North Korean Contagious Interview campaign compromised 30,000 devices and stole at least $10.71 million in cryptocurrency.
Malicious npm package indexed-btree hid its loader in runtime code, avoiding install hooks after logging millions of downloads.
SideCopy targets Indian academic institutions with spear-phishing that abuses mshta.exe to deploy ReverseRAT for collection and remote access.
WordPress fixed a comment flaw that could lead to server code execution if a logged-in administrator opened the page.
A Mac Muse flaw lets malware running as the logged-in user reroute dictation, inject instructions, and steal the assistant's ...
CISA added Zyxel CVE-2026-7273 to KEV after active exploitation, while Arctic Wolf reported attacks on a Veeam Windows flaw.
Explore the latest news, real-world incidents, expert analysis, and trends in Airwallex+cyber+attack — only on The Hacker News, the leading cybersecurity and IT news platform.
TASK#STOMP deploys a PowerShell backdoor that steals documents and Wi-Fi passwords, monitors files, and executes remote commands.
A fake LastPass Authenticator installer uses a signed kernel driver to kill security tools before a stealer collects passwords and wallet files.
Ireland's DPC fined Google €403 million over GDPR violations in how three features handled location data from 2018 to 2020.
Explore the latest news, real-world incidents, expert analysis, and trends in Birdshack+Malware — only on The Hacker News, ...
Jade Sleet compromised an Indian IT services provider through a DevOps engineer’s MacBook, where FLATROOF and ROOFDECK were detected.