BetaIT-Hub is in early access — your feedback helps us improve. Use the chat or email [email protected]

Latest
Suspicious Polyfill login prompts pop up on Toshiba, Muji websitesBleepingComputer · 7h agoFormer cyber executive turned whistleblower accuses IBM of covering up several data breachesTechCrunch Security · 8h agoCISA: Hackers now exploit SolarWinds Serv-U flaw to crash serversBleepingComputer · 9h agoMiasma Malware Hits 32 Red Hat Packages via Compromised GitHub AccountHackRead · 9h agoChinese APT deploys new malware to keep access to hacked networksBleepingComputer · 10h agoIronWorm and New Miasma Worm Variant Hit npm in Supply Chain AttacksThe Hacker News · 10h agoDark web Nemesis Market vendor gets 26 years for selling drugsBleepingComputer · 11h agoAtlas Menu Data Breach Exposes 64,000 GTA V and CS2 Cheat Service UsersHackRead · 11h agoWeekly Metasploit Update: Apache ActiveMQ RCE, Gogs Rebase RCE, and Windows Kernel Pointer EnumRapid7 · 11h agoSecuring CI/CD in an agentic world: Claude Code Github action caseMicrosoft Security · 12h agoGoogle and FBI warn of ransomware group that sends fake IT workers to hack victims in personTechCrunch Security · 12h agoAndroid Spyware Asin Targets Arabic Users via Fake News, PDF and War Map AppsThe Hacker News · 14h agoOver 900 US gas station tank gauge systems exposed to attacksBleepingComputer · 14h agoNSA said to be readying Anthropic’s Mythos for use in cyber operationsTechCrunch Security · 14h agoWhat 2026 DBIR Confirms: Attacks Are Living in the BrowserBleepingComputer · 15h agoSuspicious Polyfill login prompts pop up on Toshiba, Muji websitesBleepingComputer · 7h agoFormer cyber executive turned whistleblower accuses IBM of covering up several data breachesTechCrunch Security · 8h agoCISA: Hackers now exploit SolarWinds Serv-U flaw to crash serversBleepingComputer · 9h agoMiasma Malware Hits 32 Red Hat Packages via Compromised GitHub AccountHackRead · 9h agoChinese APT deploys new malware to keep access to hacked networksBleepingComputer · 10h agoIronWorm and New Miasma Worm Variant Hit npm in Supply Chain AttacksThe Hacker News · 10h agoDark web Nemesis Market vendor gets 26 years for selling drugsBleepingComputer · 11h agoAtlas Menu Data Breach Exposes 64,000 GTA V and CS2 Cheat Service UsersHackRead · 11h agoWeekly Metasploit Update: Apache ActiveMQ RCE, Gogs Rebase RCE, and Windows Kernel Pointer EnumRapid7 · 11h agoSecuring CI/CD in an agentic world: Claude Code Github action caseMicrosoft Security · 12h agoGoogle and FBI warn of ransomware group that sends fake IT workers to hack victims in personTechCrunch Security · 12h agoAndroid Spyware Asin Targets Arabic Users via Fake News, PDF and War Map AppsThe Hacker News · 14h agoOver 900 US gas station tank gauge systems exposed to attacksBleepingComputer · 14h agoNSA said to be readying Anthropic’s Mythos for use in cyber operationsTechCrunch Security · 14h agoWhat 2026 DBIR Confirms: Attacks Are Living in the BrowserBleepingComputer · 15h ago

Security & IT News

Live

Real-time news from 13+ trusted sources — BleepingComputer, The Hacker News, Krebs on Security, Dark Reading & more.

