לפני 12 שעות · צוות CyberHub
Metabase SQLi zero-day exploited in customer data-theft attacks
A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 13 שעות · צוות CyberHub
Unlimited Technology Systems breach impacts 3.8 million people
Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident that occurred in October 2025. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 13 שעות · צוות CyberHub
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems. "These packages appear to use AI slop squatted, or randomly generated typo-squatting p
#חדשות#The Hacker News
לכתבה המלאה →לפני 14 שעות · צוות CyberHub
ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The macOS-focused infection chain is designed to deliver a shell script that pro
#חדשות#The Hacker News
לכתבה המלאה →לפני 14 שעות · צוות CyberHub
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
A recent wave of cyber attacks targeting financial services, private equity, and professional services has been attributed to a data extortion group known as UNC6671. "UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk sta
#חדשות#The Hacker News
לכתבה המלאה →לפני 16 שעות · צוות CyberHub
Levi Strauss & Co. says hackers stole corporate data in cyberattack
Levi Strauss & Co. (Levi's) says that hackers used social engineering on three of its employees to gain access to and steal corporate data stored on their machines. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 1 ימים · צוות CyberHub
OpenAI rolls out a major ChatGPT upgrade, even if you don’t pay for it
OpenAI is rolling out a more reliable version of ChatGPT GPT-5.6 Sol for Plus and Pro users, while Free users are getting unlimited text chats with GPT-5.6 Luna. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 1 ימים · צוות CyberHub
ClickFix attack pushes macOS infostealer for crypto theft attacks
A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 1 ימים · צוות CyberHub
Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group
A recent wave of cyberattacks targeting hedge funds, private-equity firms, and other financial organizations has been linked to UNC6671, an extortion group reportedly associated with the BlackFile threat actors. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 1 ימים · צוות CyberHub
New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts
Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests. The flaw is tracked
#חדשות#The Hacker News
לכתבה המלאה →לפני 1 ימים · צוות CyberHub
Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs
Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of a comprehensive internal security review. The security issues affect Cisco Catalyst SD-WAN Software, regardless of device configuration, and
#חדשות#The Hacker News
לכתבה המלאה →לפני 1 ימים · צוות CyberHub
Canadian Man Pleads Guilty in Snowflake Extortions
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake. Connor Riley Moucka,
#חדשות#Krebs on Security
לכתבה המלאה →לפני 1 ימים · צוות CyberHub
New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs
An unprivileged Linux program can time a hardware interrupt to land in the gap between a processor sanitizing its branch predictor and the kernel using it, re-poisoning the predictor after the defense has run. MIT CSAIL researchers Daniël Trujillo and Mengjia Yan named the techni
#חדשות#The Hacker News
לכתבה המלאה →לפני 2 ימים · צוות CyberHub
Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People
Connor Riley Moucka pleaded guilty in Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft and a related conspiracy over the 2024 breaches of Snowflake customer accounts. The intrusions reached at least 165 organizations and exposed records
#חדשות#The Hacker News
לכתבה המלאה →לפני 2 ימים · צוות CyberHub
Ransom Cartel ransomware creator sentenced to 16 years in prison
Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for his role in ransomware attacks against at least 18 companies worldwide. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 2 ימים · צוות CyberHub
Canadian pleads guilty to Snowflake cloud data-theft attacks
A Canadian man pleaded guilty today to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 2 ימים · צוות CyberHub
Hackers run khunt post-exploitation toolkit from Oracle database
Hackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database that was used to breach a corporate network. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 2 ימים · צוות CyberHub
Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures
A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks. The server-side gate hides the malic
#חדשות#The Hacker News
לכתבה המלאה →לפני 2 ימים · צוות CyberHub
OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes
OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes. To that end, it banned a coordinated network of C
#חדשות#The Hacker News
לכתבה המלאה →לפני 3 ימים · צוות CyberHub
QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
Cybersecurity researchers have disclosed what has been described as a "long-standing supply chain attack" on QuickFox, a virtual private network (VPN) and network acceleration tool designed for overseas Chinese users. According to Fortinet FortiGuard Labs, the supply chain attack
#חדשות#The Hacker News
לכתבה המלאה →לפני 3 ימים · צוות CyberHub
OpenAI, Anthropic AI agents targeted real people and systems in cyber tests
OpenAI and Anthropic have confirmed that their AI models were involved in separate, newly disclosed third-party cybersecurity testing incidents that resulted in a real website being breached and social engineering attacks against people outside the intended testing boundaries. [.
#חדשות#BleepingComputer
לכתבה המלאה →לפני 3 ימים · צוות CyberHub
TP-Link patches Omada ZTP flaws allowing hackers to breach networks
TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could be chained with previously disclosed flaws to achieve remote code execution (RCE). [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 3 ימים · צוות CyberHub
Phishing service spoofs RingCentral to steal Microsoft 365 accounts
The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing targeting Microsoft 365 accounts. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 3 ימים · צוות CyberHub
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authenti
#חדשות#The Hacker News
לכתבה המלאה →לפני 3 ימים · צוות CyberHub
Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks
A credential-stealing npm worm that first appeared in keyv@6.0.0 spread beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations on August 4, 2026. SafeDep verified 353 poisoned versions across 79 package names in the npm registry. Its moni
#חדשות#The Hacker News
לכתבה המלאה →לפני 4 ימים · צוות CyberHub
Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts
Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 4 ימים · צוות CyberHub
New Pass-ta-key attacks let malware hijack Google-synced passkeys
Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager's synced passkeys to take over accounts, bypass user verification, and extract passkey private keys. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 4 ימים · צוות CyberHub
New DOUBLECUP ClickFix service hides malware in browser cache images
A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 4 ימים · צוות CyberHub
18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users
Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments. O
#חדשות#The Hacker News
לכתבה המלאה →לפני 4 ימים · צוות CyberHub
Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
Malware running as an ordinary user on a Windows machine can sign into a victim's passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim's screen. Unit 42 detailed three attack paths against Chrome's Google Password Manager cloud authe
#חדשות#The Hacker News
לכתבה המלאה →לפני 4 ימים · צוות CyberHub
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. In a report published over the weekend, Resecurity said it observed the INC Ransomware acce
#חדשות#The Hacker News
לכתבה המלאה →לפני 5 ימים · צוות CyberHub
OpenAI teases Astra, its next major AI model, after it solves 10 long-standing math problems
OpenAI has revealed Astra, an unreleased model designed to tackle complex, long-running tasks, after an internal version produced ten significant advances in mathematics and theoretical computer science. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 5 ימים · צוות CyberHub
COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft
A vulnerability in COLDCARD hardware wallet firmware allowed attackers to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose seeds were generated using a flawed random number generator. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 5 ימים · צוות CyberHub
Google Chrome may soon block New Tab hijacker extensions by default
Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing the default search engine. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 6 ימים · צוות CyberHub
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2
#חדשות#The Hacker News
לכתבה המלאה →לפני 6 ימים · צוות CyberHub
Rails patches critical Active Storage flaw with RCE potential
A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 6 ימים · צוות CyberHub
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
Attackers modified a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses. Adform detected the incident on July 27, 2026, removed the malicious code, notified affected clients, and repor
#חדשות#The Hacker News
לכתבה המלאה →לפני 7 ימים · צוות CyberHub
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score o
#חדשות#The Hacker News
לכתבה המלאה →לפני 7 ימים · צוות CyberHub
Amgen says cloud data breach exposed patient health, proprietary info
Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 7 ימים · צוות CyberHub
Arch Linux disables AUR package adoption to stop malware flood
The Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of existing packages. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 7 ימים · צוות CyberHub
Online ad firm Adform’s script compromised to steal cryptocurrency
Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors' clipboards with ones controlled by an attacker. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 7 ימים · צוות CyberHub
Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, since January 2025. Thes
#חדשות#The Hacker News
לכתבה המלאה →לפני 7 ימים · צוות CyberHub
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka. According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a link
#חדשות#The Hacker News
לכתבה המלאה →לפני 7 ימים · צוות CyberHub
Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators. Researchers named the operation Fuyao and attributed it to Zhejiang Fengwo
#חדשות#The Hacker News
לכתבה המלאה →לפני 8 ימים · צוות CyberHub
Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests
One of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 8 ימים · צוות CyberHub
South Korea fines telco giant KT $39 million for customer data breach
South Korea's Personal Information Protection Commission (PIPC) has fined telecommunications giant KT Corporation KRW 53.979 billion ($39 million) over data protection violations. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 8 ימים · צוות CyberHub
JetBrains warns of critical TeamCity remote code execution flaw
JetBrains is warning of a critical authentication bypass vulnerability affecting TeamCity On-Premises that could be exploited to achieve remote code execution. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 8 ימים · צוות CyberHub
DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Con
#חדשות#The Hacker News
לכתבה המלאה →לפני 8 ימים · צוות CyberHub
Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds
#חדשות#Krebs on Security
לכתבה המלאה →לפני 8 ימים · צוות CyberHub
ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories
A lot of security still comes down to trusting the wrong screen. This week, that screen might be a login page, an install guide, a recruiter call, or a familiar service behaving slightly wrong. Behind it: reused credentials, exposed systems, quiet loaders, abused trust, and explo
#חדשות#The Hacker News
לכתבה המלאה →לפני 8 ימים · צוות CyberHub
Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database
A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz. Wiz, which codenamed the chain CosmosEscape, said the exploit chain b
#חדשות#The Hacker News
לכתבה המלאה →לפני 9 ימים · צוות CyberHub
Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation. T
#חדשות#The Hacker News
לכתבה המלאה →לפני 9 ימים · צוות CyberHub
Russian hackers exploit Exchange OWA zero-day for long-term mailbox access
The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated backdoor called OWAReaper. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 9 ימים · צוות CyberHub
Anthropic confirms Claude is down worldwide
Claude is down for some users, with Anthropic confirming elevated errors across multiple AI models. The disruption is causing requests to fail with a "529 Overloaded" message, including in Claude and tools that rely on its API. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 9 ימים · צוות CyberHub
Cisco warns of FMC static credential flaw exploited in zero-day attacks
Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 9 ימים · צוות CyberHub
Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process en
#חדשות#The Hacker News
לכתבה המלאה →לפני 9 ימים · צוות CyberHub
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10
#חדשות#The Hacker News
לכתבה המלאה →לפני 10 ימים · צוות CyberHub
OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach
OpenAI on Tuesday revealed the rogue artificial intelligence (AI) agent that escaped its sealed evaluation environment and broke into Hugging Face's production environment, and also hacked multiple third-party accounts and services as part of the attack. The latest disclosure sho
#חדשות#The Hacker News
לכתבה המלאה →לפני 10 ימים · צוות CyberHub
Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js
Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family. The list of affected packages is as follows - @joyfill/layouts@0.1.2-2773.beta.0 @joyfill/components@4.
#חדשות#The Hacker News
לכתבה המלאה →לפני 10 ימים · צוות CyberHub
CubePilot drone software dev hit by DNS hijacking to intercept traffic
CubePilot, an Australian firm that designs flight controllers for drones (UAVs), announced a severe operational disruption caused by a DNS hijacking attack. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 10 ימים · צוות CyberHub
OpenAI models used Artifactory zero-days to escape to the internet
JFrog has confirmed that OpenAI models exploited zero-day vulnerabilities in self-hosted Artifactory servers to help escape an isolated testing environment and gain access to the internet before attacking Hugging Face. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 10 ימים · צוות CyberHub
Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack
Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on seven-round AES-128. The HAWK attack exploits a previously unused symmetry in the lattice behind the signature scheme. Anthropic's
#חדשות#The Hacker News
לכתבה המלאה →לפני 10 ימים · צוות CyberHub
CISA shares advice on isolating vital systems during cyberattacks
The U.S. and Australian governments have released new guidance urging critical infrastructure organizations to prepare to isolate vital operational technology systems in the event of a cyberattack or other major disruptions. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 11 ימים · צוות CyberHub
Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost
Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness. The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It also claims the configuration costs 50% les
#חדשות#The Hacker News
לכתבה המלאה →לפני 11 ימים · צוות CyberHub
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command injection that could pave
#חדשות#The Hacker News
לכתבה המלאה →לפני 11 ימים · צוות CyberHub
Hackers target US firms in FastJson RCE zero-day attacks
Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 11 ימים · צוות CyberHub
Arista patches VeloCloud Orchestrator zero-day exploited in attacks
Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 11 ימים · צוות CyberHub
New Dysphoria DDoS botnet spreads to 200k devices worldwide
A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 11 ימים · צוות CyberHub
NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework
NVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents. The 37-member group spans cloud, security, enterprise software, and AI companies,
#חדשות#The Hacker News
לכתבה המלאה →לפני 12 ימים · צוות CyberHub
GitHub, PyPI add time-based defenses against supply chain attacks
GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 13 ימים · צוות CyberHub
Steam forum ClickFix attacks infect gamers with XMRig cryptominers
Steam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game and computer problems but actually infect devices with cryptominers. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 13 ימים · צוות CyberHub
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
A malvertising operation dubbed SourTrade is making victims' browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fixed URL. Confiant, which detailed the campaign on July 23, 2026,
#חדשות#The Hacker News
לכתבה המלאה →לפני 13 ימים · צוות CyberHub
Malicious sites use JavaScript to build malware in browser memory
A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 13 ימים · צוות CyberHub
ShinyHunters data leaks fuel $2,000 sextortion email scam
Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 13 ימים · צוות CyberHub
