Skip to content
AttackFeed by Joe Wagner | Cybersecurity News from Across the Internet

AttackFeed by Joe Wagner

Cybersecurity News from Across the Internet

  • Attack/News Feeds
  • Gov Alerts/ISAC Feeds
  • Vulnerability Alerts
  • Privacy/Governance Feeds
  • Fraud Feeds
  • iOS App
  • Android App
AttackFeed by Joe Wagner | Google Adds Rust-Based DNS Parser into Pixel 10 Modem to Enhance Security  - The Hacker News
Attack Feeds
Google Adds Rust-Based DNS Parser into Pixel 10 Modem to Enhance Security  – The Hacker News
April 14, 2026
AttackFeed by Joe Wagner | LuxSci Launches Enterprise-Grade HIPAA-Compliant Email Security for Mid-Sized Healthcare Organizations  - Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds
LuxSci Launches Enterprise-Grade HIPAA-Compliant Email Security for Mid-Sized Healthcare Organizations  – Hackread – Cybersecurity News, Data Breaches, AI and More
May 5, 2026
AttackFeed by Joe Wagner | Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer  - The Hacker News
Attack Feeds
Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer  – The Hacker News
May 28, 2026
AttackFeed by Joe Wagner | 9 Critical IP KVM Flaws Enable Unauthenticated Root Access Across Four Vendors  - The Hacker News
Attack Feeds
9 Critical IP KVM Flaws Enable Unauthenticated Root Access Across Four Vendors  – The Hacker News
March 18, 2026
AttackFeed by Joe Wagner|Former NSA chiefs worry American offensive edge in cybersecurity is slipping  – CyberScoop
Attack Feeds
Former NSA chiefs worry American offensive edge in cybersecurity is slipping  – CyberScoop
March 26, 2026
AttackFeed by Joe Wagner | Romanian Hacker Extradited to US Admits Hacking Oregon State Network  - Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds
Romanian Hacker Extradited to US Admits Hacking Oregon State Network  – Hackread – Cybersecurity News, Data Breaches, AI and More
February 24, 2026

Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K Downloads  – The Hacker News

Posted on May 11, 2026 By [email protected] (The Hacker News) No Comments on Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K Downloads  – The Hacker News
Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K Downloads  – The Hacker News
Attack Feeds

A malicious Hugging Face repository managed to take a spot in the platform’s trending list by impersonating OpenAI’s Privacy Filter open-weight model to deliver a Rust-based information stealer to Windows users. The project, named Open-OSS/privacy-filter, masqueraded as its legitimate counterpart, released by OpenAI late last month (openai/privacy-filter), including copying the entire  – Read More  – … Read More “Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K Downloads  – The Hacker News” »

Police Shut Relaunched Crimenetwork Dark Web Marketplace –

Posted on May 11, 2026 By Joe-W No Comments on Police Shut Relaunched Crimenetwork Dark Web Marketplace –
Police Shut Relaunched Crimenetwork Dark Web Marketplace –
Privacy/Governance Feed

Spanish police have arrested the suspected administrator of German dark web marketplace Crimenetwork – Read More  –  

Two US Men Jailed for Helping North Korean Hackers Infiltrate US Firms  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on May 10, 2026 By Deeba Ahmed No Comments on Two US Men Jailed for Helping North Korean Hackers Infiltrate US Firms  – Hackread – Cybersecurity News, Data Breaches, AI and More
Two US Men Jailed for Helping North Korean Hackers Infiltrate US Firms  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Matthew Knoot and Erick Prince have been jailed for 18 months each for helping North Korean hackers infiltrate US firms through remote laptop farms.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Hackers Trick DigiCert Into Issuing Certificates Used to Sign Malware  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on May 10, 2026 By Deeba Ahmed No Comments on Hackers Trick DigiCert Into Issuing Certificates Used to Sign Malware  – Hackread – Cybersecurity News, Data Breaches, AI and More
Hackers Trick DigiCert Into Issuing Certificates Used to Sign Malware  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

DigiCert revokes 60 code signing certificates after hackers used a malicious support chat attachment to sign the Zhong Stealer malware.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak  – The Hacker News

Posted on May 10, 2026 By [email protected] (The Hacker News) No Comments on Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak  – The Hacker News
Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak  – The Hacker News
Attack Feeds

Cybersecurity researchers have disclosed a critical security vulnerability in Ollama that, if successfully exploited, could allow a remote, unauthenticated attacker to leak its entire process memory. The out-of-bounds read flaw, which likely impacts over 300,000 servers globally, is tracked as CVE-2026-7482 (CVSS score: 9.1). It has been codenamed Bleeding Llama by Cyera. Ollama is a  – … Read More “Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak  – The Hacker News” »

