Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate…
Category: The Hacker News
⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests
A blank field. A public repo. One reply to an email. A box left exposed. None of this sounds dramatic, which is partly the problem. This week’s threats…
The Credential Layer Is Expanding Faster Than Security Teams Can See It
Every modern enterprise depends on credentials. This is how humans, systems, and now AI, all connect to data, services, and each other securely.…
Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2
Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to…
Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access
Apple has announced that it’s taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by…
Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in…
New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline
Citrix has released security updates for a high-severity security flaw in NetScaler ADC and Citrix NetScaler Gateway that has been exploited as part of…
ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members
A suspected member of the ShinyHunters digital extortion group, who goes by the online alias “Rey,” has been allegedly detained by authorities in Jordan,…
China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing
A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence…
WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory
Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the…
Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new,…
MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics
The U.K.’s domestic intelligence and security agency has warned that more than 100 academics have helped China boost its intelligence gathering efforts on…
How Financial Services Companies Can Modernize Their Software Supply Chain
Every security leader at a bank, insurer, or asset manager has had a version of this conversation: Security wants to eliminate a class of vulnerabilities.…
The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations
Featuring: Cybersecurity is being reshaped by the expansion of cloud infrastructure, AI, distributed systems, and increasingly complex digital…
OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates
OpenAI on Wednesday said it identified and disrupted a coordinated distillation campaign that was designed to illicitly extract protected reasoning from…
CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN…
Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version
Google on Wednesday announced its latest frontier artificial intelligence (AI) model, Gemini 4 Argon, that it said is being rolled out to a set of trusted…
Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path
Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in…
Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft
Cryptocurrency exchange Bitget on Wednesday confirmed that attackers who stole $387.5 million last week exploited a zero-day flaw in third-party security…
MetaMask Security Incident Prompts Exit of Affected Ethereum Validators
MetaMask on Thursday said it’s responding to what it described as an “ongoing security incident” impacting part of its infrastructure. “We are actively…
