BetaIT-Hub is in early access — your feedback helps us improve. Use the chat or email [email protected]

Latest
Suspicious Polyfill login prompts pop up on Toshiba, Muji websitesBleepingComputer · 22m agoFormer cyber executive turned whistleblower accuses IBM of covering up several data breachesTechCrunch Security · 1h agoCISA: Hackers now exploit SolarWinds Serv-U flaw to crash serversBleepingComputer · 3h agoMiasma Malware Hits 32 Red Hat Packages via Compromised GitHub AccountHackRead · 3h agoChinese APT deploys new malware to keep access to hacked networksBleepingComputer · 4h agoIronWorm and New Miasma Worm Variant Hit npm in Supply Chain AttacksThe Hacker News · 4h agoDark web Nemesis Market vendor gets 26 years for selling drugsBleepingComputer · 4h agoAtlas Menu Data Breach Exposes 64,000 GTA V and CS2 Cheat Service UsersHackRead · 5h agoSecuring CI/CD in an agentic world: Claude Code Github action caseMicrosoft Security · 5h agoGoogle and FBI warn of ransomware group that sends fake IT workers to hack victims in personTechCrunch Security · 6h agoAndroid Spyware Asin Targets Arabic Users via Fake News, PDF and War Map AppsThe Hacker News · 7h agoOver 900 US gas station tank gauge systems exposed to attacksBleepingComputer · 7h agoNSA said to be readying Anthropic’s Mythos for use in cyber operationsTechCrunch Security · 7h agoWhat 2026 DBIR Confirms: Attacks Are Living in the BrowserBleepingComputer · 8h agoReaper macOS Infostealer Abuses Script Editor to Steal Crypto and PasswordsHackRead · 9h agoSuspicious Polyfill login prompts pop up on Toshiba, Muji websitesBleepingComputer · 22m agoFormer cyber executive turned whistleblower accuses IBM of covering up several data breachesTechCrunch Security · 1h agoCISA: Hackers now exploit SolarWinds Serv-U flaw to crash serversBleepingComputer · 3h agoMiasma Malware Hits 32 Red Hat Packages via Compromised GitHub AccountHackRead · 3h agoChinese APT deploys new malware to keep access to hacked networksBleepingComputer · 4h agoIronWorm and New Miasma Worm Variant Hit npm in Supply Chain AttacksThe Hacker News · 4h agoDark web Nemesis Market vendor gets 26 years for selling drugsBleepingComputer · 4h agoAtlas Menu Data Breach Exposes 64,000 GTA V and CS2 Cheat Service UsersHackRead · 5h agoSecuring CI/CD in an agentic world: Claude Code Github action caseMicrosoft Security · 5h agoGoogle and FBI warn of ransomware group that sends fake IT workers to hack victims in personTechCrunch Security · 6h agoAndroid Spyware Asin Targets Arabic Users via Fake News, PDF and War Map AppsThe Hacker News · 7h agoOver 900 US gas station tank gauge systems exposed to attacksBleepingComputer · 7h agoNSA said to be readying Anthropic’s Mythos for use in cyber operationsTechCrunch Security · 7h agoWhat 2026 DBIR Confirms: Attacks Are Living in the BrowserBleepingComputer · 8h agoReaper macOS Infostealer Abuses Script Editor to Steal Crypto and PasswordsHackRead · 9h ago

Security & IT News

Live

Real-time news from 13+ trusted sources — BleepingComputer, The Hacker News, Krebs on Security, Dark Reading & more.

63 results in Research

🧪 ResearchThe Hacker News·2d ago
Beyond the Zero-Day: See Your Network Like an Attacker | Webinar with HD Moore

Assume the breach. Zero-days keep shipping, AI is writing exploits faster than anyone patches, and "patch everything in time" stopped working years ago. Stop betting the org on winning that race. You don't control which bug lands. You control what it can reach once it does. That is a question about the shape of your network, and most teams have the shape wrong. HD Moore, creator of Metasploit

🧪 ResearchSchneier on Security·3d ago
Microsoft Threatening Security Researcher

An anonymous security researcher called “Nightmare Eclipse” has been publishing a series of significant security exploits against Microsoft Windows—including one that breaks BitLocker. Microsoft has threatened legal action against the researcher. Lots of recriminations are being traded back and forth.

🧪 ResearchThe Hacker News·8d ago
Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal

Microsoft has come out strongly in favor of Coordinated Vulnerability Disclosure (CVD), urging the research community to share their findings and give affected vendors an opportunity to better understand the impact and address them before they are publicly disclosed. The development comes after a researcher named Chaotic Eclipse (aka Nightmare-Eclipse) disclosed details of multiple zero-day

🧪 ResearchThe Hacker News·15d ago
ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New Stories

This week starts small. A token leaks. A bad package slips in. A login trick works. An old tool shows up again. At first, it feels like the usual mess. Then you see the pattern: attackers are not always breaking in. They are using the parts we already trust. That is what makes it worrying. The danger is in normal things now - updates, apps, cloud buttons, support chats, trusted accounts. AI

🧪 ResearchSchneier on Security·18d ago
Zero-Day Exploit Against Windows BitLocker

It’s nasty , but it requires physical access to the computer: The exploit, named YellowKey, was published earlier this week by a researcher who goes by the alias Nightmare-Eclipse. It reliably bypasses default Windows 11 deployments of BitLocker, the full-volume encryption protection Microsoft provides to make disk contents off-limits to anyone without the decryption key, which is stored in a secured piece of hardware known as a trusted platform module (TPM). BitLocker is a mandatory protection for many organizations, including those that contract with governments. Slashdot thread . And here’s Nightmare-Eclipse’s GitHub account.

🧪 ResearchThe Hacker News·18d ago
MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems

Chaotic Eclipse, the security researcher behind the recently disclosed Windows flaws, YellowKey and GreenPlasma, has released a proof-of-concept (PoC) for a Windows privilege escalation zero-day flaw that grants attackers SYSTEM privileges on fully patched Windows systems. Codenamed MiniPlasma, the vulnerability impacts "cldflt.sys," which refers to the Windows Cloud Files Mini Filter Driver,