> TODAY'S SUMMARY (109 articles)
Today's cybersecurity landscape reveals several critical developments. AWS AgentCore's security vulnerabilities, including weak VM isolation and excessive permissions, have been exposed, potentially facilitating attacks. In international law enforcement, Japan has extradited a Russian national linked to the Qilin ransomware gang to Germany, where further arrests have occurred, despite ongoing attacks by the group. The FBI has also arrested members of the ShinyHunters extortion group, underscoring the persistent threat of data breaches. Meanwhile, unpatched vulnerabilities in the AhsayCBS backup platform are being actively exploited for webshell deployment and cryptocurrency mining. A noticeable trend is the shift in ransomware tactics, with attackers increasingly opting for data theft rather than encryption. Lastly, the U.S. and allies have disrupted Chinese state-sponsored hacking tools, illustrating ongoing geopolitical cybersecurity tensions.
|
// AI-powered summary generated at 20:00
Kaspersky researchers uncovered another supply chain compromise involving a popular Windows tool: Daemon Tools, an app for mounting disk image files as virtual drives that is widely used by gamers, developers, and IT professionals. Since April 8, 2026, the official Daemon Tools download site (at Dea...
The Iranian state-sponsored hacking group known as MuddyWater (aka Mango Sandstorm, Seedworm, and Static Kitten) has been attributed to a ransomware attack in what has been described as a "false flag" operation.
The attack, observed by Rapid7 in early 2026, has been found to leverage social engineer...
Likely perpetrated by MuddyWater, the attack combined social engineering, persistence, credential harvesting, and data theft.
The post Iranian APT Intrusion Masquerades as Chaos Ransomware Attack appeared first on SecurityWeek.
Rapid7 reveals an Iranian false flag operation masquerading as a Chaos ransomware attack
Most network incidents don't escalate due to a lack of alerts; they escalate when response breaks down. This webinar explores how to fix gaps in triage, enrichment, and coordination. [...]
A legitimate developer tool is being repurposed by attackers to package and spread this Windows infostealer in harder-to-detect ways.
Researchers at Kaspersky said attackers tampered with installers for Daemon Tools — a popular program used to mount disk images as virtual drives — and distributed them through the software’s official website.
ShinyHunters claims it stole personal data from 275 million users on Instructure’s Canvas platform across schools and education providers.
For nearly 20 years, we at The Hacker News have mostly told scary stories about cyberspace — big hacks, broken systems, and new threats.
But behind every headline, there’s a quieter, better story.
It’s the story of leaders making tough calls under pressure, teams building smarter defenses, and secur...
Gavril Sandu, 53, was indicted in 2017, but was arrested and extradited to the United States only in 2026.
The post Romanian Extradited to US for Role in Hacking Scheme 17 Years Ago appeared first on SecurityWeek.
This blog is a preview of our forthcoming report, “The New Rails: How Digital Assets Are Reshaping the Foundations of…
The post Where to Build: A Data-Driven Guide to Blockchain Infrastructure for TradFi Tokenization appeared first on Chainalysis.
The VoidStealer malware employs a new technique to circumvent Chrome’s App-Bound Encryption mechanism, gaining access to session cookies and other sensitive user data.
Attackers have found a new way to turn Linux systems into stealthy supply chain distribution hubs that are resistant to takedowns.
Researchers from Trend Micro have disclosed a new malware framework, dubbed Quasar Linux or QLNX, describing it as a modular Linux remote acces...
Palo Alto Networks warns of firewall RCE zero-day exploited in attacks Palo Alto Networks warned that attackers are exploiting CVE-2026-0300, a critical PAN-OS buffer overflow vulnerability affecting the User-ID Authentication Portal, also known as the Captive Portal. The flaw can allow unauthentica...
Microsoft Edge keeps all saved passwords in plaintext memory instead of encrypting them. Here’s what you risk and what you should do instead.
Apache fixed several flaws in HTTP Server, including CVE-2026-23918 (CVSS score of 8.8), a double-free bug in HTTP/2 that could allow remote code execution. The Apache Software Foundation has released updates to fix multiple vulnerabilities in its HTTP Server, including CVE-2026-23918 (CVSS score of...
Analysts recently confirmed what identity security teams have quietly feared: AI agents are being deployed faster than enterprises can govern them. In their inaugural Market Guide for Guardian Agents, Gartner states that “enterprise adoption of AI agents is accelerating, outpacing maturity of govern...
Intel 471 has announced Retroactive Threat Detections (RTD), a new capability within its Verity471 platform. RTD helps security teams quickly understand the impact of new threats on their environments. This transforms static intelligence reports into actionable answers within minutes, enabling faste...
Extreme Networks has introduced Extreme Agent ONE, a new class of AI agents for enterprise networking. Moving beyond generic, prompt-based AI, Extreme Agent ONE runs on the Extreme AI stack purpose-built for enterprise environments, which combines advanced AI reasoning, live network context, and ope...
A new rowhammer attack gives complete control of NVIDIA CPUs.
On Thursday, two research teams, working independently of each other, demonstrated attacks against two cards from Nvidia’s Ampere generation that take GPU rowhammering into new—Âand potentially much more consequential—Âterritory: GDDR bit...