- Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K Downloadsby info@thehackernews.com (The Hacker News) on May 11, 2026
A malicious Hugging Face repository managed to take a spot in the platform's trending list by impersonating OpenAI's Privacy Filter open-weight model to […]
- Hackers abuse Google ads, Claude.ai chats to push Mac malwareby Ax Sharma on May 10, 2026
Attackers are abusing Google Ads and legitimate Claude.ai shared chats in an active malvertising campaign. Users searching for "Claude mac download" may come […]
- Police shut down reboot of Crimenetwork marketplace, arrest adminby Bill Toulas on May 10, 2026
German authorities have shut down a relaunch version of the criminal marketplace 'Crimenetwork' that generated more than 3.6 million euros, and arrested its […]
- Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leakby info@thehackernews.com (The Hacker News) on May 10, 2026
Cybersecurity researchers have disclosed a critical security vulnerability in Ollama that, if successfully exploited, could allow a remote, unauthenticated […]
- JDownloader site hacked to replace installers with Python RAT malwareby Lawrence Abrams on May 9, 2026
The website for the popular JDownloader download manager was compromised earlier this week to distribute malicious Windows and Linux installers, with the […]
- Fake OpenAI repository on Hugging Face pushes infostealer malwareby Bill Toulas on May 9, 2026
A malicious Hugging Face repository that reached the platform's trending list impersonated OpenAI's "Privacy Filter" project to deliver information-stealing […]
- cPanel, WHM Release Fixes for Three New Vulnerabilities — Patch Nowby info@thehackernews.com (The Hacker News) on May 9, 2026
cPanel has released updates to address three vulnerabilities in cPanel and Web Host Manager (WHM) that could be exploited to achieve privilege escalation, code […]
- TCLBANKER Banking Trojan Targets Financial Platforms via WhatsApp and Outlook Wormsby info@thehackernews.com (The Hacker News) on May 8, 2026
Threat hunters have flagged a previously undocumented Brazilian banking trojan dubbed TCLBANKER that's capable of targeting 59 banking, fintech, and […]
- CISA Launches Initiative to Improve Critical Infrastructure Resilience During Geopolitical Conflictsby Steve Alder on May 8, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has announced a new initiative aimed at improving critical infrastructure cyber resilience […]
- NVIDIA confirms GeForce NOW data breach affecting Armenian usersby Bill Toulas on May 8, 2026
NVIDIA has confirmed in a statement for BleepingComputer that GeForce NOW user information has been exposed in a data breach. [...]
- Fake Call History Apps Stole Payments From Users After 7.3 Million Play Store Downloadsby info@thehackernews.com (The Hacker News) on May 8, 2026
Cybersecurity researchers have discovered fraudulent apps on the official Google Play Store for Android that falsely claimed to offer access to call histories […]
- Healthcare Organizations Exposing Patient Data Via Poorly Secured DICOM Serversby Steve Alder on May 8, 2026
Healthcare organizations are exposing a vast amount of patient data by failing to implement even basic security measures for DICOM The post Healthcare […]
- Why More Analysts Won’t Solve Your SOC’s Alert Problemby Sponsored by Prophet Security on May 8, 2026
Attackers move faster than overwhelmed SOC teams can realistically investigate alerts. Prophet Security breaks down how AI can help analysts investigate alerts […]
- One Click, Total Shutdown: The "Patient Zero" Webinar on Killing Stealth Breachesby info@thehackernews.com (The Hacker News) on May 8, 2026
The hardest part of cybersecurity isn't the technology, it’s the people. Every major breach you’ve read about lately usually starts the same way: one […]
- Trellix source code breach claimed by RansomHouse hackersby Bill Toulas on May 8, 2026
The attack on the Trellix source code repository disclosed last week has been claimed by the RansomHouse threat group, which leaked a small set of images as […]
- CISA gives feds four days to patch Ivanti flaw exploited as zero-dayby Sergiu Gatlan on May 8, 2026
CISA has given U.S. federal agencies four days to secure their networks against a high-severity vulnerability in Ivanti Endpoint Manager Mobile (EPMM) […]
- Quasar Linux RAT Steals Developer Credentials for Software Supply Chain Compromiseby info@thehackernews.com (The Hacker News) on May 8, 2026
A previously undocumented Linux implant codenamed Quasar Linux RAT (QLNX) is targeting developers' systems to establish a silent foothold as well as facilitate […]
- Zara data breach exposed personal information of 197,000 peopleby Sergiu Gatlan on May 8, 2026
Hackers who gained access to the databases of Spanish fast-fashion retailer Zara stole data belonging to more than 197,000 customers, according to data breach […]
- One Missed Threat Per Week: What 25M Alerts Reveal About Low-Severity Riskby info@thehackernews.com (The Hacker News) on May 8, 2026
The dark secret of enterprise security operations is that defenders have quietly institutionalized the practice of not looking. This is not just anecdotal, but […]
- Former govt contractor convicted for wiping dozens of federal databasesby Sergiu Gatlan on May 8, 2026
A 34-year-old Virginia man was found guilty of conspiring to destroy dozens of government databases after getting fired from his job as a federal contractor. […]
- New Linux PamDOORa Backdoor Uses PAM Modules to Steal SSH Credentialsby info@thehackernews.com (The Hacker News) on May 8, 2026
Cybersecurity researchers have disclosed details of a new Linux backdoor named PamDOORa that's being advertised on the Rehub Russian cybercrime forum for […]
- New Linux 'Dirty Frag' zero-day gives root on all major distrosby Sergiu Gatlan on May 8, 2026
A new Linux zero-day exploit, named Dirty Frag, allows local attackers to gain root privileges on most major Linux distributions with a single command. [...]
