BetaIT-Hub is in early access — your feedback helps us improve. Use the chat or email [email protected]

Latest
DentaQuest data breach exposed info of 2.6 million accountsBleepingComputer · 2h agoiFood Confirms Data Breach Affecting 1.2 Million Users in BrazilHackRead · 3h agoCisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes PublicThe Hacker News · 3h agoUN food agency discloses breach affecting 600,000 Gaza householdsBleepingComputer · 4h agoEverest Forms Pro Vulnerability Allows Remote Code Execution on WordPress SitesInfosecurity Magazine · 4h agoNew IronWorm malware hits 36 packages in npm supply-chain attackBleepingComputer · 5h agoClaude Code GitHub Action Flaw Let One Malicious Issue Hijack RepositoriesThe Hacker News · 5h agoAgentic AI Is Transforming Defense, But Only Secure IT Infrastructure Will Maximize ItThe Hacker News · 5h agoWhy eSIMs Are Replacing Traditional SIM CardsHackRead · 5h agoChinese spies are using LinkedIn to lure Westerners into sharing sensitive informationTechCrunch Security · 5h agoHackers Are After the Gaps in Your Vulnerability Program: Here's Their PlaybookBleepingComputer · 6h agoThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New StoriesThe Hacker News · 6h agoInfosecurity Europe: AI Adoption Creates New Opportunities for Attackers to Distribute Malware, Microsoft WarnsInfosecurity Magazine · 6h agoChinese-Speaking Actor TA4922 Widens Its Global ReachInfosecurity Magazine · 6h agoHow the “Swiss Cheese” model can help you choose the right MDR providerRapid7 · 6h agoDentaQuest data breach exposed info of 2.6 million accountsBleepingComputer · 2h agoiFood Confirms Data Breach Affecting 1.2 Million Users in BrazilHackRead · 3h agoCisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes PublicThe Hacker News · 3h agoUN food agency discloses breach affecting 600,000 Gaza householdsBleepingComputer · 4h agoEverest Forms Pro Vulnerability Allows Remote Code Execution on WordPress SitesInfosecurity Magazine · 4h agoNew IronWorm malware hits 36 packages in npm supply-chain attackBleepingComputer · 5h agoClaude Code GitHub Action Flaw Let One Malicious Issue Hijack RepositoriesThe Hacker News · 5h agoAgentic AI Is Transforming Defense, But Only Secure IT Infrastructure Will Maximize ItThe Hacker News · 5h agoWhy eSIMs Are Replacing Traditional SIM CardsHackRead · 5h agoChinese spies are using LinkedIn to lure Westerners into sharing sensitive informationTechCrunch Security · 5h agoHackers Are After the Gaps in Your Vulnerability Program: Here's Their PlaybookBleepingComputer · 6h agoThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New StoriesThe Hacker News · 6h agoInfosecurity Europe: AI Adoption Creates New Opportunities for Attackers to Distribute Malware, Microsoft WarnsInfosecurity Magazine · 6h agoChinese-Speaking Actor TA4922 Widens Its Global ReachInfosecurity Magazine · 6h agoHow the “Swiss Cheese” model can help you choose the right MDR providerRapid7 · 6h ago

Security & IT News

Live

Real-time news from 13+ trusted sources — BleepingComputer, The Hacker News, Krebs on Security, Dark Reading & more.

VulnerabilityRapid7·22d ago
When IT Support Calls: Dissecting a ModeloRAT Campaign from Teams to Domain Compromise

Overview Attackers do not need to break into the front door when they can convince employees to open it for them through the tools they already trust. In April 2026, Rapid7 investigated an enterprise intrusion that began with a Microsoft Teams message from a fake “IT Support” account and quickly escalated into a full compromise chain involving malware deployment, privilege escalation, credential theft, lateral movement, and exfiltration. The incident illustrates a critical risk for modern enterprises: Collaboration platforms have become part of the attack surface, and when combined with identity abuse and Living-off-the-Land techniques, they can provide attackers with a low-friction path into the environment. Therefore, this attack was particularly concerning due to the way the intrusion shifted from endpoint compromise to broader identity-driven risk. And while it was not surprising that the attacker used a novel technique, what was concerning was how the attacker was able to chain together familiar enterprise weaknesses into a fast-moving and operationally effective intrusion. By abusing Teams external access, the threat actor delivered a Dropbox-hosted Python payload that established command-and-control, deployed multiple backdoors, and began mapping the internal environment. The attacker then escalated privileges to SYSTEM using CVE-2023-36036 before deploying a fake Windows lock screen designed to harvest the user’s domain password. Once valid credentials were obtained, the intrusion shifted from endpoint compromise to broader identity-driven risk. The attacker moved laterally to a second host, used legitimate tooling such as DumpIt to collect system memory, which was likely exfiltrated via an anonymous file-sharing service. This progression underscores a key reality for defenders: Once collaboration, identity, and endpoint controls are bypassed or weakened, attackers can rapidly convert initial access into meaningful enterprise exposure. Rapid7’s technical analysis linked the Python malware to ModeloRAT, a framework previously documented by multiple security vendors in browser extension campaigns and associated with the KongTuke group. More broadly, this intrusion demonstrates how trusted communication channels, Living-off-the-Land techniques, and credential-focused tradecraft continue to challenge traditional security controls. The takeaways here are clear: For CISOs: Collaboration tools are part of your attack surface. Attackers used Teams to reach users directly. Security, identity protection, endpoint visibility, and rapid detection engineering must be treated as connected parts of the same defense strategy, not separate control domains. For defenders: Old vulnerabilities and trusted tools still work. The attack combined a patched vulnerability (CVE-2023-36036) with widely trusted tools like Python, PowerShell, and Dropbox. None of these are unusual in enterprise environments, which is precisely what allowed the attacker to blend in whi

