BetaIT-Hub is in early access — your feedback helps us improve. Use the chat or email [email protected]

Latest
PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay NetworkThe Hacker News · 1h agoISC Stormcast For Friday, June 5th, 2026 https://isc.sans.edu/podcastdetail/9960, (Fri, Jun 5th)SANS ISC · 4h agoFiltr is a new privacy tool that blocks ads in almost every iPhone and Mac appTechCrunch Security · 8h agoBrave Software releases Origin for a paid, bloat-free browsing experienceBleepingComputer · 9h agoDefense tech, AI, and fundraising take center stage at StrictlyVC Los Angeles on June 18TechCrunch Security · 9h agoHola Browser for Windows compromised to deliver cryptominerBleepingComputer · 9h agoCredit card theft campaign abuses Stripe to host stolen payment infoBleepingComputer · 9h agoUpdating the taxonomy of failure modes in agentic AI systems: What a year of red teaming taught usMicrosoft Security · 11h agoDentaQuest data breach exposed info of 2.6 million accountsBleepingComputer · 12h agoiFood Confirms Data Breach Affecting 1.2 Million Users in BrazilHackRead · 13h agoCisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes PublicThe Hacker News · 13h agoUN food agency discloses breach affecting 600,000 Gaza householdsBleepingComputer · 13h agoEverest Forms Pro Vulnerability Allows Remote Code Execution on WordPress SitesInfosecurity Magazine · 14h agoNew IronWorm malware hits 36 packages in npm supply-chain attackBleepingComputer · 15h agoClaude Code GitHub Action Flaw Let One Malicious Issue Hijack RepositoriesThe Hacker News · 15h agoPCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay NetworkThe Hacker News · 1h agoISC Stormcast For Friday, June 5th, 2026 https://isc.sans.edu/podcastdetail/9960, (Fri, Jun 5th)SANS ISC · 4h agoFiltr is a new privacy tool that blocks ads in almost every iPhone and Mac appTechCrunch Security · 8h agoBrave Software releases Origin for a paid, bloat-free browsing experienceBleepingComputer · 9h agoDefense tech, AI, and fundraising take center stage at StrictlyVC Los Angeles on June 18TechCrunch Security · 9h agoHola Browser for Windows compromised to deliver cryptominerBleepingComputer · 9h agoCredit card theft campaign abuses Stripe to host stolen payment infoBleepingComputer · 9h agoUpdating the taxonomy of failure modes in agentic AI systems: What a year of red teaming taught usMicrosoft Security · 11h agoDentaQuest data breach exposed info of 2.6 million accountsBleepingComputer · 12h agoiFood Confirms Data Breach Affecting 1.2 Million Users in BrazilHackRead · 13h agoCisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes PublicThe Hacker News · 13h agoUN food agency discloses breach affecting 600,000 Gaza householdsBleepingComputer · 13h agoEverest Forms Pro Vulnerability Allows Remote Code Execution on WordPress SitesInfosecurity Magazine · 14h agoNew IronWorm malware hits 36 packages in npm supply-chain attackBleepingComputer · 15h agoClaude Code GitHub Action Flaw Let One Malicious Issue Hijack RepositoriesThe Hacker News · 15h ago

Security & IT News

Live

Real-time news from 13+ trusted sources — BleepingComputer, The Hacker News, Krebs on Security, Dark Reading & more.

VulnerabilityCISA·43d ago
CISA Adds One Known Exploited Vulnerability to Catalog

p CISA has added one new vulnerability to its a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" data-entity-type="node" data-entity-uuid="79453b83-86b9-4e2f-b1ec-abf73c6eb291" data-entity-substitution="canonical" title="Known Exploited Vulnerabilities Catalog" Known Exploited Vulnerabilities (KEV) Catalog /a , based on evidence of active exploitation. /p ul li a href="https://www.cve.org/CVERecord?id=CVE-2026-33825" target="_blank" CVE-2026-33825 /a Microsoft Defender Insufficient Granularity of Access Control Vulnerability /li /ul p This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. /p p a href="https://www.cisa.gov/binding-operational-directive-22-01" Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities /a established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the a href="https://www.cisa.gov/sites/default/files/publications/Reducing_the_Significant_Risk_of_Known_Exploited_Vulnerabilities_211103.pdf" BOD 22-01 Fact Sheet /a for more information. /p p Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" data-entity-type="node" data-entity-uuid="79453b83-86b9-4e2f-b1ec-abf73c6eb291" data-entity-substitution="canonical" title="Known Exploited Vulnerabilities Catalog" KEV Catalog vulnerabilities /a as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the a href="https://www.cisa.gov/known-exploited-vulnerabilities" data-entity-type="node" data-entity-uuid="f2adba9a-0404-494c-a90c-4363a4a5c934" data-entity-substitution="canonical" title="Reducing the Significant Risk of Known Exploited Vulnerabilities" specified criteria /a . nbsp; /p

🦠 MalwareThe Hacker News·43d ago
Lotus Wiper Malware Targets Venezuelan Energy Systems in Destructive Attack

Cybersecurity researchers have discovered a previously undocumented data wiper that has been used in attacks targeting Venezuela at the end of last year and the start of 2026. Dubbed Lotus Wiper, the novel file wiper has been used in a destructive campaign targeting the energy and utilities sector in Venezuela, per findings from Kaspersky. "Two batch scripts are responsible for initiating the

VulnerabilityThe Hacker News·43d ago
Toxic Combinations: When Cross-App Permissions Stack into Risk

On January 31, 2026, researchers disclosed that Moltbook, a social network built for AI agents, had left its database wide open, exposing 35,000 email addresses and 1.5 million agent API tokens across 770,000 active agents. The more worrying part sat inside the private messages. Some of those conversations held plaintext third-party credentials, including OpenAI API keys shared between agents,

🩹 PatchThe Hacker News·43d ago
Microsoft Patches Critical ASP.NET Core CVE-2026-40372 Privilege Escalation Bug

Microsoft has released out-of-band updates to address a security vulnerability in ASP.NET Core that could allow an attacker to escalate privileges. The vulnerability, tracked as CVE-2026-40372, carries a CVSS score of 9.1 out of 10.0. It's rated Important in severity. An anonymous researcher has been credited with discovering and reporting the flaw. "Improper verification of cryptographic