
- Two Chrome Extensions Caught Stealing ChatGPT and DeepSeek Chats from 900,000 Usersby info@thehackernews.com (The Hacker News) (The Hacker News) on January 6, 2026 at 5:21 pm
Cybersecurity researchers have discovered two new malicious extensions on the Chrome Web Store that are designed to exfiltrate OpenAI ChatGPT and DeepSeek conversations alongside […]
- Unpatched Firmware Flaw Exposes TOTOLINK EX200 to Full Remote Device Takeoverby info@thehackernews.com (The Hacker News) (The Hacker News) on January 6, 2026 at 3:47 pm
The CERT Coordination Center (CERT/CC) has disclosed details of an unpatched security flaw impacting TOTOLINK EX200 wireless range extender that could allow a remote authenticated […]
- Fake Booking Emails Redirect Hotel Staff to Fake BSoD Pages Delivering DCRatby info@thehackernews.com (The Hacker News) (The Hacker News) on January 6, 2026 at 12:13 pm
Source: Securonix Cybersecurity researchers have disclosed details of a new campaign dubbed PHALT#BLYX that has leveraged ClickFix-style lures to display fixes for fake blue […]
- What is Identity Dark Matter?by info@thehackernews.com (The Hacker News) (The Hacker News) on January 6, 2026 at 11:30 am
The Invisible Half of the Identity Universe Identity used to live in one place – an LDAP directory, an HR system, a single IAM portal. Not anymore. Today, identity is fragmented […]
- VS Code Forks Recommend Missing Extensions, Creating Supply Chain Risk in Open VSXby info@thehackernews.com (The Hacker News) (The Hacker News) on January 6, 2026 at 11:25 am
Popular artificial intelligence (AI)-powered Microsoft Visual Studio Code (VS Code) forks such as Cursor, Windsurf, Google Antigravity, and Trae have been found to recommend […]
- New n8n Vulnerability (9.9 CVSS) Lets Authenticated Users Execute System Commandsby info@thehackernews.com (The Hacker News) (The Hacker News) on January 6, 2026 at 5:08 am
A new critical security vulnerability has been disclosed in n8n, an open-source workflow automation platform, that could enable an authenticated attacker to execute arbitrary […]
- Critical AdonisJS Bodyparser Flaw (CVSS 9.2) Enables Arbitrary File Write on Serversby info@thehackernews.com (The Hacker News) (The Hacker News) on January 6, 2026 at 3:30 am
Users of the “@adonisjs/bodyparser” npm package are being advised to update to the latest version following the disclosure of a critical security vulnerability that, if […]
- Russia-Aligned Hackers Abuse Viber to Target Ukrainian Military and Governmentby info@thehackernews.com (The Hacker News) (The Hacker News) on January 5, 2026 at 5:56 pm
The Russia-aligned threat actor known as UAC-0184 has been observed targeting Ukrainian military and government entities by leveraging the Viber messaging platform to deliver […]
- Kimwolf Android Botnet Infects Over 2 Million Devices via Exposed ADB and Proxy Networksby info@thehackernews.com (The Hacker News) (The Hacker News) on January 5, 2026 at 4:41 pm
The botnet known as Kimwolf has infected more than 2 million Android devices by tunneling through residential proxy networks, according to findings from Synthient. “Key actors […]
- ⚡ Weekly Recap: IoT Exploits, Wallet Breaches, Rogue Extensions, AI Abuse & Moreby info@thehackernews.com (The Hacker News) (The Hacker News) on January 5, 2026 at 12:53 pm
The year opened without a reset. The same pressure carried over, and in some places it tightened. Systems people assume are boring or stable are showing up in the wrong places. […]
- The State of Cybersecurity in 2025: Key Segments, Insights, and Innovations by info@thehackernews.com (The Hacker News) (The Hacker News) on January 5, 2026 at 11:55 am
Featuring: Cybersecurity is being reshaped by forces that extend beyond individual threats or tools. As organizations operate across cloud infrastructure, distributed endpoints, […]
- Bitfinex Hack Convict Ilya Lichtenstein Released Early Under U.S. First Step Actby info@thehackernews.com (The Hacker News) (The Hacker News) on January 5, 2026 at 9:42 am
Ilya Lichtenstein, who was sentenced to prison last year for money laundering charges in connection with his role in the massive hack of cryptocurrency exchange Bitfinex in 2016, […]
- New VVS Stealer Malware Targets Discord Accounts via Obfuscated Python Codeby info@thehackernews.com (The Hacker News) (The Hacker News) on January 5, 2026 at 7:48 am