- Linux Kernel Dirty Frag LPE Exploit Enables Root Access Across Major Distributionsby info@thehackernews.com (The Hacker News) on May 8, 2026
Details have emerged about a new, unpatched local privilege escalation (LPE) vulnerability impacting the Linux kernel. Dubbed Dirty Frag, it has been described […]
- Canvas Breach Disrupts Schools & Colleges Nationwideby BrianKrebs on May 8, 2026
An ongoing data extortion attack targeting the widely-used education technology platform Canvas disrupted classes and coursework at school districts and […]
- Canvas login portals hacked in mass ShinyHunters extortion campaignby Lawrence Abrams on May 7, 2026
The ShinyHunters extortion gang has breached education technology giant Instructure again, this time exploiting another vulnerability to deface Canvas login […]
- New TCLBanker malware self-spreads over WhatsApp and Outlookby Bill Toulas on May 7, 2026
A new trojan named TCLBanker, which targets 59 banking, fintech, and cryptocurrency platforms, uses a trojanized MSI installer for Logitech AI Prompt Builder […]
- New PCPJack worm steals credentials, cleans TeamPCP infectionsby Bill Toulas on May 7, 2026
A new malware framework called PCPJack is stealing credentials from exposed cloud infrastructure while actively removing TeamPCP's access to the systems. [...]
- Australia warns of ClickFix attacks pushing Vidar Stealer malwareby Bill Toulas on May 7, 2026
The Australian Cyber Security Center (ACSC) is warning organizations of an ongoing malware campaign using the ClickFix social engineering technique to […]
- Ivanti EPMM CVE-2026-6973 RCE Under Active Exploitation Grants Admin-Level Accessby info@thehackernews.com (The Hacker News) on May 7, 2026
Ivanti is warning that a new security flaw impacting Endpoint Manager Mobile (EPMM) has been explored in limited attacks in the wild. The high-severity […]
- PCPJack Credential Stealer Exploits 5 CVEs to Spread Worm-Like Across Cloud Systemsby info@thehackernews.com (The Hacker News) on May 7, 2026
Cybersecurity researchers have disclosed details of a new credential theft framework dubbed PCPJack that targets exposed cloud infrastructure and ousts any […]
- Settlement Resolves FTC Lawsuit Against Kochava Over Sale of Geolocation Databy Steve Alder on May 7, 2026
A settlement has been reached between the Federal Trade Commission (FTC) and the Idaho-based data broker Kochava and its subsidiary The post Settlement […]
- PAN-OS RCE Exploit Under Active Use Enabling Root Access and Espionageby info@thehackernews.com (The Hacker News) on May 7, 2026
Palo Alto Networks has disclosed that threat actors may have attempted to unsuccessfully exploit a recently disclosed critical security flaw as early as April […]
- ThreatsDay Bulletin: Edge Plaintext Passwords, ICS 0-Days, Patch-or-Die Alerts and 25+ New Storiesby info@thehackernews.com (The Hacker News) on May 7, 2026
Bad week. Turns out the easiest way to get hacked in 2026 is still the same old garbage: shady packages, fake apps, forgotten DNS junk, scam ads, and stolen […]
- New Cyber Resilience Readiness Program Developed by Joint Commission; AHAby Steve Alder on May 7, 2026
Joint Commission and the American Hospital Association (AHA) have partnered to create a new Cyber Resilience Readiness program for hospitals The post New […]
- Day Zero Readiness: The Operational Gaps That Break Incident Responseby info@thehackernews.com (The Hacker News) on May 7, 2026
Having an incident response retainer, or even a pre-approved external incident response firm, is not the same as being ready for an incident. A retainer means […]
- PyPI Packages Deliver ZiChatBot Malware via Zulip APIs on Windows and Linuxby info@thehackernews.com (The Hacker News) on May 7, 2026
Cybersecurity researchers have discovered three packages on the Python Package Index (PyPI) repository that are designed to stealthily deliver a previously […]
- Fake call logs, real payments: How CallPhantom tricks Android userson May 7, 2026
ESET researchers uncovered fraudulent apps on Google Play that claim to provide the call history “for any number” and had been downloaded more than seven […]
- Fixing the password problem is as easy as 123456on May 7, 2026
How come it’s still possible to ‘secure’ an online account with a six-digit string?