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process. Tracked
#חדשות#The Hacker News
לכתבה המלאה →לפני 13 ימים · צוות CyberHub
Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six weeks earlier, on June 10. It runs commands as git on any self-managed 18.11.3 server that has not taken the update. Any authenticated user who can push to a pro
#חדשות#The Hacker News
לכתבה המלאה →לפני 14 ימים · צוות CyberHub
OnTrac notifies customers of data breach after network hack
OnTrac parcel delivery company is informing that hackers breached its corporate network and may have accessed personal details belonging to its customers. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 14 ימים · צוות CyberHub
Hermes AI agent used to automate attack on Thai Finance Ministry
A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 14 ימים · צוות CyberHub
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 14 ימים · צוות CyberHub
BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malwar
#חדשות#The Hacker News
לכתבה המלאה →לפני 14 ימים · צוות CyberHub
Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine. They codenamed the flaw Certighost. Because Domain Controller accounts carry d
#חדשות#The Hacker News
לכתבה המלאה →לפני 14 ימים · צוות CyberHub
ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
Cybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial intelligence (AI) agent inside a victim's organization. The vu
#חדשות#The Hacker News
לכתבה המלאה →לפני 15 ימים · צוות CyberHub
New Dolphin X malware uses AI to rank high-value targets
A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 15 ימים · צוות CyberHub
Australian energy provider Origin says data breach exposes client data
Origin Energy has confirmed that an unauthorized party accessed and subsequently leaked customer data online, exposing sensitive personally identifiable information (PII), among others. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 15 ימים · צוות CyberHub
Fake Claude app promoted by Bing ads pushes SectopRAT malware
A malvertising campaign on the Bing search service is pushing a fake Claude desktop app installer hosted on a legitimate Claude.ai domain to deliver the SectopRAT malware. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 15 ימים · צוות CyberHub
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client. The payload goes after the last 90 days of email, the organization's entire email directory, the password saved in the browser and the codes ke
#חדשות#The Hacker News
לכתבה המלאה →לפני 15 ימים · צוות CyberHub
ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories
Most of this week's trouble came dressed as something useful. A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders to an AI agent. Other threats hid in open systems, weak code, and normal network traffic. The threat
#חדשות#The Hacker News
לכתבה המלאה →לפני 15 ימים · צוות CyberHub
Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic's Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which the agent runs to read or write files anywhere on the Mac. Accomplish AI, which sh
#חדשות#The Hacker News
לכתבה המלאה →לפני 16 ימים · צוות CyberHub
Upbound says hack caused $13 million in fraudulent Acima leases
The Upbound Group fintech company disclosed that threat actors who stole data from its systems leveraged it to create $13 million in Acima leases. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 16 ימים · צוות CyberHub
South Korea discloses data breach impacting diplomats worldwide
South Korea disclosed that hackers breached the National Diplomatic Academy's online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), including overseas diplomats. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 16 ימים · צוות CyberHub
GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier
Beginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severity level. Critical findings will drop from $20,000-$30,000+ to a fixed $10,000, while its permanent invite-only VIP tier will pay $30,000 or more. Reports filed before that date, in
#חדשות#The Hacker News
לכתבה המלאה →לפני 16 ימים · צוות CyberHub
Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs
Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root access and gain complete control of a target environment. The high-severity flaw, tracked as CVE-2026-8933
#חדשות#The Hacker News
לכתבה המלאה →לפני 16 ימים · צוות CyberHub
Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack
Swiss rail vehicle manufacturer Stadler Rail says the Everest ransomware gang demanded about $12.3 million after breaching a data exchange platform shared with one of its suppliers. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 16 ימים · צוות CyberHub
Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data
Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million users, which, if exploited, could facilitate a silent hijack of a user's WhatsApp data. The shortcoming has been codenamed Hermeti
#חדשות#The Hacker News
לכתבה המלאה →לפני 17 ימים · צוות CyberHub
Chick-fil-A discloses data breach after credential stuffing attacks
American fast food restaurant chain Chick-fil-A is notifying customers of a data breach after their accounts were hacked in a wave of recent credential stuffing attacks. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 17 ימים · צוות CyberHub
Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library
Cybersecurity researchers have discovered a NuGet typosquat that's unlike the typical information-stealing malware distributed via package registries: usual info-stealers: it's designed to rig live game results on Digitain. The package, named "Newtonsoftt.Json.Net," masquerades a
#חדשות#The Hacker News
לכתבה המלאה →לפני 17 ימים · צוות CyberHub
OpenAI says its AI models hacked Hugging Face during testing
OpenAI says its AI models, including GPT‑5.6 Sol and a pre-release model, hacked into the Hugging Face artificial intelligence repository while being tested in a sandboxed testing environment. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 17 ימים · צוות CyberHub
Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents
A single invisible comment in an Azure DevOps pull request can turn a reviewer's own AI coding agent against them, driving it into projects the attacker has no rights to reach and quietly leaking what it finds. The flaw is in Microsoft's official Azure DevOps MCP server, and it w
#חדשות#The Hacker News
לכתבה המלאה →לפני 17 ימים · צוות CyberHub
OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark
OpenAI on Tuesday said a combination of its artificial intelligence (AI) models, including GPT-5.6 Sol and an "even more capable pre-release model," was behind the security incident that targeted Hugging Face's production infrastructure last week. The AI company said the models w
#חדשות#The Hacker News
לכתבה המלאה →לפני 17 ימים · צוות CyberHub
LG to Ban Residential Proxies from Smart TV Apps
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and oth
#חדשות#Krebs on Security
לכתבה המלאה →לפני 17 ימים · צוות CyberHub
Police dismantle Kratos phishing platform, arrest developer
Authorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its developer was arrested in Indonesia. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 18 ימים · צוות CyberHub
Estée Lauder discloses data breach via Oracle E-Business flaw
Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 18 ימים · צוות CyberHub
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 18 ימים · צוות CyberHub
Hackers steal $23.7 million in crypto from Ostium in off-chain attack
The Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week, after compromising off-chain infrastructure used to feed prices into the protocol. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 18 ימים · צוות CyberHub
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a malware family known as SmartLoader as part of an ongoing campaign cod
#חדשות#The Hacker News
לכתבה המלאה →לפני 18 ימים · צוות CyberHub
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Me
#חדשות#The Hacker News
לכתבה המלאה →לפני 18 ימים · צוות CyberHub
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050. Group-IB, which named the malware HollowGraph, say
#חדשות#The Hacker News
לכתבה המלאה →לפני 19 ימים · צוות CyberHub
World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent
In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system. The company said it detected and responded to the incident targeting its production infrastructure earlier la
#חדשות#The Hacker News
לכתבה המלאה →לפני 19 ימים · צוות CyberHub
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads. The rogue gems are listed below - git_credential_man
#חדשות#The Hacker News
לכתבה המלאה →לפני 19 ימים · צוות CyberHub
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched on July 15 in nginx 1.30.4 (stable) and 1.31.3 (mainline), and in NGINX Plus 37.
