BetaIT-Hub is in early access — your feedback helps us improve. Use the chat or email [email protected]

Latest
Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch AvailableThe Hacker News · 1h agoSuspicious Polyfill login prompts pop up on Toshiba, Muji websitesBleepingComputer · 8h agoFormer cyber executive turned whistleblower accuses IBM of covering up several data breachesTechCrunch Security · 9h agoCISA: Hackers now exploit SolarWinds Serv-U flaw to crash serversBleepingComputer · 11h agoMiasma Malware Hits 32 Red Hat Packages via Compromised GitHub AccountHackRead · 11h agoChinese APT deploys new malware to keep access to hacked networksBleepingComputer · 12h agoIronWorm and New Miasma Worm Variant Hit npm in Supply Chain AttacksThe Hacker News · 12h agoDark web Nemesis Market vendor gets 26 years for selling drugsBleepingComputer · 12h agoAtlas Menu Data Breach Exposes 64,000 GTA V and CS2 Cheat Service UsersHackRead · 13h agoWeekly Metasploit Update: Apache ActiveMQ RCE, Gogs Rebase RCE, and Windows Kernel Pointer EnumRapid7 · 13h agoSecuring CI/CD in an agentic world: Claude Code Github action caseMicrosoft Security · 13h agoGoogle and FBI warn of ransomware group that sends fake IT workers to hack victims in personTechCrunch Security · 14h agoAndroid Spyware Asin Targets Arabic Users via Fake News, PDF and War Map AppsThe Hacker News · 15h agoOver 900 US gas station tank gauge systems exposed to attacksBleepingComputer · 15h agoNSA said to be readying Anthropic’s Mythos for use in cyber operationsTechCrunch Security · 15h agoCisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch AvailableThe Hacker News · 1h agoSuspicious Polyfill login prompts pop up on Toshiba, Muji websitesBleepingComputer · 8h agoFormer cyber executive turned whistleblower accuses IBM of covering up several data breachesTechCrunch Security · 9h agoCISA: Hackers now exploit SolarWinds Serv-U flaw to crash serversBleepingComputer · 11h agoMiasma Malware Hits 32 Red Hat Packages via Compromised GitHub AccountHackRead · 11h agoChinese APT deploys new malware to keep access to hacked networksBleepingComputer · 12h agoIronWorm and New Miasma Worm Variant Hit npm in Supply Chain AttacksThe Hacker News · 12h agoDark web Nemesis Market vendor gets 26 years for selling drugsBleepingComputer · 12h agoAtlas Menu Data Breach Exposes 64,000 GTA V and CS2 Cheat Service UsersHackRead · 13h agoWeekly Metasploit Update: Apache ActiveMQ RCE, Gogs Rebase RCE, and Windows Kernel Pointer EnumRapid7 · 13h agoSecuring CI/CD in an agentic world: Claude Code Github action caseMicrosoft Security · 13h agoGoogle and FBI warn of ransomware group that sends fake IT workers to hack victims in personTechCrunch Security · 14h agoAndroid Spyware Asin Targets Arabic Users via Fake News, PDF and War Map AppsThe Hacker News · 15h agoOver 900 US gas station tank gauge systems exposed to attacksBleepingComputer · 15h agoNSA said to be readying Anthropic’s Mythos for use in cyber operationsTechCrunch Security · 15h ago

Security & IT News

Live

Real-time news from 13+ trusted sources — BleepingComputer, The Hacker News, Krebs on Security, Dark Reading & more.

448 results in Breach

🔴 BreachKrebs on Security·45d ago
‘Scattered Spider’ Member ‘Tylerb’ Pleads Guilty

A 24-year-old British national and senior member of the cybercrime group “ Scattered Spider ” has pleaded guilty to wire fraud conspiracy and aggravated identity theft. Tyler Robert Buchanan admitted his role in a series of text-message phishing attacks in the summer of 2022 that allowed the group to hack into at least a dozen major technology companies and steal tens of millions of dollars worth of cryptocurrency from investors. Buchanan’s hacker handle “ Tylerb ” once graced a leaderboard in the English-language criminal hacking scene that tracked the most accomplished cyber thieves. Now in U.S. custody and awaiting sentencing, the Dundee, Scotland native is facing the possibility of more than 20 years in prison. Two photos published in a Daily Mail story dated May 3, 2025 show Buchanan as a child (left) and as an adult being detained by airport authorities in Spain. “M S” in this screenshot refers to Marks Spencer, a major U.K. retail chain that suffered a ransomware attack last year at the hands of Scattered Spider. Scattered Spider is the name given to a prolific English-speaking cybercrime group known for using social engineering tactics to break into companies and steal data for ransom, often impersonating employees or contractors to deceive IT help desks into granting access. As part of his guilty plea, Buchanan admitted conspiring with other Scattered Spider members to launch tens of thousands of SMS-based phishing attacks in 2022 that led to intrusions at a number of technology companies, including Twilio, LastPass, DoorDash, and Mailchimp. The group then used data stolen in those breaches to carry out SIM-swapping attacks that siphoned funds from individual cryptocurrency investors. In an unauthorized SIM-swap, crooks transfer the target’s phone number to a device they control and intercept any text messages or phone calls to the victim’s device — such as one-time passcodes for authentication and password reset links sent via SMS. The U.S. Justice Department said Buchanan admitted to stealing at least $8 million in virtual currency from individual victims throughout the United States. FBI investigators tied Buchanan to the 2022 SMS phishing attacks after discovering the same username and email address was used to register numerous phishing domains seen in the campaign. The domain registrar NameCheap found that less than a month before the phishing spree, the account that registered those domains logged in from an Internet address in the U.K. FBI investigators said the Scottish police told them the address was leased to Buchanan throughout 2022. As first reported by KrebsOnSecurity, Buchanan fled the United Kingdom in February 2023, after a rival cybercrime gang hired thugs to invade his home, assault his mother, and threaten to burn him with a blowtorch unless he gave up the keys to his cryptocurrency wallet. That same year, U.K. investigators found a device at Buchanan’s Scotland residen

🔴 BreachThe Hacker News·46d ago
⚡ Weekly Recap: Vercel Hack, Push Fraud, QEMU Abused, New Android RATs Emerge & More

Monday’s recap shows the same pattern in different places. A third-party tool becomes a way in, then leads to internal access. A trusted download path is briefly swapped to deliver malware. Browser extensions act normally while pulling data and running code. Even update channels are used to push payloads. It’s not breaking systems—it’s bending trust. There’s also a shift in how attacks run.

🔴 BreachThe Hacker News·47d ago
Vercel Breach Tied to Context AI Hack Exposes Limited Customer Credentials

Web infrastructure provider Vercel has disclosed a security breach that allows bad actors to gain unauthorized access to "certain" internal Vercel systems. The incident stemmed from the compromise of Context.ai, a third-party artificial intelligence (AI) tool, that was used by an employee at the company. "The attacker used that access to take over the employee's Vercel Google Workspace account,