Security news

Latest security news

174 of 1,256 storiesTopic: MalwareClear all

Mon, 14 Sept 2026

  1. Hackers hijack HBO Max Reddit account to push malware in ClickFix ads

    Hackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware.

    BleepingComputerWindows
  2. 3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials

    An attacker was operating inside the network of 3BB, one of Thailand's largest broadband providers, and maintained remote control of internal machines using a legitimate management tool called MeshCentral, threat intelligence firm Hunt.io said. The company uncovered the intrusion by examining a server the attacker had left open on the internet, which held the attacker's own tools and a list of

    The Hacker News
  3. Pro-Ukraine Hacking Cat group deploying new malware against Russian targets

    The pro-Ukraine hacktivist group Hacking Cat has evolved from carrying out website defacements and data leaks to more sophisticated and destructive attacks on Russian targets, researchers said.

    The Record
  4. ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits

    AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job. Some models are also crossing lines on their own. That is not a great combination. The rest of the week is more familiar: old bugs still working, fresh exploit chains, exposed systems, weak defaults, and simple paths that should have been harder to abuse. A few of

    The Hacker NewsPaperCut

Sun, 13 Sept 2026

  1. Hackers exploit Tencent app flaw to deploy GrayRabbit malware

    Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor.

    BleepingComputerWindows

Sat, 12 Sept 2026

Fri, 11 Sept 2026

  1. Artifactory flaws chained in attacks deploying backdoor malware

    Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers.

    BleepingComputer
  2. Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection

    Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve. The operation has been attributed to a cyber espionage group it calls GTG-20006 (where "GTG" stands for Generative Threat Group), which aligns with broader reporting linking the cluster to Midnight

    The Hacker News
  3. How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface

    Threat actors are abusing trusted AI platforms to host malicious content, poison search results, and trick users into installing malware. Huntress examines campaigns targeting AI users through weaponized Claude Artifacts, shared AI conversations, sponsored search results, and ClickFix-style lures.

    BleepingComputer
  4. Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars

    Swapping legal work for malware development ended in extradition and a guilty plea

    The Register

About this news

1,256
Stories
41
Added in the last 24 hours
19
Critical in the last 7 days
4
Reported by several outlets