BetaIT-Hub is in early access — your feedback helps us improve. Use the chat or email [email protected]

Latest
Chinese hackers use new Atlas RAT malware in European cyberattacksBleepingComputer · 2h agoHow to Recover Data from iCloud Backup Without Resetting Your iPhoneHackRead · 2h agoThe U.S. sanctions Nobitex crypto exchange used by ransomwareBleepingComputer · 3h agoCISA warns of cyberattacks targeting fuel tank monitoring systemsBleepingComputer · 3h agoWhatsApp, Slack Notifications Could Hijack Google Gemini on AndroidThe Hacker News · 4h agoNew 'HTTP/2 Bomb' DoS attack crashes web servers in under a minuteBleepingComputer · 4h agoUltrahuman says hackers accessed customers’ wellness data via internal toolTechCrunch Security · 6h agoGoogle DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RATThe Hacker News · 7h agoA Day in the Life of an MDR Analyst: Inside the Modern SOCRapid7 · 7h agoInstagram is alerting users who were targeted by hackers during AI chatbot attacksTechCrunch Security · 7h agoCISA warns of active attacks exploiting Android, Linux bugsBleepingComputer · 8h agoMicrosoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug FlagThe Hacker News · 9h agoThe worst hacks and breaches of 2026 (so far)TechCrunch Security · 10h agoWhat 345 Days of Untested Exposure Looks Like at a BankBleepingComputer · 10h agoAutonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479)The Hacker News · 10h agoChinese hackers use new Atlas RAT malware in European cyberattacksBleepingComputer · 2h agoHow to Recover Data from iCloud Backup Without Resetting Your iPhoneHackRead · 2h agoThe U.S. sanctions Nobitex crypto exchange used by ransomwareBleepingComputer · 3h agoCISA warns of cyberattacks targeting fuel tank monitoring systemsBleepingComputer · 3h agoWhatsApp, Slack Notifications Could Hijack Google Gemini on AndroidThe Hacker News · 4h agoNew 'HTTP/2 Bomb' DoS attack crashes web servers in under a minuteBleepingComputer · 4h agoUltrahuman says hackers accessed customers’ wellness data via internal toolTechCrunch Security · 6h agoGoogle DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RATThe Hacker News · 7h agoA Day in the Life of an MDR Analyst: Inside the Modern SOCRapid7 · 7h agoInstagram is alerting users who were targeted by hackers during AI chatbot attacksTechCrunch Security · 7h agoCISA warns of active attacks exploiting Android, Linux bugsBleepingComputer · 8h agoMicrosoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug FlagThe Hacker News · 9h agoThe worst hacks and breaches of 2026 (so far)TechCrunch Security · 10h agoWhat 345 Days of Untested Exposure Looks Like at a BankBleepingComputer · 10h agoAutonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479)The Hacker News · 10h ago

Security & IT News

Live

Real-time news from 13+ trusted sources — BleepingComputer, The Hacker News, Krebs on Security, Dark Reading & more.

428 results in Breach

🔴 BreachThe Hacker News·17h ago
Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content

Cybersecurity researchers have flagged a new campaign targeting Minecraft players via YouTube to spread malware capable of gaining control of victims' systems. The Minecraft-focused malware-as-a-service (MaaS) campaign has been codenamed Weedhack by McAfee Labs, stating the activity has been active since January 2026 and impersonates Minecraft clients and mods to infect users. In all, 3820

🔴 BreachKrebs on Security·2d ago
Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts

The Instagram accounts for the Obama White House and the Chief Master Sergeant of the U.S. Space Force were briefly defaced with pro-Iranian images and messages over the weekend, after instructions began circulating on Telegram showing how to trick Meta’s “AI support assistant” bot into resetting account passwords. A screenshot from a video released on Telegram claiming to show how Meta’s AI customer support bot could be tricked into resetting a target’s password. On May 31, word began to spread on several Telegram instant message channels that Meta’s AI bot would happily add an email address to an existing account as part of the bot’s standard password reset flow. A video released on Telegram by pro-Iran hackers claimed to document a remarkably simple exploit that appears to have involved using a VPN connection with an IP address that is in or near the target’s usual hometown, requesting a password reset for the account, and then choosing to chat with Meta’s AI support assistant. From there, the video shows the attacker told the bot to link the account in question to a new email address, after which the bot dutifully sent that address a one-time code that allowed a password reset. The Telegram account that posted the video also linked to screenshots of pro-Iran images, videos and messages that defaced the hacked Instagram accounts, saying hackers had used the exploit to hijack a number of valuable (read: short) Instagram account names that allegedly have a resale value of more than a half million dollars. Meta has not responded to requests for comment on the video’s claims, but Meta’s Andy Stone said on Twitter/X that the issue had been resolved and that they were securing impacted accounts. The security blog thecybersecguru.com reports that Meta pushed an emergency patch over the weekend, and clarified that no back end database was breached. “Instagram has notoriously poor human support infrastructure,” Cybersecguru wrote. “Recovering a locked account – especially a high-value one can take weeks of back-and-forth with an automated ticketing system. Meta’s solution was to deploy a conversational AI layer to handle common recovery workflows: relinking a lost email address, triggering a password reset, verifying account ownership. The assistant, presumably, was supposed to reduce friction for legitimate users stuck in account-access hell.” Ian Goldin , a threat researcher at Lumen’s Black Lotus Labs , said we’re entering unchartered security territory as more large online platforms start allowing AI chatbots to handle sensitive account recovery requests. Just like human customer support employees can be social engineered into providing unauthorized access to someone’s account, AI bots are equally eager to help and vulnerable to persuasion and trickery, he said. “AI chatbots create interesting new attack surface, and we’re likely going