Hackers Hijack JDownloader Site to Deliver Malware Through Installers  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on May 10, 2026 By Deeba Ahmed No Comments on Hackers Hijack JDownloader Site to Deliver Malware Through Installers  – Hackread – Cybersecurity News, Data Breaches, AI and More
Hackers Hijack JDownloader Site to Deliver Malware Through Installers  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

JDownloader confirms a security breach where hackers manipulated official download links to distribute malicious files between 6 and 7 May 2026.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

cPanel, WHM Release Fixes for Three New Vulnerabilities — Patch Now  – The Hacker News

Posted on May 9, 2026 By [email protected] (The Hacker News) No Comments on cPanel, WHM Release Fixes for Three New Vulnerabilities — Patch Now  – The Hacker News
cPanel, WHM Release Fixes for Three New Vulnerabilities — Patch Now  – The Hacker News
Attack Feeds

cPanel has released updates to address three vulnerabilities in cPanel and Web Host Manager (WHM) that could be exploited to achieve privilege escalation, code execution, and denial-of-service. The list of vulnerabilities is as follows – CVE-2026-29201 (CVSS score: 4.3) – An insufficient input validation of the feature file name in the “feature::LOADFEATUREFILE” adminbin call that … Read More “cPanel, WHM Release Fixes for Three New Vulnerabilities — Patch Now  – The Hacker News” »

Fake macOS Troubleshooting Sites Used to Steal iCloud Data in ClickFix Scam  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on May 8, 2026 By Deeba Ahmed No Comments on Fake macOS Troubleshooting Sites Used to Steal iCloud Data in ClickFix Scam  – Hackread – Cybersecurity News, Data Breaches, AI and More
Fake macOS Troubleshooting Sites Used to Steal iCloud Data in ClickFix Scam  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Microsoft researchers warn of a new ClickFix campaign targeting macOS with fake guides on Medium and Craft to deploy AMOS and SHub Stealer via Terminal commands.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

TCLBANKER Banking Trojan Targets Financial Platforms via WhatsApp and Outlook Worms  – The Hacker News

Posted on May 8, 2026 By [email protected] (The Hacker News) No Comments on TCLBANKER Banking Trojan Targets Financial Platforms via WhatsApp and Outlook Worms  – The Hacker News
TCLBANKER Banking Trojan Targets Financial Platforms via WhatsApp and Outlook Worms  – The Hacker News
Attack Feeds

Threat hunters have flagged a previously undocumented Brazilian banking trojan dubbed TCLBANKER that’s capable of targeting 59 banking, fintech, and cryptocurrency platforms. The activity is being tracked by Elastic Security Labs under the moniker REF3076. The malware family is assessed to be a major update of the Maverick, which is known to leverage a worm … Read More “TCLBANKER Banking Trojan Targets Financial Platforms via WhatsApp and Outlook Worms  – The Hacker News” »

Sen. Schumer seeks DHS plan on AI cyber coordination with state, local governments  – CyberScoop

Posted on May 8, 2026 By Tim Starks No Comments on Sen. Schumer seeks DHS plan on AI cyber coordination with state, local governments  – CyberScoop
Sen. Schumer seeks DHS plan on AI cyber coordination with state, local governments  – CyberScoop
Attack Feeds

The Senate’s top Democrat called on the Department of Homeland Security Friday to work closely with state and local governments to defend against artificial intelligence-strengthened hacks.  Senate Minority Leader Chuck Schumer, D-N.Y., wrote to DHS Secretary Markwayne Mullin to make sure state, local, tribal and territorial (SLTT) governments aren’t left behind as AI models advance, … Read More “Sen. Schumer seeks DHS plan on AI cyber coordination with state, local governments  – CyberScoop” »

Fake Call History Apps Stole Payments From Users After 7.3 Million Play Store Downloads  – The Hacker News

Posted on May 8, 2026 By [email protected] (The Hacker News) No Comments on Fake Call History Apps Stole Payments From Users After 7.3 Million Play Store Downloads  – The Hacker News
Fake Call History Apps Stole Payments From Users After 7.3 Million Play Store Downloads  – The Hacker News
Attack Feeds

Cybersecurity researchers have discovered fraudulent apps on the official Google Play Store for Android that falsely claimed to offer access to call histories for any phone number, only to trick users into joining a subscription that provided fake data and incurred financial loss. The 28 apps have collectively racked up more than 7.3 million downloads, … Read More “Fake Call History Apps Stole Payments From Users After 7.3 Million Play Store Downloads  – The Hacker News” »

