דלג לתוכן
← לכל המאמרים

מאמרים בנושא #BleepingComputer

113 מאמרים בתגית הזו.

📰 חדשות

Metabase SQLi zero-day exploited in customer data-theft attacks

A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. [...]

צוות CyberHub · לפני 14 שעות · 1 דק׳ קריאה

📰 חדשות

Unlimited Technology Systems breach impacts 3.8 million people

Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident that occurred in October 2025. [...]

צוות CyberHub · לפני 14 שעות · 1 דק׳ קריאה

📰 חדשות

Levi Strauss & Co. says hackers stole corporate data in cyberattack

Levi Strauss & Co. (Levi's) says that hackers used social engineering on three of its employees to gain access to and steal corporate data stored on their machines. [...]

צוות CyberHub · לפני 18 שעות · 1 דק׳ קריאה

📰 חדשות

OpenAI rolls out a major ChatGPT upgrade, even if you don’t pay for it

OpenAI is rolling out a more reliable version of ChatGPT GPT-5.6 Sol for Plus and Pro users, while Free users are getting unlimited text chats with GPT-5.6 Luna. [...]

צוות CyberHub · לפני 1 ימים · 1 דק׳ קריאה

📰 חדשות

ClickFix attack pushes macOS infostealer for crypto theft attacks

A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials. [...]

צוות CyberHub · לפני 1 ימים · 1 דק׳ קריאה

📰 חדשות

Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group

A recent wave of cyberattacks targeting hedge funds, private-equity firms, and other financial organizations has been linked to UNC6671, an extortion group reportedly associated with the BlackFile threat actors. [...]

צוות CyberHub · לפני 1 ימים · 1 דק׳ קריאה

📰 חדשות

Ransom Cartel ransomware creator sentenced to 16 years in prison

Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for his role in ransomware attacks against at least 18 companies worldwide. [...]

צוות CyberHub · לפני 2 ימים · 1 דק׳ קריאה

📰 חדשות

Canadian pleads guilty to Snowflake cloud data-theft attacks

A Canadian man pleaded guilty today to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims. [...]

צוות CyberHub · לפני 2 ימים · 1 דק׳ קריאה

📰 חדשות

Hackers run khunt post-exploitation toolkit from Oracle database

Hackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database that was used to breach a corporate network. [...]

צוות CyberHub · לפני 2 ימים · 1 דק׳ קריאה

📰 חדשות

OpenAI, Anthropic AI agents targeted real people and systems in cyber tests

OpenAI and Anthropic have confirmed that their AI models were involved in separate, newly disclosed third-party cybersecurity testing incidents that resulted in a real website being breached and social engineering attacks against people outside the intended testing boundaries. [.

צוות CyberHub · לפני 3 ימים · 1 דק׳ קריאה

📰 חדשות

TP-Link patches Omada ZTP flaws allowing hackers to breach networks

TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could be chained with previously disclosed flaws to achieve remote code execution (RCE). [...]

צוות CyberHub · לפני 3 ימים · 1 דק׳ קריאה

📰 חדשות

Phishing service spoofs RingCentral to steal Microsoft 365 accounts

The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing targeting Microsoft 365 accounts. [...]

צוות CyberHub · לפני 3 ימים · 1 דק׳ קריאה

📰 חדשות

Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts

Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. [...]

צוות CyberHub · לפני 4 ימים · 1 דק׳ קריאה

📰 חדשות

New Pass-ta-key attacks let malware hijack Google-synced passkeys

Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager's synced passkeys to take over accounts, bypass user verification, and extract passkey private keys. [...]

צוות CyberHub · לפני 4 ימים · 1 דק׳ קריאה

📰 חדשות

New DOUBLECUP ClickFix service hides malware in browser cache images

A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems. [...]