Cybersecurity researchers have disclosed details of a new Python-based information stealer called VVS Stealer (also styled as VVS $tealer) that’s capable of harvesting Discord […]
- Transparent Tribe Launches New RAT Attacks Against Indian Government and Academiaby info@thehackernews.com (The Hacker News) (The Hacker News) on January 2, 2026 at 1:52 pm
The threat actor known as Transparent Tribe has been attributed to a fresh set of attacks targeting Indian governmental, academic, and strategic entities with a remote access […]
- The ROI Problem in Attack Surface Managementby info@thehackernews.com (The Hacker News) (The Hacker News) on January 2, 2026 at 11:30 am
Attack Surface Management (ASM) tools promise reduced risk. What they usually deliver is more information. Security teams deploy ASM, asset inventories grow, alerts start […]
- Cybercriminals Abuse Google Cloud Email Feature in Multi-Stage Phishing Campaignby info@thehackernews.com (The Hacker News) (The Hacker News) on January 2, 2026 at 9:14 am
Cybersecurity researchers have disclosed details of a phishing campaign that involves the attackers impersonating legitimate Google-generated messages by abusing Google Cloud’s […]
- ThreatsDay Bulletin: GhostAd Drain, macOS Attacks, Proxy Botnets, Cloud Exploits, and 12+ Storiesby info@thehackernews.com (The Hacker News) (The Hacker News) on January 1, 2026 at 3:52 pm
The first ThreatsDay Bulletin of 2026 lands on a day that already feels symbolic — new year, new breaches, new tricks. If the past twelve months taught defenders anything, […]
- RondoDox Botnet Exploits Critical React2Shell Flaw to Hijack IoT Devices and Web Serversby info@thehackernews.com (The Hacker News) (The Hacker News) on January 1, 2026 at 9:19 am
Cybersecurity researchers have disclosed details of a persistent nine-month-long campaign that has targeted Internet of Things (IoT) devices and web applications to enroll them […]
- How To Browse Faster and Get More Done Using Adapt Browserby info@thehackernews.com (The Hacker News) (The Hacker News) on January 1, 2026 at 5:47 am
As web browsers evolve into all-purpose platforms, performance and productivity often suffer. Feature overload, excessive background processes, and fragmented workflows can slow […]
- Trust Wallet Chrome Extension Hack Drains $8.5M via Shai-Hulud Supply Chain Attackby info@thehackernews.com (The Hacker News) (The Hacker News) on December 31, 2025 at 4:29 pm
Trust Wallet on Tuesday revealed that the second iteration of the Shai-Hulud (aka Sha1-Hulud) supply chain outbreak in November 2025 was likely responsible for the hack of its […]
- DarkSpectre Browser Extension Campaigns Exposed After Impacting 8.8 Million Users Worldwideby info@thehackernews.com (The Hacker News) (The Hacker News) on December 31, 2025 at 4:14 pm
The threat actor behind two malicious browser extension campaigns, ShadyPanda and GhostPoster, has been attributed to a third attack campaign codenamed DarkSpectre that has […]
- Critical CVSS 9.8 Flaw Found in IBM API Connect Authentication Systemby info@thehackernews.com (The Hacker News) (The Hacker News) on December 31, 2025 at 1:37 pm
IBM has disclosed details of a critical security flaw in API Connect that could allow attackers to gain remote access to the application. The vulnerability, tracked as […]
- Researchers Spot Modified Shai-Hulud Worm Testing Payload on npm Registryby info@thehackernews.com (The Hacker News) (The Hacker News) on December 31, 2025 at 1:29 pm
Cybersecurity researchers have disclosed details of what appears to be a new strain of Shai Hulud on the npm registry with slight modifications from the previous wave observed […]
- U.S. Treasury Lifts Sanctions on Three Individuals Linked to Intellexa and Predator Spywareby info@thehackernews.com (The Hacker News) (The Hacker News) on December 31, 2025 at 5:17 am
The U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) on Tuesday removed three individuals linked to the Intellexa Consortium, the holding company behind a […]
- CSA Issues Alert on Critical SmarterMail Bug Allowing Remote Code Executionby info@thehackernews.com (The Hacker News) (The Hacker News) on December 30, 2025 at 4:28 pm
The Cyber Security Agency of Singapore (CSA) has issued a bulletin warning of a maximum-severity security flaw in SmarterTools SmarterMail email software that could be exploited […]