ClaudeBleed Vulnerability Lets Hackers Hijack Claude Chrome Extension to Steal Data  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on May 8, 2026 By Deeba Ahmed No Comments on ClaudeBleed Vulnerability Lets Hackers Hijack Claude Chrome Extension to Steal Data  – Hackread – Cybersecurity News, Data Breaches, AI and More
ClaudeBleed Vulnerability Lets Hackers Hijack Claude Chrome Extension to Steal Data  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

The ClaudeBleed vulnerability allows hackers to bypass Claude for Chrome guardrails to exfiltrate private Google Drive and Gmail data.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Inside Department 4: Russia’s secret school for hackers  – GRAHAM CLULEY

Posted on May 8, 2026 By Graham Cluley No Comments on Inside Department 4: Russia’s secret school for hackers  – GRAHAM CLULEY
Inside Department 4: Russia’s secret school for hackers  – GRAHAM CLULEY
Attack Feeds

Most universities have a careers fair. At Bauman Moscow State Technical University, however, an elite group of students appear to have something rather more unusual: a direct pipeline into some of the world’s most notorious state-sponsored hacking groups. Read more in my article on the Hot for Security blog.  – Read More  – GRAHAM CLULEY 

One in eight UK workers has sold their company passwords, and bosses think it’s fine  – GRAHAM CLULEY

Posted on May 8, 2026 By Graham Cluley No Comments on One in eight UK workers has sold their company passwords, and bosses think it’s fine  – GRAHAM CLULEY
Attack Feeds

One in eight UK workers admits to selling their company login credentials – or knowing someone who has – in the past 12 months. The really alarming bit? Their bosses are even more relaxed about it. Read more in my article on the Fortra blog.  – Read More  – GRAHAM CLULEY 

ShinyHunters claims nearly 9,000 schools affected by Canvas data breach  – CyberScoop

Posted on May 8, 2026 By Greg Otto No Comments on ShinyHunters claims nearly 9,000 schools affected by Canvas data breach  – CyberScoop
ShinyHunters claims nearly 9,000 schools affected by Canvas data breach  – CyberScoop
Attack Feeds

The post ShinyHunters claims nearly 9,000 schools affected by Canvas data breach appeared first on CyberScoop.   – Read More  – CyberScoop 

Flaw in Claude’s Chrome extension allowed ‘any’ other plugin to hijack victims’ AI  – CyberScoop

Posted on May 8, 2026 By djohnson No Comments on Flaw in Claude’s Chrome extension allowed ‘any’ other plugin to hijack victims’ AI  – CyberScoop
Flaw in Claude’s Chrome extension allowed ‘any’ other plugin to hijack victims’ AI  – CyberScoop
Attack Feeds

As businesses and governments turn to AI agents to access the internet and perform higher-level tasks, researchers continue to find serious flaws in large language models that can be exploited by bad actors. The latest discovery comes from browser security firm LayerX, involving a bug in the Chrome extension for Anthropic’s Claude AI model that … Read More “Flaw in Claude’s Chrome extension allowed ‘any’ other plugin to hijack victims’ AI  – CyberScoop” »

Quasar Linux RAT Steals Developer Credentials for Software Supply Chain Compromise  – The Hacker News

Posted on May 8, 2026 By [email protected] (The Hacker News) No Comments on Quasar Linux RAT Steals Developer Credentials for Software Supply Chain Compromise  – The Hacker News
Quasar Linux RAT Steals Developer Credentials for Software Supply Chain Compromise  – The Hacker News
Attack Feeds

A previously undocumented Linux implant codenamed Quasar Linux RAT (QLNX) is targeting developers’ systems to establish a silent foothold as well as facilitate a broad range of post-compromise functionality, such as credential harvesting, keylogging, file manipulation, clipboard monitoring, and network tunneling. “QLNX targets developers and DevOps credentials across the software supply chain,”  – Read More  … Read More “Quasar Linux RAT Steals Developer Credentials for Software Supply Chain Compromise  – The Hacker News” »

Australian Cyber Security Centre Issues Alert Over ClickFix Attacks –

Posted on May 8, 2026 By Joe-W No Comments on Australian Cyber Security Centre Issues Alert Over ClickFix Attacks –
Australian Cyber Security Centre Issues Alert Over ClickFix Attacks –
Privacy/Governance Feed

ACSC warns over a campaign targeting organizations which uses ClickFix to deliver Vidar infostealer malware – Read More  –  

