20+ Hijacked Government Websites Became an Attack ChannelThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Vulnerability42
OpenAI’s GPT-Red Automates Prompt Injection Testing to Harden GPTThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026AI safety & security30
North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer SecretsThe Hacker News·Jul 3, 16:07 UTC · Jul 3, 2026Data breach57
Mirage2FA phishing kit uses HTML smuggling to steal Microsoft 365 credentialsHelp Net Security·Jun 26, 00:00 UTC · Jun 26, 2026Phishing & fraud130
Embedding Forbidden Text in Spyware to Discourage AI AnalysisSchneier on Security·Jun 24, 11:04 UTC · Jun 24, 2026Malware30
Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and TorThe Hacker News·Jun 20, 17:30 UTC · Jun 20, 2026Malware42
Tor-Based Clipper Malware Targets Wallet Seed PhrasesSecurity Affairs·Jun 18, 18:32 UTC · Jun 18, 2026Malware42
Embedding Forbidden Text in Spyware to Discourage AI AnalysisSchneier on Security·Jun 18, 11:04 UTC · Jun 18, 2026Malware30
Attackers compromised Awesome Motive CDN files, backdooring WordPress sites running OptinMonster, TrustPulse, and PushEngageSecurity Affairs·Jun 15, 08:52 UTC · Jun 15, 2026Malware42
LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway ServersThe Hacker News·Jun 15, 00:00 UTC · Jun 15, 2026AI safety & security in the wildCVE-2026-47101CVE-2026-47102CVE-2026-40217+1 CVEs50
⚡ Weekly Recap: Instagram Account Hacks, Android ZeroThe Hacker News·Jun 9, 05:53 UTC · Jun 9, 2026Exploit / PoC in the wildCVE-2025-48595CVE-2026-28318CVE-2026-39210+43 CVEs60
Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over SitesThe Hacker News·Jun 5, 08:38 UTC · Jun 5, 2026VulnerabilityCVE-2026-330060
Google Is Quietly Buying Code From Play Store Developers to Train AI404 Media·Jun 3, 00:16 UTC · Jun 3, 2026AI industry30
March 2026 CVE Landscape: 31 High-Impact Vulnerabilities Identified, Interlock Ransomware Group Exploits Cisco FMC ZeroRecorded Future·Jun 3, 00:00 UTC · Jun 3, 2026Ransomware in the wildCVE-2017-7921CVE-2026-27483CVE-2026-27944+10 CVEs260
OWASP Agent Memory Guard: Stop AI agents from being weaponized through their own memoryHelp Net Security·Jun 1, 00:00 UTC · Jun 1, 2026AI safety & security130
Claude now reviews and fixes vulnerabilities as you write codeHelp Net Security·May 27, 00:00 UTC · May 27, 2026Vulnerability30
Ghostwriter Is Back, Using a Ukrainian Learning Platform as Bait to Hit Government TargetsSecurity Affairs·May 23, 09:39 UTC · May 23, 2026Data breach57
Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing MalwareThe Hacker News·May 23, 07:09 UTC · May 23, 2026Malware42
Tuskira’s Kairo exposes hidden AI-driven breach pathsHelp Net Security·May 13, 00:00 UTC · May 13, 2026Exploit / PoC60
Claude finds 353 zeroSansec (Magento / e-commerce security)·Apr 14, 19:49 UTC · Apr 14, 2026Data breach60
Building a faster YARA engine in pure GoSansec (Magento / e-commerce security)·Apr 14, 19:49 UTC · Apr 14, 2026Malware42
NaturalFreshMall: a Magento Mass HackSansec (Magento / e-commerce security)·Apr 14, 19:49 UTC · Apr 14, 2026Vulnerability42
Over 200 PrestaShop stores expose installer, allowing full takeoverSansec (Magento / e-commerce security)·Apr 14, 13:40 UTC · Apr 14, 2026Vulnerability in the wildCVE-2026-7565060
GlassWorm Malware Uses Solana Dead Drops to Deliver RAT and Steal Browser, Crypto DataThe Hacker News·Mar 25, 16:42 UTC · Mar 25, 2026Malware30
Google's TurboQuant cuts AI memory use without losing accuracyHelp Net Security·Mar 25, 00:00 UTC · Mar 25, 2026AI research30
GlassWorm Attack Uses Stolen GitHub Tokens to ForceThe Hacker News·Mar 21, 07:03 UTC · Mar 21, 2026Data breach57
CVE-2026-1731 fuels ongoing attacks on BeyondTrust remote access productsSecurity Affairs·Feb 23, 12:09 UTC · Feb 23, 2026Vulnerability in the wildCVE-2026-173160
OpenClaw Integrates VirusTotal Scanning to Detect Malicious ClawHub SkillsThe Hacker News·Feb 9, 07:27 UTC · Feb 9, 2026Vulnerability55
Bandit: Open-source tool designed to find security issues in Python codeHelp Net Security·Jan 21, 00:00 UTC · Jan 21, 2026Tools130
Microsoft Legal Action Disrupts RedVDS Cybercrime Infrastructure Used for Online FraudThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2026Phishing & fraud42
Fake OSINT and GPT Utility GitHub Repos Spread PyStoreRAT Malware PayloadsThe Hacker News·Dec 12, 18:50 UTC · Dec 12, 2025Malware30
October 2025 CVE LandscapeRecorded Future·Dec 9, 00:00 UTC · Dec 9, 2025Ransomware in the wildCVE-2025-59287CVE-2025-61882CVE-2025-41244+29 CVEs60
Contagious Interview campaign expands with 197 npm Ppackages spreading new OtterCookie malwareSecurity Affairs·Nov 30, 01:02 UTC · Nov 30, 2025Malware42
Understanding Accellion’s FTA Appliance Compromise, DEWMODE, and Its Supply Chain ImpactRecorded Future·Nov 21, 00:00 UTC · Nov 21, 2025RansomwareCVE-2021-27101CVE-2021-27102CVE-2021-27103+1 CVEs60
⚡ Weekly Recap: Fortinet Exploited, China's AI Hacks, PhaaS Empire Falls & MoreThe Hacker News·Nov 17, 12:37 UTC · Nov 17, 2025Exploit / PoC in the wildCVE-2025-64446CVE-2025-64740CVE-2025-64741+24 CVEs60
RondoDox Exploits Unpatched XWiki Servers to Pull More Devices Into Its BotnetThe Hacker News·Nov 15, 00:00 UTC · Nov 15, 2025Vulnerability in the wildCVE-2025-2489360
Millions of sites at risk from Imunify360 critical flaw exploitSecurity Affairs·Nov 14, 14:58 UTC · Nov 14, 2025Exploit / PoC in the wild60
⚡ Weekly Recap: Hyper-V Malware, Malicious AI Bots, RDP Exploits, WhatsApp Lockdown and MoreThe Hacker News·Nov 10, 12:51 UTC · Nov 10, 2025MalwareCVE-2025-21042160
SesameOp: New backdoor exploits OpenAI API for covert C2Security Affairs·Nov 4, 17:06 UTC · Nov 4, 2025Malware42
Over 100 VS Code Extensions Exposed Developers to Hidden Supply Chain RisksThe Hacker News·Oct 31, 07:59 UTC · Oct 31, 2025Ransomware60