צוות CyberHub · לפני 4 ימים · 1 דק׳ קריאה

📰 חדשות

OpenAI teases Astra, its next major AI model, after it solves 10 long-standing math problems

OpenAI has revealed Astra, an unreleased model designed to tackle complex, long-running tasks, after an internal version produced ten significant advances in mathematics and theoretical computer science. [...]

צוות CyberHub · לפני 5 ימים · 1 דק׳ קריאה

📰 חדשות

COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft

A vulnerability in COLDCARD hardware wallet firmware allowed attackers to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose seeds were generated using a flawed random number generator. [...]

צוות CyberHub · לפני 5 ימים · 1 דק׳ קריאה

📰 חדשות

Google Chrome may soon block New Tab hijacker extensions by default

Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing the default search engine. [...]

צוות CyberHub · לפני 5 ימים · 1 דק׳ קריאה

📰 חדשות

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

צוות CyberHub · לפני 6 ימים · 1 דק׳ קריאה

📰 חדשות

Amgen says cloud data breach exposed patient health, proprietary info

Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers. [...]

צוות CyberHub · לפני 7 ימים · 1 דק׳ קריאה

📰 חדשות

Arch Linux disables AUR package adoption to stop malware flood

The Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of existing packages. [...]

צוות CyberHub · לפני 7 ימים · 1 דק׳ קריאה

📰 חדשות

Online ad firm Adform’s script compromised to steal cryptocurrency

Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors' clipboards with ones controlled by an attacker. [...]

צוות CyberHub · לפני 7 ימים · 1 דק׳ קריאה

📰 חדשות

Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests

One of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies. [...]

צוות CyberHub · לפני 8 ימים · 1 דק׳ קריאה

📰 חדשות

South Korea fines telco giant KT $39 million for customer data breach

South Korea's Personal Information Protection Commission (PIPC) has fined telecommunications giant KT Corporation KRW 53.979 billion ($39 million) over data protection violations. [...]

צוות CyberHub · לפני 8 ימים · 1 דק׳ קריאה

📰 חדשות

JetBrains warns of critical TeamCity remote code execution flaw

JetBrains is warning of a critical authentication bypass vulnerability affecting TeamCity On-Premises that could be exploited to achieve remote code execution. [...]

צוות CyberHub · לפני 8 ימים · 1 דק׳ קריאה

📰 חדשות

Russian hackers exploit Exchange OWA zero-day for long-term mailbox access

The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated backdoor called OWAReaper. [...]

צוות CyberHub · לפני 9 ימים · 1 דק׳ קריאה

📰 חדשות

Anthropic confirms Claude is down worldwide

Claude is down for some users, with Anthropic confirming elevated errors across multiple AI models. The disruption is causing requests to fail with a "529 Overloaded" message, including in Claude and tools that rely on its API. [...]

צוות CyberHub · לפני 9 ימים · 1 דק׳ קריאה

📰 חדשות

Cisco warns of FMC static credential flaw exploited in zero-day attacks

Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices. [...]

צוות CyberHub · לפני 9 ימים · 1 דק׳ קריאה

📰 חדשות

CubePilot drone software dev hit by DNS hijacking to intercept traffic

CubePilot, an Australian firm that designs flight controllers for drones (UAVs), announced a severe operational disruption caused by a DNS hijacking attack. [...]

צוות CyberHub · לפני 10 ימים · 1 דק׳ קריאה

📰 חדשות

OpenAI models used Artifactory zero-days to escape to the internet

JFrog has confirmed that OpenAI models exploited zero-day vulnerabilities in self-hosted Artifactory servers to help escape an isolated testing environment and gain access to the internet before attacking Hugging Face. [...]

צוות CyberHub · לפני 10 ימים · 1 דק׳ קריאה

📰 חדשות

CISA shares advice on isolating vital systems during cyberattacks

The U.S. and Australian governments have released new guidance urging critical infrastructure organizations to prepare to isolate vital operational technology systems in the event of a cyberattack or other major disruptions. [...]

