Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
The Hacker Newsby info@thehackernews.com (The Hacker News)·2d ago
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being...
Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure
The Hacker Newsby info@thehackernews.com (The Hacker News)·2d ago
Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, after correlating recurring endpoint and network behaviors across changing...
Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
The Hacker Newsby info@thehackernews.com (The Hacker News)·2d ago
A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically designed for the enterprise Product Lifecycle...
Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
The Hacker Newsby info@thehackernews.com (The Hacker News)·2d ago
Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other...
Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
The Hacker Newsby info@thehackernews.com (The Hacker News)·2d ago
Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT)...
Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000
The Hacker Newsby info@thehackernews.com (The Hacker News)·2d ago
A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups' servers in exchange...
AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files
The Hacker Newsby info@thehackernews.com (The Hacker News)·2d ago
Security researchers at Anthropic and Switzerland's EPFL have demonstrated that self-propagating payloads can spread from one artificial intelligence (AI) agent to the next through the editable...
TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks
The Hacker Newsby info@thehackernews.com (The Hacker News)·2d ago
Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT.
One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025
The Hacker Newsby info@thehackernews.com (The Hacker News)·3d ago
A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year, according to research published this...
16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
The Hacker Newsby info@thehackernews.com (The Hacker News)·3d ago
Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer.
SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers
The Hacker Newsby info@thehackernews.com (The Hacker News)·3d ago
SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798...
CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
The Hacker Newsby info@thehackernews.com (The Hacker News)·3d ago
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active...
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
The Hacker Newsby info@thehackernews.com (The Hacker News)·3d ago
GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an...
Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection
The Hacker Newsby info@thehackernews.com (The Hacker News)·3d ago
Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository that it said could be...
Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
The Hacker Newsby info@thehackernews.com (The Hacker News)·3d ago
A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on...
Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic
The Hacker Newsby info@thehackernews.com (The Hacker News)·3d ago
Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in...
How MCP Servers Can Expose Enterprise Secrets
The Hacker Newsby info@thehackernews.com (The Hacker News)·4d ago
MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access and prompt injection, often before security teams even know the server is running.
Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access
The Hacker Newsby info@thehackernews.com (The Hacker News)·4d ago
Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through a VoLTE video call...
Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies
The Hacker Newsby info@thehackernews.com (The Hacker News)·4d ago
Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn...
Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware
The Hacker Newsby info@thehackernews.com (The Hacker News)·4d ago
Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT).
Your filters hide everything on this page. Adjust them in preferences.