IT Security News

Cybersecurity news and articles about information security, vulnerabilities, exploits, hacks, laws, spam, viruses, malware, breaches.

Main menu

Skip to content
  • Advertising
  • Contact
  • Legal and Contact information
  • Opt-out preferences
  • Privacy Policy
  • Social Media
    • Telegram Channel
EN, GBHackers Security | #1 Globally Trusted Cyber Security News Platform

NPM Supply Chain Attack Uses undicy-http to Deploy RAT

2026-04-01 08:04

A highly sophisticated npm supply chain attack that abuses a fake HTTP client package to deliver both a powerful RAT and a stealthy browser stealer. The malicious package, undicy-http@2.0.0, was uploaded to npm to impersonate undici, the official HTTP client…

Read more →

EN, Securelist

A laughing RAT: CrystalX combines spyware, stealer, and prankware features

2026-04-01 08:04

Kaspersky researchers analyze a new CrystalX RAT distributed as MaaS and featuring extensive spyware, stealer, and prankware capabilities. This article has been indexed from Securelist Read the original article: A laughing RAT: CrystalX combines spyware, stealer, and prankware features

Read more →

EN, Security Boulevard

Axios Front-End Library npm Supply Chain Poisoning Alert

2026-04-01 07:04

Overview On March 31, NSFOCUS CERT detected that the npm repository of the HTTP client library Axios was poisoned by the supply chain. The attacker bypassed the normal GitHub Actions CI/CD pipeline of the project, changed the account email address…

Read more →

EN, Help Net Security

Mimecast makes enterprise email security deployable in minutes

2026-04-01 07:04

Most organizations running Microsoft 365 rely on native email controls as their primary line of defense. According to Mimecast research, 38% of organizations depend exclusively on those native controls for collaboration security, and 64% say those controls are insufficient against…

Read more →

EN, GBHackers Security | #1 Globally Trusted Cyber Security News Platform

XLoader malware Sharpens Obfuscation, Masks C2 Traffic via Decoy Servers

2026-04-01 07:04

XLoader’s developers have released new versions that significantly harden the malware’s code and hide its command‑and‑control (C2) traffic behind layers of encryption and decoy servers, making analysis and detection more difficult for defenders. This article summarizes the latest obfuscation changes…

Read more →

EN, GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Hackers Actively Exploit Critical WebLogic RCE Vulnerabilities in Ongoing Attacks

2026-04-01 07:04

A maximum-severity vulnerability in Oracle WebLogic Server is facing rapid exploitation in the wild. Tracked as CVE-2026-21962, this unauthenticated Remote Code Execution (RCE) flaw carries a maximum CVSS score of 10.0. According to a recent honeypot study, attackers began weaponizing…

Read more →

EN, GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Google Cloud’s Vertex AI Hit by Vulnerability Enabling Sensitive Data Access

2026-04-01 07:04

Artificial intelligence agents are transforming enterprise workflows, but they also introduce dangerous new attack vectors. Security researchers from Palo Alto Networks’ Unit 42 recently uncovered a significant vulnerability in Google Cloud Platform’s (GCP) Vertex AI Agent Engine. By exploiting overly…

Read more →

Cyber Security News, EN

Google Now Allows You to Change Your @gmail.com Address in a Few Simple Steps

2026-04-01 07:04

For over two decades, the permanence of a Google Account username has been a strict rule of the digital landscape. Many users found it frustrating to create new accounts and transfer data after outgrowing their childhood email addresses or changing…

Read more →

Cyber Security News, EN

Mercor AI Confirms Data Breach Following Lapsus$ Claims of 4TB Data Theft

2026-04-01 07:04

Mercor AI has officially confirmed a severe data breach following claims by the notorious Lapsus$ hacking group that they stole 4 terabytes of sensitive company data. The incident, stemming from a recent supply chain attack on the open-source LiteLLM project,…

