BetaIT-Hub is in early access — your feedback helps us improve. Use the chat or email [email protected]

Latest
How AI is Rewriting the Zero-Day Playbook for Preemptive SecurityRapid7 · just nowPhantomEnigma Infects Organizations with Malware via Hijacked Government WebsitesHackRead · 18m agoShinyHunters Claims Ernst & Young (EY) Data Breach, Threatens July 31 LeakHackRead · 1h agoAembit Joins Snowflake to Tackle AI’s Next Security Frontier: Trusted Agent InteroperabilityHackRead · 2h agoBugs in Hugging Face Diffusers Bypass Custom Code SafeguardInfosecurity Magazine · 2h agoTengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its ProcessThe Hacker News · 2h agoAI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/schedInfosecurity Magazine · 3h ago24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before LoginThe Hacker News · 3h agoIs Your SSO Protected Against Modern Credential Attacks?BleepingComputer · 3h agoJFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face BreachThe Hacker News · 4h agoFrom Payments to Portfolios: How Financial Super Apps Rewrite Economics of Global InvestingHackRead · 4h agoPhishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion TechniquesInfosecurity Magazine · 4h agoThe Next Evolution of MDR: Preemptive Defense and Agentic InvestigationRapid7 · 4h agoRapid7 Cyber GRC is now available: Turn security action into compliance proofRapid7 · 4h agoCritical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as RootThe Hacker News · 4h agoHow AI is Rewriting the Zero-Day Playbook for Preemptive SecurityRapid7 · just nowPhantomEnigma Infects Organizations with Malware via Hijacked Government WebsitesHackRead · 18m agoShinyHunters Claims Ernst & Young (EY) Data Breach, Threatens July 31 LeakHackRead · 1h agoAembit Joins Snowflake to Tackle AI’s Next Security Frontier: Trusted Agent InteroperabilityHackRead · 2h agoBugs in Hugging Face Diffusers Bypass Custom Code SafeguardInfosecurity Magazine · 2h agoTengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its ProcessThe Hacker News · 2h agoAI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/schedInfosecurity Magazine · 3h ago24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before LoginThe Hacker News · 3h agoIs Your SSO Protected Against Modern Credential Attacks?BleepingComputer · 3h agoJFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face BreachThe Hacker News · 4h agoFrom Payments to Portfolios: How Financial Super Apps Rewrite Economics of Global InvestingHackRead · 4h agoPhishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion TechniquesInfosecurity Magazine · 4h agoThe Next Evolution of MDR: Preemptive Defense and Agentic InvestigationRapid7 · 4h agoRapid7 Cyber GRC is now available: Turn security action into compliance proofRapid7 · 4h agoCritical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as RootThe Hacker News · 4h ago

Security & IT News

Live

Real-time news from 13+ trusted sources — BleepingComputer, The Hacker News, Krebs on Security, Dark Reading & more.

772 results in Breach

🔴 BreachThe Hacker News·38d ago
Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys

Threat actors are exploiting a recently patched security flaw impacting Gravity SMTP, a WordPress plugin that's installed on about 100,000 sites. The vulnerability, tracked as CVE-2026-4020 (CVSS score: 5.3), is a medium-severity information disclosure flaw that can allow unauthenticated attackers to extract sensitive data, such as configuration data, API keys, secrets, and OAuth tokens