#חדשות#The Hacker News
לכתבה המלאה →לפני 19 ימים · צוות CyberHub
Hackers abuse ViPNet software to target Russian govt agencies
An advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 20 ימים · צוות CyberHub
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
7-Zip version 26.02 was released to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 20 ימים · צוות CyberHub
WordPress Core "wp2shell" RCE flaws get public exploits, patch now
Public exploits have been released for the critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 20 ימים · צוות CyberHub
Microsoft warns of surge in ACR Stealer attacks on customers
Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 21 ימים · צוות CyberHub
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story below reflects all of it. An anonymous HTTP request can run code on a WordPress sit
#חדשות#The Hacker News
לכתבה המלאה →לפני 21 ימים · צוות CyberHub
Abbott probes two cyber incidents amid extortion claims
Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that attackers breached its LabCentral portal and
#חדשות#BleepingComputer
לכתבה המלאה →לפני 21 ימים · צוות CyberHub
OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests
Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte fix in June with no CVE, no advisory, and no chan
#חדשות#The Hacker News
לכתבה המלאה →לפני 21 ימים · צוות CyberHub
Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which wa
#חדשות#The Hacker News
לכתבה המלאה →לפני 21 ימים · צוות CyberHub
HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload
A vulnerability dubbed HollowByte allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers with a malicious payload of just 11 bytes. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 21 ימים · צוות CyberHub
Ernst & Young discloses data breach after support system hack
Ernst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 22 ימים · צוות CyberHub
New ClickLock macOS malware traps users into revealing login password
A new macOS information-stealing malware dubbed ClickLock terminates all visible processes to force users into entering their system login password. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 22 ימים · צוות CyberHub
Coca-Cola says Fairlife ransomware attack halts US dairy production
The Coca-Cola Company disclosed today that a ransomware attack impacting its Fairlife dairy subsidiary has disrupted operations, temporarily suspending production of Fairlife products across the United States. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 22 ימים · צוות CyberHub
Claude Chrome extension flaw lets malicious extensions trigger AI actions
A flaw in Anthropic's Claude for Chrome browser extension could allow a malicious extension to trigger predefined AI actions by simulating user clicks, potentially allowing it to abuse Claude's access to connected services such as Gmail, Google Docs, Google Calendar, and Salesfor
#חדשות#BleepingComputer
לכתבה המלאה →לפני 22 ימים · צוות CyberHub
Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack
Owen Flowers, 18, and Thalha Jubair, 20, were each sentenced to five and a half years at Woolwich Crown Court on Thursday, 16 July 2026, for the 2024 hack of Transport for London. The attack left 148 TfL systems inoperable and forced all 27,000 of the transport authority's employ
#חדשות#The Hacker News
לכתבה המלאה →לפני 22 ימים · צוות CyberHub
ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories
A lot of this week’s trouble starts with something that looks close enough. A familiar repo. A useful installer. A harmless sync setting. Then the handoff goes bad, the box starts talking to someone else, and the damage moves faster than the explanation. Old bugs are back, weak d
#חדשות#The Hacker News
לכתבה המלאה →לפני 22 ימים · צוות CyberHub
n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer
n8n, the workflow automation platform, handed out the wrong accounts at login. On Enterprise instances configured to trust more than one external token issuer, it matched an incoming JWT to a local user on the sub claim alone and ignored iss. A valid token from issuer A carrying
#חדשות#The Hacker News
לכתבה המלאה →לפני 23 ימים · צוות CyberHub
Dutch police bust investment fraud ring stealing over €100 million
The Dutch Police announced the arrest of multiple individuals suspected of being part of an international investment fraud scheme estimated to have tens of thousands of victims. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 23 ימים · צוות CyberHub
Zoom warns of critical account takeover vulnerability
Zoom is warning of a critical vulnerability in its desktop client and software development kit for Windows that could be exploited by an unauthenticated party to hijack accounts. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 23 ימים · צוות CyberHub
TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development
Cybersecurity researchers have disclosed details of a previously unreported Internet-of-Things (IoT) botnet framework dubbed TuxBot v3 Evolution that shows signs of being developed with assistance from a large language model (LLM), albeit with not so successful results. "While th
#חדשות#The Hacker News
לכתבה המלאה →לפני 23 ימים · צוות CyberHub
Google Gemini CLI abused as a hacking agent, malware botnet operator
A Russian-speaking threat actor known as "bandcampro" used Google's open-source Gemini CLI AI tool as a hacking agent and to operate a small-scale botnet. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 23 ימים · צוות CyberHub
OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps
A malware framework called OkoBot has been running on Windows machines since April 2025, and one of its modules is built to con hardware wallet owners out of their recovery phrase. On an infected PC, the request comes from inside the wallet's own desktop software. Sometimes it wa
#חדשות#The Hacker News
לכתבה המלאה →לפני 23 ימים · צוות CyberHub
Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws
Mozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published. The vulnerabilities are listed below - CVE-2026-15718, an invalid pointer in the JavaScript: WebAssembly component CVE-2026-15719, a site isolation in t
#חדשות#The Hacker News
לכתבה המלאה →לפני 24 ימים · צוות CyberHub
Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands
SonicWall has warned of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which could be exploited to achieve arbitrary command execution. The vulnerabilities are listed below - CVE-2026-15409 (CVSS score: 10.0
#חדשות#The Hacker News
לכתבה המלאה →לפני 24 ימים · צוות CyberHub
SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now
SonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day attacks and urges customers to install the newly released security updates. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 24 ימים · צוות CyberHub
Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack
Microsoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that attackers are already exploiting. The release covers 622 of Microsoft's own CVEs by its Security Update Guide count, more than triple June's previous high of around 200. Those two l
#חדשות#The Hacker News
לכתבה המלאה →לפני 24 ימים · צוות CyberHub
Spanish Police take down €140 million cyber fraud ring, arrest four
The Spanish Police dismantled a cybercrime and money-laundering organization that made €140 million ($160 million) from investment fraud and business email compromise (BEC) attacks. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 24 ימים · צוות CyberHub
Microsoft Patches a Record 570 Security Flaws
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attribu
#חדשות#Krebs on Security
לכתבה המלאה →לפני 24 ימים · צוות CyberHub
Nearly 300 GitHub repos pose as legit software to push malware
A threat actor has published hundreds of fake GitHub repositories impersonating legitimate software and security projects to distribute infostealer malware. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 24 ימים · צוות CyberHub
SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data
SAP has rolled out updates to address multiple vulnerabilities as part of its July 2026 security updates, including a critical flaw in SAP NetWeaver Application Server ABAP. The vulnerability in question is CVE-2026-44747 (CVSS score: 9.9), an out-of-bounds write flaw that allows
#חדשות#The Hacker News
לכתבה המלאה →לפני 25 ימים · צוות CyberHub
Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths
Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform. The way in has been the trust the organization had already extended, usually throug
#חדשות#The Hacker News
לכתבה המלאה →לפני 25 ימים · צוות CyberHub
Japan's largest taxi operator shuts systems after cyberattack
Japan's largest taxi operator, Nihon Kotsu, announced that its systems were compromised in a cyberattack, forcing the company to shut down part of its infrastructure. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 25 ימים · צוות CyberHub
Hackers backdoor Jscrambler npm package with infostealer malware
The Jscrambler client-side web security company disclosed that a threat actor published a malicious version of its npm package that has been downloaded almost 1,500 times. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 25 ימים · צוות CyberHub
New CrashStealer malware poses as Apple crash reporting tool
A new macOS information-stealing malware called CrashStealer pretends to be Apple's crash-reporting tool to steal credentials, keychain data, and crypto wallets. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 25 ימים · צוות CyberHub
CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks
Cybersecurity researchers have flagged a new macOS information stealer called CrashStealer that's capable of harvesting sensitive data from compromised systems. Unlike other information stealers that are built on AppleScript droppers or Objective-C-based wrappers, CrashStealer is
#חדשות#The Hacker News
לכתבה המלאה →לפני 25 ימים · צוות CyberHub
Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found
