2026-08-25 11:52 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-25 12:45 UTC
Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. "While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn't do harm, the threat actor’s use of npm isn't to infect developers who install it, but to use the
P0
2026-08-25 11:45 UTC
Security Journalism
The Record · indexed 2026-08-25 11:55 UTC
The Norwegian Digitalisation Agency said it was working with its IT partner to stabilize systems affected by a distributed denial-of-service attack, with some services gradually coming back online.
P0
2026-08-25 11:33 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-25 12:45 UTC
Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE. While threat actors are known to abuse legitimate services to point to additional command-and-control (C2) infrastructure and blend in with regular network traffic, the development
P0
2026-08-25 11:14 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-25 12:45 UTC
Vulnerability management has been a staple of security programs since the dawn of the cybersecurity discipline. The symbiotic relationship between vulnerability and patch management teams has also existed for that time and has gone through waves of contention and thankfulness. While this relationship required thoughtful care and feeding from both sides, both sides were aiming to work toward a
P0
2026-08-25 10:53 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-08-25 11:00 UTC
Law enforcement agencies from 22 countries helped identify 263 suspects and arrested 58 individuals linked to cybercrime networks coordinated by African crime groups. [...]
P0
2026-08-25 10:00 UTC
Vendor Research
Palo Alto Networks Unit 42 · Sara McBroom · indexed 2026-08-25 10:20 UTC
Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution. The post The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution appeared first on Unit 42.
P0
2026-08-25 10:00 UTC
Vendor Research
Cisco Talos Intelligence Blog · David J. Bianco · indexed 2026-08-25 10:15 UTC
As frontier AI models become increasingly restrictive, security teams are facing a "safety penalty" that hampers real-time incident response. Discover how organizations can move toward operational sovereignty to ensure their defensive AI keeps pace with unconstrained adversaries.
P0
2026-08-25 08:48 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-25 09:40 UTC
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Oracle flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw, tracked as CVE-2026-21962 (CVSS score of 10,0), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-21962 is a critical, unauthenticated vulnerability […]
P35
2026-08-25 08:34 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-25 09:40 UTC
Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators. The vulnerabilities, as disclosed by Patchstack, are listed below - CVE-2026-61979 (CVSS score: 8.1) - An unauthenticated privilege escalation
P15
2026-08-25 07:15 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-25 07:25 UTC
WeedHack Minecraft Malware Survives C2 Takedown: Fake Client Sites Still Active, SEO Poisoning Puts Malicious Downloads at the Top of Google McAfee Labs published a follow-up report on the WeedHack Malware-as-a-Service campaign this week, documenting ten active malicious sites and multiple file-hosting accounts that are still spreading the infostealer despite a disruption to its command-and-control […]
P0
2026-08-25 06:12 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-25 06:55 UTC
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-21962 (CVSS score: 10.0), allows an unauthenticated attacker with network access via HTTP to
P60
2026-08-25 02:00 UTC
Community
SANS Internet Storm Center · indexed 2026-08-25 02:15 UTC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
P0
2026-08-24 23:00 UTC
Security Journalism
The Record · indexed 2026-08-24 23:00 UTC
The U.S. sanctioned several Iranian nationals for cyberattacks on critical infrastructure just days after reports emerged of a cyber intrusion on a small power plant in the United Kingdom.
P0
2026-08-24 21:46 UTC
Security Journalism
Dark Reading · Jai Vijayan · indexed 2026-08-24 22:15 UTC
CISA issued a three-day deadline for agencies to patch a Zimbra security vulnerability, CVE-2026-73570, which allows full takeover of a user's communications.
P5
2026-08-24 21:14 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-24 21:15 UTC
An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers used by multiple U.S. broadband providers allows remote, unauthenticated attackers to create port-forwarding rules that can expose local network devices to the public internet. [...]
P0
2026-08-24 20:51 UTC
Security Journalism
Dark Reading · Alexander Culafi · indexed 2026-08-24 21:15 UTC
ClickFix-style threat campaigns are using a new trick to evade detection and deliver Amatera, an increasingly prevalent infostealer.
P0
2026-08-24 20:36 UTC
Security Journalism
The Record · indexed 2026-08-24 20:45 UTC
The legislation would mandate that high-risk social media platforms such as Instagram, TikTok, Snapchat and Facebook take “reasonable steps” to ensure users are over age 16 by using tools like facial age estimation, digital ID services, formal IDs and existing account information for verification.
P0
2026-08-24 19:26 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-24 19:35 UTC
Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. [...]
P10
2026-08-24 18:30 UTC
Security Journalism
The Record · indexed 2026-08-24 18:50 UTC
A Jersey City resident is facing charges for his alleged role as a money mule for overseas cyberscammers who stole millions from elderly New Yorkers.
P0
2026-08-24 17:56 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-24 18:10 UTC
The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children's Online Privacy Protection Act (COPPA). [...]
P0
2026-08-24 17:41 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-24 12:10 UTC
If your developers are using AI coding tools, you are probably already seeing the upside: faster development, more code, and less time spent on routine work. The harder part is what comes after. AI can also introduce open-source packages at a pace your security team was never built to handle. More dependencies mean more vulnerabilities to review, more remediation work, and a backlog that can
P0
2026-08-24 17:41 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-24 23:15 UTC
Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft clients. McAfee Labs said it detected and blocked more than 6,300 attempts to access malicious sites, adding that it found lookalike gaming websites designed to mimic legitimate projects, including branding, feature lists, FAQs,
P0
2026-08-24 17:27 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-24 18:10 UTC
A fake 113GB GTA VI build is packed with malware, using massive empty files to hide a tiny malicious payload. GTA VI hype has reached the point where people are volunteering to infect their own computers just to check if a leak is real. Someone on X asked their followers to “take one for the […]
P0
2026-08-24 16:18 UTC
Vendor Research
Rapid7 · Stephen Fewer · indexed 2026-08-24 17:30 UTC
P20
2026-08-24 15:17 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-24 15:30 UTC
Cybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a member of the security team. [...]
P0
2026-08-24 15:02 UTC
Security Journalism
Dark Reading · Nate Nelson · indexed 2026-08-24 15:50 UTC
An advanced, multilingual malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along with a slew of novel features.
P15
2026-08-24 14:34 UTC
Security Journalism
Dark Reading · Elizabeth Montalbano · indexed 2026-08-24 15:05 UTC
The latest version of the Android malware has new features that expand its global reach and put more than users' financial applications at risk.
P0
2026-08-24 14:32 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-24 16:05 UTC
A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet. That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes exploit work cheaper, and researchers keep finding attacks that sound harder than they actually are. Plenty to clean up. Here’s the short version. ⚡ Threat of the Week U.S.
P0
2026-08-24 14:00 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-08-24 14:05 UTC
Microsoft is rolling out a new Teams meeting protection policy that allows administrators to automatically block all identified external bots from joining Teams meetings. [...]
P0
2026-08-24 14:00 UTC
Security Journalism
BleepingComputer · Sponsored by Penta Security · indexed 2026-08-24 14:05 UTC
A breach at South Korea's government-backed startup platform exposed encrypted personal data after an encryption key was included in an API. Penta Security explains why encryption keys must be securely managed and kept separate from the data they protect. [...]
P0