
- Docker Fixes Critical Ask Gordon AI Flaw Allowing Code Execution via Image Metadataby info@thehackernews.com (The Hacker News) (The Hacker News) on February 3, 2026 at 4:41 pm
Cybersecurity researchers have disclosed details of a now-patched security flaw impacting Ask Gordon, an artificial intelligence (AI) assistant built into Docker Desktop and the […]
- [Webinar] The Smarter SOC Blueprint: Learn What to Build, Buy, and Automateby info@thehackernews.com (The Hacker News) (The Hacker News) on February 3, 2026 at 2:14 pm
Most security teams today are buried under tools. Too many dashboards. Too much noise. Not enough real progress. Every vendor promises “complete coverage” or “AI-powered […]
- Hackers Exploit Metro4Shell RCE Flaw in React Native CLI npm Packageby info@thehackernews.com (The Hacker News) (The Hacker News) on February 3, 2026 at 2:00 pm
Threat actors have been observed exploiting a critical security flaw impacting the Metro Development Server in the popular “@react-native-community/cli” npm package. Cybersecurity […]
- When Cloud Outages Ripple Across the Internetby info@thehackernews.com (The Hacker News) (The Hacker News) on February 3, 2026 at 11:00 am
Recent major cloud service outages have been hard to miss. High-profile incidents affecting providers such as AWS, Azure, and Cloudflare have disrupted large parts of the […]
- APT28 Uses Microsoft Office CVE-2026-21509 in Espionage-Focused Malware Attacksby info@thehackernews.com (The Hacker News) (The Hacker News) on February 3, 2026 at 9:12 am
The Russia-linked state-sponsored threat actor known as APT28 (aka UAC-0001) has been attributed to attacks exploiting a newly disclosed security flaw in Microsoft Office as part […]
- Mozilla Adds One-Click Option to Disable Generative AI Features in Firefoxby info@thehackernews.com (The Hacker News) (The Hacker News) on February 3, 2026 at 5:39 am
Mozilla on Monday announced a new controls section in its Firefox desktop browser settings that allows users to completely turn off generative artificial intelligence (GenAI) […]
- Notepad++ Hosting Breach Attributed to China-Linked Lotus Blossom Hacking Groupby info@thehackernews.com (The Hacker News) (The Hacker News) on February 3, 2026 at 4:55 am
A China-linked threat actor known as Lotus Blossom has been attributed with medium confidence to the recently discovered compromise of the infrastructure hosting Notepad++. The […]
- Researchers Find 341 Malicious ClawHub Skills Stealing Data from OpenClaw Usersby info@thehackernews.com (The Hacker News) (The Hacker News) on February 2, 2026 at 5:49 pm
A security audit of 2,857 skills on ClawHub has found 341 malicious skills across multiple campaigns, according to new findings from Koi Security, exposing users to new supply […]
- OpenClaw Bug Enables One-Click Remote Code Execution via Malicious Linkby info@thehackernews.com (The Hacker News) (The Hacker News) on February 2, 2026 at 4:28 pm
A high-severity security flaw has been disclosed in OpenClaw (formerly referred to as Clawdbot and Moltbot) that could allow remote code execution (RCE) through a crafted […]
- Microsoft Begins NTLM Phase-Out With Three-Stage Plan to Move Windows to Kerberosby info@thehackernews.com (The Hacker News) (The Hacker News) on February 2, 2026 at 3:59 pm
Microsoft has announced a three-phase approach to phase out New Technology LAN Manager (NTLM) as part of its efforts to shift Windows environments toward stronger, Kerberos-based […]
- ⚡ Weekly Recap: Proxy Botnet, Office Zero-Day, MongoDB Ransoms, AI Hijacks & New Threatsby info@thehackernews.com (The Hacker News) (The Hacker News) on February 2, 2026 at 11:59 am
Every week brings new discoveries, attacks, and defenses that shape the state of cybersecurity. Some threats are stopped quickly, while others go unseen until they cause real […]
- Securing the Mid-Market Across the Complete Threat Lifecycleby info@thehackernews.com (The Hacker News) (The Hacker News) on February 2, 2026 at 11:45 am
For mid-market organizations, cybersecurity is a constant balancing act. Proactive, preventative security measures are essential to protect an expanding attack surface. Combined […]
- Notepad++ Official Update Mechanism Hijacked to Deliver Malware to Select Usersby info@thehackernews.com (The Hacker News) (The Hacker News) on February 2, 2026 at 8:55 am