Google and Microsoft have pulled ModHeader, a popular header-editing extension with roughly 1.6 million installs across Chrome and Edge, after researchers found a hidden browsing-history collector built into its official store version. The collector was dormant. An empty allow-li
#חדשות#The Hacker News
לכתבה המלאה →לפני 25 ימים · צוות CyberHub
Lessons Learned from CISA’s Recent GitHub Leak
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almost six months before being notified by Kr
#חדשות#Krebs on Security
לכתבה המלאה →לפני 26 ימים · צוות CyberHub
OpenAI temporarily relaxes GPT-5.6 Sol usage limits
OpenAI is temporarily relaxing GPT-5.6 Sol usage after demand for the company's most powerful model surged over the past 48 hours. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 26 ימים · צוות CyberHub
Claude Fable 5 stays free for paid users until July 19 as Anthropic buys more time
Anthropic has just extended access to Claude Fable 5 for paid subscribers until July 19, giving you another week to keep using the most powerful model. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 26 ימים · צוות CyberHub
RedHook Android malware now uses Wireless ADB for shell access
A new version of the RedHook Android malware abuses the Android Wireless Debugging (Wireless ADB) mechanism in a novel way to gain shell-level privileges without requiring a computer connection. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 27 ימים · צוות CyberHub
Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
The jscrambler npm package was compromised, and simply installing its 8.14.0 release runs an infostealer on your machine. Published on July 11, 2026, the malicious version carries a preinstall hook that drops and executes a native binary, one build each for Windows, macOS, and Li
#חדשות#The Hacker News
לכתבה המלאה →לפני 27 ימים · צוות CyberHub
Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns
Cybersecurity researchers have disclosed details of sustained cyber espionage activity against several Pakistani law enforcement organizations undertaken by suspected China- and India-aligned threat actors between February 2024 and April 2026. "At Balochistan Police, the compromi
#חדשות#The Hacker News
לכתבה המלאה →לפני 27 ימים · צוות CyberHub
Australia warns of global campaign targeting vulnerable CMS platforms
The Australian Cyber Security Centre (ACSC) issued an alert about a global exploitation campaign targeting vulnerable content management systems (CMS) and plugins. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 27 ימים · צוות CyberHub
'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets
A PNG hiding a prompt injection could steal your repo's secrets, researchers demonstrate. The technique, dubbed 'Ghostcommit,' slipped past AI code reviewers CodeRabbit and Bugbot, which never open image files at all, then convinced a coding agent to read a repo's .env and write
#חדשות#BleepingComputer
לכתבה המלאה →לפני 28 ימים · צוות CyberHub
Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions
Zimbra is urging customers to apply updates to address a critical security vulnerability impacting the Classic Web Client that could result in arbitrary code execution. The vulnerability has been described as a case of stored cross-site scripting (XSS) that could allow specially
#חדשות#The Hacker News
לכתבה המלאה →לפני 28 ימים · צוות CyberHub
New U-Boot flaws could enable stealthy firmware attacks
Six vulnerabilities in the widely used U-Boot bootloader have been discovered that could allow attackers to execute malicious code during device boot, potentially enabling stealthy firmware attacks that compromise security protections and install persistent malware. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 28 ימים · צוות CyberHub
Ryuk ransomware member pleads guilty in the US, faces 15 years in prison
A 34-year-old Armenian man has pleaded guilty to hacking U.S. companies and deploying the infamous Ryuk ransomware to encrypt their systems. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 28 ימים · צוות CyberHub
Police suspects Dutch hackers were involved in Odido breach
The Dutch National Police (Politie) says it has found "strong indications" that Dutch hackers have been involved in a February breach at the telecommunications provider Odido. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 28 ימים · צוות CyberHub
URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat
Progress Software has told ShareFile customers to shut down the Windows servers running their Storage Zone Controllers, confirming to The Hacker News that it is responding to a "credible external security threat." The company has temporarily disabled access to the affected accoun
#חדשות#The Hacker News
לכתבה המלאה →לפני 28 ימים · צוות CyberHub
Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages
Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and mnemonic seed phrases. The compromised version, @injectivelabs/sdk-ts@1.20.21,
#חדשות#The Hacker News
לכתבה המלאה →לפני 28 ימים · צוות CyberHub
Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot
Researchers at firmware security firm Binarly have found six new flaws in U-Boot, the small program that starts up hardware as varied as home routers, smart cameras, and the management chips inside data-center servers. Four of the bugs can crash a device. The other two could let
#חדשות#The Hacker News
לכתבה המלאה →לפני 29 ימים · צוות CyberHub
OpenMandriva Linux says contributor tried to sabotage the project
The OpenMandriva Linux project announced that it was the target of an attempted act of internal sabotage after a dispute among contributors. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 29 ימים · צוות CyberHub
Injective SDK on npm infected with cryptocurrency wallet stealer
Hackers compromised the Injective Labs SDK project's GitHub repository and used it to publish a malicious package on the Node Package Manager (npm) that stole cryptocurrency wallet private keys and mnemonic seed phrases. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 29 ימים · צוות CyberHub
Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs
Datadog Security Labs is warning of "several overlapping campaigns" that are systematically enumerating corporate GitHub organizations, repositories, and user accounts through the GitHub API. "Operators rely on automated scraping tooling with custom or legitimate-sounding user ag
#חדשות#The Hacker News
לכתבה המלאה →לפני 29 ימים · צוות CyberHub
New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware
Microsoft has taken apart a destructive Windows backdoor it calls GigaWiper. What stands out is how it is built: not one tool but three older destructive programs bolted into one, offered as commands the operator can choose from. Each is a different way to break a machine: wipe t
#חדשות#The Hacker News
לכתבה המלאה →לפני 29 ימים · צוות CyberHub
New Helix vishing group emerges in SharePoint data theft attacks
A new data-extortion group called Helix is using identity-focused tactics such as voice phishing (vishing), device code phishing, and multi-factor authentication (MFA) abuse to steal data from SharePoint environments. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 29 ימים · צוות CyberHub
npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk
GitHub has officially announced the release of npm version 12 with install scripts disabled by default, along with deprecating granular access tokens (GATs) designed to bypass two-factor authentication (2FA). The Microsoft-owned subsidiary noted that the following npm install beh
#חדשות#The Hacker News
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Microsoft patches RoguePlanet Defender zero-day vulnerability
Microsoft has released a security patch to address a Defender zero-day vulnerability known as "RoguePlanet," disclosed after the June 2026 Patch Tuesday. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It
Ask an AI coding agent to scan open-source code for security holes, and it might run the attacker's code on your own machine instead. That is the finding in a proof-of-concept published Wednesday by the AI Now Institute, an attack it calls "Friendly Fire." It works against Anthro
#חדשות#The Hacker News
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents
Researchers at Wiz found that a flaw in six popular AI coding assistants lets a booby-trapped code project quietly take control of a developer's computer. The assistant asks permission to edit one harmless-looking file, but the write lands on a sensitive one instead. The affected
#חדשות#The Hacker News
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes
Cybersecurity researchers have disclosed details of a new threat actor dubbed Lurking Lizard that has been operating an end-to-end malicious residential proxy business using an infrastructure comprising more than 230 lookalike domains. The activity dates back to at least August 2
#חדשות#The Hacker News
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Mount Royal University confirms breach as hackers claim attack
Mount Royal University in Calgary says hackers stole and then deleted data from its file storage systems after breaching the university's network. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials
Malicious packages on the Node Package Manager (npm) and the Python Package Index (PyPI) delivered stealer malware to developers and users of Paysafe, Skrill, and Neteller payment applications. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Felons, Fraudsters Flog Offensive Cybersecurity Startup
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based
#חדשות#Krebs on Security
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros
Researchers at Nebula Security have disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel flaw that lets any logged-in user take full root control of a machine that has not been patched. The vulnerable code has shipped by default in essentially every mainstream distrib
#חדשות#The Hacker News
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2026-48282 (CVSS score: 10.0) - A path tr
#חדשות#The Hacker News
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Accenture confirms breach after hacker offers stolen data for sale