צוות CyberHub · לפני 10 ימים · 1 דק׳ קריאה

📰 חדשות

Hackers target US firms in FastJson RCE zero-day attacks

Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. [...]

צוות CyberHub · לפני 11 ימים · 1 דק׳ קריאה

📰 חדשות

Arista patches VeloCloud Orchestrator zero-day exploited in attacks

Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks. [...]

צוות CyberHub · לפני 11 ימים · 1 דק׳ קריאה

📰 חדשות

New Dysphoria DDoS botnet spreads to 200k devices worldwide

A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations. [...]

צוות CyberHub · לפני 11 ימים · 1 דק׳ קריאה

📰 חדשות

GitHub, PyPI add time-based defenses against supply chain attacks

GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact. [...]

צוות CyberHub · לפני 12 ימים · 1 דק׳ קריאה

📰 חדשות

Steam forum ClickFix attacks infect gamers with XMRig cryptominers

Steam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game and computer problems but actually infect devices with cryptominers. [...]

צוות CyberHub · לפני 13 ימים · 1 דק׳ קריאה

📰 חדשות

Malicious sites use JavaScript to build malware in browser memory

A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory. [...]

צוות CyberHub · לפני 13 ימים · 1 דק׳ קריאה

📰 חדשות

ShinyHunters data leaks fuel $2,000 sextortion email scam

Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin. [...]

צוות CyberHub · לפני 13 ימים · 1 דק׳ קריאה

📰 חדשות

OnTrac notifies customers of data breach after network hack

OnTrac parcel delivery company is informing that hackers breached its corporate network and may have accessed personal details belonging to its customers. [...]

צוות CyberHub · לפני 14 ימים · 1 דק׳ קריאה

📰 חדשות

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

צוות CyberHub · לפני 14 ימים · 1 דק׳ קריאה

📰 חדשות

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

צוות CyberHub · לפני 14 ימים · 1 דק׳ קריאה

📰 חדשות

New Dolphin X malware uses AI to rank high-value targets

A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first. [...]

צוות CyberHub · לפני 15 ימים · 1 דק׳ קריאה

📰 חדשות

Australian energy provider Origin says data breach exposes client data

Origin Energy has confirmed that an unauthorized party accessed and subsequently leaked customer data online, exposing sensitive personally identifiable information (PII), among others. [...]

צוות CyberHub · לפני 15 ימים · 1 דק׳ קריאה

📰 חדשות

Fake Claude app promoted by Bing ads pushes SectopRAT malware

A malvertising campaign on the Bing search service is pushing a fake Claude desktop app installer hosted on a legitimate Claude.ai domain to deliver the SectopRAT malware. [...]

צוות CyberHub · לפני 15 ימים · 1 דק׳ קריאה

📰 חדשות

Upbound says hack caused $13 million in fraudulent Acima leases

The Upbound Group fintech company disclosed that threat actors who stole data from its systems leveraged it to create $13 million in Acima leases. [...]

צוות CyberHub · לפני 16 ימים · 1 דק׳ קריאה

📰 חדשות

South Korea discloses data breach impacting diplomats worldwide

South Korea disclosed that hackers breached the National Diplomatic Academy's online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), including overseas diplomats. [...]

צוות CyberHub · לפני 16 ימים · 1 דק׳ קריאה

📰 חדשות

Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack

Swiss rail vehicle manufacturer Stadler Rail says the Everest ransomware gang demanded about $12.3 million after breaching a data exchange platform shared with one of its suppliers. [...]

צוות CyberHub · לפני 16 ימים · 1 דק׳ קריאה

📰 חדשות

Chick-fil-A discloses data breach after credential stuffing attacks

American fast food restaurant chain Chick-fil-A is notifying customers of a data breach after their accounts were hacked in a wave of recent credential stuffing attacks. [...]

צוות CyberHub · לפני 17 ימים · 1 דק׳ קריאה

📰 חדשות

OpenAI says its AI models hacked Hugging Face during testing

OpenAI says its AI models, including GPT‑5.6 Sol and a pre-release model, hacked into the Hugging Face artificial intelligence repository while being tested in a sandboxed testing environment. [...]

