Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
The Hacker Newsby info@thehackernews.com (The Hacker News)·14h ago
The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose...
57%plop scoreSuspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts
The Hacker Newsby info@thehackernews.com (The Hacker News)·14h ago
Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense...
56%plop scoreNew Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data
The Hacker Newsby info@thehackernews.com (The Hacker News)·20h ago
Adversa AI has disclosed an attack technique that it says can cause xAI's Grok chatbot to send a user's name, approximate location, subscription tier, and the prompts from the ongoing conversation...
57%plop scoreIsolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE
The Hacker Newsby info@thehackernews.com (The Hacker News)·21h ago
Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that could allow attackers to...
52%plop scoreCritical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers
The Hacker Newsby info@thehackernews.com (The Hacker News)·21h ago
Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability.
43%plop scoreAttackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution
The Hacker Newsby info@thehackernews.com (The Hacker News)·21h ago
A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska).
Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments
The Hacker Newsby info@thehackernews.com (The Hacker News)·22h ago
Researchers at the University of Massachusetts Amherst have demonstrated an attack that revives expired Visa contactless credit cards for real in-store purchases by rewriting the expiration date a...
57%plop scoreWhy "Shady AI" is Security's Next Big Governance Problem
The Hacker Newsby info@thehackernews.com (The Hacker News)·23h ago
In March 2026, an internal AI agent at Meta triggered a “Sev 1” incident after sensitive company and user data was exposed to employees who weren’t authorized to access it.
57%plop scoreCDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification
The Hacker Newsby info@thehackernews.com (The Hacker News)·23h ago
Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks (CDNs) convert client-facing HTTP/3 traffic into HTTP/1.1 requests to...
53%plop scoreManic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices
The Hacker Newsby info@thehackernews.com (The Hacker News)·23h ago
A new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, government and identity services, and messaging applications, as well as Russian and European financial...
54%plop scoreNASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands
The Hacker Newsby info@thehackernews.com (The Hacker News)·23h ago
Security researchers at Cycode have disclosed a chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL's open-source AMMOS Instrument Toolkit, that allow an unauthenticated...
56%plop scoreToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud
The Hacker Newsby info@thehackernews.com (The Hacker News)·1d ago
Cybersecurity researchers have shed light on an updated version of ToxicPanda (aka TgToxic) that comes with "significant enhancements," including a set of 167 remote commands and expands its...
53%plop score40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets
The Hacker Newsby info@thehackernews.com (The Hacker News)·1d ago
A set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX, Rabby Wallet, TronLink, and other Web3 products.
51%plop scoreElementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code
The Hacker Newsby info@thehackernews.com (The Hacker News)·1d ago
Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution.
54%plop scoreCloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second
The Hacker Newsby info@thehackernews.com (The Hacker News)·1d ago
Cybersecurity researchers have disclosed details of a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located Worker in the production environment at...
53%plop scoreOpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behavior
The Hacker Newsby info@thehackernews.com (The Hacker News)·1d ago
OpenAI on Tuesday revealed that it paused reinforcement learning (RL) training for its latest artificial intelligence (AI) models for two weeks while it shored up additional defenses and increased...
55%plop scoreSilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs
The Hacker Newsby info@thehackernews.com (The Hacker News)·1d ago
A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia.
55%plop scoreHackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P
The Hacker Newsby info@thehackernews.com (The Hacker News)·1d ago
Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two...
53%plop scorePhishing 3.0: The Fight Moves to Agent Versus Agent
The Hacker Newsby info@thehackernews.com (The Hacker News)·1d ago
Most email defenses still do the job they did a decade ago. Scan the message, look for something malicious, block it. That worked when the danger sat in the payload, a bad link or an attachment.
59%plop scoreStopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data
The Hacker Newsby info@thehackernews.com (The Hacker News)·1d ago
Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store...
54%plop scoreYour filters hide everything on this page. Adjust them in preferences.