
- TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain Attackby info@thehackernews.com (The Hacker News) (The Hacker News) on May 11, 2026 at 6:30 pm
Checkmarx has confirmed that a modified version of the Jenkins AST plugin was published to the Jenkins Marketplace. “If you are using Checkmarx Jenkins AST plugin, you need to […]
- cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager Backdoorby info@thehackernews.com (The Hacker News) (The Hacker News) on May 11, 2026 at 5:54 pm
A threat actor named Mr_Rot13 has been attributed to the exploitation of a recently disclosed critical cPanel flaw to deploy a backdoor codenamed Filemanager on compromised […]
- Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitationby info@thehackernews.com (The Hacker News) (The Hacker News) on May 11, 2026 at 3:45 pm
Google on Monday disclosed that it identified an unknown threat actor using a zero-day exploit that it said was likely developed with an artificial intelligence (AI) system, […]
- ⚡ Weekly Recap: Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and Moreby info@thehackernews.com (The Hacker News) (The Hacker News) on May 11, 2026 at 12:36 pm
Rough Monday. Somebody poisoned a trusted download again, somebody else turned cloud servers into public housing, and a few crews are still getting into boxes with bugs that […]
- Your Purple Team Isn’t Purple — It’s Just Red and Blue in the Same Roomby info@thehackernews.com (The Hacker News) (The Hacker News) on May 11, 2026 at 11:30 am
Defending a network at 2 am looks a lot like this: an analyst copy-pasting a hash from a PDF into a SIEM query. A red team script is being rewritten by hand so the blue team can […]
- Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K Downloadsby info@thehackernews.com (The Hacker News) (The Hacker News) on May 11, 2026 at 7:05 am
A malicious Hugging Face repository managed to take a spot in the platform’s trending list by impersonating OpenAI’s Privacy Filter open-weight model to deliver a Rust-based […]
- Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leakby info@thehackernews.com (The Hacker News) (The Hacker News) on May 10, 2026 at 12:41 pm
Cybersecurity researchers have disclosed a critical security vulnerability in Ollama that, if successfully exploited, could allow a remote, unauthenticated attacker to leak its […]
- cPanel, WHM Release Fixes for Three New Vulnerabilities — Patch Nowby info@thehackernews.com (The Hacker News) (The Hacker News) on May 9, 2026 at 7:16 am
cPanel has released updates to address three vulnerabilities in cPanel and Web Host Manager (WHM) that could be exploited to achieve privilege escalation, code execution, and […]
- TCLBANKER Banking Trojan Targets Financial Platforms via WhatsApp and Outlook Wormsby info@thehackernews.com (The Hacker News) (The Hacker News) on May 8, 2026 at 6:12 pm
Threat hunters have flagged a previously undocumented Brazilian banking trojan dubbed TCLBANKER that’s capable of targeting 59 banking, fintech, and cryptocurrency platforms. The […]
- Fake Call History Apps Stole Payments From Users After 7.3 Million Play Store Downloadsby info@thehackernews.com (The Hacker News) (The Hacker News) on May 8, 2026 at 3:08 pm
Cybersecurity researchers have discovered fraudulent apps on the official Google Play Store for Android that falsely claimed to offer access to call histories for any phone […]
- One Click, Total Shutdown: The “Patient Zero” Webinar on Killing Stealth Breachesby info@thehackernews.com (The Hacker News) (The Hacker News) on May 8, 2026 at 2:01 pm
The hardest part of cybersecurity isn’t the technology, it’s the people. Every major breach you’ve read about lately usually starts the same way: one employee, one clever […]
- Quasar Linux RAT Steals Developer Credentials for Software Supply Chain Compromiseby info@thehackernews.com (The Hacker News) (The Hacker News) on May 8, 2026 at 11:00 am
A previously undocumented Linux implant codenamed Quasar Linux RAT (QLNX) is targeting developers’ systems to establish a silent foothold as well as facilitate a broad range of […]
- One Missed Threat Per Week: What 25M Alerts Reveal About Low-Severity Riskby info@thehackernews.com (The Hacker News) (The Hacker News) on May 8, 2026 at 10:30 am
