BetaIT-Hub is in early access — your feedback helps us improve. Use the chat or email [email protected]

Latest
New ChatGPT Lockdown Mode Limits Tools That Could Enable Data ExfiltrationThe Hacker News · 2h agoFree Apps Are Quietly Turning Smart TVs Into Web-Scraping Proxies for AIThe Hacker News · 7h agoAI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 BugsThe Hacker News · 8h agoMiasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain AttackThe Hacker News · 8h agoCisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch AvailableThe Hacker News · 11h agoSuspicious Polyfill login prompts pop up on Toshiba, Muji websitesBleepingComputer · 17h agoFormer cyber executive turned whistleblower accuses IBM of covering up several data breachesTechCrunch Security · 19h agoCISA: Hackers now exploit SolarWinds Serv-U flaw to crash serversBleepingComputer · 20h agoMiasma Malware Hits 32 Red Hat Packages via Compromised GitHub AccountHackRead · 20h agoChinese APT deploys new malware to keep access to hacked networksBleepingComputer · 21h agoIronWorm and New Miasma Worm Variant Hit npm in Supply Chain AttacksThe Hacker News · 21h agoDark web Nemesis Market vendor gets 26 years for selling drugsBleepingComputer · 21h agoAtlas Menu Data Breach Exposes 64,000 GTA V and CS2 Cheat Service UsersHackRead · 22h agoWeekly Metasploit Update: Apache ActiveMQ RCE, Gogs Rebase RCE, and Windows Kernel Pointer EnumRapid7 · 22h agoSecuring CI/CD in an agentic world: Claude Code Github action caseMicrosoft Security · 22h agoNew ChatGPT Lockdown Mode Limits Tools That Could Enable Data ExfiltrationThe Hacker News · 2h agoFree Apps Are Quietly Turning Smart TVs Into Web-Scraping Proxies for AIThe Hacker News · 7h agoAI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 BugsThe Hacker News · 8h agoMiasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain AttackThe Hacker News · 8h agoCisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch AvailableThe Hacker News · 11h agoSuspicious Polyfill login prompts pop up on Toshiba, Muji websitesBleepingComputer · 17h agoFormer cyber executive turned whistleblower accuses IBM of covering up several data breachesTechCrunch Security · 19h agoCISA: Hackers now exploit SolarWinds Serv-U flaw to crash serversBleepingComputer · 20h agoMiasma Malware Hits 32 Red Hat Packages via Compromised GitHub AccountHackRead · 20h agoChinese APT deploys new malware to keep access to hacked networksBleepingComputer · 21h agoIronWorm and New Miasma Worm Variant Hit npm in Supply Chain AttacksThe Hacker News · 21h agoDark web Nemesis Market vendor gets 26 years for selling drugsBleepingComputer · 21h agoAtlas Menu Data Breach Exposes 64,000 GTA V and CS2 Cheat Service UsersHackRead · 22h agoWeekly Metasploit Update: Apache ActiveMQ RCE, Gogs Rebase RCE, and Windows Kernel Pointer EnumRapid7 · 22h agoSecuring CI/CD in an agentic world: Claude Code Github action caseMicrosoft Security · 22h ago

Security & IT News

Live

Real-time news from 13+ trusted sources — BleepingComputer, The Hacker News, Krebs on Security, Dark Reading & more.

🦠 MalwareThe Hacker News·19d ago
⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More

Monday opens with a trust problem. A mail server flaw is under active use. A network control system was targeted. Trusted packages were poisoned. A fake model page pushed a stealer. Then came the familiar ransom claim: the data was returned and deleted. The pattern is clear. One weak dependency can leak keys. One leaked key can open cloud access. One cloud foothold can become a production

VulnerabilityThe Hacker News·19d ago
How to Reduce Phishing Exposure Before It Turns into Business Disruption

What happens when a phishing email looks clean enough to pass through security, but dangerous enough to expose the business after one click? That is the gap many SOCs still struggle with: the attacks that leave teams unsure what was exposed, who else was targeted, and how far the risk has spread. Early phishing detection closes that gap. It helps teams move from uncertainty to evidence faster,

VulnerabilityThe Hacker News·19d ago
Developer Workstations Are Now Part of the Software Supply Chain

Supply chain attackers are not only trying to slip malicious code into trusted software. They are trying to steal the access that makes trusted software possible. Recently, three separate campaigns hit npm, PyPI, and Docker Hub in a 48-hour window, and all three targeted secrets from developer environments and CI/CD pipelines, including API keys, cloud credentials, SSH keys, and tokens. This is

🧪 ResearchSchneier on Security·19d ago
Zero-Day Exploit Against Windows BitLocker

It’s nasty , but it requires physical access to the computer: The exploit, named YellowKey, was published earlier this week by a researcher who goes by the alias Nightmare-Eclipse. It reliably bypasses default Windows 11 deployments of BitLocker, the full-volume encryption protection Microsoft provides to make disk contents off-limits to anyone without the decryption key, which is stored in a secured piece of hardware known as a trusted platform module (TPM). BitLocker is a mandatory protection for many organizations, including those that contract with governments. Slashdot thread . And here’s Nightmare-Eclipse’s GitHub account.

🩹 PatchThe Hacker News·19d ago
Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flaws

Ivanti, Fortinet, n8n, SAP, and VMware have released security fixes for various vulnerabilities that could be exploited by bad actors to bypass authentication and execute arbitrary code. Topping the list is a critical flaw impacting Ivanti Xtraction (CVE-2026-8043, CVSS score: 9.6) that could be exploited to achieve information disclosure or client-side attacks. "External control of a file name

🦠 MalwareThe Hacker News·19d ago
Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware

Cybersecurity researchers have discovered four new npm packages containing information-stealing malware, one of which is a clone of the Shai-Hulud worm open-sourced by TeamPCP. The list of identified packages is below - chalk-tempalte (825 Downloads) @deadcode09284814/axios-util (284 Downloads) axois-utils (963 Downloads) color-style-utils (934 Downloads) "One of the packages (chalk-tempalte)

🦠 MalwareThe Hacker News·19d ago
Pre-Stuxnet Fast16 Malware Tampered with Nuclear Weapons Simulations

A new analysis of the Lua-based fast16 malware has confirmed that it was a cyber sabotage tool designed to tamper with nuclear weapons testing simulations. According to Broadcom-owned Symantec and Carbon Black teams, the pre-Stuxnet tool was engineered to corrupt uranium-compression simulations that are central to nuclear weapon design. "Fast16's hook engine is selectively interested in