BetaIT-Hub is in early access — your feedback helps us improve. Use the chat or email [email protected]

Latest
Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch AvailableThe Hacker News · 3h agoSuspicious Polyfill login prompts pop up on Toshiba, Muji websitesBleepingComputer · 9h agoFormer cyber executive turned whistleblower accuses IBM of covering up several data breachesTechCrunch Security · 11h agoCISA: Hackers now exploit SolarWinds Serv-U flaw to crash serversBleepingComputer · 12h agoMiasma Malware Hits 32 Red Hat Packages via Compromised GitHub AccountHackRead · 12h agoChinese APT deploys new malware to keep access to hacked networksBleepingComputer · 13h agoIronWorm and New Miasma Worm Variant Hit npm in Supply Chain AttacksThe Hacker News · 13h agoDark web Nemesis Market vendor gets 26 years for selling drugsBleepingComputer · 13h agoAtlas Menu Data Breach Exposes 64,000 GTA V and CS2 Cheat Service UsersHackRead · 14h agoWeekly Metasploit Update: Apache ActiveMQ RCE, Gogs Rebase RCE, and Windows Kernel Pointer EnumRapid7 · 14h agoSecuring CI/CD in an agentic world: Claude Code Github action caseMicrosoft Security · 14h agoGoogle and FBI warn of ransomware group that sends fake IT workers to hack victims in personTechCrunch Security · 15h agoAndroid Spyware Asin Targets Arabic Users via Fake News, PDF and War Map AppsThe Hacker News · 16h agoOver 900 US gas station tank gauge systems exposed to attacksBleepingComputer · 16h agoNSA said to be readying Anthropic’s Mythos for use in cyber operationsTechCrunch Security · 17h agoCisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch AvailableThe Hacker News · 3h agoSuspicious Polyfill login prompts pop up on Toshiba, Muji websitesBleepingComputer · 9h agoFormer cyber executive turned whistleblower accuses IBM of covering up several data breachesTechCrunch Security · 11h agoCISA: Hackers now exploit SolarWinds Serv-U flaw to crash serversBleepingComputer · 12h agoMiasma Malware Hits 32 Red Hat Packages via Compromised GitHub AccountHackRead · 12h agoChinese APT deploys new malware to keep access to hacked networksBleepingComputer · 13h agoIronWorm and New Miasma Worm Variant Hit npm in Supply Chain AttacksThe Hacker News · 13h agoDark web Nemesis Market vendor gets 26 years for selling drugsBleepingComputer · 13h agoAtlas Menu Data Breach Exposes 64,000 GTA V and CS2 Cheat Service UsersHackRead · 14h agoWeekly Metasploit Update: Apache ActiveMQ RCE, Gogs Rebase RCE, and Windows Kernel Pointer EnumRapid7 · 14h agoSecuring CI/CD in an agentic world: Claude Code Github action caseMicrosoft Security · 14h agoGoogle and FBI warn of ransomware group that sends fake IT workers to hack victims in personTechCrunch Security · 15h agoAndroid Spyware Asin Targets Arabic Users via Fake News, PDF and War Map AppsThe Hacker News · 16h agoOver 900 US gas station tank gauge systems exposed to attacksBleepingComputer · 16h agoNSA said to be readying Anthropic’s Mythos for use in cyber operationsTechCrunch Security · 17h ago

Security & IT News

Live

Real-time news from 13+ trusted sources — BleepingComputer, The Hacker News, Krebs on Security, Dark Reading & more.

448 results in Breach

🔴 BreachThe Hacker News·57d ago
Backdoored Smart Slider 3 Pro Update Distributed via Compromised Nextend Servers

Unknown threat actors have hijacked the update system for the Smart Slider 3 Pro plugin for WordPress and Joomla to push a poisoned version containing a backdoor. The incident impacts Smart Slider 3 Pro version 3.5.1.35 for WordPress, per WordPress security company Patchstack. Smart Slider 3 is a popular WordPress slider plugin with more than 800,000 active installations across its free and Pro

🔴 BreachThe Hacker News·57d ago
EngageLab SDK Flaw Exposed 50M Android Users, Including 30M Crypto Wallets

Details have emerged about a now-patched security vulnerability in a widely used third-party Android software development kit (SDK) called EngageLab SDK that could have put millions of cryptocurrency wallet users at risk. "This flaw allows apps on the same device to bypass Android security sandbox and gain unauthorized access to private data," the Microsoft Defender

🔴 BreachMicrosoft Security·57d ago
Intent redirection vulnerability in third-party SDK exposed millions of Android wallets to potential risk

In this article Technical details Disclosure timeline Mitigation and protection guidance References Learn more During routine security research, we identified a severe intent redirection vulnerability in a widely used third-party Android SDK called EngageSDK. This flaw allows apps on the same device to bypass Android security sandbox and gain unauthorized access to private data. With over 30 million installations of third-party crypto wallet applications alone, the exposure of PII, user credentials and financial data were exposed to risk. All of the detected apps using vulnerable versions have been removed from Google Play. Following our Coordinated Vulnerability Disclosure practices (via Microsoft Security Vulnerability Research), we notified EngageLab and the Android Security Team. We collaborated with all parties to investigate and validate the issue, which was resolved as of November 3, 2025 in version 5.2.1 of the EngageSDK. This case shows how weaknesses in third‑party SDKs can have large‑scale security implications, especially in high‑value sectors like digital asset management. As of the time of writing, we are not aware of any evidence indicating that this vulnerability has been exploited in the wild. Nevertheless, we strongly recommend that developers who integrate the affected SDK upgrade to the latest available version. While this is a vulnerability introduced by a third-party SDK, Android’s existing layered security model is capable of providing additional mitigations against exploitation of vulnerabilities through intents. Android has updated these automatic user protections to provide additional mitigation against the specific EngageSDK risks described in this report while developers update to the non-vulnerable version of EngageSDK. Users who previously downloaded a vulnerable app are protected. In this blog, we provide a technical analysis of a vulnerability that bypasses core Android security mechanisms. We also examine why this issue is significant in the current landscape: apps increasingly rely on third‑party SDKs, creating large and often opaque supply‑chain dependencies. As mobile wallets and other high‑value apps become more common, even small flaws in upstream libraries can impact millions of devices. These risks increase when integrations expose exported components or rely on trust assumptions that aren’t validated across app boundaries. Because Android apps frequently depend on external libraries, insecure integrations can introduce attack surfaces into otherwise secure applications. We provide resources for three key audiences: Developers: In addition to the best practices Android provides its developers, we provide practical guidance on identifying and preventing similar flaws, including how to review dependencies and validate exported components. Researchers: Insights into how we discovered the issue and the methodology we used to confirm its impact. General readers: An explanation of the implications of this vulnera

🔴 BreachThe Hacker News·57d ago
Bitter-Linked Hack-for-Hire Campaign Targets Journalists Across MENA Region

An apparent hack-for-hire campaign likely orchestrated by a threat actor with suspected ties to the Indian government targeted journalists, activists, and government officials across the Middle East and North Africa (MENA), according to findings from Access Now, Lookout, and SMEX. Two of the targets included prominent Egyptian journalists and government critics, Mostafa