BetaIT-Hub is in early access — your feedback helps us improve. Use the chat or email [email protected]

Latest
Extradited Ukrainian Man Admits Role in Conti Ransomware AttacksHackRead · 1h agoChinese hackers hijack auth flow, spy on isolated network for a decadeBleepingComputer · 2h agoCritical Splunk Enterprise Flaw Lets Attackers Run Code Without AuthenticationThe Hacker News · 3h agoThe FBI built its own replica small town to simulate real-world cyberattacksTechCrunch Security · 5h agoU.S. Orders Anthropic to Suspend Fable 5 and Mythos 5 Access for Foreign NationalsThe Hacker News · 10h agoWeekly Metasploit Update: New Kerberos/Certificate tracing options, and multiple new modulesRapid7 · 16h agoFriday Squid Blogging: Squid-Inspired Fluid PumpSchneier on Security · 19h agoChinese cybercrime operation that used AI to scam ‘hundreds of thousands of victims’ sued by GoogleTechCrunch Security · 19h ago400+ Arch Linux AUR Packages Hijacked to Install Rust Credential StealerThe Hacker News · 21h agoGoogle Sues Chinese Smishing Network Accused of Using Gemini AI in PhishingThe Hacker News · 21h agophpBB forum fixes auth bypass bug lurking for a decadeBleepingComputer · 22h agoChina-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a DecadeThe Hacker News · 22h agoAtomic Arch Campaign Hijacks 20+ Linux AUR Packages to Deliver MalwareHackRead · 22h agoUkrainian national pleads guilty to role in Conti ransomware operationBleepingComputer · 22h agoGoogle sues alleged Chinese cybercrime operation that used AI to send scam textsTechCrunch Security · 23h agoExtradited Ukrainian Man Admits Role in Conti Ransomware AttacksHackRead · 1h agoChinese hackers hijack auth flow, spy on isolated network for a decadeBleepingComputer · 2h agoCritical Splunk Enterprise Flaw Lets Attackers Run Code Without AuthenticationThe Hacker News · 3h agoThe FBI built its own replica small town to simulate real-world cyberattacksTechCrunch Security · 5h agoU.S. Orders Anthropic to Suspend Fable 5 and Mythos 5 Access for Foreign NationalsThe Hacker News · 10h agoWeekly Metasploit Update: New Kerberos/Certificate tracing options, and multiple new modulesRapid7 · 16h agoFriday Squid Blogging: Squid-Inspired Fluid PumpSchneier on Security · 19h agoChinese cybercrime operation that used AI to scam ‘hundreds of thousands of victims’ sued by GoogleTechCrunch Security · 19h ago400+ Arch Linux AUR Packages Hijacked to Install Rust Credential StealerThe Hacker News · 21h agoGoogle Sues Chinese Smishing Network Accused of Using Gemini AI in PhishingThe Hacker News · 21h agophpBB forum fixes auth bypass bug lurking for a decadeBleepingComputer · 22h agoChina-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a DecadeThe Hacker News · 22h agoAtomic Arch Campaign Hijacks 20+ Linux AUR Packages to Deliver MalwareHackRead · 22h agoUkrainian national pleads guilty to role in Conti ransomware operationBleepingComputer · 22h agoGoogle sues alleged Chinese cybercrime operation that used AI to send scam textsTechCrunch Security · 23h ago

Security & IT News

Live

Real-time news from 13+ trusted sources — BleepingComputer, The Hacker News, Krebs on Security, Dark Reading & more.

🔴 BreachThe Hacker News·27d ago
Grafana GitHub Token Breach Led to Codebase Download and Extortion Attempt

Grafana has disclosed that an "unauthorized party" obtained a token that granted them the ability to access the company's GitHub environment and download its codebase. "Our investigation has determined that no customer data or personal information was accessed during this incident, and we have found no evidence of impact to customer systems or operations," Grafana said in a series of

VulnerabilityThe Hacker News·28d ago
Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming

A critical security vulnerability impacting the Funnel Builder plugin for WordPress has come under active exploitation in the wild to inject malicious JavaScript code into WooCommerce checkout pages with the goal of stealing payment data. Details of the activity were published by Sansec this week. The vulnerability currently does not have an official CVE identifier. It

VulnerabilityRapid7·28d ago
Metasploit Wrap-Up 05/15/2026

Weaponizing a text editor for fun and profit Gather round, dear readers, because today, we (by we, we mean @h00die) dropped the ultimate persistence mechanism: Vim plugin persistence. And honestly, calling it "persistence" feels redundant — Vim is already the most persistent thing ever. Somewhere, somehow, there will still be a Vim session open since 2011, because no one has figured out how to close it. So we are not so much establishing a foothold here as we are joining an existing hostage situation. Elsewhere this week, Marvell's QConvergeConsole has been caught handing arbitrary files to unauthenticated visitors, as is tradition (CVE-2025-6793), GestioIP 3.5.7 ships an upload handler, so trusting it will cheerfully let an admin overwrite the handler with a backdoor and then dutifully execute it (CVE-2024-48760). And of course, we can't forget about Dolibarr ERP/CRM, which blocks PHP injections by checking — and we cannot stress this enough — by searching for string ?php. So @M4nu02 brought an elaborate module which changes ?php to ?PHP in the payload to successfully bypass this mitigation (CVE-2023-30253). Truly a wonderful time to be alive. New module content (4) Marvell QConvergeConsole Path Traversal (CVE-2025-6793) Authors: Michael Heinzl and rgod Type: Auxiliary Pull request: #21322 contributed by h4x-x0r Path: gather/qconvergeconsole_traversal CVE reference: ZDI-25-450 Description: This adds a new auxiliary module that exploits a path traversal vulnerability (CVE-2025-6793) in Marvell QConvergeConsole to read arbitrary files from the target host. Marvell QConvergeConsole versions 5.5.0.85 and earlier are vulnerable, and no authentication is required to exploit the issue. VIM Plugin Persistence Author: h00die Type: Exploit Pull request: #21206 contributed by h00die Path: linux/persistence/vim_plugin Description: This adds a new Linux persistence module, which establishes persistence by writing a Vim plugin to the target user's ~/.vim/plugin/ directory. The next time that user launches Vim, the plugin executes the configured payload and opens a new session as that user. GestioIP 3.5.7 Remote Command Execution Authors: maxibelino and odeez24 Type: Exploit Pull request: #21041 contributed by Odeez24 Path: multi/http/gestioip_rce AttackerKB reference: CVE-2024-48760 Description: This adds an exploit module for an authenticated remote code execution vulnerability in GestioIP 3.5.7 (CVE-2024-48760). An attacker with admin credentials can abuse the unsafe upload handler at /api/upload.cgi to overwrite the script itself with a backdoor, which is then invoked to execute attacker-supplied commands. Dolibarr ERP/CRM Authenticated Code Injection Authors: Emanuele Cervelli and Tinexta Cyber Offensive Security Team Type: Exploit Pull request: #21362 contributed by M4nu02 Path: unix/http/dolibarr_cms_rce_cve_2023_30253 AttackerKB reference: CVE-2023-30253 Description: This adds a new exploit module for Dolibarr ERP/CRM (CVE-2023-30253), an authenticated

🦠 MalwareThe Hacker News·28d ago
Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent Access

The Russian state-sponsored hacking group known as Turla has transformed its custom backdoor Kazuar into a modular peer-to-peer (P2P) botnet that's engineered for stealth and persistent access to compromised hosts. Turla, per the U.S. Cybersecurity and Infrastructure Security Agency (CISA), is assessed to be affiliated with Center 16 of Russia's Federal Security Service (FSB)