IT services giant Accenture has confirmed it suffered a security breach after a threat actor claimed to have stolen 35 GB of source code and other data from the company. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Chinese hackers develop LONGLEASH malware to expand ORB network
Chinese hackers tracked as 'UAT-7810' are actively evolving their malware to expand their Operational Relay Box (ORB) network by compromising internet-facing networking devices, primarily unpatched Ruckus routers. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Hidden backdoor in Tenda router firmware grants admin access
A hidden authentication backdoor has been found in multiple Tenda router firmware versions, potentially allowing an attacker to gain administrative access to the device's web management panel. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service
A new Android malware operation called RedWing is being rented out on Telegram as a ready-made bank-fraud service. It lets even low-skill criminals take over a victim's phone, steal their banking logins, and capture the one-time codes that protect their accounts. Zimperium's zLab
#חדשות#The Hacker News
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA
BeyondTrust has released updates to address two critical security flaws affecting Remote Support (RS) and Privileged Remote Access (PRA) products that, if successfully exploited, could allow unauthenticated attackers to take control of susceptible devices. The vulnerabilities are
#חדשות#The Hacker News
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Phishing poses as big-brand job interview to steal Google accounts
A phishing campaign is impersonating more than 30 well-known brands, including Adobe, Netflix, Coca-Cola, and OpenAI, in fake job interviews to steal Google account credentials from marketing professionals. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Fake IT support calls on Microsoft Teams push EtherRAT malware
Threat actors are abusing Microsoft Teams voice calls by impersonating corporate IT support staff to trick employees into installing the EtherRAT malware, giving attackers initial access to corporate networks. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations
An Iranian hacking group affiliated with Iran's Ministry of Intelligence and Security (MOIS) has been wielding a previously undocumented modular command-and-control (C2) framework dubbed Cavern (aka Cav3rn) targeting Israeli organizations. The activity, which has primarily single
#חדשות#The Hacker News
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Vietnam arrests suspects behind HiAnime anime piracy service
Vietnamese authorities have arrested and are prosecuting seven suspects believed to have run HiAnime, the largest anime piracy streaming service before its shutdown in June. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems
A use-after-free bug in Linux's KVM hypervisor can be triggered from a guest virtual machine to corrupt the shadow-page state of the host kernel that runs it. Dubbed 'Januscape' and tracked as CVE-2026-53359, the flaw sits in the shadow MMU code that KVM shares across both Intel
#חדשות#The Hacker News
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Flipper Zero firmware development continues with community help
Flipper Devices says development of the Flipper Zero firmware will continue, albeit with a smaller internal team and greater reliance on community contributions. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
JadePuffer ransomware used AI agent to automate entire attack
Researchers identified what they believe is the first documented case of a ransomware operation, JadePuffer, conducted entirely by a large language model (LLM) agent. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case
A U.S. government entity paid about $1 million to keep stolen files from being leaked, according to a new case study by Rakesh Krishnan for Ransom-ISAC, built on a leaked negotiation chat and the blockchain trail the payment left. The odd part: the group that took the money calls
#חדשות#The Hacker News
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign
The North Korean threat actors linked to the Contagious Interview campaign have been observed publishing 108 unique packages and web browser extensions spanning npm, Packagist, Go, and Google Chrome as part of an ongoing activity referred to as PolinRider. "The campaign remains a
#חדשות#The Hacker News
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices
Security firm runZero has disclosed seven vulnerabilities in FatFs, a small filesystem library that lets a device read and write the FAT and exFAT formats used on USB drives and SD cards. The flaws matter because FatFs is nearly everywhere. It ships inside the firmware that runs
#חדשות#The Hacker News
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android
A newly disclosed Linux kernel flaw called Bad Epoll (CVE-2026-46242) lets an ordinary user with no special access take full control of a machine as root. It affects Linux desktops, servers, and Android, and a fix is out. Bad Epoll sits in the same small stretch of kernel code wh
#חדשות#The Hacker News
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
New Avalon Malware Framework Packs CrownX Ransomware Capabilities
Cybersecurity researchers have discovered a previously undocumented modular malware framework codenamed Avalon that's distributed by means of a multi-stage phishing chain capable of bypassing traditional security controls. Avalon combines credential collection, lateral movement,
#חדשות#The Hacker News
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
NetNut proxy network disrupted, 2 million infected devices cut off
A joint operation involving Google has disrupted NetNut, a residential proxy network that gave access to millions of compromised Android devices, including smart TVs and streaming boxes. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
ARToken PhaaS exposes EvilTokens' Microsoft 365 phishing toolkit
A new phishing-as-a-service (PhaaS) platform dubbed "ARToken" appears to operate as an affiliate of the EvilTokens phishing platform, giving researchers a glimpse into an extensive toolkit designed to compromise Microsoft 365. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Claude Fable 5 isn’t permanently leaving subscriptions, Anthropic says
Anthropic says Claude Fable 5 won't be accessible via Claude subscriptions after July 7, but it's not a permanent change, and the company expects the model to return outside the usage-based plan soon. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Claude Fable relaunch disappoints users with nerfed performance
Claude Fable, the company's most powerful model, is now available to all users, but early impressions are disappointing, as it appears to be nowhere near the original release. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
FBI Seizes NetNut Proxy Platform, Popa Botnet
The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes ro
#חדשות#Krebs on Security
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Google Disrupts NetNut Residential Proxy Network Spanning 2 Million Home Devices
Google has significantly degraded NetNut, one of the biggest networks that turns home devices into rented relays for other people's traffic. Working with the FBI, Lumen, and others, Google's Threat Intelligence Group (GTIG) said this week it had reduced the network's pool of usab
#חדשות#The Hacker News
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials
Threat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain initial access. "Although tactics differ between affiliates, common patterns emerged in tradecraft through use of legitimate Remo
#חדשות#The Hacker News
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories
This week’s security news is mostly about weak spots. Browsers, bots, sandboxes, AI systems, and email flows all show the same problem in different ways. Everything looks normal until someone tests a small gap and finds a way through. This is not one big break. It is small permis
#חדשות#The Hacker News
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Google loses final appeal to overturn €4.1 billion EU fine
Court of Justice of the European Union (CJEU) has dismissed Google's final appeal against a €4.1 billion ($4.7 billion) antitrust fine over the company's use of Android to promote its Chrome browser and search service. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a high-severity flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-4565
#חדשות#The Hacker News
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Medtronic notifies customers impacted by ShinyHunters data breach
Healthcare device firm Medtronic is notifying affected customers about a data breach that exposed their personal data to an unauthorized third party. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
FortiBleed credential-theft campaign linked to Lynx ransomware
The massive FortiBleed credential theft campaign has been linked to the INC and Lynx ransomware operations, suggesting the stolen Fortinet credentials were intended to fuel future network intrusions. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Kubota says hackers had month-long access to network systems
Kubota North America Corporation disclosed that hackers had access to some of its network systems for more than a month earlier this year. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters
Argo CD, a widely used tool for deploying software to Kubernetes, has an unpatched flaw in its repo-server component that lets an unauthenticated attacker run code, provided they can reach the component's internal network port. Synacktiv, which found the bug, says it can lead to
#חדשות#The Hacker News
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges
A teenager accused of belonging to the hacking group Scattered Spider has been extradited from Finland to face U.S. charges of conspiracy, computer intrusion, and fraud, the U.S. Department of Justice announced on July 1. Peter Stokes, 19, a dual U.S. and Estonian citizen, appear
#חדשות#The Hacker News
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ Attempts