צוות CyberHub · לפני 17 ימים · 1 דק׳ קריאה

📰 חדשות

Police dismantle Kratos phishing platform, arrest developer

Authorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its developer was arrested in Indonesia. [...]

צוות CyberHub · לפני 17 ימים · 1 דק׳ קריאה

📰 חדשות

Estée Lauder discloses data breach via Oracle E-Business flaw

Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. [...]

צוות CyberHub · לפני 18 ימים · 1 דק׳ קריאה

📰 חדשות

SonicWall SMA1000 flaws exploited as zero-days to push custom malware

Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances. [...]

צוות CyberHub · לפני 18 ימים · 1 דק׳ קריאה

📰 חדשות

Hackers steal $23.7 million in crypto from Ostium in off-chain attack

The Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week, after compromising off-chain infrastructure used to feed prices into the protocol. [...]

צוות CyberHub · לפני 18 ימים · 1 דק׳ קריאה

📰 חדשות

Hackers abuse ViPNet software to target Russian govt agencies

An advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies. [...]

צוות CyberHub · לפני 19 ימים · 1 דק׳ קריאה

📰 חדשות

Update now: 7-Zip fixes RCE flaw exploitable with malicious archives

7-Zip version 26.02 was released to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files. [...]

צוות CyberHub · לפני 20 ימים · 1 דק׳ קריאה

📰 חדשות

WordPress Core "wp2shell" RCE flaws get public exploits, patch now

Public exploits have been released for the critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately. [...]

צוות CyberHub · לפני 20 ימים · 1 דק׳ קריאה

📰 חדשות

Microsoft warns of surge in ACR Stealer attacks on customers

Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers. [...]

צוות CyberHub · לפני 20 ימים · 1 דק׳ קריאה

📰 חדשות

Abbott probes two cyber incidents amid extortion claims

Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that attackers breached its LabCentral portal and

צוות CyberHub · לפני 21 ימים · 1 דק׳ קריאה

📰 חדשות

HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload

A vulnerability dubbed HollowByte allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers with a malicious payload of just 11 bytes. [...]

צוות CyberHub · לפני 21 ימים · 1 דק׳ קריאה

📰 חדשות

Ernst & Young discloses data breach after support system hack

Ernst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel. [...]

צוות CyberHub · לפני 21 ימים · 1 דק׳ קריאה

📰 חדשות

New ClickLock macOS malware traps users into revealing login password

A new macOS information-stealing malware dubbed ClickLock terminates all visible processes to force users into entering their system login password. [...]

צוות CyberHub · לפני 22 ימים · 1 דק׳ קריאה

📰 חדשות

Coca-Cola says Fairlife ransomware attack halts US dairy production

The Coca-Cola Company disclosed today that a ransomware attack impacting its Fairlife dairy subsidiary has disrupted operations, temporarily suspending production of Fairlife products across the United States. [...]

צוות CyberHub · לפני 22 ימים · 1 דק׳ קריאה

📰 חדשות

Claude Chrome extension flaw lets malicious extensions trigger AI actions

A flaw in Anthropic's Claude for Chrome browser extension could allow a malicious extension to trigger predefined AI actions by simulating user clicks, potentially allowing it to abuse Claude's access to connected services such as Gmail, Google Docs, Google Calendar, and Salesfor

צוות CyberHub · לפני 22 ימים · 1 דק׳ קריאה

📰 חדשות

Dutch police bust investment fraud ring stealing over €100 million

The Dutch Police announced the arrest of multiple individuals suspected of being part of an international investment fraud scheme estimated to have tens of thousands of victims. [...]

צוות CyberHub · לפני 23 ימים · 1 דק׳ קריאה

📰 חדשות

Zoom warns of critical account takeover vulnerability

Zoom is warning of a critical vulnerability in its desktop client and software development kit for Windows that could be exploited by an unauthenticated party to hijack accounts. [...]

