The Hacker News·23h ago criticalAttackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure#cve-2026-87902#exploit#malware 16 sources in the wild 2 min1
The Hacker News·1d ago criticalOpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files#ai-agent#australia#breach 22 sources in the wild 5 min
CSO Online·1d agoDocumentation placeholder domain used in ClickFix attacks#clickfix#social-engineering#powershell 4 sources in the wild
BleepingComputer·1d ago highNew Carbonato malware uses AI agents to hijack exposed Docker hosts#carbonato#docker#botnet 3 sources in the wild 3 min
Kaspersky Securelist·1d ago highMacSync under the microscope: new delivery methods and a new payload#backdoor#crypto#dropper 4 sources in the wild 15 min
SANS Internet Storm Center·2d agoMacfinger ClickFix campaign, (Tue, Sep 22nd)#clickfix#macos#malware 3 sources in the wild 6 min
oss-security·2d ago highRe: CVE-2026-95831: Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL#cpan#perl#supply-chainCVE-2026-95831 4 sources in the wild
Dark Reading·2d agoSectopRAT Returns, Hiding Inside a Legitimate Application#sectoprat#rat#malware in the wild
Hacker News · AI·2d agoGitHub has not removed malicious imitation software after 3 weeks#github#malware#impersonation
SOCRadar·2d agoOperation Conflict Compass: Konni Targets Ukraine via Malicious LNK Lures#apt#cyber-espionage#konni 3 sources in the wild
BleepingComputer·2d ago highMalicious npm packages evade install-script defenses at runtime#checkmarx#ethereum#javascript 8 sources in the wild 3 min
Cisco Talos·3d agoThe Closed Quorum: Inside the first reported autonomous AI C2 implant#ai#autonomous#c2 13 sources 15 min
Cyber Security News·3d ago highThe Malware Hiding in Developer Tools That Turned Terraform Providers Into Attack Paths#c2#ethereum#golang 4 sources in the wild 5 min
Cyber Security News·3d agoThe Domains Keep Disappearing, but the Malware Infrastructure Behind Them Never Moves#fake-captcha#clickfix#malware in the wild 11 min
GBHackers·3d ago highAI-Powered Threats Exploit Digital Trust Through Autonomous Breach Techniques#ai-threats#apt#china 2 sources in the wild 4 min
Cyber Security News·3d agoA Fake Streaming App Turned Android Phones Into Remote-Controlled Devices#streamrat#android#malware 2 sources in the wild 5 min
Cyber Security News·4d ago highWordPress Malware Uses Hidden Plugin and Blockchain C2 to Stay Undetected#wordpress#malware#etherhiding 3 sources in the wild 6 min1
Schneier on Security·4d agoGPT-6 Astra Breaks an Old Enigma Message#cyber#malware#threat-actorThreat actor
GBHackers·4d ago highCritical MaxKB AI Agent Flaw Lets Prompt Injection Execute System Commands#cyber#exploit#malware in the wild 4 min2
Hugging Face Blog·5d agoJun Kim, oMLX creator and maintainer, joins Hugging Face to support the MLX community#cyber#exploit#malwareThreat actor in the wild
Dark Reading·5d agoCybercriminals Are Hiding New Malware in Torrents for Popular Films#malware#torrents#piracy in the wild
Help Net Security·5d ago highNorth Korea’s job interview scam runs both ways#apt#credential-theft#malware 3 sources in the wild 5 min
SOCRadar·5d agoDominican Republic Leak, Celestial Malware, Money Network Sale, CVV Auction, and US VPN Access#celestial#cvv#darkweb
Hacker News · security·6d ago highNorth Korean Hackers Posed as Recruiters. They Infected 30k Devices Worldwide#espionage#fake-recruiter#job-lureThreat actor in the wild