
Medtech giant Stryker says it’s back up after Iranian cyberattack  – CyberScoop
Attack Feeds

Medtech company Stryker says it’s back to being “fully operational,” three weeks after it became the most prominent victim to date of Iranian hackers, who said they attacked the Michigan-based company in retaliation over the conflict with the United States and Israel. A March 11 wiper attack from the pro-Palestinian, Iranian government-connected group Handala damaged … Read More “Medtech giant Stryker says it’s back up after Iranian cyberattack  – CyberScoop” »

New ‘Storm’ Infostealer Remotely Decrypts Stolen Credentials –

Posted on April 2, 2026 By Joe-W No Comments on New ‘Storm’ Infostealer Remotely Decrypts Stolen Credentials –
New ‘Storm’ Infostealer Remotely Decrypts Stolen Credentials –
Privacy/Governance Feed

This modern infostealer adopted server-side decryption of stolen credentials to bypass security controls – Read More  –  

ThreatsDay Bulletin: Pre-Auth Chains, Android Rootkits, CloudTrail Evasion & 10 More Stories  – The Hacker News

Posted on April 2, 2026 By [email protected] (The Hacker News) No Comments on ThreatsDay Bulletin: Pre-Auth Chains, Android Rootkits, CloudTrail Evasion & 10 More Stories  – The Hacker News
ThreatsDay Bulletin: Pre-Auth Chains, Android Rootkits, CloudTrail Evasion & 10 More Stories  – The Hacker News
Attack Feeds

The latest ThreatsDay Bulletin is basically a cheat sheet for everything breaking on the internet right now. No corporate fluff or boring lectures here, just a quick and honest look at the messy reality of keeping systems safe this week. Things are moving fast. The list includes researchers chaining small bugs together to create massive backdoors, old software flaws  – … Read More “ThreatsDay Bulletin: Pre-Auth Chains, Android Rootkits, CloudTrail Evasion & 10 More Stories  – The Hacker News” »

Storm Infostealer Sold as Service, Targets Browsers, Wallets and Accounts  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 2, 2026 By Deeba Ahmed No Comments on Storm Infostealer Sold as Service, Targets Browsers, Wallets and Accounts  – Hackread – Cybersecurity News, Data Breaches, AI and More
Storm Infostealer Sold as Service, Targets Browsers, Wallets and Accounts  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

New research from Varonis Threat Labs reveals Storm infostealer, a malicious subscription service that bypasses Google Chrome encryption.…  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Yurei Ransomware Uses Common Tools, Adds Stranger Things References  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 2, 2026 By Deeba Ahmed No Comments on Yurei Ransomware Uses Common Tools, Adds Stranger Things References  – Hackread – Cybersecurity News, Data Breaches, AI and More
Yurei Ransomware Uses Common Tools, Adds Stranger Things References  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Team Cymru details the Yurei ransomware campaign, using standard tools and a few Stranger Things–named payloads to breach and encrypt systems.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

GitHub Used as Covert Channel in Multi-Stage Malware Campaign –

Posted on April 2, 2026 By Joe-W No Comments on GitHub Used as Covert Channel in Multi-Stage Malware Campaign –
GitHub Used as Covert Channel in Multi-Stage Malware Campaign –
Privacy/Governance Feed

LNK files use GitHub C2, embedded decoders and PowerShell for persistence and data exfiltration – Read More  –  

Researchers Observe Sub-One-Hour Ransomware Attacks –

Posted on April 2, 2026 By Joe-W No Comments on Researchers Observe Sub-One-Hour Ransomware Attacks –
Researchers Observe Sub-One-Hour Ransomware Attacks –
Privacy/Governance Feed

Halcyon says Akira is now capable of carrying out an entire ransomware attack in less than an hour – Read More  –  

Apple Expands iOS 18 Security Updates Amid DarkSword Threat –

Posted on April 2, 2026 By Joe-W No Comments on Apple Expands iOS 18 Security Updates Amid DarkSword Threat –
Apple Expands iOS 18 Security Updates Amid DarkSword Threat –
Privacy/Governance Feed

iOS/iPadOS 18.7.7 updates expanded to protect older devices from DarkSword web exploit kit – Read More  –  

NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts –

Posted on April 2, 2026 By Joe-W No Comments on NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts –
NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts –
Privacy/Governance Feed

The UK’s cybersecurity agency offered advice to “high-risk’ individuals” on how to protect against social engineering and cyber-attacks – Read More  –  

