BetaIT-Hub is in early access — your feedback helps us improve. Use the chat or email [email protected]

Latest
How AI is Rewriting the Zero-Day Playbook for Preemptive SecurityRapid7 · just nowvBulletin fixes critical pre-auth RCE flaw with public exploitBleepingComputer · 10m agoPhantomEnigma Infects Organizations with Malware via Hijacked Government WebsitesHackRead · 45m agoShinyHunters Claims Ernst & Young (EY) Data Breach, Threatens July 31 LeakHackRead · 1h agoAembit Joins Snowflake to Tackle AI’s Next Security Frontier: Trusted Agent InteroperabilityHackRead · 3h agoBugs in Hugging Face Diffusers Bypass Custom Code SafeguardInfosecurity Magazine · 3h agoTengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its ProcessThe Hacker News · 3h agoAI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/schedInfosecurity Magazine · 3h ago24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before LoginThe Hacker News · 3h agoIs Your SSO Protected Against Modern Credential Attacks?BleepingComputer · 4h agoJFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face BreachThe Hacker News · 4h agoFrom Payments to Portfolios: How Financial Super Apps Rewrite Economics of Global InvestingHackRead · 4h agoPhishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion TechniquesInfosecurity Magazine · 5h agoThe Next Evolution of MDR: Preemptive Defense and Agentic InvestigationRapid7 · 5h agoRapid7 Cyber GRC is now available: Turn security action into compliance proofRapid7 · 5h agoHow AI is Rewriting the Zero-Day Playbook for Preemptive SecurityRapid7 · just nowvBulletin fixes critical pre-auth RCE flaw with public exploitBleepingComputer · 10m agoPhantomEnigma Infects Organizations with Malware via Hijacked Government WebsitesHackRead · 45m agoShinyHunters Claims Ernst & Young (EY) Data Breach, Threatens July 31 LeakHackRead · 1h agoAembit Joins Snowflake to Tackle AI’s Next Security Frontier: Trusted Agent InteroperabilityHackRead · 3h agoBugs in Hugging Face Diffusers Bypass Custom Code SafeguardInfosecurity Magazine · 3h agoTengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its ProcessThe Hacker News · 3h agoAI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/schedInfosecurity Magazine · 3h ago24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before LoginThe Hacker News · 3h agoIs Your SSO Protected Against Modern Credential Attacks?BleepingComputer · 4h agoJFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face BreachThe Hacker News · 4h agoFrom Payments to Portfolios: How Financial Super Apps Rewrite Economics of Global InvestingHackRead · 4h agoPhishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion TechniquesInfosecurity Magazine · 5h agoThe Next Evolution of MDR: Preemptive Defense and Agentic InvestigationRapid7 · 5h agoRapid7 Cyber GRC is now available: Turn security action into compliance proofRapid7 · 5h ago

Security & IT News

Live

Real-time news from 13+ trusted sources — BleepingComputer, The Hacker News, Krebs on Security, Dark Reading & more.

772 results in Breach

🔴 BreachThe Hacker News·92d ago
PhantomCore Exploits TrueConf Vulnerabilities to Breach Russian Networks

A pro-Ukrainian hacktivist group called PhantomCore has been attributed to attacks actively targeting servers running TrueConf video conferencing software in Russia since September 2025. That's according to a report published by Positive Technologies, which found the threat actors to be leveraging an exploit chain comprising three vulnerabilities to execute commands remotely on susceptible

🔴 BreachThe Hacker News·96d ago
Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign

Bitwarden CLI has been compromised as part of the newly discovered and ongoing Checkmarx supply chain campaign, according to new findings from JFrog and Socket. "The affected package version appears to be @bitwarden/[email protected], and the malicious code was published in 'bw1.js,' a file included in the package contents," the application security company said. "The attack appears to have leveraged

🔴 BreachThe Hacker News·96d ago
ThreatsDay Bulletin: $290M DeFi Hack, macOS LotL Abuse, ProxySmart SIM Farms +25 New Stories