Read more →

EN, Help Net Security

Financial groups lay out a plan to fight AI identity attacks

2026-04-01 07:04

Generative AI tools have brought the cost of deepfake production low enough that criminals and state-sponsored actors now use them routinely against financial institutions. A joint paper from the American Bankers Association, the Better Identity Coalition, and the Financial Services…

Read more →

Cybersecurity Today, EN

Cisco Breached: Source Code Stolen – Cybersecurity Today

2026-04-01 06:04

Cisco Source Code Stolen in Trivy Fallout, Axios Supply Chain Attack, and Active Exploitation of Fortinet and Citrix Flaws David Shipley reports multiple major security incidents: attackers used credentials stolen in the Trivy supply-chain attack via a malicious GitHub action…

Read more →

EN, Security Boulevard

Workload IAM vs. Secrets Management: A Practical Decision Guide

2026-04-01 06:04

6 min readMost organizations start their nonhuman identity security program with a secrets manager. It’s a sensible first step. But as workloads multiply across clouds and the credential sprawl grows, the question shifts from “where do we store secrets?” to…

Read more →

EN, Security Boulevard

Workload Identity and Access Management: The Definitive Guide

2026-04-01 06:04

6 min readFor every human identity your IAM program governs, there are roughly 82 machine identities operating outside it. Most of them authenticate with static credentials that were provisioned once and never reviewed. The post Workload Identity and Access Management:…

Read more →

EN, Help Net Security

Malware detectors trained on one dataset often stumble on another

2026-04-01 06:04

Machine learning models built to catch malware on Windows systems are typically evaluated on data that closely resembles their training set. In practice, the malware arriving on enterprise endpoints looks different, comes from different sources, and in many cases has…

Read more →

hourly summary

IT Security News Hourly Summary 2026-04-01 06h : 2 posts

2026-04-01 06:04

2 posts were published in the last hour 3:13 : Phantom Project Bundles Infostealer, Crypter and RAT For Sale 3:13 : Maryland Man Charged Over $53m Uranium Finance Crypto Hack

Read more →

EN, www.infosecurity-magazine.com

Phantom Project Bundles Infostealer, Crypter and RAT For Sale

2026-04-01 05:04

Phantom Stealer .NET harvests browser credentials, cookies, cards, sessions, as stealer-as-a-service This article has been indexed from www.infosecurity-magazine.com Read the original article: Phantom Project Bundles Infostealer, Crypter and RAT For Sale

Read more →

EN, www.infosecurity-magazine.com

Maryland Man Charged Over $53m Uranium Finance Crypto Hack

2026-04-01 05:04

Maryland man accused of $53m Uranium Finance hack, exploited smart contract flaws, laundered funds This article has been indexed from www.infosecurity-magazine.com Read the original article: Maryland Man Charged Over $53m Uranium Finance Crypto Hack

Read more →

EN, SANS Internet Storm Center, InfoCON: green

ISC Stormcast For Wednesday, April 1st, 2026 https://isc.sans.edu/podcastdetail/9874, (Wed, Apr 1st)

2026-04-01 04:04

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from SANS Internet Storm Center, InfoCON: green Read the original article: ISC Stormcast For Wednesday, April 1st, 2026…

Read more →

EN, welivesecurity

This month in security with Tony Anscombe – March 2026 edition

2026-04-01 04:04

The past four weeks have seen a slew of new cybersecurity wake-up calls that showed why every organization needs a well-thought-out cyber-resilience plan This article has been indexed from WeLiveSecurity Read the original article: This month in security with Tony…

Read more →

EN, Security News | TechCrunch

Mercor says it was hit by cyberattack tied to compromise of open-source LiteLLM project

2026-04-01 04:04

The AI recruiting startup confirmed a security incident after an extortion hacking crew took credit for stealing data from the company’s systems. This article has been indexed from Security News | TechCrunch Read the original article: Mercor says it was…