New Linux PamDOORa Backdoor Uses PAM Modules to Steal SSH Credentials  – The Hacker News

Posted on May 8, 2026 By [email protected] (The Hacker News) No Comments on New Linux PamDOORa Backdoor Uses PAM Modules to Steal SSH Credentials  – The Hacker News
New Linux PamDOORa Backdoor Uses PAM Modules to Steal SSH Credentials  – The Hacker News
Attack Feeds

Cybersecurity researchers have disclosed details of a new Linux backdoor named PamDOORa that’s being advertised on the Rehub Russian cybercrime forum for $1,600 by a threat actor called “darkworm.” The backdoor is designed as a Pluggable Authentication Module (PAM)-based post-exploitation toolkit that enables persistent SSH access by means of a magic password and specific TCP … Read More “New Linux PamDOORa Backdoor Uses PAM Modules to Steal SSH Credentials  – The Hacker News” »

One Missed Threat Per Week: What 25M Alerts Reveal About Low-Severity Risk  – The Hacker News

Posted on May 8, 2026 By [email protected] (The Hacker News) No Comments on One Missed Threat Per Week: What 25M Alerts Reveal About Low-Severity Risk  – The Hacker News
One Missed Threat Per Week: What 25M Alerts Reveal About Low-Severity Risk  – The Hacker News
Attack Feeds

The dark secret of enterprise security operations is that defenders have quietly institutionalized the practice of not looking. This is not just anecdotal, but rather backed by a recent report investigating more than 25 million security alerts, including informational and low-severity, across live enterprise environments.  The dataset behind these findings includes 10 million monitored  – … Read More “One Missed Threat Per Week: What 25M Alerts Reveal About Low-Severity Risk  – The Hacker News” »

Sri Lanka makes 37 arrests as it raids another scam centre  – GRAHAM CLULEY

Posted on May 8, 2026 By Graham Cluley No Comments on Sri Lanka makes 37 arrests as it raids another scam centre  – GRAHAM CLULEY
Sri Lanka makes 37 arrests as it raids another scam centre  – GRAHAM CLULEY
Attack Feeds

You don’t need to live near a scam compound for it to wreck your life. Americans lost $5.8 billion to crypto investment scams last year alone – and a raid in Sri Lanka this month shows exactly how the operations behind them keep finding new places to hide. Read more in my article on the … Read More “Sri Lanka makes 37 arrests as it raids another scam centre  – GRAHAM CLULEY” »

PCPJack Campaign Boots TeamPCP Off Compromised Machines –

Posted on May 8, 2026 By Joe-W No Comments on PCPJack Campaign Boots TeamPCP Off Compromised Machines –
PCPJack Campaign Boots TeamPCP Off Compromised Machines –
Privacy/Governance Feed

SentinelOne believes the PCPJack campaign may be the brainchild of a former TeamPCP member – Read More  –  

Linux Kernel Dirty Frag LPE Exploit Enables Root Access Across Major Distributions  – The Hacker News

Posted on May 8, 2026 By [email protected] (The Hacker News) No Comments on Linux Kernel Dirty Frag LPE Exploit Enables Root Access Across Major Distributions  – The Hacker News
Linux Kernel Dirty Frag LPE Exploit Enables Root Access Across Major Distributions  – The Hacker News
Attack Feeds

Details have emerged about a new, unpatched local privilege escalation (LPE) vulnerability impacting the Linux kernel. Dubbed Dirty Frag, it has been described as a successor to Copy Fail (CVE-2026-31431, CVSS score: 7.8), a recently disclosed LPE flaw impacting the Linux kernel that has since come under active exploitation in the wild. The vulnerability was … Read More “Linux Kernel Dirty Frag LPE Exploit Enables Root Access Across Major Distributions  – The Hacker News” »

Canvas Breach Disrupts Schools & Colleges Nationwide  – Krebs on Security

Posted on May 7, 2026 By BrianKrebs No Comments on Canvas Breach Disrupts Schools & Colleges Nationwide  – Krebs on Security
Canvas Breach Disrupts Schools & Colleges Nationwide  – Krebs on Security
Attack Feeds

An ongoing data extortion attack targeting the widely-used education technology platform Canvas disrupted classes and coursework at school districts and universities across the United States today, after a cybercrime group defaced the service’s login page with a ransom demand that threatened to leak data from 275 million students and faculty across nearly 9,000 educational institutions. … Read More “Canvas Breach Disrupts Schools & Colleges Nationwide  – Krebs on Security” »