The maintainer of Notepad++ has revealed that state-sponsored attackers hijacked the utility’s update mechanism to redirect update traffic to malicious servers instead. “The […]
- eScan Antivirus Update Servers Compromised to Deliver Multi-Stage Malwareby info@thehackernews.com (The Hacker News) (The Hacker News) on February 2, 2026 at 5:47 am
The update infrastructure for eScan antivirus, a security solution developed by Indian cybersecurity company MicroWorld Technologies, has been compromised by unknown attackers to […]
- Open VSX Supply Chain Attack Used Compromised Dev Account to Spread GlassWormby info@thehackernews.com (The Hacker News) (The Hacker News) on February 2, 2026 at 5:04 am
Cybersecurity researchers have disclosed details of a supply chain attack targeting the Open VSX Registry in which unidentified threat actors compromised a legitimate developer’s […]
- Iran-Linked RedKitten Cyber Campaign Targets Human Rights NGOs and Activistsby info@thehackernews.com (The Hacker News) (The Hacker News) on January 31, 2026 at 12:02 pm
A Farsi-speaking threat actor aligned with Iranian state interests is suspected to be behind a new campaign targeting non-governmental organizations and individuals involved in […]
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platformsby info@thehackernews.com (The Hacker News) (The Hacker News) on January 31, 2026 at 7:58 am
Google-owned Mandiant on Friday said it identified an “expansion in threat activity” that uses tradecraft consistent with extortion-themed attacks orchestrated by a financially […]
- CERT Polska Details Coordinated Cyber Attacks on 30+ Wind and Solar Farmsby info@thehackernews.com (The Hacker News) (The Hacker News) on January 31, 2026 at 7:05 am
CERT Polska, the Polish computer emergency response team, revealed that coordinated cyber attacks targeted more than 30 wind and photovoltaic farms, a private company from the […]
- Researchers Uncover Chrome Extensions Abusing Affiliate Links and Stealing ChatGPT Accessby info@thehackernews.com (The Hacker News) (The Hacker News) on January 30, 2026 at 1:42 pm
Cybersecurity researchers have discovered malicious Google Chrome extensions that come with capabilities to hijack affiliate links, steal data, and collect OpenAI ChatGPT […]
- China-Linked UAT-8099 Targets IIS Servers in Asia with BadIIS SEO Malwareby info@thehackernews.com (The Hacker News) (The Hacker News) on January 30, 2026 at 12:08 pm
Cybersecurity researchers have discovered a new campaign attributed to a China-linked threat actor known as UAT-8099 that took place between late 2025 and early 2026. The […]
- Badges, Bytes and Blackmailby info@thehackernews.com (The Hacker News) (The Hacker News) on January 30, 2026 at 11:30 am
Behind the scenes of law enforcement in cyber: what do we know about caught cybercriminals? What brought them in, where do they come from and what was their function in the […]
- Ex-Google Engineer Convicted for Stealing AI Secrets for China Startupby info@thehackernews.com (The Hacker News) (The Hacker News) on January 30, 2026 at 7:35 am
A former Google engineer accused of stealing thousands of the company’s confidential documents to build a startup in China has been convicted in the U.S., the Department of […]
- SmarterMail Fixes Critical Unauthenticated RCE Flaw with CVSS 9.3 Scoreby info@thehackernews.com (The Hacker News) (The Hacker News) on January 30, 2026 at 7:09 am
SmarterTools has addressed two more security flaws in SmarterMail email software, including one critical security flaw that could result in arbitrary code execution. The […]
- Two Ivanti EPMM Zero-Day RCE Flaws Actively Exploited, Security Updates Releasedby info@thehackernews.com (The Hacker News) (The Hacker News) on January 30, 2026 at 4:43 am
Ivanti has rolled out security updates to address two security flaws impacting Ivanti Endpoint Manager Mobile (EPMM) that have been exploited in zero-day attacks, one of which has […]
- Researchers Find 175,000 Publicly Exposed Ollama AI Servers Across 130 Countriesby info@thehackernews.com (The Hacker News) (The Hacker News) on January 29, 2026 at 6:37 pm
A new joint investigation by SentinelOne SentinelLABS, and Censys has revealed that the open-source artificial intelligence (AI) deployment has created a vast “unmanaged, publicly […]