Cybersecurity researchers have warned of a "massive, ongoing, automated password spray attack" aimed at Microsoft's Azure command-line interface (CLI), compromising dozens of accounts in the process. The activity, per Huntress, originates from an IPv6 address range (2a0a:d683::/3
#חדשות#The Hacker News
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API-Driven Malware Delivery
ClickFix, the trick that fools people into running malware by hand, has quietly grown a back office. New research shows the malicious commands behind its fake "prove you're human" pages are now handed out by API-driven servers that give each visitor the same malware in a differen
#חדשות#The Hacker News
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service
Citrix on Tuesday released security updates to address multiple flaws in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) that could be exploited by an attacker to facilitate arbitrary file reads or trigger a denial-of-service (DoS) condition. T
#חדשות#The Hacker News
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Anthropic to restore Claude Fable access on Wednesday
Anthropic has confirmed that the Department of Commerce has lifted export controls on Claude's two most powerful models, Fable 5 and Mythos 5. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Anthropic rolls out Sonnet 5 with near-Opus 4.8 performance at a lower price
Anthropic is now rolling out Sonnet 5, and it's almost as good as the Opus range, but it is designed to be cheaper than the company's flagship model. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
New BioShocking attack manipulates AI browser into data theft
A new prompt injection attack dubbed "BioShocking" could trick AI-powered browsers into treating real-world risky actions as part of a fictional scenario, causing them to ignore any safety guardrails. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild
A critical security flaw impacting Oracle E-Business Suite has come under active exploitation in the wild, according to Defused Cyber. The vulnerability, tracked as CVE-2026-46817 (CVSS score: 9.8), refers to an improper privilege management and authentication flaw in Oracle Paym
#חדשות#The Hacker News
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Nissan discloses employee data breach linked to Oracle zero-day attacks
Nissan is warning that it suffered a data breach affecting current and former employees after threat actors exploited an Oracle PeopleSoft vulnerability in data theft attacks previously linked to the ShinyHunters extortion group. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
NAIC says public data stolen in ShinyHunters' PeopleSoft breach
The National Association of Insurance Commissioners (NAIC) says the ShinyHunters extortion group stole only publicly available data, outdated logs, and configuration files after breaching its systems by exploiting a zero-day vulnerability in an Oracle PeopleSoft server. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input
Microsoft has found a malicious Chrome extension that posed as the AI search engine Perplexity and quietly logged what people searched for. It routed every query and every character typed into the address bar through an attacker-controlled server before redirecting users to real
#חדשות#The Hacker News
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
WhatsApp rolls out usernames to help users hide their phone number
WhatsApp is finally allowing users to reserve usernames, a privacy feature that lets them hide their phone numbers from people not in their contact list. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
WhatsApp is Finally Getting Usernames to Help Keep Phone Numbers Private
WhatsApp on Monday officially announced the start of global reservations of usernames with an aim to protect the privacy of more than three billion users on the messaging platform. The optional feature is designed to help users connect with someone on the service through username
#חדשות#The Hacker News
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer
Cybersecurity researchers have uncovered two hijacked npm packages and a cluster of Go packages that are designed to deploy a Python-based information stealer on compromised Windows, Linux, and macOS hosts. "This attack avoids the most common npm execution paths through lifecycle
#חדשות#The Hacker News
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Data breach exposes up to 14.2 million email logins at six ISPs
Japanese telecommunications operator KDDI Corporation disclosed a data breach where threat actors gained access to one of its email systems used by five other internet service providers (ISPs) in the country. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Ukraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging Credentials
The Security Service of Ukraine (SSU) said it, together with the U.S. Federal Bureau of Investigation (FBI), uncovered a long-running campaign orchestrated by Russian intelligence services to break into the messaging accounts of government officials, military personnel, politicia
#חדשות#The Hacker News
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Clean GitHub repo tricks AI coding agents into running malware
An agentic coding tool tasked with cloning and setting up a seemingly benign GitHub repository could execute a malicious payload that remains invisible to security scanners, AI agents, and human reviewers. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
OpenAI Previews GPT-5.6 Sol With Restricted Access and Stronger Cyber Safeguards
OpenAI on Friday released three versions of GPT-5.6, called Sol, Terra, and Luna, as a limited preview to a small number of companies as part of an ongoing engagement with the U.S. government. While Sol is the latest flagship model and the most powerful, Terra strikes a balance b
#חדשות#The Hacker News
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
FBI: Russian hackers now target Signal backup recovery keys
The FBI and CISA are warning that a phishing campaign targeting Signal users tied to Russian intelligence services has evolved to steal Signal Backup Recovery Keys, allowing attackers to access victims' historical messages. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
CISA sets urgent deadline to fix Cisco flaw exploited in attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is giving federal agencies until Sunday to patch a vulnerability in Cisco Unified Communications Manager Server that is being actively exploited. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys
The FBI and CISA have updated their March warning about Russian intelligence phishing Signal accounts, and the operators have added a step: they now coax targets into handing over their Signal Backup Recovery Key. Hand it over once, and the attacker can restore the account's back
#חדשות#The Hacker News
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks
A newly discovered cyber attack campaign has been observed delivering a previously undocumented malware family called SharkLoader that acts as a loader for deploying Cobalt Strike Beacon on compromised hosts. Kaspersky, which is tracking the activity under the moniker StrikeShark
#חדשות#The Hacker News
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Polymarket customers lose $3 million in supply-chain attack
Polymarket says it will fully reimburse customers who lost an estimated $3 million after hackers injected a malicious script into the platform's frontend following a breach at a third-party vendor. [...]
#חדשות#BleepingComputer
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign
A Chinese-speaking advanced persistent threat (APT) actor has been linked to a new custom backdoor called TinyRCT as part of cyber attacks aimed at government entities and critical infrastructure in Southeast Asia. The activity, particularly aimed at state-owned enterprises in th
#חדשות#The Hacker News
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Scattered Spider Hackers Plead Guilty on Day 1 of Trial
Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The duo were key members of a prolific cyber
#חדשות#Krebs on Security
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded t
#חדשות#Krebs on Security
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
ShinyHunters ניצלו חולשה ב-Oracle PeopleSoft — אוניברסיטאות נפגעו במיוחד
קבוצת הסחיטה ShinyHunters ניצלה חולשה לא-מתוקנת ב-Oracle PeopleSoft כדי לחדור לארגונים ולגנוב מידע. הפעילות תוארכה ל-27 במאי עד 9 ביוני 2026, כשמוסדות אקדמיים ספגו את עיקר הפגיעה.
💼 למי שעובד במקצוע
צוותי IT: מערכות ERP/HR (כמו PeopleSoft) מחזיקות מידע רגיש בכמות — תעדפו את התיקון שלהן ובדקו גישה חריגה. הפעילו את עדכוני האבטחה הרבעוניים של Oracle מיד עם פרסומם.
#ניתוח-אירוע#גניבת-מידע#oracle#אקטואלי
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
כ-30,000 חומות אש של Fortinet נמצאו חשופות לפריצה
חברת SOCRadar זיהתה כ-30,000 התקני חומת אש של Fortinet שחשופים לאינטרנט ומסכנים את הרשתות שמאחוריהם. תזכורת חדה: גם מכשירי ההגנה עצמם הם יעד.
💼 למי שעובד במקצוע
אדמיני רשת: אל תחשפו ממשקי ניהול של מכשירי אבטחה לאינטרנט. הגבילו גישה ל-VPN/IP מורשים, עדכנו firmware מיד, ובדקו את קטלוג ה-KEV של CISA למוצרי Fortinet.
#ניתוח-אירוע#חולשות#fortinet#רשתות#אקטואלי
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
חולשה קריטית ב-Palo Alto PAN-OS מנוצלת באופן פעיל (CVE-2026-0257)
Palo Alto Networks חשפה ניצול פעיל של CVE-2026-0257 — חולשת עקיפת-אימות ב-PAN-OS שמאפשרת גישה לא-מורשית לפורטלי GlobalProtect. CISA הוסיפה אותה לקטלוג ה-KEV.
💼 למי שעובד במקצוע
צוותי IT/אבטחה: אם אתם מריצים PAN-OS עם GlobalProtect — עדכנו מיד לגרסה המתוקנת ובדקו לוגים לגישה חריגה. עקבו אחרי קטלוג ה-KEV של CISA: חולשות שם מנוצלות בפועל ומחייבות תיקון בעדיפות עליונה.
#חדשות#CVE#PAN-OS#אקטואלי
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
CISA הוסיפה חולשה קריטית (CVSS 10) ב-Joomla JCE לקטלוג ה-KEV
CISA הוסיפה לקטלוג ה-Known Exploited Vulnerabilities חולשה בדרגת חומרה מקסימלית (CVE-2026-48907, CVSS 10.0) ברכיב Joomla Content Editor, שמאפשרת הרצת קוד שרירותי.
💼 למי שעובד במקצוע
מנהלי אתרים: עדכנו תוספי Joomla/CMS מיד — תוספים הם הווקטור הנפוץ ביותר לפריצת אתרים. עקבו אחרי קטלוג ה-KEV של CISA: חולשות שם מנוצלות בפועל ומחייבות תיקון בעדיפות עליונה.