ShinyHunters Defaces Canvas LMS Portal, Hundreds of Universities Affected  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on May 7, 2026 By Waqas No Comments on ShinyHunters Defaces Canvas LMS Portal, Hundreds of Universities Affected  – Hackread – Cybersecurity News, Data Breaches, AI and More
ShinyHunters Defaces Canvas LMS Portal, Hundreds of Universities Affected  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

ShinyHunters hackers defaced the official Canvas LMS portal after breaching Instructure systems, disrupting university access worldwide.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Hackers Use Fake Claude AI Site to Infect Users With New Beagle Malware  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on May 7, 2026 By Deeba Ahmed No Comments on Hackers Use Fake Claude AI Site to Infect Users With New Beagle Malware  – Hackread – Cybersecurity News, Data Breaches, AI and More
Hackers Use Fake Claude AI Site to Infect Users With New Beagle Malware  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Researchers have discovered a new malvertising campaign using a fake Claude AI website to plant a new, undocumented backdoor named Beagle on user devices.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Ivanti customers confront yet another actively exploited zero-day  – CyberScoop

Posted on May 7, 2026 By Matt Kapko No Comments on Ivanti customers confront yet another actively exploited zero-day  – CyberScoop
Ivanti customers confront yet another actively exploited zero-day  – CyberScoop
Attack Feeds

Attackers are hitting Ivanti customers yet again — circling back to a common target and consistently susceptible vendor in the network edge space — by exploiting a zero-day vulnerability in one of the company’s most besieged products.  Ivanti warned customers that attackers have successfully exploited CVE-2026-6973, an improper input validation defect in Ivanti Endpoint Manager … Read More “Ivanti customers confront yet another actively exploited zero-day  – CyberScoop” »

Trump officials are steering a cybersecurity scholarship program toward AI  – CyberScoop

Posted on May 7, 2026 By Tim Starks No Comments on Trump officials are steering a cybersecurity scholarship program toward AI  – CyberScoop
Trump officials are steering a cybersecurity scholarship program toward AI  – CyberScoop
Attack Feeds

The Trump administration is redirecting a cybersecurity scholarship program that requires recipients to work in government service toward artificial intelligence, leaving some current program scholars dismayed and bewildered. In an email to participating school program coordinators obtained by CyberScoop, the Office of Personnel Management and National Science Foundation said the CyberCorps Scholarship For Service program … Read More “Trump officials are steering a cybersecurity scholarship program toward AI  – CyberScoop” »

PCPJack Credential Stealer Exploits 5 CVEs to Spread Worm-Like Across Cloud Systems  – The Hacker News

Posted on May 7, 2026 By [email protected] (The Hacker News) No Comments on PCPJack Credential Stealer Exploits 5 CVEs to Spread Worm-Like Across Cloud Systems  – The Hacker News
PCPJack Credential Stealer Exploits 5 CVEs to Spread Worm-Like Across Cloud Systems  – The Hacker News
Attack Feeds

Cybersecurity researchers have disclosed details of a new credential theft framework dubbed PCPJack that targets exposed cloud infrastructure and ousts any artifacts linked to TeamPCP from the environments. “The toolset harvests credentials from cloud, container, developer, productivity, and financial services, then exfiltrates the data through attacker-controlled infrastructure while attempting  – Read More  – The Hacker … Read More “PCPJack Credential Stealer Exploits 5 CVEs to Spread Worm-Like Across Cloud Systems  – The Hacker News” »

Ivanti EPMM CVE-2026-6973 RCE Under Active Exploitation Grants Admin-Level Access  – The Hacker News

Posted on May 7, 2026 By [email protected] (The Hacker News) No Comments on Ivanti EPMM CVE-2026-6973 RCE Under Active Exploitation Grants Admin-Level Access  – The Hacker News
Ivanti EPMM CVE-2026-6973 RCE Under Active Exploitation Grants Admin-Level Access  – The Hacker News
Attack Feeds

Ivanti is warning that a new security flaw impacting Endpoint Manager Mobile (EPMM) has been explored in limited attacks in the wild. The high-severity vulnerability, CVE-2026-6973 (CVSS score: 7.2), is a case of improper input validation affecting EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1. It allows “a remotely authenticated user with administrative access to achieve … Read More “Ivanti EPMM CVE-2026-6973 RCE Under Active Exploitation Grants Admin-Level Access  – The Hacker News” »

Multiple Vulnerabilities in Mozilla Products Could Allow for Arbitrary Code Execution  – Cyber Security Advisories – MS-ISAC