448 results in Breach

🔴 BreachThe Hacker News·43d ago
Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign

Bitwarden CLI has been compromised as part of the newly discovered and ongoing Checkmarx supply chain campaign, according to new findings from JFrog and Socket. "The affected package version appears to be @bitwarden/[email protected], and the malicious code was published in 'bw1.js,' a file included in the package contents," the application security company said. "The attack appears to have leveraged

🔴 BreachThe Hacker News·43d ago
ThreatsDay Bulletin: $290M DeFi Hack, macOS LotL Abuse, ProxySmart SIM Farms +25 New Stories

You scroll past one incident and see another that feels familiar, like it should have been fixed years ago, but it still works with small changes. Same bugs. Same mistakes. The supply chain is messy. Packages you did not check are stealing data, adding backdoors, and spreading. Attacking the systems behind apps is easier than breaking the apps themselves. The exploits are simple but still work

🔴 BreachCISA·43d ago
Defending Against China-Nexus Covert Networks of Compromised Devices

div class="SCXW131754345 BCX8" div class="OutlineElement Ltr SCXW131754345 BCX8" h2 a class="c-button c-button--on-dark" href="https://urldefense.us/v3/__https://www.ncsc.gov.uk/news/defending-against-china-nexus-covert-networks-of-compromised-devices__;!!BClRuOV5cvtbuNI!Cvg8stIR3jHWVZgHhCVvEwbwDXxXIRSprOQ9JtY2YKwxUIGVovuDAu7QrFsfw3sfAVd8-gxEMIpgldwlY-jTD7G0%24" Defending against china-nexus covert networks of compromised devices /a /h2 h2 a class="c-button c-button--on-dark" href="https://urldefense.us/v3/__https://www.ncsc.gov.uk/news/executive-summary-defending-against-china-nexus-covert-networks-of-compromised-devices__;!!BClRuOV5cvtbuNI!Cvg8stIR3jHWVZgHhCVvEwbwDXxXIRSprOQ9JtY2YKwxUIGVovuDAu7QrFsfw3sfAVd8-gxEMIpgldwlYzP90Ign%24" executive summary /a /h2 h2 strong Defending against China-nexus covert networks of compromised devices nbsp; /strong /h2 p Explaining the widespread shift in tactics, techniques and procedures (TTPs) towards networks of compromised infrastructure, and how to defend against it nbsp; /p h3 strong Summary /strong /h3 p With support from the UK a href="https://www.ncsc.gov.uk/information/cyber-league" target="_blank" u Cyber League /u /a , this advisory has been jointly released by the National Cyber Security Centre (NCSC-UK) and international partners: nbsp; /p ul li Australian Signals Directorate’s (ASD’s) Australian Cyber Security Centre (ACSC) /li li Communications Security Establishment Canada’s (CSE’s) Canadian Centre for Cyber Security (Cyber Centre) /li li Germany Federal Office for the Protection of the Constitution - nbsp; nbsp; Bundesamt für Verfassungsschutz (BfV) /li li Germany Federal Intelligence Service – Bundesnachrichtendienst (BND) /li li Germany Federal Office for Information Security - Bundesamt für Sicherheit in der Informationstechnik (BSI) /li li Japan National Cybersecurity Office (NCO) - 国家サイバー統括室 /li li Netherlands General Intelligence and Security Service - Algemene Inlichtingen- en Veiligheidsdienst (AIVD) /li li Netherlands Defence Intelligence and Security Service - Militaire Inlichtingen- en Veiligheidsdienst (MIVD) /li li New Zealand National Cyber Security Centre (NCSC-NZ) /li li Spain National Cryptologic Centre – Centro Criptológico Nacional (CCN) /li li Sweden National Cyber Security Centre - Nationellt cybersäkerhetscenter (NCSC-SE) /li li United States Cybersecurity and Infrastructure Security Agency (CISA) /li li United States Department of Defense Cyber Crime Center (DC3) /li li United States Federal Bureau of Investigation (FBI) /li li United States National Security Agency (NSA) nbsp; /li /ul p Its purpose is to provide network defenders with the tools needed to defend against China-nexus cyber actors and their tactic of using large scale networks of compromised devices (covert networks) to route their cyber activity. nbsp; /p h3 strong Introduction nbsp; nbsp; /strong /h3 p Over the past few years there has been a major shift in the tactics, techniques and procedures (TTPs) use

🔴 BreachThe Hacker News·43d ago
Vercel Finds More Compromised Accounts in Context.ai-Linked Breach

Vercel on Wednesday revealed that it has identified an additional set of customer accounts that were compromised as part of a security incident that enabled unauthorized access to its internal systems. The company said it made the discovery after expanding its investigation to include an extra set of compromise indicators, alongside a review of requests to the Vercel network and environment