You scroll past one incident and see another that feels familiar, like it should have been fixed years ago, but it still works with small changes. Same bugs. Same mistakes. The supply chain is messy. Packages you did not check are stealing data, adding backdoors, and spreading. Attacking the systems behind apps is easier than breaking the apps themselves. The exploits are simple but still work

🔴 BreachCISA·96d ago
Defending Against China-Nexus Covert Networks of Compromised Devices

div class="SCXW131754345 BCX8" div class="OutlineElement Ltr SCXW131754345 BCX8" h2 a class="c-button c-button--on-dark" href="https://urldefense.us/v3/__https://www.ncsc.gov.uk/news/defending-against-china-nexus-covert-networks-of-compromised-devices__;!!BClRuOV5cvtbuNI!Cvg8stIR3jHWVZgHhCVvEwbwDXxXIRSprOQ9JtY2YKwxUIGVovuDAu7QrFsfw3sfAVd8-gxEMIpgldwlY-jTD7G0%24" Defending against china-nexus covert networks of compromised devices /a /h2 h2 a class="c-button c-button--on-dark" href="https://urldefense.us/v3/__https://www.ncsc.gov.uk/news/executive-summary-defending-against-china-nexus-covert-networks-of-compromised-devices__;!!BClRuOV5cvtbuNI!Cvg8stIR3jHWVZgHhCVvEwbwDXxXIRSprOQ9JtY2YKwxUIGVovuDAu7QrFsfw3sfAVd8-gxEMIpgldwlYzP90Ign%24" executive summary /a /h2 h2 strong Defending against China-nexus covert networks of compromised devices nbsp; /strong /h2 p Explaining the widespread shift in tactics, techniques and procedures (TTPs) towards networks of compromised infrastructure, and how to defend against it nbsp; /p h3 strong Summary /strong /h3 p With support from the UK a href="https://www.ncsc.gov.uk/information/cyber-league" target="_blank" u Cyber League /u /a , this advisory has been jointly released by the National Cyber Security Centre (NCSC-UK) and international partners: nbsp; /p ul li Australian Signals Directorate’s (ASD’s) Australian Cyber Security Centre (ACSC) /li li Communications Security Establishment Canada’s (CSE’s) Canadian Centre for Cyber Security (Cyber Centre) /li li Germany Federal Office for the Protection of the Constitution - nbsp; nbsp; Bundesamt für Verfassungsschutz (BfV) /li li Germany Federal Intelligence Service – Bundesnachrichtendienst (BND) /li li Germany Federal Office for Information Security - Bundesamt für Sicherheit in der Informationstechnik (BSI) /li li Japan National Cybersecurity Office (NCO) - 国家サイバー統括室 /li li Netherlands General Intelligence and Security Service - Algemene Inlichtingen- en Veiligheidsdienst (AIVD) /li li Netherlands Defence Intelligence and Security Service - Militaire Inlichtingen- en Veiligheidsdienst (MIVD) /li li New Zealand National Cyber Security Centre (NCSC-NZ) /li li Spain National Cryptologic Centre – Centro Criptológico Nacional (CCN) /li li Sweden National Cyber Security Centre - Nationellt cybersäkerhetscenter (NCSC-SE) /li li United States Cybersecurity and Infrastructure Security Agency (CISA) /li li United States Department of Defense Cyber Crime Center (DC3) /li li United States Federal Bureau of Investigation (FBI) /li li United States National Security Agency (NSA) nbsp; /li /ul p Its purpose is to provide network defenders with the tools needed to defend against China-nexus cyber actors and their tactic of using large scale networks of compromised devices (covert networks) to route their cyber activity. nbsp; /p h3 strong Introduction nbsp; nbsp; /strong /h3 p Over the past few years there has been a major shift in the tactics, techniques and procedures (TTPs) use

🔴 BreachThe Hacker News·96d ago
Vercel Finds More Compromised Accounts in Context.ai-Linked Breach

Vercel on Wednesday revealed that it has identified an additional set of customer accounts that were compromised as part of a security incident that enabled unauthorized access to its internal systems. The company said it made the discovery after expanding its investigation to include an extra set of compromise indicators, alongside a review of requests to the Vercel network and environment