Posted on May 7, 2026 By Joe-W No Comments on Multiple Vulnerabilities in Mozilla Products Could Allow for Arbitrary Code Execution  – Cyber Security Advisories – MS-ISAC
Gov/ISAC Feeds

Multiple vulnerabilities have been discovered in Mozilla products, the most severe of which could allow for arbitrary code execution.  Mozilla Firefox is a web browser used to access the Internet. Mozilla Firefox ESR is a version of the web browser intended to be deployed in large organizations. Successful exploitation of the most severe of these … Read More “Multiple Vulnerabilities in Mozilla Products Could Allow for Arbitrary Code Execution  – Cyber Security Advisories – MS-ISAC” »

Researcher Shows Edge Browser Stores Saved Passwords in Plaintext  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on May 7, 2026 By Deeba Ahmed No Comments on Researcher Shows Edge Browser Stores Saved Passwords in Plaintext  – Hackread – Cybersecurity News, Data Breaches, AI and More
Researcher Shows Edge Browser Stores Saved Passwords in Plaintext  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Cybersecurity expert Tom Rønning finds Microsoft Edge loads all saved passwords into computer memory as cleartext, making them easy for hackers to steal.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Cline Kanban Flaw Lets Websites Hijack AI Coding Agents –

Posted on May 7, 2026 By Joe-W No Comments on Cline Kanban Flaw Lets Websites Hijack AI Coding Agents –
Cline Kanban Flaw Lets Websites Hijack AI Coding Agents –
Privacy/Governance Feed

Oasis Security finds critical Cline kanban WebSocket flaw exposing AI coding agents to hijack – Read More  –  

Legacy Security Tools Are Failing Data Protection, Capital One Software Report Finds –

Posted on May 7, 2026 By Joe-W No Comments on Legacy Security Tools Are Failing Data Protection, Capital One Software Report Finds –
Legacy Security Tools Are Failing Data Protection, Capital One Software Report Finds –
Privacy/Governance Feed

Traditional network security tools are undermining data protection, with Forrester and Capital One Software research warning AI adoption is impossible without rethinking data security – Read More  –  

One Click, Total Shutdown: The “Patient Zero” Webinar on Killing Stealth Breaches  – The Hacker News

Posted on May 7, 2026 By [email protected] (The Hacker News) No Comments on One Click, Total Shutdown: The “Patient Zero” Webinar on Killing Stealth Breaches  – The Hacker News
One Click, Total Shutdown: The “Patient Zero” Webinar on Killing Stealth Breaches  – The Hacker News
Attack Feeds

The hardest part of cybersecurity isn’t the technology, it’s the people. Every major breach you’ve read about lately usually starts the same way: one employee, one clever email, and one “Patient Zero” infection. In 2026, hackers are using AI to make these “first clicks” nearly impossible to spot. If a single laptop gets compromised on … Read More “One Click, Total Shutdown: The “Patient Zero” Webinar on Killing Stealth Breaches  – The Hacker News” »

American duo sentenced for hosting laptop farms for North Korean IT workers  – CyberScoop

Posted on May 7, 2026 By Greg Otto No Comments on American duo sentenced for hosting laptop farms for North Korean IT workers  – CyberScoop
American duo sentenced for hosting laptop farms for North Korean IT workers  – CyberScoop
Attack Feeds

Two U.S. nationals were sentenced to 18 months in prison for running laptop farms that facilitated North Korea’s expansive remote IT workers scheme, the Justice Department said Wednesday. Matthew Issac Knoot and Erick Ntekereze Prince both received and hosted laptops at their residences to dupe U.S. companies into thinking remote IT workers they hired were … Read More “American duo sentenced for hosting laptop farms for North Korean IT workers  – CyberScoop” »

Fake Claude AI Site Drops Beagle Backdoor on Windows Users –

Posted on May 7, 2026 By Joe-W No Comments on Fake Claude AI Site Drops Beagle Backdoor on Windows Users –
Fake Claude AI Site Drops Beagle Backdoor on Windows Users –
Privacy/Governance Feed

Sophos finds fake Claude site spreading DonutLoader and a new Beagle backdoor via DLL sideloading – Read More  –  

OpenAI and Anthropic LLMs Used in Critical Infrastructure Cyber-Attack, Warns Dragos –

Posted on May 7, 2026 By Joe-W No Comments on OpenAI and Anthropic LLMs Used in Critical Infrastructure Cyber-Attack, Warns Dragos –
OpenAI and Anthropic LLMs Used in Critical Infrastructure Cyber-Attack, Warns Dragos –
Privacy/Governance Feed