- vm2 Node.js Library Vulnerabilities Enable Sandbox Escape and Arbitrary Code Executionby info@thehackernews.com (The Hacker News) on May 7, 2026
A dozen critical security vulnerabilities have been disclosed in the vm2 Node.js library that could be exploited by bad actors to break out of the sandbox and […]
- Mirai-Based xlabs_v1 Botnet Exploits ADB to Hijack IoT Devices for DDoS Attacksby info@thehackernews.com (The Hacker News) on May 6, 2026
Cybersecurity researchers have exposed a new Mirai-derived botnet that self-identifies as xlabs_v1 and targets internet-exposed devices running Android Debug […]
- MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attackby info@thehackernews.com (The Hacker News) on May 6, 2026
The Iranian state-sponsored hacking group known as MuddyWater (aka Mango Sandstorm, Seedworm, and Static Kitten) has been attributed to a ransomware attack in […]
- The Hacker News Launches 'Cybersecurity Stars Awards 2026' — Submissions Now Openby info@thehackernews.com (The Hacker News) on May 6, 2026
For nearly 20 years, we at The Hacker News have mostly told scary stories about cyberspace — big hacks, broken systems, and new threats. But behind every […]
- Your AI Agents Are Already Inside the Perimeter. Do You Know What They're Doing?by info@thehackernews.com (The Hacker News) on May 6, 2026
Analysts recently confirmed what identity security teams have quietly feared: AI agents are being deployed faster than enterprises can govern them. In their […]
- Google's Android Apps Get Public Verification to Stop Supply Chain Attacksby info@thehackernews.com (The Hacker News) on May 6, 2026
Google has announced expanded Binary Transparency for Android as a way to safeguard the ecosystem from supply chain attacks. "This new public ledger ensures […]
- Windows Phone Link Exploited by CloudZ RAT to Steal Credentials and OTPsby info@thehackernews.com (The Hacker News) on May 6, 2026
Cybersecurity researchers have disclosed details of an intrusion that involved the use of a CloudZ remote access tool (RAT) and a previous undocumented plugin […]
- Palo Alto PAN-OS Flaw Under Active Exploitation Enables Remote Code Executionby info@thehackernews.com (The Hacker News) on May 6, 2026
Palo Alto Networks has released an advisory warning that a critical buffer overflow vulnerability in its PAN-OS software has been exploited in the wild. The […]
- Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCEby info@thehackernews.com (The Hacker News) on May 5, 2026
The Apache Software Foundation (ASF) has released security updates to address several security vulnerabilities in the HTTP Server, including a severe […]
- DAEMON Tools Supply Chain Attack Compromises Official Installers with Malwareby info@thehackernews.com (The Hacker News) on May 5, 2026
A newly identified supply chain attack targeting DAEMON Tools software has compromised its installers to serve a malicious payload, according to findings from […]
- China-Linked UAT-8302 Targets Governments Using Shared APT Malware Across Regionsby info@thehackernews.com (The Hacker News) on May 5, 2026
A sophisticated China-nexus advanced persistent threat (APT) group has been attributed to attacks targeting government entities in South America since at least […]
- Urgent Action Required by MOVEit Automation Usersby Steve Alder on May 5, 2026
Progress Software has issued a warning to customers about a critical authentication bypass vulnerability within the MOVEit Automation application. MOVEit The […]



