צוות CyberHub · לפני 23 ימים · 1 דק׳ קריאה

📰 חדשות

Google Gemini CLI abused as a hacking agent, malware botnet operator

A Russian-speaking threat actor known as "bandcampro" used Google's open-source Gemini CLI AI tool as a hacking agent and to operate a small-scale botnet. [...]

צוות CyberHub · לפני 23 ימים · 1 דק׳ קריאה

📰 חדשות

SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now

SonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day attacks and urges customers to install the newly released security updates. [...]

צוות CyberHub · לפני 24 ימים · 1 דק׳ קריאה

📰 חדשות

Spanish Police take down €140 million cyber fraud ring, arrest four

The Spanish Police dismantled a cybercrime and money-laundering organization that made €140 million ($160 million) from investment fraud and business email compromise (BEC) attacks. [...]

צוות CyberHub · לפני 24 ימים · 1 דק׳ קריאה

📰 חדשות

Nearly 300 GitHub repos pose as legit software to push malware

A threat actor has published hundreds of fake GitHub repositories impersonating legitimate software and security projects to distribute infostealer malware. [...]

צוות CyberHub · לפני 24 ימים · 1 דק׳ קריאה

📰 חדשות

Japan's largest taxi operator shuts systems after cyberattack

Japan's largest taxi operator, Nihon Kotsu, announced that its systems were compromised in a cyberattack, forcing the company to shut down part of its infrastructure. [...]

צוות CyberHub · לפני 25 ימים · 1 דק׳ קריאה

📰 חדשות

Hackers backdoor Jscrambler npm package with infostealer malware

The Jscrambler client-side web security company disclosed that a threat actor published a malicious version of its npm package that has been downloaded almost 1,500 times. [...]

צוות CyberHub · לפני 25 ימים · 1 דק׳ קריאה

📰 חדשות

New CrashStealer malware poses as Apple crash reporting tool

A new macOS information-stealing malware called CrashStealer pretends to be Apple's crash-reporting tool to steal credentials, keychain data, and crypto wallets. [...]

צוות CyberHub · לפני 25 ימים · 1 דק׳ קריאה

📰 חדשות

OpenAI temporarily relaxes GPT-5.6 Sol usage limits

OpenAI is temporarily relaxing GPT-5.6 Sol usage after demand for the company's most powerful model surged over the past 48 hours. [...]

צוות CyberHub · לפני 26 ימים · 1 דק׳ קריאה

📰 חדשות

Claude Fable 5 stays free for paid users until July 19 as Anthropic buys more time

Anthropic has just extended access to Claude Fable 5 for paid subscribers until July 19, giving you another week to keep using the most powerful model. [...]

צוות CyberHub · לפני 26 ימים · 1 דק׳ קריאה

📰 חדשות

RedHook Android malware now uses Wireless ADB for shell access

A new version of the RedHook Android malware abuses the Android Wireless Debugging (Wireless ADB) mechanism in a novel way to gain shell-level privileges without requiring a computer connection. [...]

צוות CyberHub · לפני 26 ימים · 1 דק׳ קריאה

📰 חדשות

Australia warns of global campaign targeting vulnerable CMS platforms

The Australian Cyber Security Centre (ACSC) issued an alert about a global exploitation campaign targeting vulnerable content management systems (CMS) and plugins. [...]

צוות CyberHub · לפני 27 ימים · 1 דק׳ קריאה

📰 חדשות

'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets

A PNG hiding a prompt injection could steal your repo's secrets, researchers demonstrate. The technique, dubbed 'Ghostcommit,' slipped past AI code reviewers CodeRabbit and Bugbot, which never open image files at all, then convinced a coding agent to read a repo's .env and write

צוות CyberHub · לפני 28 ימים · 1 דק׳ קריאה

📰 חדשות

New U-Boot flaws could enable stealthy firmware attacks

Six vulnerabilities in the widely used U-Boot bootloader have been discovered that could allow attackers to execute malicious code during device boot, potentially enabling stealthy firmware attacks that compromise security protections and install persistent malware. [...]