Commercial AI models were used to help plan and conduct cyber-attack against operational technology of a water and drainage facility, say researchers – Read More  –  

Google Chrome Accused of Silently Installing 4GB AI Model on User Devices  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on May 7, 2026 By Deeba Ahmed No Comments on Google Chrome Accused of Silently Installing 4GB AI Model on User Devices  – Hackread – Cybersecurity News, Data Breaches, AI and More
Google Chrome Accused of Silently Installing 4GB AI Model on User Devices  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Cybersecurity researcher Alexander Hanff claims that Google Chrome automatically installs a 4GB Gemini Nano AI model without user notification or consent.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

PAN-OS RCE Exploit Under Active Use Enabling Root Access and Espionage  – The Hacker News

Posted on May 7, 2026 By [email protected] (The Hacker News) No Comments on PAN-OS RCE Exploit Under Active Use Enabling Root Access and Espionage  – The Hacker News
PAN-OS RCE Exploit Under Active Use Enabling Root Access and Espionage  – The Hacker News
Attack Feeds

Palo Alto Networks has disclosed that threat actors may have attempted to unsuccessfully exploit a recently disclosed critical security flaw as early as April 9, 2026. The vulnerability in question is CVE-2026-0300 (CVSS score: 9.3/8.7), a buffer overflow vulnerability in the User-ID Authentication Portal service of Palo Alto Networks PAN-OS software that could allow an … Read More “PAN-OS RCE Exploit Under Active Use Enabling Root Access and Espionage  – The Hacker News” »

Scammers Use Hidden Text to Bypass AI Email Filters in Phishing Scams  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on May 7, 2026 By Deeba Ahmed No Comments on Scammers Use Hidden Text to Bypass AI Email Filters in Phishing Scams  – Hackread – Cybersecurity News, Data Breaches, AI and More
Scammers Use Hidden Text to Bypass AI Email Filters in Phishing Scams  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Scammers are hiding invisible text inside phishing emails to manipulate AI-powered email filters and increase the chances of scams reaching inboxes.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Day Zero Readiness: The Operational Gaps That Break Incident Response  – The Hacker News

Posted on May 7, 2026 By [email protected] (The Hacker News) No Comments on Day Zero Readiness: The Operational Gaps That Break Incident Response  – The Hacker News
Day Zero Readiness: The Operational Gaps That Break Incident Response  – The Hacker News
Attack Feeds

Having an incident response retainer, or even a pre-approved external incident response firm, is not the same as being ready for an incident. A retainer means someone will answer the phone. Operational readiness determines whether that team can do meaningful work the moment they do.  That distinction matters far more than many organizations realize. In … Read More “Day Zero Readiness: The Operational Gaps That Break Incident Response  – The Hacker News” »

ThreatsDay Bulletin: Edge Plaintext Passwords, ICS 0-Days, Patch-or-Die Alerts and 25+ New Stories  – The Hacker News

Posted on May 7, 2026 By [email protected] (The Hacker News) No Comments on ThreatsDay Bulletin: Edge Plaintext Passwords, ICS 0-Days, Patch-or-Die Alerts and 25+ New Stories  – The Hacker News
ThreatsDay Bulletin: Edge Plaintext Passwords, ICS 0-Days, Patch-or-Die Alerts and 25+ New Stories  – The Hacker News
Attack Feeds

Bad week. Turns out the easiest way to get hacked in 2026 is still the same old garbage: shady packages, fake apps, forgotten DNS junk, scam ads, and stolen logins getting dumped into Discord channels like it’s normal. Some of these attack chains don’t even feel sophisticated anymore. More like some tired guy with a … Read More “ThreatsDay Bulletin: Edge Plaintext Passwords, ICS 0-Days, Patch-or-Die Alerts and 25+ New Stories  – The Hacker News” »

Why Outdated Maintenance Software Is a Growing Ransomware Risk  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on May 7, 2026 By Uzair Amir No Comments on Why Outdated Maintenance Software Is a Growing Ransomware Risk  – Hackread – Cybersecurity News, Data Breaches, AI and More
Why Outdated Maintenance Software Is a Growing Ransomware Risk  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Outdated maintenance software increases ransomware risk by exposing weak access controls, unpatched systems, and critical operational data to attackers.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

DPDP Compliance for Healthcare and Pharma: Securing Patient Data with CryptoBind Encryption – JISA Softech Pvt Ltd