Why GitHub Developers Are Targeted by Token Giveaway Scams  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 2, 2026 By Owais Sultan No Comments on Why GitHub Developers Are Targeted by Token Giveaway Scams  – Hackread – Cybersecurity News, Data Breaches, AI and More
Why GitHub Developers Are Targeted by Token Giveaway Scams  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

GitHub developers face rising giveaway scams. Verify repos, links, and maintainers before acting. Avoid rushed clicks, fake rewards, and risky wallet actions.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

The State of Trusted Open Source Report  – The Hacker News

Posted on April 2, 2026 By [email protected] (The Hacker News) No Comments on The State of Trusted Open Source Report  – The Hacker News
The State of Trusted Open Source Report  – The Hacker News
Attack Feeds

In December 2025, we shared the first-ever The State of Trusted Open Source report, featuring insights from our product data and customer base on open source consumption across our catalog of container image projects, versions, images, language libraries, and builds. These insights shed light on what teams pull, deploy, and maintain day to day, alongside the vulnerabilities and  … Read More “The State of Trusted Open Source Report  – The Hacker News” »

Researchers Uncover Mining Operation Using ISO Lures to Spread RATs and Crypto Miners  – The Hacker News

Posted on April 2, 2026 By [email protected] (The Hacker News) No Comments on Researchers Uncover Mining Operation Using ISO Lures to Spread RATs and Crypto Miners  – The Hacker News
Researchers Uncover Mining Operation Using ISO Lures to Spread RATs and Crypto Miners  – The Hacker News
Attack Feeds

A financially motivated operation codenamed REF1695 has been observed leveraging fake installers to deploy remote access trojans (RATs) and cryptocurrency miners since November 2023. “Beyond cryptomining, the threat actor monetizes infections through CPA (Cost Per Action) fraud, directing victims to content locker pages under the guise of software registration,” Elastic  – Read More  – The Hacker News 

WhatsApp Alerts 200 Users After Fake iOS App Installed Spyware; Italian Firm Faces Action  – The Hacker News

Posted on April 2, 2026 By [email protected] (The Hacker News) No Comments on WhatsApp Alerts 200 Users After Fake iOS App Installed Spyware; Italian Firm Faces Action  – The Hacker News
WhatsApp Alerts 200 Users After Fake iOS App Installed Spyware; Italian Firm Faces Action  – The Hacker News
Attack Feeds

Meta-owned messaging platform WhatsApp said it alerted about 200 users who were tricked into installing a bogus version of its iOS app that was infected with spyware. According to reports from Italian newspaper La Repubblica and news agency ANSA, the vast majority of the targets are located in Italy. It’s assessed that the threat actors behind the activity … Read More “WhatsApp Alerts 200 Users After Fake iOS App Installed Spyware; Italian Firm Faces Action  – The Hacker News” »

Most CNI Firms Face Up to £5m in Downtime from OT Attacks –

Posted on April 2, 2026 By Joe-W
Most CNI Firms Face Up to £5m in Downtime from OT Attacks –
Privacy/Governance Feed

E2e-assure says 80% of critical infrastructure providers could face millions in downtime from cyber-attacks – Read More  –  

Apple Expands iOS 18.7.7 Update to More Devices to Block DarkSword Exploit  – The Hacker News

Posted on April 2, 2026 By [email protected] (The Hacker News)
Apple Expands iOS 18.7.7 Update to More Devices to Block DarkSword Exploit  – The Hacker News
Attack Feeds

Apple on Wednesday expanded the availability of iOS 18.7.7 and iPadOS 18.7.7 to a broader range of devices to protect users from the risk posed by a recently disclosed exploit kit known as DarkSword. “We enabled the availability of iOS 18.7.7 for more devices on April 1, 2026, so users with Automatic Updates turned on can automatically receive important security  – … Read More “Apple Expands iOS 18.7.7 Update to More Devices to Block DarkSword Exploit  – The Hacker News” »

A Practical Guide to Data Discovery and Mapping for DPDP Compliance – JISA Softech Pvt Ltd

Posted on April 2, 2026 By Aakash Chaudhary
A Practical Guide to Data Discovery and Mapping for DPDP Compliance – JISA Softech Pvt Ltd
Privacy/Governance Feed

As India takes strong steps toward the implementation of the Digital Personal Data Protection Act (DPDP) in 2026, organizations… The post A Practical Guide to Data Discovery and Mapping for DPDP Compliance appeared first on JISA Softech Pvt Ltd.  – Read More  – JISA Softech Pvt Ltd 

Google Introduces Android Dev Verification Amid Openness Debate –

Posted on April 1, 2026 By Joe-W
Google Introduces Android Dev Verification Amid Openness Debate –
Privacy/Governance Feed