צוות CyberHub · לפני 28 ימים · 1 דק׳ קריאה

📰 חדשות

Ryuk ransomware member pleads guilty in the US, faces 15 years in prison

A 34-year-old Armenian man has pleaded guilty to hacking U.S. companies and deploying the infamous Ryuk ransomware to encrypt their systems. [...]

צוות CyberHub · לפני 28 ימים · 1 דק׳ קריאה

📰 חדשות

Police suspects Dutch hackers were involved in Odido breach

The Dutch National Police (Politie) says it has found "strong indications" that Dutch hackers have been involved in a February breach at the telecommunications provider Odido. [...]

צוות CyberHub · לפני 28 ימים · 1 דק׳ קריאה

📰 חדשות

OpenMandriva Linux says contributor tried to sabotage the project

The OpenMandriva Linux project announced that it was the target of an attempted act of internal sabotage after a dispute among contributors. [...]

צוות CyberHub · לפני 29 ימים · 1 דק׳ קריאה

📰 חדשות

Injective SDK on npm infected with cryptocurrency wallet stealer

Hackers compromised the Injective Labs SDK project's GitHub repository and used it to publish a malicious package on the Node Package Manager (npm) that stole cryptocurrency wallet private keys and mnemonic seed phrases. [...]

צוות CyberHub · לפני 29 ימים · 1 דק׳ קריאה

📰 חדשות

New Helix vishing group emerges in SharePoint data theft attacks

A new data-extortion group called Helix is using identity-focused tactics such as voice phishing (vishing), device code phishing, and multi-factor authentication (MFA) abuse to steal data from SharePoint environments. [...]

צוות CyberHub · לפני 29 ימים · 1 דק׳ קריאה

📰 חדשות

Microsoft patches RoguePlanet Defender zero-day vulnerability

Microsoft has released a security patch to address a Defender zero-day vulnerability known as "RoguePlanet," disclosed after the June 2026 Patch Tuesday. [...]

צוות CyberHub · לפני 1 חודשים · 1 דק׳ קריאה

📰 חדשות

Mount Royal University confirms breach as hackers claim attack

Mount Royal University in Calgary says hackers stole and then deleted data from its file storage systems after breaching the university's network. [...]

צוות CyberHub · לפני 1 חודשים · 1 דק׳ קריאה

📰 חדשות

Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials

Malicious packages on the Node Package Manager (npm) and the Python Package Index (PyPI) delivered stealer malware to developers and users of Paysafe, Skrill, and Neteller payment applications. [...]

צוות CyberHub · לפני 1 חודשים · 1 דק׳ קריאה

📰 חדשות

Accenture confirms breach after hacker offers stolen data for sale

IT services giant Accenture has confirmed it suffered a security breach after a threat actor claimed to have stolen 35 GB of source code and other data from the company. [...]

צוות CyberHub · לפני 1 חודשים · 1 דק׳ קריאה

📰 חדשות

Chinese hackers develop LONGLEASH malware to expand ORB network

Chinese hackers tracked as 'UAT-7810' are actively evolving their malware to expand their Operational Relay Box (ORB) network by compromising internet-facing networking devices, primarily unpatched Ruckus routers. [...]

צוות CyberHub · לפני 1 חודשים · 1 דק׳ קריאה

📰 חדשות

Hidden backdoor in Tenda router firmware grants admin access

A hidden authentication backdoor has been found in multiple Tenda router firmware versions, potentially allowing an attacker to gain administrative access to the device's web management panel. [...]

צוות CyberHub · לפני 1 חודשים · 1 דק׳ קריאה

📰 חדשות

Phishing poses as big-brand job interview to steal Google accounts

A phishing campaign is impersonating more than 30 well-known brands, including Adobe, Netflix, Coca-Cola, and OpenAI, in fake job interviews to steal Google account credentials from marketing professionals. [...]

