Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag ImagesThe Hacker News·Jul 19, 18:14 UTC · Jul 19, 2026Malware42
Modular macOS Stealer Uses Kill Loops to Force Password EntryInfosecurity Magazine·Jul 16, 13:30 UTC · Jul 16, 2026Malware42
Smarter Cybersecurity with IPv6: How Drip Architecture Defeats Spray-andRecorded Future·Jul 16, 00:00 UTC · Jul 16, 2026RansomwareCVE-2025-31324CVE-2024-3400CVE-2023-4966+1 CVEs60
New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their PasswordThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Malware42
Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters ActivityThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Ransomware45
Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During InstallThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Malware30
Week in review: Accenture data breach, great open-source cybersecurity toolsHelp Net Security·Jul 12, 00:00 UTC · Jul 12, 2026Data breach in the wildCVE-2026-48282CVE-2026-55255CVE-2026-50656160
Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 ServersThe Hacker News·Jul 10, 11:47 UTC · Jul 10, 2026Vulnerability in the wildCVE-2026-4253060
The Kill Chain Is Obsolete When Your AI Agent Is the ThreatThe Hacker News·Jul 9, 15:37 UTC · Jul 9, 2026Vulnerability55
New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet MalwareThe Hacker News·Jul 8, 15:19 UTC · Jul 8, 2026Malware30
SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking UsersThe Hacker News·Jul 8, 12:52 UTC · Jul 8, 2026Malware30
GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in CodeThe Hacker News·Jul 8, 11:21 UTC · Jul 8, 2026AI safety & security130
⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and MoreThe Hacker News·Jul 6, 13:02 UTC · Jul 6, 2026RansomwareCVE-2026-48276CVE-2026-48283CVE-2026-48277+69 CVEs160
When checking the URL isn't enough: phishing via the Microsoft identity platformKaspersky Securelist·Jul 6, 09:00 UTC · Jul 6, 2026Phishing & fraud30
North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider CampaignThe Hacker News·Jul 4, 11:17 UTC · Jul 4, 2026Threat actor45
North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer SecretsThe Hacker News·Jul 3, 16:07 UTC · Jul 3, 2026Data breach57
New infosec products of the week: July 3, 2026Help Net Security·Jul 3, 00:00 UTC · Jul 3, 2026Policy & legal30
New iboss platform gives organizations instant visibility into AI tools and usageHelp Net Security·Jul 2, 00:00 UTC · Jul 2, 2026Policy & legal130
Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python InfostealerThe Hacker News·Jul 1, 10:25 UTC · Jul 1, 2026Malware142
Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak DataThe Hacker News·Jun 30, 17:46 UTC · Jun 30, 2026Data breach57
GuardFall Exposes Open-Source AI Coding Agents to DecadesThe Hacker News·Jun 30, 14:26 UTC · Jun 30, 2026Vulnerability142
Hottest cybersecurity open-source tools of the month: June 2026Help Net Security·Jun 30, 00:00 UTC · Jun 30, 2026Policy & legal30
Week in review: Fortibleed campaign’s impact on orgs, Cisco Unified CM flaw exploitedHelp Net Security·Jun 28, 00:00 UTC · Jun 28, 2026Threat actor in the wildCVE-2026-2023060
Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP ConfigsThe Hacker News·Jun 26, 13:53 UTC · Jun 26, 2026Exploit / PoCCVE-2026-12957CVE-2026-12958CVE-2025-59536+2 CVEs60
The Tokenpocalypse Is Here: Companies Are Scrambling To Stop Spending So Much on AI404 Media·Jun 25, 14:24 UTC · Jun 25, 2026Industry130
Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer DataThe Hacker News·Jun 25, 05:27 UTC · Jun 25, 2026Ransomware45
Legit Security brings agentic AI to AppSec remediation and risk reductionHelp Net Security·Jun 17, 00:00 UTC · Jun 17, 2026Policy & legal55
North Korean Hackers Are Turning Developer Tools Into Malware Delivery ChannelsThe Hacker News·Jun 15, 00:00 UTC · Jun 15, 2026Malware42
Agentjacking Attack Tricks AI Coding Agents Into Running Malicious CodeThe Hacker News·Jun 12, 12:04 UTC · Jun 12, 2026Vulnerability155
New “Agentjacking” Attacks Could Hijack AI Coding AgentsInfosecurity Magazine·Jun 11, 09:15 UTC · Jun 11, 2026Phishing & fraud55
Prompt injection still drives most agentic AI security failures in productionHelp Net Security·Jun 11, 00:00 UTC · Jun 11, 2026AI safety & securityCVE-2025-6514CVE-2026-22708CVE-2025-5953235
New SilabRAT Trojan Hijacks Sessions to Steal CryptoInfosecurity Magazine·Jun 10, 15:30 UTC · Jun 10, 2026Malware30
CVE-2026-23111: Linux nf_tables Flaw Enables Root ExploitsSecurity Affairs·Jun 9, 07:27 UTC · Jun 9, 2026VulnerabilityCVE-2026-2311135
Elastic brings AI-driven incident investigation to Kubernetes and observability toolsHelp Net Security·Jun 9, 00:00 UTC · Jun 9, 2026Industry30
New Relic expands observability into AI-assisted software developmentHelp Net Security·Jun 8, 00:00 UTC · Jun 8, 2026Policy & legal130
IronWorm and New Miasma Worm Variant Hit npm in Supply Chain AttacksThe Hacker News·Jun 6, 06:23 UTC · Jun 6, 2026Data breach57
ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New StoriesThe Hacker News·Jun 4, 14:00 UTC · Jun 4, 2026Malware in the wildCVE-2026-20230160
Threat Actor Uses AI to Build EDR Evasion ToolsInfosecurity Magazine·Jun 2, 11:00 UTC · Jun 2, 2026Threat actor57
Sophos uncovers AI-powered malware lab built for EDR evasionHelp Net Security·Jun 2, 00:00 UTC · Jun 2, 2026Malware142