Read more →

EN, Security Boulevard

Granular Policy Enforcement Engines for Post-Quantum MCP Governance

2026-04-01 04:04

Learn how to secure Model Context Protocol (MCP) deployments using granular policy engines and post-quantum cryptography to prevent AI tool poisoning and puppet attacks. The post Granular Policy Enforcement Engines for Post-Quantum MCP Governance appeared first on Security Boulevard. This…

Read more →

hourly summary

IT Security News Hourly Summary 2026-04-01 03h : 1 posts

2026-04-01 03:04

1 posts were published in the last hour 1:4 : Apple Will Push Out Rare ‘Backported’ Patches to Protect iOS 18 Users From DarkSword Hacking Tool

Read more →

EN, Security Latest

Apple Will Push Out Rare ‘Backported’ Patches to Protect iOS 18 Users From DarkSword Hacking Tool

2026-04-01 03:04

As a DarkSword takeover technique spreads, Apple tells WIRED it will release fixes for millions of iPhone owners who remain on iOS 18 rather than force them to update to iOS 26 simply to be protected. This article has been…

Read more →

EN, Threat Intelligence

North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack

2026-04-01 01:04

Written by: Austin Larsen, Dima Lenz, Adrian Hernandez, Tyler McLellan, Christopher Gardner, Ashley Zaya, Michael Rudden Introduction  Google Threat Intelligence Group (GTIG) is tracking an active software supply chain attack targeting the popular Node Package Manager (NPM) package “axios.” Between…

Read more →

Page 19 of 5188
« 1 … 17 18 19 20 21 … 5,188 »

Pages

  • Advertising
  • Contact
  • Legal and Contact information
  • Opt-out preferences
  • Privacy Policy
  • Social Media
    • Telegram Channel

Recent Posts

  • FBI Declares Surveillance System Breach a ‘Major Incident’ April 3, 2026
  • Android Alert: 50 Google Play Apps Linked to ‘NoVoice’ Malware Reached 2.3M Downloads April 3, 2026
  • Hackers Abuse Trusted Platforms to Steal Bank Credentials From Philippine Users April 3, 2026
  • Axios Maintainer Confirms The npm Compromise Was via a Targeted Social Engineering Attack April 3, 2026
  • Kimsuky Deploys Malicious LNK Files to Deliver Python-Based Backdoor in Multi-Stage Attack April 3, 2026
  • Researchers warn of critical flaws in Progress ShareFile April 3, 2026
  • Trump’s FY2027 budget again targets CISA April 3, 2026
  • Hybrid work, expanded risk: what needs to change April 3, 2026
  • Armis State of Cyberwarfare Report: AI-Powered Cyber Attacks Accelerate Worldwide April 3, 2026
  • High-Severity Vulnerabilities, Supply Chain Breaches, and AI Threats Redefine Cybersecurity This Week April 3, 2026
  • Europe’s cyber agency blames hacking gangs for massive data breach and leak April 3, 2026
  • [un]prompted 2026 – Evaluating Threats & Automating Defense At Google April 3, 2026
  • How AWS KMS and AWS Encryption SDK overcome symmetric encryption bounds April 3, 2026
  • IT Security News Hourly Summary 2026-04-03 18h : 7 posts April 3, 2026
  • AI Firm Mercor Confirms Breach as Hackers Claim 4TB of Stolen Data April 3, 2026
  • AI Breakthroughs, Security Breaches, and Industry Shakeups Define the Week in Tech April 3, 2026
  • NHI Governance Is the Outcome. GitGuardian Is How You Get There April 3, 2026
  • Government agencies see cyber threats as major barrier to tech improvements April 3, 2026
  • Blocking children from social media is a badly executed good idea April 3, 2026
  • North Korea–linked hackers drain $285M from Drift in sophisticated attack April 3, 2026

Copyright © 2026 IT Security News. All Rights Reserved. The Magazine Basic Theme by bavotasan.com.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}