BetaIT-Hub is in early access — your feedback helps us improve. Use the chat or email [email protected]

Latest
The FBI built its own replica small town to simulate real-world cyberattacksTechCrunch Security · 1h agoU.S. Orders Anthropic to Suspend Fable 5 and Mythos 5 Access for Foreign NationalsThe Hacker News · 7h agoWeekly Metasploit Update: New Kerberos/Certificate tracing options, and multiple new modulesRapid7 · 12h agoFriday Squid Blogging: Squid-Inspired Fluid PumpSchneier on Security · 15h agoChinese cybercrime operation that used AI to scam ‘hundreds of thousands of victims’ sued by GoogleTechCrunch Security · 16h ago400+ Arch Linux AUR Packages Hijacked to Install Rust Credential StealerThe Hacker News · 17h agoGoogle Sues Chinese Smishing Network Accused of Using Gemini AI in PhishingThe Hacker News · 17h agophpBB forum fixes auth bypass bug lurking for a decadeBleepingComputer · 18h agoChina-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a DecadeThe Hacker News · 18h agoAtomic Arch Campaign Hijacks 20+ Linux AUR Packages to Deliver MalwareHackRead · 18h agoUkrainian national pleads guilty to role in Conti ransomware operationBleepingComputer · 18h agoGoogle sues alleged Chinese cybercrime operation that used AI to send scam textsTechCrunch Security · 19h agoOver 400 Arch Linux packages compromised to push rootkit, infostealerBleepingComputer · 19h agoEarly Warning Signs of Supply-Chain Attacks Live in the Dark WebBleepingComputer · 22h agoRansomware Payment Crypto Laundering Platform Taken Out by FBI and EuropolInfosecurity Magazine · 22h agoThe FBI built its own replica small town to simulate real-world cyberattacksTechCrunch Security · 1h agoU.S. Orders Anthropic to Suspend Fable 5 and Mythos 5 Access for Foreign NationalsThe Hacker News · 7h agoWeekly Metasploit Update: New Kerberos/Certificate tracing options, and multiple new modulesRapid7 · 12h agoFriday Squid Blogging: Squid-Inspired Fluid PumpSchneier on Security · 15h agoChinese cybercrime operation that used AI to scam ‘hundreds of thousands of victims’ sued by GoogleTechCrunch Security · 16h ago400+ Arch Linux AUR Packages Hijacked to Install Rust Credential StealerThe Hacker News · 17h agoGoogle Sues Chinese Smishing Network Accused of Using Gemini AI in PhishingThe Hacker News · 17h agophpBB forum fixes auth bypass bug lurking for a decadeBleepingComputer · 18h agoChina-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a DecadeThe Hacker News · 18h agoAtomic Arch Campaign Hijacks 20+ Linux AUR Packages to Deliver MalwareHackRead · 18h agoUkrainian national pleads guilty to role in Conti ransomware operationBleepingComputer · 18h agoGoogle sues alleged Chinese cybercrime operation that used AI to send scam textsTechCrunch Security · 19h agoOver 400 Arch Linux packages compromised to push rootkit, infostealerBleepingComputer · 19h agoEarly Warning Signs of Supply-Chain Attacks Live in the Dark WebBleepingComputer · 22h agoRansomware Payment Crypto Laundering Platform Taken Out by FBI and EuropolInfosecurity Magazine · 22h ago

Security & IT News

Live

Real-time news from 13+ trusted sources — BleepingComputer, The Hacker News, Krebs on Security, Dark Reading & more.

VulnerabilityThe Hacker News·24d ago
Typosquatting Is No Longer a User Problem. It's a Supply Chain Problem

AI-generated lookalike domains are now embedded inside the third-party scripts running on your web properties. Here's why your current stack can't see them, and what detection actually requires. Download the CISO Expert Guide to Typosquatting in the AI Era → TL;DR Typosquatting is no longer a user problem. Attackers now embed lookalike domains inside legitimate third-party scripts.

VulnerabilityThe Hacker News·24d ago
Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit

Microsoft on Tuesday released a mitigation for a BitLocker bypass vulnerability named YellowKey following its public disclosure last week. The zero-day flaw, now tracked as CVE-2026-45585, carries a CVSS score of 6.8. It has been described as a BitLocker security feature bypass. "Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as 'YellowKey,'" the

🔴 BreachThe Hacker News·24d ago
Grafana GitHub Breach Exposes Source Code via TanStack npm Attack

Grafana Labs, on May 19, 2026, said an investigation into its recent breach found no evidence of customer production systems or operations being compromised. It said the scope of the incident is limited to the Grafana Labs GitHub environment, which includes public and private source code along with internal GitHub repositories. "After the initial assessment, we found that in addition to source