#ניתוח-אירוע#CVE#joomla#KEV#אקטואלי
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
קמפיין פישינג בהתחזות לרשת Boots — כ-9 מיליון נמענים
קמפיין פישינג רחב-היקף התחזה לרשת הקמעונאות הבריטית Boots, והציע 'מתנות חינם' ותגמולים כדי לגנוב פרטים אישיים ופיננסיים. הוערך שכ-9 מיליון אנשים היו יעד.
💼 למי שעובד במקצוע
מודעות לעובדים/משתמשים: 'מתנה חינם' + דחיפות = נורה אדומה קלאסית. ארגונים: חזקו DMARC/SPF/DKIM כדי שיהיה קשה להתחזות למותג שלכם, ודווחו על דומיינים מתחזים לפלטפורמות.
#חדשות#פישינג#הונאה#אקטואלי
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
מיקרוסופט מתקנת חולשת Zero-Day ב-Defender (CVE-2026-50656, 'RoguePlanet')
מיקרוסופט הודיעה על תיקון לחולשת zero-day ב-Microsoft Defender (CVE-2026-50656, CVSS 7.8) שכונתה RoguePlanet — חולשת הסלמת הרשאות שמאפשרת לתוקף לקבל הרשאות גבוהות במערכת.
💼 למי שעובד במקצוע
צוותי IT: החילו את עדכון ה-Patch Tuesday מיד, גם על כלי אבטחה. הסלמת הרשאות היא 'מכפיל כוח' — היא הופכת דריסת רגל קטנה לשליטה מלאה, אז סגרו אותה מהר.
#ניתוח-אירוע#CVE#microsoft#zero-day#אקטואלי
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Europol שיבשה את שירות הלבנת-הקריפטו AudiA6 ששירת כנופיות כופרה
ב-12 ביוני 2026 שיבשה Europol את AudiA6, שירות להלבנת מטבעות קריפטו ששימש כנופיות כופרה ורשתות פשיעת-סייבר. צעד נוסף במאבק הגלובלי בתשתיות הפשיעה.
💼 למי שעובד במקצוע
מגינים: שיבוש תשתיות הלבנה מקשה על מודל הרווח של תוקפים, אבל לא מבטל את האיום. המשיכו בבסיס — גיבויים offline, MFA, ועדכונים. אל תסמכו על אכיפה שתעצור מתקפה שכבר בדרך אליכם.
#חדשות#אכיפה#כופרה#קריפטו
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
מגמה: התקפות פישינג מבוססות-AI נעשות משכנעות יותר
כלי בינה מלאכותית מאפשרים לתוקפים לכתוב מיילים נקיים משגיאות, מותאמים אישית, ואפילו לזייף קול. הסימנים הישנים (שגיאות כתיב) כבר לא מספיקים.
💼 למי שעובד במקצוע
צוותי אבטחה: עדכנו את הדרכות המודעות — 'חפשו שגיאות כתיב' כבר לא רלוונטי. התמקדו באימות זהות וערוץ-חוזר, והגבירו הגנות טכניות (DMARC, סינון, MFA עמיד-פישינג כמו FIDO2).
#חדשות#AI#פישינג#מגמות
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
Who Runs the Ransomware Group ‘The Gentlemen?’
A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of any ransom paid by victims. This post e
#חדשות#Krebs on Security
לכתבה המלאה →לפני 1 חודשים · צוות CyberHub
מגמה: עלייה במתקפות על שרשרת האספקה (Supply Chain)
במקום לתקוף מטרה חזקה ישירות, תוקפים פוגעים בספק קטן וחלש שדרכו מגיעים אליה. הבנת המגמה הזו חשובה לכל מי שמשתמש בקוד פתוח או בספקים חיצוניים.
💼 למי שעובד במקצוע
מפתחים: הצמידו גרסאות (lockfile), הריצו `npm audit`/Dependabot, ובדקו תלות לפני שדרוג. DevOps/SOC: החזיקו SBOM מעודכן כדי לדעת בדקות מי מושפע כשמתפרסמת חולשה ברכיב פופולרי.
#חדשות#שרשרת-אספקה#supply-chain#ניהול-סיכונים
לכתבה המלאה →לפני 2 חודשים · צוות CyberHub
למה אתם שומעים על CVE כל הזמן?
CVE הוא מספר זיהוי אחיד לכל חולשת אבטחה ידועה בעולם. הבנת השיטה עוזרת לכם לעקוב אחרי איומים רלוונטיים ולעדכן בזמן.
💼 למי שעובד במקצוע
מפתחים: חברו פיד CVE של הספריות שאתם משתמשים בהן ל-CI כדי לקבל התראה אוטומטית. צוותי IT/SOC: תעדפו תיקון לפי CVSS + האם יש exploit פעיל בשטח (KEV של CISA), לא רק לפי הציון.
#חדשות#CVE#ניהול-חולשות
לכתבה המלאה →לפני 2 חודשים · צוות CyberHub
ניתוח אירוע: Log4Shell — החולשה ששיתקה את האינטרנט (CVE-2021-44228)
בדצמבר 2021 התגלתה חולשה בספריית Log4j (Java) שאיפשרה הרצת קוד מרחוק בשורה אחת. כי הספרייה נמצאת בכל מקום — חצי האינטרנט היה פגיע בן-לילה.
💼 למי שעובד במקצוע
מפתחים/DevOps: החזיקו SBOM מעודכן כדי לדעת בדקות אם רכיב פגיע נמצא אצלכם. אל תתעדו קלט משתמש גולמי ללוג בלי סינון. צוותי הגנה: חסמו תעבורת LDAP/RMI יוצאת מהשרתים.
#ניתוח-אירוע#CVE#java#log4j#supply-chain
לכתבה המלאה →לפני 2 חודשים · צוות CyberHub
ניתוח אירוע: מתקפת SolarWinds — כשהעדכון עצמו היה הנשק
בשנת 2020 תוקפים מתוחכמים השתילו דלת אחורית בעדכון רשמי של תוכנת SolarWinds Orion. ~18,000 ארגונים התקינו את ה'עדכון' — כולל סוכנויות ממשל.
💼 למי שעובד במקצוע
צוותי הגנה: אמצו עקרונות Zero Trust — גם תוכנה 'מהימנה' צריכה להיות מנוטרת. נטרו התנהגות חריגה (יוצאת) של שרתים פנימיים, לא רק חתימות. חתימת קוד והקשחת צינור ה-CI/CD הם קריטיים.
#ניתוח-אירוע#supply-chain#apt#מתקדם
לכתבה המלאה →לפני 2 חודשים · צוות CyberHub
ניתוח אירוע: הדלת האחורית ב-XZ Utils (CVE-2024-3094) — איך כמעט נפרץ כל לינוקס
בשנת 2024 התגלתה דלת אחורית מתוחכמת שהושתלה בכלי דחיסה נפוץ בלינוקס (xz/liblzma). היא כמעט הגיעה לכל שרת לינוקס בעולם — ונתפסה כמעט במקרה.
💼 למי שעובד במקצוע
מתחזקי קוד פתוח: היזהרו מ'תורמים' שצוברים אמון לאורך זמן ואז דוחפים שינוי חשוד. בדקו commits של build-scripts ובינאריים בבדיקות, לא רק קוד מקור. ארגונים: עקבו אחרי גרסאות והימנעו מ-bleeding edge בפרודקשן.
#ניתוח-אירוע#open-source#supply-chain#מתקדם
לכתבה המלאה →