🌍 Live Cyber News
The latest threats, breaches and vulnerabilities — tagged with where they happened, so you can see what's relevant to you. Updated every 30 minutes.
Where it happened
Country-level only. Locations are taken from the headline when it states one; stories without a stated location are listed as "Location not reported" and not mapped.
Today's Top 5
-
Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
📍 Location not reported
-
SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
📍 Location not reported
-
Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
📍 Location not reported
-
Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
📍 Location not reported
-
Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
📍 Location not reported
50 stories
-
Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
📍 Location not reported
-
Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
📍 Location not reported
-
Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
📍 Location not reported
-
Zero Trust for AI Agents Starts With Fixing Zero Visibility
📍 Location not reported
-
Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
📍 Location not reported
-
SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
📍 Location not reported
-
Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack
📍 Location not reported
-
Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware
📍 Location not reported
-
PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
📍 Location not reported
-
The SOC Doesn't Need to Start Over with Every Alert
📍 Location not reported
-
Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise
📍 Location not reported
-
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
📍 Location not reported
-
Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data
📍 Location not reported
-
WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
📍 Location not reported
-
Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions
📍 Location not reported
-
ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories
📍 Location not reported
-
Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content
📍 Location not reported
-
Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer
📍 🇺🇦 Ukraine
-
Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls
📍 Location not reported
-
Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore
📍 Location not reported
-
17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360
📍 Location not reported
-
OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files
📍 🇦🇺 Australia
-
TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords
📍 Location not reported
-
Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure
📍 Location not reported
-
Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
📍 Location not reported
-
A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You
📍 Location not reported
-
MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
📍 Location not reported
-
This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move
📍 Location not reported
-
Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
📍 Location not reported
-
New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control
📍 Location not reported
-
545 Hackers Tested It First. Now XRanges for AI Scores Your Security Agent
📍 Location not reported
-
Anthropic and OpenAI Models Still Attempt Restricted Actions in Safety Tests
📍 Location not reported
-
Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape
📍 Location not reported
-
F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
📍 Location not reported
-
Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
📍 Location not reported
-
Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input
📍 Location not reported
-
ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
📍 Location not reported
-
Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks
📍 Location not reported
-
WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers
📍 Location not reported
-
Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials
📍 Location not reported
-
Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
📍 Location not reported
-
Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
📍 Location not reported
-
Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates
📍 Location not reported
-
AI Agents Are Rewriting the Rules of Lateral Movement
📍 Location not reported
-
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
📍 Location not reported
-
DORA Year Two: Can Your SOC Actually See the Attack?
📍 Location not reported
-
New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory
📍 Location not reported
-
SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE
📍 Location not reported
-
Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal
📍 Location not reported
-
SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing
📍 🇮🇳 India
No stories match these filters.
Source: The Hacker News (thehackernews.com). We show headlines only, with our own classification, and link to the original article. Last updated (cached).