צוות CyberHub · לפני 1 חודשים · 1 דק׳ קריאה

📰 חדשות

Fake IT support calls on Microsoft Teams push EtherRAT malware

Threat actors are abusing Microsoft Teams voice calls by impersonating corporate IT support staff to trick employees into installing the EtherRAT malware, giving attackers initial access to corporate networks. [...]

צוות CyberHub · לפני 1 חודשים · 1 דק׳ קריאה

📰 חדשות

Vietnam arrests suspects behind HiAnime anime piracy service

​Vietnamese authorities have arrested and are prosecuting seven suspects believed to have run HiAnime, the largest anime piracy streaming service before its shutdown in June. [...]

צוות CyberHub · לפני 1 חודשים · 1 דק׳ קריאה

📰 חדשות

Flipper Zero firmware development continues with community help

Flipper Devices says development of the Flipper Zero firmware will continue, albeit with a smaller internal team and greater reliance on community contributions. [...]

צוות CyberHub · לפני 1 חודשים · 1 דק׳ קריאה

📰 חדשות

JadePuffer ransomware used AI agent to automate entire attack

Researchers identified what they believe is the first documented case of a ransomware operation, JadePuffer, conducted entirely by a large language model (LLM) agent. [...]

צוות CyberHub · לפני 1 חודשים · 1 דק׳ קריאה

📰 חדשות

NetNut proxy network disrupted, 2 million infected devices cut off

A joint operation involving Google has disrupted NetNut, a residential proxy network that gave access to millions of compromised Android devices, including smart TVs and streaming boxes. [...]

צוות CyberHub · לפני 1 חודשים · 1 דק׳ קריאה

📰 חדשות

ARToken PhaaS exposes EvilTokens' Microsoft 365 phishing toolkit

A new phishing-as-a-service (PhaaS) platform dubbed "ARToken" appears to operate as an affiliate of the EvilTokens phishing platform, giving researchers a glimpse into an extensive toolkit designed to compromise Microsoft 365. [...]

צוות CyberHub · לפני 1 חודשים · 1 דק׳ קריאה

📰 חדשות

Claude Fable 5 isn’t permanently leaving subscriptions, Anthropic says

Anthropic says Claude Fable 5 won't be accessible via Claude subscriptions after July 7, but it's not a permanent change, and the company expects the model to return outside the usage-based plan soon. [...]

צוות CyberHub · לפני 1 חודשים · 1 דק׳ קריאה

📰 חדשות

Claude Fable relaunch disappoints users with nerfed performance

Claude Fable, the company's most powerful model, is now available to all users, but early impressions are disappointing, as it appears to be nowhere near the original release. [...]

צוות CyberHub · לפני 1 חודשים · 1 דק׳ קריאה

📰 חדשות

Google loses final appeal to overturn €4.1 billion EU fine

Court of Justice of the European Union (CJEU) has dismissed Google's final appeal against a €4.1 billion ($4.7 billion) antitrust fine over the company's use of Android to promote its Chrome browser and search service. [...]

צוות CyberHub · לפני 1 חודשים · 1 דק׳ קריאה

📰 חדשות

Medtronic notifies customers impacted by ShinyHunters data breach

Healthcare device firm Medtronic is notifying affected customers about a data breach that exposed their personal data to an unauthorized third party. [...]

צוות CyberHub · לפני 1 חודשים · 1 דק׳ קריאה

📰 חדשות

FortiBleed credential-theft campaign linked to Lynx ransomware

The massive FortiBleed credential theft campaign has been linked to the INC and Lynx ransomware operations, suggesting the stolen Fortinet credentials were intended to fuel future network intrusions. [...]

