The state of Berlin confirms that it is the victim of an extortion attempt after allegedly having its network hacked back in August. Authorities say they…
OpenAI Is Pulling Its AI Models From Cursor Following SpaceX Acquisition
OpenAI is pulling its AI models from Cursor following SpaceX’s acquisition of the AI coding assistant, notifying SpaceX that it will wind down the…
Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and…
McKesson Probes Data Theft After ShinyHunters Claims Access to Patient Records
McKesson Corporation is investigating a cybersecurity incident involving unauthorized access to third-party applications and data exfiltration, while the…
US Says Chinese Hackers Hit Federal Agencies
The U.S. says a China-linked hacking operation broke into or targeted systems at NASA, the Federal Reserve, the Justice Department, the Senate, and other…
OSCP Certification Guide: How to Prepare and Pass in 2026
By HOC Team | Last updated: August 29, 2026 | Read time: ~28 min OSCP Certification Guide: How…
Bitcoin Lightning Nodes Drained Through Critical BTCPay Server Flaw
There has been another security breach of Bitcoin payment infrastructure as attackers exploited critical vulnerabilities in BTCPay Server deployments to…
Hack One Robot, Reach the Next: Unitree G1 Security Flaws
A researcher chained two Unitree G1 flaws to gain root access remotely and showed how a compromised robot could attack others nearby. Security researcher…
AI-driven OSINT in the wrong hands – and why everyone could be a target for fraud
It’s getting cheaper and easier for cybercriminals to research potential victims. Here’s what’s still in your control.
Hasbro Data Breach Exposed Employee Personal Information
A cyberattack caused disruptions at the toy and game giant earlier this year and the company is now disclosing a data breach.
Rhysida Ransomware Group Targets Berlin Government Ahead of Vote
Berlin ‘s government faces a Rhysida ransomware attack weeks before elections, with officials refusing to pay despite a claimed 5.79 TB data theft.…
The Cybersecurity Apocalypse Is Coming in ‘Months,’ AI Giants Warn
Plus: Hackers target over 100 US water systems, ICE puts in an order for robot dogs, and you’ll never guess what “MrChildPorn” was arrested for.
Philippine Nuclear and Naval Targets Hit by Suspected Chinese Operator
An alleged Chinese-speaking actor breached Philippine nuclear and naval targets by exploiting known flaws, stealing sensitive data. A suspected…
Best SIEM Tools For SOC Analysts: Splunk vs Sentinel vs QRadar (2026)
By HOC Team | Last updated: August 29, 2026 | Read time: ~25 min In 2026, the average…
Critical Gogs Flaw Enables Remote Code Execution Through Path Traversal
A critical vulnerability in Gogs, the self-hosted Git service, could allow authenticated attackers to execute commands on the server by abusing path…
Malvertising Is Moving From Deceptive Content to Weaponized Infrastructure
Malvertising is becoming harder to identify by looking at the ad itself. A growing share of malicious advertising activity now depends on what happens…
Hackers Compromise TanStack Query npm Package to Steal Developer Credentials
A supply-chain worm has compromised multiple releases of @7nohe/openapi-react-query-codegen, an npm package that generates type-safe TanStack Query hooks.…
Hackers Use Fake Cloudflare CAPTCHA to Deploy TerminalFix Reverse Tunnel
A newly documented TerminalFix campaign is using fake Cloudflare CAPTCHA prompts to trick users into manually executing malicious PowerShell commands,…
Chinese Hackers Deploy PackClient RAT via Tax-Themed Phishing Attacks to Steal Data
A Chinese-speaking threat actor tracked as TA4922 is deploying the PackClient remote access trojan via tax-themed phishing campaigns targeting…
TerminalFix campaign deploys a reverse tunnel through multistage intrusion
Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with…
Critical ServiceNow Flaws Let Attackers Execute Code and Access Data
ServiceNow has released security updates for four vulnerabilities in its Now Platform and ServiceNow AI platform, including three critical flaws that…
700 AI Agents Secretly Coordinated to Hack Hugging Face After Breaking Their Isolation
A large group of AI agents reportedly bypassed their intended isolation, created a covert communication channel, and coordinated an attack on Hugging Face…
Hackers Can Take Full Control of Unitree G1 Humanoid Robots Over Bluetooth
A critical attack chain could let attackers within Bluetooth range take full control of Unitree G1 humanoid robots, gaining root-level code execution on…
How Varonis hacks AIs into snitching on themselves
Varonis AI Threat Lead on Copilot Exploits, Prompt Injection, and the AI Hacking Trifecta The host interviews Mark Vaitsman, AI threat research lead at…