ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New StoriesThe Hacker News·Jun 4, 14:00 UTC · Jun 4, 2026Malware in the wildCVE-2026-20230160
ThreatsDay Bulletin: Edge Plaintext Passwords, ICS 0-Days, Patch-orThe Hacker News·May 7, 17:59 UTC · May 7, 2026VulnerabilityCVE-2026-7411CVE-2026-7412CVE-2026-467060
Roundcube RCE: Dark web activity signals imminent attacks (CVE-2025-49113)Help Net Security·Feb 23, 10:54 UTC · Feb 23, 2026Vulnerability in the wildCVE-2025-49113CVE-2024-42009CVE-2025-6846160
Researchers Spot Modified Shai-Hulud Worm Testing Payload on npm RegistryThe Hacker News·Jan 1, 10:11 UTC · Jan 1, 2026Malware42
Most Parked Domains Now Serving Malicious ContentKrebs on Security·Dec 15, 00:00 UTC · Dec 15, 2025Malware30
Analysis of TAG-140 Campaign and DRAT V2 Development Targeting Indian Government OrganizationsRecorded Future·Nov 21, 00:00 UTC · Nov 21, 2025Malware42
Detour Dog Caught Running DNS-Powered Malware Factory for Strela StealerThe Hacker News·Oct 4, 14:36 UTC · Oct 4, 2025Malware42
RedAlpha Conducts Multi-Year Credential Theft Campaign Targeting Global Humanitarian, Think Tank, and Government OrganizationsRecorded Future·Aug 22, 00:00 UTC · Aug 22, 2025Threat actor60
FTC warns tech companies not to weaken encryption, free speech practices for foreign governmentsCyberScoop·Aug 21, 18:12 UTC · Aug 21, 2025Policy & legal in the wild60
Chinese State-Sponsored Group TA413 Adopts New Capabilities in Pursuit of Tibetan TargetsRecorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Threat actorCVE-2022-1040CVE-2022-3019060
Investigating Cyber Vigilantes in #OpAntiISISRecorded Future·Jun 27, 00:00 UTC · Jun 27, 2025Policy & legal30
WordPress Sites Turned Weapon: How VexTrio and Affiliates Run a Global Scam NetworkThe Hacker News·Jun 15, 00:00 UTC · Jun 15, 2025Phishing & fraud30
Hackers Are Calling Your Office: FBI Alerts Law Firms to Luna Moth’s Stealth Phishing CampaignThe Hacker News·May 28, 10:52 UTC · May 28, 2025Threat actor57
AkiraBot Targets 420,000 Sites with OpenAI-Generated Spam, Bypassing CAPTCHA ProtectionsThe Hacker News·Apr 12, 05:13 UTC · Apr 12, 2025Ransomware45
A flaw in Verizon ’s iOS Call Filter app exposed call records of millionsSecurity Affairs·Apr 5, 18:59 UTC · Apr 5, 2025Vulnerability42
WordPress Skimmers Evade Detection by Injecting Themselves into Database TablesThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2025Data breach145
Russia disrupts internet access in multiple regions to test ‘sovereign internet’The Record·Dec 9, 18:47 UTC · Dec 9, 2024Policy & legal30
Beware: Fake Google Meet Pages Deliver Infostealers in Ongoing ClickFix CampaignThe Hacker News·Nov 7, 04:20 UTC · Nov 7, 2024Malware30
GiveWP WordPress Plugin Vulnerability Puts 100,000+ Websites at RiskThe Hacker News·Aug 21, 04:35 UTC · Aug 21, 2024VulnerabilityCVE-2024-5932CVE-2024-6500CVE-2024-7094+4 CVEs60
DigiCert to Revoke 83,000+ SSL Certificates Due to Domain Validation OversightThe Hacker News·Aug 15, 04:59 UTC · Aug 15, 2024Industry55
Cyber Threat Landscape: 7 Key Findings and Upcoming Trends for 2024The Hacker News·Jan 25, 13:43 UTC · Jan 25, 2024Ransomware57
Balada Injector Infects Over 7,100 WordPress Sites Using Plugin VulnerabilityThe Hacker News·Jan 22, 01:32 UTC · Jan 22, 2024VulnerabilityCVE-2023-600047
How today's workforce stays secure and what apps it prefersHelp Net Security·Dec 14, 14:30 UTC · Dec 14, 2023Research130
ManageEngine launches PAM360, a privileged access security solution for enterprise ITHelp Net Security·Dec 14, 12:39 UTC · Dec 14, 2023Data breach60
Spotting and blacklisting malicious COVID-19-themed sitesHelp Net Security·Nov 14, 12:24 UTC · Nov 14, 2023Malware30
.US Harbors Prolific Malicious Link Shortening ServiceKrebs on Security·Oct 31, 15:13 UTC · Oct 31, 2023Malware42
Email forwarding flaws enable attackers to impersonate high-profile domainsHelp Net Security·Sep 11, 00:00 UTC · Sep 11, 2023Vulnerability30
Cybercriminals Increasingly Using EvilProxy Phishing Kit to Target ExecutivesThe Hacker News·Aug 10, 09:45 UTC · Aug 10, 2023Phishing & fraud30
Hackers Exploit Outdated WordPress Plugin to Backdoor Thousands of WordPress SitesThe Hacker News·Apr 28, 03:19 UTC · Apr 28, 2023Malware42
Over 1 Million WordPress Sites Infected by Balada Injector Malware CampaignThe Hacker News·Apr 11, 04:31 UTC · Apr 11, 2023Malware42
Nudge Security launches SaaS attack surface management capabilitiesHelp Net Security·Feb 23, 00:00 UTC · Feb 23, 2023Threat actor60
Massive AdSense Fraud Campaign UncoveredThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2023Threat actor57
Over 4,500 WordPress Sites Hacked to Redirect Visitors to Sketchy Ad PagesThe Hacker News·Jan 28, 05:30 UTC · Jan 28, 2023Malware30
WordPress Security Alert: New Linux Malware Exploiting Over Two Dozen CMS FlawsThe Hacker News·Jan 17, 12:32 UTC · Jan 17, 2023MalwareCVE-2016-10972CVE-2019-17232CVE-2019-1723347
Thousands of npm accounts use email addresses with expired domainsThe Record·Jan 17, 00:00 UTC · Jan 17, 2023Vulnerability42
Ridding Hackers From Government Networks Will Be “Highly Complex and Challenging,” CISA WarnsThe Record·Nov 17, 09:36 UTC · Nov 17, 2022Advisory55
ReasonLabs Unveils Multimillion Dollar Global Credit Card ScamInfosecurity Magazine·Sep 26, 17:00 UTC · Sep 26, 2022Phishing & fraud42
Crooks are using lures related to Her Majesty Queen Elizabeth II in phishing attacksSecurity Affairs·Sep 15, 05:22 UTC · Sep 15, 2022Phishing & fraud42
New EvilProxy Phishing Service Allowing Cybercriminals to Bypass 2The Hacker News·Sep 6, 09:06 UTC · Sep 6, 2022Phishing & fraud42