WindRelay pairs with SpyNote to relay live NFC card data from infected Android phones, enabling contactless payment fraud in real time.
APT36-linked hackers target Afghan telecom and Indian networks with new PATCHCORD and SHEETCORD backdoors using fake tools and Google Sheets for C2.
AmnesiaStealer uses a ClickFix lure to infect macOS, steal browser sessions, and give attackers live Chromium control via CDP.
Attackers exploit SharePoint CVE-2026-55040 after a Rapid7 PoC release, forging JWTs to impersonate site users or admins.
Replayable AI reasoning blocks let researchers recover API keys and passwords from public logs; they say the main extraction attack is now mitigated.
Malicious LiteLLM PyPI releases stole cloud and SSH keys, Kubernetes tokens, and other secrets, potentially exposing 2,500+ ...
Lazarus-linked attacks exploit Windows CVE-2026-68820 as a zero-day to gain SYSTEM access and deploy Troy against defense and aerospace firms.
Adobe patches seven ColdFusion, Commerce, and Campaign Classic flaws that could enable code execution, privilege escalation, or denial-of-service.
Chrome VPN extensions with 75,486 installs route browser traffic through SOCKS5 proxies, putting the operator in an AitM position.
Picus' Blue Report 2026 finds 69% prevention across more than 338 million simulations, but post-compromise prevention falls to 37%.
Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access | Read more hacking news on The Hacker News cybersecurity news website and learn how to protect against cyberattacks and ...
Microsoft says Storm-1175 is deploying new StormEncryptor ransomware, likely after exploiting N-able N-central CVE-2026-18577 ...