Android requires dev identity verification for sideloaded apps; phased global rollout from September – Read More  –  

Smashing Security podcast #461: This man hid $400 million in a fishing rod. Then it vanished  – GRAHAM CLULEY

Posted on April 1, 2026 By Graham Cluley
Attack Feeds

A cannabis-growing, beekeeping, gyrocopter-flying Irishman invested his drug money in Bitcoin back in 2011 – and now sits on a fortune worth $400 million. There’s just one small problem: the access codes were tucked inside his fishing rod case, which has mysteriously vanished. Or has it? Because this week, one of his frozen wallets suddenly … Read More “Smashing Security podcast #461: This man hid $400 million in a fishing rod. Then it vanished  – GRAHAM CLULEY” »

Apple Pushes Rare iOS 18 Patch for Devices at Risk from DarkSword Exploit  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 1, 2026 By Waqas
Apple Pushes Rare iOS 18 Patch for Devices at Risk from DarkSword Exploit  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Apple pushes rare iOS 18 security patch to protect devices at risk from the DarkSword exploit, urging users to update or move to iOS 26 for stronger protection.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Multiple Vulnerabilities in Apple Products Could Allow for Privilege Escalation  – Cyber Security Advisories – MS-ISAC

Posted on April 1, 2026 By Joe-W
Gov/ISAC Feeds

Multiple vulnerabilities have been discovered in Apple products, the most severe of which could allow for privilege escalation. Successful exploitation of the most severe of these vulnerabilities could allow a user to elevate privileges. Depending on the privileges associated with the user, they may be able to modify protected system files.   – Read More – Cyber … Read More “Multiple Vulnerabilities in Apple Products Could Allow for Privilege Escalation  – Cyber Security Advisories – MS-ISAC” »

Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution  – Cyber Security Advisories – MS-ISAC

Posted on April 1, 2026 By Joe-W
Gov/ISAC Feeds

Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install programs; … Read More “Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution  – Cyber Security Advisories – MS-ISAC” »

LinkedIn Phishing Scam Uses Fake Notifications to Hijack Accounts  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 1, 2026 By Deeba Ahmed
LinkedIn Phishing Scam Uses Fake Notifications to Hijack Accounts  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

A LinkedIn phishing scam uses fake notifications and lookalike domains to steal credentials, hijack accounts, and access sensitive professional data.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

CERT-UA Impersonation Campaign Spread AGEWHEEZE Malware to 1 Million Emails  – The Hacker News

Posted on April 1, 2026 By [email protected] (The Hacker News)
CERT-UA Impersonation Campaign Spread AGEWHEEZE Malware to 1 Million Emails  – The Hacker News
Attack Feeds

The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new phishing campaign in which the cybersecurity agency itself was impersonated to distribute a remote administration tool known as AGEWHEEZE. As part of the attacks, the threat actors, tracked as UAC-0255, sent emails on March 26 and 27, 2026, posing as CERT-UA … Read More “CERT-UA Impersonation Campaign Spread AGEWHEEZE Malware to 1 Million Emails  – The Hacker News” »

Anthropic Leaks 512,000 Lines of Claude AI Code in Major Blunder  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on April 1, 2026 By Deeba Ahmed
Anthropic Leaks 512,000 Lines of Claude AI Code in Major Blunder  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Human error exposed 512,000+ lines of Anthropic Claude AI Code, revealing KAIROS and Capybara secrets, pushing users to switch to the Native Installer.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

European-Chinese geopolitical issues drive renewed cyberespionage campaign  – CyberScoop

Posted on April 1, 2026 By Tim Starks
European-Chinese geopolitical issues drive renewed cyberespionage campaign  – CyberScoop
Attack Feeds

A Chinese cyberespionage group has shifted its gaze back to Europe after years of focusing on other parts of the world, Proofpoint research published Wednesday found. The surge began in mid-2025, with a bevy of issues bubbling up between China and Europe, the company said. Proofpoint labels the government-linked group TA416, but other companies track … Read More “European-Chinese geopolitical issues drive renewed cyberespionage campaign  – CyberScoop” »

Posts pagination

Previous 1 … 20 21 22 … 40 Next
  • Attack Feeds
  • Privacy/Governance Feed
  • Gov/ISAC Feeds
  • Alert Feeds
  • Privacy Policy
  • Wagner Cybersecurity

Copyright © 2026 AttackFeed by Joe Wagner.

Theme: Oceanly News Dark by ScriptsTown

We are using cookies for analytics purposes only.  We do not store, track or sell user information.

You can find out more about which cookies we are using or switch them off in .

AttackFeed by Joe Wagner
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.