BetaIT-Hub is in early access — your feedback helps us improve. Use the chat or email [email protected]

Latest
Free Apps Are Quietly Turning Smart TVs Into Web-Scraping Proxies for AIThe Hacker News · 28m agoAI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 BugsThe Hacker News · 1h agoMiasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain AttackThe Hacker News · 1h agoCisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch AvailableThe Hacker News · 4h agoSuspicious Polyfill login prompts pop up on Toshiba, Muji websitesBleepingComputer · 11h agoFormer cyber executive turned whistleblower accuses IBM of covering up several data breachesTechCrunch Security · 12h agoCISA: Hackers now exploit SolarWinds Serv-U flaw to crash serversBleepingComputer · 13h agoMiasma Malware Hits 32 Red Hat Packages via Compromised GitHub AccountHackRead · 13h agoChinese APT deploys new malware to keep access to hacked networksBleepingComputer · 14h agoIronWorm and New Miasma Worm Variant Hit npm in Supply Chain AttacksThe Hacker News · 14h agoDark web Nemesis Market vendor gets 26 years for selling drugsBleepingComputer · 15h agoAtlas Menu Data Breach Exposes 64,000 GTA V and CS2 Cheat Service UsersHackRead · 15h agoWeekly Metasploit Update: Apache ActiveMQ RCE, Gogs Rebase RCE, and Windows Kernel Pointer EnumRapid7 · 15h agoSecuring CI/CD in an agentic world: Claude Code Github action caseMicrosoft Security · 16h agoGoogle and FBI warn of ransomware group that sends fake IT workers to hack victims in personTechCrunch Security · 16h agoFree Apps Are Quietly Turning Smart TVs Into Web-Scraping Proxies for AIThe Hacker News · 28m agoAI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 BugsThe Hacker News · 1h agoMiasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain AttackThe Hacker News · 1h agoCisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch AvailableThe Hacker News · 4h agoSuspicious Polyfill login prompts pop up on Toshiba, Muji websitesBleepingComputer · 11h agoFormer cyber executive turned whistleblower accuses IBM of covering up several data breachesTechCrunch Security · 12h agoCISA: Hackers now exploit SolarWinds Serv-U flaw to crash serversBleepingComputer · 13h agoMiasma Malware Hits 32 Red Hat Packages via Compromised GitHub AccountHackRead · 13h agoChinese APT deploys new malware to keep access to hacked networksBleepingComputer · 14h agoIronWorm and New Miasma Worm Variant Hit npm in Supply Chain AttacksThe Hacker News · 14h agoDark web Nemesis Market vendor gets 26 years for selling drugsBleepingComputer · 15h agoAtlas Menu Data Breach Exposes 64,000 GTA V and CS2 Cheat Service UsersHackRead · 15h agoWeekly Metasploit Update: Apache ActiveMQ RCE, Gogs Rebase RCE, and Windows Kernel Pointer EnumRapid7 · 15h agoSecuring CI/CD in an agentic world: Claude Code Github action caseMicrosoft Security · 16h agoGoogle and FBI warn of ransomware group that sends fake IT workers to hack victims in personTechCrunch Security · 16h ago

Security & IT News

Live

Real-time news from 13+ trusted sources — BleepingComputer, The Hacker News, Krebs on Security, Dark Reading & more.

448 results in Breach

🔴 BreachSANS ISC·58d ago
TeamPCP Supply Chain Campaign: Update 007 - Cisco Source Code Stolen via Trivy-Linked Breach, Google GTIG Tracks TeamPCP as UNC6780, and CISA KEV Deadline Arrives with No Standalone Advisory, (Wed, Apr 8th)

This is the seventh update to the TeamPCP supply chain campaign threat intelligence report, When the Security Scanner Became the Weapon (v3.0, March 25, 2026). Update 006 covered developments through April 3, including the CERT-EU European Commission breach disclosure, ShinyHunters' confirmation of credential sharing, Sportradar breach details, and Mandiant's quantification of 1,000+ compromised SaaS environments. This update consolidates five days of intelligence from April 3 through April 8, 2026. HIGH: Cisco Development Environment Breached via Trivy Supply Chain, 300+ Repositories Stolen BleepingComputer reported that threat actors leveraged credentials stolen through the Trivy supply chain compromise (%%cve:2026-33634%%) to breach Cisco's internal development environment. The attackers gained access to build systems and developer workstations through a malicious GitHub Action plugin. The breach scope is substantial: Over 300 private GitHub repositories containing Cisco source code were cloned, including code for AI-powered products and unreleased items Customer repositories belonging to banks, business process outsourcing firms, and US government agencies were among those exfiltrated AWS keys were stolen and used for unauthorized activities across Cisco's cloud accounts Multiple threat actors were reportedly involved in the Cisco CI/CD and AWS account breaches, with varying degrees of activity ShinyHunters subsequently expanded their claims beyond the development environment, alleging access to 3 million or more Salesforce records, additional GitHub repositories, and AWS S3 buckets. The claimed dataset allegedly includes records tied to personnel at FBI, DHS, DISA, IRS, and NASA, as well as the Australian Ministry of Defense and Indian government agencies. These expanded claims have not been independently verified. ShinyHunters set an extortion deadline of approximately April 3. As of April 8, no public data dump has materialized and Cisco has not issued a public statement specifically addressing the ShinyHunters extortion claim. The deadline passage without publication, combined with CipherForce's infrastructure outage documented below, represents the second data point suggesting potential friction in the campaign's monetization pipeline. The Cisco breach is significant because it is the highest-profile technology company confirmed as a direct victim of the Trivy supply chain compromise. The involvement of multiple threat actors in a single victim's environment is consistent with the credential-sharing pattern documented in Update 006 . The theft of customer source code repositories for banks and US government agencies creates secondary exposure obligations for downstream organizations. Recommended action: Organizations that are Cisco customers or partners, particularly those with source code or build artifacts hosted in Cisco's development infrastructure, should contact Cisco to determine whether their repos

🔴 BreachThe Hacker News·59d ago
N. Korean Hackers Spread 1,700 Malicious Packages Across npm, PyPI, Go, Rust

The North Korea-linked persistent campaign known as Contagious Interview has spread its tentacles by publishing malicious packages targeting the Go, Rust, and PHP ecosystems. "The threat actor's packages were designed to impersonate legitimate developer tooling [...], while quietly functioning as malware loaders, extending Contagious Interview’s established playbook into a coordinated

🔴 BreachThe Hacker News·59d ago
Iran-Linked Hackers Disrupt U.S. Critical Infrastructure by Targeting Internet-Exposed PLCs

Iran-affiliated cyber actors are targeting internet-facing operational technology (OT) devices across critical infrastructures in the U.S., including programmable logic controllers (PLCs), cybersecurity and intelligence agencies warned Tuesday. "These attacks have led to diminished PLC functionality, manipulation of display data and, in some cases, operational disruption and financial