The dark secret of enterprise security operations is that defenders have quietly institutionalized the practice of not looking. This is not just anecdotal, but rather backed by a […]
- New Linux PamDOORa Backdoor Uses PAM Modules to Steal SSH Credentialsby info@thehackernews.com (The Hacker News) (The Hacker News) on May 8, 2026 at 8:41 am
Cybersecurity researchers have disclosed details of a new Linux backdoor named PamDOORa that’s being advertised on the Rehub Russian cybercrime forum for $1,600 by a threat actor […]
- Linux Kernel Dirty Frag LPE Exploit Enables Root Access Across Major Distributionsby info@thehackernews.com (The Hacker News) (The Hacker News) on May 8, 2026 at 5:12 am
Details have emerged about a new, unpatched local privilege escalation (LPE) vulnerability impacting the Linux kernel. Dubbed Dirty Frag, it has been described as a successor to […]
- Ivanti EPMM CVE-2026-6973 RCE Under Active Exploitation Grants Admin-Level Accessby info@thehackernews.com (The Hacker News) (The Hacker News) on May 7, 2026 at 5:55 pm
Ivanti is warning that a new security flaw impacting Endpoint Manager Mobile (EPMM) has been explored in limited attacks in the wild. The high-severity vulnerability, […]
- PCPJack Credential Stealer Exploits 5 CVEs to Spread Worm-Like Across Cloud Systemsby info@thehackernews.com (The Hacker News) (The Hacker News) on May 7, 2026 at 5:45 pm
Cybersecurity researchers have disclosed details of a new credential theft framework dubbed PCPJack that targets exposed cloud infrastructure and ousts any artifacts linked to […]
- PAN-OS RCE Exploit Under Active Use Enabling Root Access and Espionageby info@thehackernews.com (The Hacker News) (The Hacker News) on May 7, 2026 at 1:34 pm
Palo Alto Networks has disclosed that threat actors may have attempted to unsuccessfully exploit a recently disclosed critical security flaw as early as April 9, 2026. The […]
- ThreatsDay Bulletin: Edge Plaintext Passwords, ICS 0-Days, Patch-or-Die Alerts and 25+ New Storiesby info@thehackernews.com (The Hacker News) (The Hacker News) on May 7, 2026 at 11:33 am
Bad week. Turns out the easiest way to get hacked in 2026 is still the same old garbage: shady packages, fake apps, forgotten DNS junk, scam ads, and stolen logins getting dumped […]
- Day Zero Readiness: The Operational Gaps That Break Incident Responseby info@thehackernews.com (The Hacker News) (The Hacker News) on May 7, 2026 at 10:54 am
Having an incident response retainer, or even a pre-approved external incident response firm, is not the same as being ready for an incident. A retainer means someone will answer […]
- PyPI Packages Deliver ZiChatBot Malware via Zulip APIs on Windows and Linuxby info@thehackernews.com (The Hacker News) (The Hacker News) on May 7, 2026 at 9:20 am
Cybersecurity researchers have discovered three packages on the Python Package Index (PyPI) repository that are designed to stealthily deliver a previously unknown malware family […]
- vm2 Node.js Library Vulnerabilities Enable Sandbox Escape and Arbitrary Code Executionby info@thehackernews.com (The Hacker News) (The Hacker News) on May 7, 2026 at 4:15 am
A dozen critical security vulnerabilities have been disclosed in the vm2 Node.js library that could be exploited by bad actors to break out of the sandbox and execute arbitrary […]
- Mirai-Based xlabs_v1 Botnet Exploits ADB to Hijack IoT Devices for DDoS Attacksby info@thehackernews.com (The Hacker News) (The Hacker News) on May 6, 2026 at 8:21 pm
Cybersecurity researchers have exposed a new Mirai-derived botnet that self-identifies as xlabs_v1 and targets internet-exposed devices running Android Debug Bridge (ADB) to […]
- MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attackby info@thehackernews.com (The Hacker News) (The Hacker News) on May 6, 2026 at 1:00 pm
The Iranian state-sponsored hacking group known as MuddyWater (aka Mango Sandstorm, Seedworm, and Static Kitten) has been attributed to a ransomware attack in what has been […]
- The Hacker News Launches ‘Cybersecurity Stars Awards 2026’ — Submissions Now Openby info@thehackernews.com (The Hacker News) (The Hacker News) on May 6, 2026 at 12:03 pm
For nearly 20 years, we at The Hacker News have mostly told scary stories about cyberspace — big hacks, broken systems, and new threats. But behind every headline, there’s a […]