Posted on May 7, 2026 By Aakash Chaudhary No Comments on DPDP Compliance for Healthcare and Pharma: Securing Patient Data with CryptoBind Encryption – JISA Softech Pvt Ltd
DPDP Compliance for Healthcare and Pharma: Securing Patient Data with CryptoBind Encryption – JISA Softech Pvt Ltd
Privacy/Governance Feed

The Digital Personal Data Protection (DPDP) Act, 2023, represents a major paradigm shift to how the handling of personal… The post DPDP Compliance for Healthcare and Pharma: Securing Patient Data with CryptoBind Encryption appeared first on JISA Softech Pvt Ltd.  – Read More  – JISA Softech Pvt Ltd 

One House Democrat is pressing Commerce on the government’s spyware use  – CyberScoop

Posted on May 7, 2026 By Tim Starks No Comments on One House Democrat is pressing Commerce on the government’s spyware use  – CyberScoop
One House Democrat is pressing Commerce on the government’s spyware use  – CyberScoop
Attack Feeds

A House Democrat who’s been at the forefront of congressional efforts to scrutinize the federal government’s use of commercial spyware wants the Commerce Department to brief Capitol Hill amid apprehension that the Trump administration might further embrace the technology. Rep. Summer Lee, D-Pa., sent a letter to the department Thursday seeking a briefing on several … Read More “One House Democrat is pressing Commerce on the government’s spyware use  – CyberScoop” »

Daemon Tools Developer Confirms Software Was Trojanized –

Posted on May 7, 2026 By Joe-W No Comments on Daemon Tools Developer Confirms Software Was Trojanized –
Daemon Tools Developer Confirms Software Was Trojanized –
Privacy/Governance Feed

A China-linked threat actor backdoored a version of Daemon Tools to infect thousands – Read More  –  

PyPI Packages Deliver ZiChatBot Malware via Zulip APIs on Windows and Linux  – The Hacker News

Posted on May 7, 2026 By [email protected] (The Hacker News) No Comments on PyPI Packages Deliver ZiChatBot Malware via Zulip APIs on Windows and Linux  – The Hacker News
PyPI Packages Deliver ZiChatBot Malware via Zulip APIs on Windows and Linux  – The Hacker News
Attack Feeds

Cybersecurity researchers have discovered three packages on the Python Package Index (PyPI) repository that are designed to stealthily deliver a previously unknown malware family called ZiChatBot on Windows and Linux systems. “While these wheel packages do implement the features described on their PyPI web pages, their true purpose is to covertly deliver malicious files,” Kaspersky   – … Read More “PyPI Packages Deliver ZiChatBot Malware via Zulip APIs on Windows and Linux  – The Hacker News” »

AI Software Leak Lets Scammers Add Malware and Steal Data and Your Money  – Da Vinci Cybersecurity: Leading Cyber Security Services in South Africa.

Posted on May 7, 2026 By cyberpro No Comments on AI Software Leak Lets Scammers Add Malware and Steal Data and Your Money  – Da Vinci Cybersecurity: Leading Cyber Security Services in South Africa.
AI Software Leak Lets Scammers Add Malware and Steal Data and Your Money  – Da Vinci Cybersecurity: Leading Cyber Security Services in South Africa.
Attack Feeds

AI Leak Fuels Malware Scams. Company source code is proprietary and typically held as top secret. However, a recent software leak accident by Anthropic has led to a cascade of nefarious behaviours by hackers. Anthropic is the well-known creator of Claude AI, and the accidental leak of the source code has allowed scammers to create … Read More “AI Software Leak Lets Scammers Add Malware and Steal Data and Your Money  – Da Vinci Cybersecurity: Leading Cyber Security Services in South Africa.” »

Researchers Spot Uptick in Use of Vercel for Phishing Campaigns –

Posted on May 7, 2026 By Joe-W No Comments on Researchers Spot Uptick in Use of Vercel for Phishing Campaigns –
Researchers Spot Uptick in Use of Vercel for Phishing Campaigns –
Privacy/Governance Feed

Cofense has warned of a “significant” increase in phishing campaigns abusing Vercel platform – Read More  –  

Posts pagination

Previous 1 … 8 9 10 … 41 Next
  • Attack Feeds
  • Privacy/Governance Feed
  • Gov/ISAC Feeds
  • Alert Feeds
  • Privacy Policy
  • Wagner Cybersecurity

Copyright © 2026 AttackFeed by Joe Wagner.

Theme: Oceanly News Dark by ScriptsTown

We are using cookies for analytics purposes only.  We do not store, track or sell user information.

You can find out more about which cookies we are using or switch them off in .

AttackFeed by Joe Wagner
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.