צוות CyberHub · לפני 1 חודשים · 1 דק׳ קריאה

📰 חדשות

Kubota says hackers had month-long access to network systems

Kubota North America Corporation disclosed that hackers had access to some of its network systems for more than a month earlier this year. [...]

צוות CyberHub · לפני 1 חודשים · 1 דק׳ קריאה

📰 חדשות

Anthropic to restore Claude Fable access on Wednesday

Anthropic has confirmed that the Department of Commerce has lifted export controls on Claude's two most powerful models, Fable 5 and Mythos 5. [...]

צוות CyberHub · לפני 1 חודשים · 1 דק׳ קריאה

📰 חדשות

Anthropic rolls out Sonnet 5 with near-Opus 4.8 performance at a lower price

Anthropic is now rolling out Sonnet 5, and it's almost as good as the Opus range, but it is designed to be cheaper than the company's flagship model. [...]

צוות CyberHub · לפני 1 חודשים · 1 דק׳ קריאה

📰 חדשות

New BioShocking attack manipulates AI browser into data theft

A new prompt injection attack dubbed "BioShocking" could trick AI-powered browsers into treating real-world risky actions as part of a fictional scenario, causing them to ignore any safety guardrails. [...]

צוות CyberHub · לפני 1 חודשים · 1 דק׳ קריאה

📰 חדשות

Nissan discloses employee data breach linked to Oracle zero-day attacks

Nissan is warning that it suffered a data breach affecting current and former employees after threat actors exploited an Oracle PeopleSoft vulnerability in data theft attacks previously linked to the ShinyHunters extortion group. [...]

צוות CyberHub · לפני 1 חודשים · 1 דק׳ קריאה

📰 חדשות

NAIC says public data stolen in ShinyHunters' PeopleSoft breach

The National Association of Insurance Commissioners (NAIC) says the ShinyHunters extortion group stole only publicly available data, outdated logs, and configuration files after breaching its systems by exploiting a zero-day vulnerability in an Oracle PeopleSoft server. [...]

צוות CyberHub · לפני 1 חודשים · 1 דק׳ קריאה

📰 חדשות

WhatsApp rolls out usernames to help users hide their phone number

WhatsApp is finally allowing users to reserve usernames, a privacy feature that lets them hide their phone numbers from people not in their contact list. [...]

צוות CyberHub · לפני 1 חודשים · 1 דק׳ קריאה

📰 חדשות

Data breach exposes up to 14.2 million email logins at six ISPs

Japanese telecommunications operator KDDI Corporation disclosed a data breach where threat actors gained access to one of its email systems used by five other internet service providers (ISPs) in the country. [...]

צוות CyberHub · לפני 1 חודשים · 1 דק׳ קריאה

📰 חדשות

Clean GitHub repo tricks AI coding agents into running malware

An agentic coding tool tasked with cloning and setting up a seemingly benign GitHub repository could execute a malicious payload that remains invisible to security scanners, AI agents, and human reviewers. [...]

צוות CyberHub · לפני 1 חודשים · 1 דק׳ קריאה

📰 חדשות

FBI: Russian hackers now target Signal backup recovery keys

The FBI and CISA are warning that a phishing campaign targeting Signal users tied to Russian intelligence services has evolved to steal Signal Backup Recovery Keys, allowing attackers to access victims' historical messages. [...]

צוות CyberHub · לפני 1 חודשים · 1 דק׳ קריאה

📰 חדשות

CISA sets urgent deadline to fix Cisco flaw exploited in attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is giving federal agencies until Sunday to patch a vulnerability in Cisco Unified Communications Manager Server that is being actively exploited. [...]

צוות CyberHub · לפני 1 חודשים · 1 דק׳ קריאה

📰 חדשות

Polymarket customers lose $3 million in supply-chain attack

Polymarket says it will fully reimburse customers who lost an estimated $3 million after hackers injected a malicious script into the platform's frontend following a breach at a third-party vendor. [...]

צוות CyberHub · לפני 1 חודשים · 1 דק׳ קריאה