BetaIT-Hub is in early access — your feedback helps us improve. Use the chat or email [email protected]

Latest
Extradited Ukrainian Man Admits Role in Conti Ransomware AttacksHackRead · 1h agoChinese hackers hijack auth flow, spy on isolated network for a decadeBleepingComputer · 1h agoCritical Splunk Enterprise Flaw Lets Attackers Run Code Without AuthenticationThe Hacker News · 2h agoThe FBI built its own replica small town to simulate real-world cyberattacksTechCrunch Security · 4h agoU.S. Orders Anthropic to Suspend Fable 5 and Mythos 5 Access for Foreign NationalsThe Hacker News · 10h agoWeekly Metasploit Update: New Kerberos/Certificate tracing options, and multiple new modulesRapid7 · 15h agoFriday Squid Blogging: Squid-Inspired Fluid PumpSchneier on Security · 18h agoChinese cybercrime operation that used AI to scam ‘hundreds of thousands of victims’ sued by GoogleTechCrunch Security · 19h ago400+ Arch Linux AUR Packages Hijacked to Install Rust Credential StealerThe Hacker News · 20h agoGoogle Sues Chinese Smishing Network Accused of Using Gemini AI in PhishingThe Hacker News · 20h agophpBB forum fixes auth bypass bug lurking for a decadeBleepingComputer · 21h agoChina-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a DecadeThe Hacker News · 21h agoAtomic Arch Campaign Hijacks 20+ Linux AUR Packages to Deliver MalwareHackRead · 21h agoUkrainian national pleads guilty to role in Conti ransomware operationBleepingComputer · 21h agoGoogle sues alleged Chinese cybercrime operation that used AI to send scam textsTechCrunch Security · 22h agoExtradited Ukrainian Man Admits Role in Conti Ransomware AttacksHackRead · 1h agoChinese hackers hijack auth flow, spy on isolated network for a decadeBleepingComputer · 1h agoCritical Splunk Enterprise Flaw Lets Attackers Run Code Without AuthenticationThe Hacker News · 2h agoThe FBI built its own replica small town to simulate real-world cyberattacksTechCrunch Security · 4h agoU.S. Orders Anthropic to Suspend Fable 5 and Mythos 5 Access for Foreign NationalsThe Hacker News · 10h agoWeekly Metasploit Update: New Kerberos/Certificate tracing options, and multiple new modulesRapid7 · 15h agoFriday Squid Blogging: Squid-Inspired Fluid PumpSchneier on Security · 18h agoChinese cybercrime operation that used AI to scam ‘hundreds of thousands of victims’ sued by GoogleTechCrunch Security · 19h ago400+ Arch Linux AUR Packages Hijacked to Install Rust Credential StealerThe Hacker News · 20h agoGoogle Sues Chinese Smishing Network Accused of Using Gemini AI in PhishingThe Hacker News · 20h agophpBB forum fixes auth bypass bug lurking for a decadeBleepingComputer · 21h agoChina-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a DecadeThe Hacker News · 21h agoAtomic Arch Campaign Hijacks 20+ Linux AUR Packages to Deliver MalwareHackRead · 21h agoUkrainian national pleads guilty to role in Conti ransomware operationBleepingComputer · 21h agoGoogle sues alleged Chinese cybercrime operation that used AI to send scam textsTechCrunch Security · 22h ago

Security & IT News

Live

Real-time news from 13+ trusted sources — BleepingComputer, The Hacker News, Krebs on Security, Dark Reading & more.

VulnerabilityThe Hacker News·26d ago
Developer Workstations Are Now Part of the Software Supply Chain

Supply chain attackers are not only trying to slip malicious code into trusted software. They are trying to steal the access that makes trusted software possible. Recently, three separate campaigns hit npm, PyPI, and Docker Hub in a 48-hour window, and all three targeted secrets from developer environments and CI/CD pipelines, including API keys, cloud credentials, SSH keys, and tokens. This is

🧪 ResearchSchneier on Security·26d ago
Zero-Day Exploit Against Windows BitLocker

It’s nasty , but it requires physical access to the computer: The exploit, named YellowKey, was published earlier this week by a researcher who goes by the alias Nightmare-Eclipse. It reliably bypasses default Windows 11 deployments of BitLocker, the full-volume encryption protection Microsoft provides to make disk contents off-limits to anyone without the decryption key, which is stored in a secured piece of hardware known as a trusted platform module (TPM). BitLocker is a mandatory protection for many organizations, including those that contract with governments. Slashdot thread . And here’s Nightmare-Eclipse’s GitHub account.

🩹 PatchThe Hacker News·26d ago
Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flaws

Ivanti, Fortinet, n8n, SAP, and VMware have released security fixes for various vulnerabilities that could be exploited by bad actors to bypass authentication and execute arbitrary code. Topping the list is a critical flaw impacting Ivanti Xtraction (CVE-2026-8043, CVSS score: 9.6) that could be exploited to achieve information disclosure or client-side attacks. "External control of a file name

🦠 MalwareThe Hacker News·26d ago
Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware

Cybersecurity researchers have discovered four new npm packages containing information-stealing malware, one of which is a clone of the Shai-Hulud worm open-sourced by TeamPCP. The list of identified packages is below - chalk-tempalte (825 Downloads) @deadcode09284814/axios-util (284 Downloads) axois-utils (963 Downloads) color-style-utils (934 Downloads) "One of the packages (chalk-tempalte)

🦠 MalwareThe Hacker News·26d ago
Pre-Stuxnet Fast16 Malware Tampered with Nuclear Weapons Simulations

A new analysis of the Lua-based fast16 malware has confirmed that it was a cyber sabotage tool designed to tamper with nuclear weapons testing simulations. According to Broadcom-owned Symantec and Carbon Black teams, the pre-Stuxnet tool was engineered to corrupt uranium-compression simulations that are central to nuclear weapon design. "Fast16's hook engine is selectively interested in

🧪 ResearchThe Hacker News·26d ago
MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems

Chaotic Eclipse, the security researcher behind the recently disclosed Windows flaws, YellowKey and GreenPlasma, has released a proof-of-concept (PoC) for a Windows privilege escalation zero-day flaw that grants attackers SYSTEM privileges on fully patched Windows systems. Codenamed MiniPlasma, the vulnerability impacts "cldflt.sys," which refers to the Windows Cloud Files Mini Filter Driver,

VulnerabilityThe Hacker News·27d ago
NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE

A newly disclosed security flaw impacting NGINX Plus and NGINX Open has come under active exploitation in the wild, days after its public disclosure, according to VulnCheck. The vulnerability, tracked as CVE-2026-42945 (CVSS score: 9.2), is a heap buffer overflow in ngx_http_rewrite_module affecting NGINX versions 0.6.27 through 1.30.0. According to AI-native security company depthfirst, the