VulnerabilityRapid7·22d ago
Rapid7 Partner Academy: Driving Impact with Gold Stevie Award-Winning Partner Services Certifications

At Rapid7, our commitment to our partners is built on the foundation of the PACT (Partnering with Accountability, Consistency, and Transparency) program. Central to this mission is the Rapid7 Partner Academy, which was recently honored with a Gold Stevie Award in the 2026 American Business Awards® for Achievement in Collaboration and Partnership . This recognition underscores our dedication to providing world-class training that translates directly into partner success and customer resilience. A new era of partner-led services To meet the evolving needs of the cybersecurity landscape, Rapid7 Partner Academy has introduced specialized Partner Services Certifications . These role-based learning paths are designed to move beyond traditional "product training" by focusing on high-fidelity service delivery and outcome-driven results, including how to build, deliver, and scale services on Rapid7 solutions. The training and certification program was specifically recognized for its "Partner-First" design, which was built through extensive collaboration with our global partner ecosystem to ensure alignment with real-world sales and technical challenges. Our award-winning partner services certification ecosystem focuses on three critical pillars of the Rapid7 Command Platform: Partner Services for InsightIDR: Equips partners with the skills and knowledge necessary to effectively guide customers through the post-sale phases of the InsightIDR solution. Partner Services for Exposure Command: Focuses on the transition from static vulnerability scanning to continuous attack surface validation, diving into the setup, management, and troubleshooting of Exposure Command. Partner Services for Vulnerability Management: Empowers partners to provide impactful services around deployment, management, and ongoing support for InsightVM that drive customer success. All three of these Partner Services Certifications enable our partners to deliver services around Rapid7 solutions from deployment and onboarding, to management and best practices for usage, to express health checks and troubleshooting. Upon successful completion of the course theoretical exam, you are eligible to enroll in the Services Validation Component. After validating your services capabilities, you will receive the prestigious distinction of achieving the Rapid7 Partner Services Certification and Badge. This achievement helps to differentiate your services to your customers and prospects with official recognition among the most capable Rapid7 MSSPs and service delivery partners. Real-world impact: From training to execution The Gold Stevie Award recognizes more than just curriculum—it recognizes the impact these certifications have on the partner's ability to drive business and accelerate their profitability with Rapid7. By completing these Rapid7 Partner Academy certifications, partners gain: Operational excellence: Technical specialists learn to deploy and manage Rapid7 solutions with a "Gold Standard"

🩹 PatchThe Hacker News·22d ago
Microsoft's MDASH AI System Finds 16 Windows Flaws Fixed in Patch Tuesday

Microsoft has unveiled a new multi-model artificial intelligence (AI)-driven system called MDASH to facilitate vulnerability discovery and remediation at scale, adding that it's being tested by some customers as part of a limited private preview. MDASH, short for multi-model agentic scanning harness, is designed as a model-agnostic system that uses bespoke AI agents for different vulnerability

VulnerabilityThe Hacker News·22d ago
Azerbaijani Energy Firm Hit by Repeated Microsoft Exchange Exploitation

A threat actor with affiliations to China has been linked to a "multi-wave intrusion" targeting an unnamed Azerbaijani oil and gas company between late December 2025 and late February 2026, marking an expansion of its targeting. The activity has been attributed by Bitdefender with moderate-to-high confidence to a hacking group known as FamousSparrow (aka UAT-9244), which shares some level of

VulnerabilityThe Hacker News·22d ago
[Webinar] How Modern Attack Paths Cross Code, Pipelines, and Cloud

TL;DR: Stop chasing thousands of "toast" alerts. Join experts from Wiz to learn how hackers connect tiny flaws to build a "Lethal Chain" to your data—and how to break it. Register for the Strategic Briefing Here. Most security tools work like a smoke alarm that goes off every time you burn a piece of toast. You get so many alerts that you eventually start to ignore them. The real danger? While