Veeam Patches Critical RCE Vulnerability with CVSS 9.0 in Backup & Replication
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 07/01/2026 10:41
Veeam has released security updates to address multiple flaws in its Backup & Replication software, including a "critical" issue that could result in remote code execution (RCE). The vulnerability, tracked as CVE-2025-59470, carries a CVSS score of...
Lire l'article →
Microsoft Warns Misconfigured Email Routing Can Enable Internal Domain Phishing
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 07/01/2026 09:42
Threat actors engaging in phishing attacks are exploiting routing scenarios and misconfigured spoof protections to impersonate organizations' domains and distribute emails that appear as if they have been sent internally. "Threat actors have...
Lire l'article →
Ongoing Attacks Exploiting Critical RCE Vulnerability in Legacy D-Link DSL Routers
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 07/01/2026 04:31
A newly discovered critical security flaw in legacy D-Link DSL gateway routers has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-0625 (CVSS score: 9.3), concerns a case of command injection in the "dnscfg.cgi"...
Lire l'article →
Two Chrome Extensions Caught Stealing ChatGPT and DeepSeek Chats from 900,000 Users
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 06/01/2026 17:21
Cybersecurity researchers have discovered two new malicious extensions on the Chrome Web Store that are designed to exfiltrate OpenAI ChatGPT and DeepSeek conversations alongside browsing data to servers under the attackers' control. The names of...
Lire l'article →
Unpatched Firmware Flaw Exposes TOTOLINK EX200 to Full Remote Device Takeover
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 06/01/2026 15:47
The CERT Coordination Center (CERT/CC) has disclosed details of an unpatched security flaw impacting TOTOLINK EX200 wireless range extender that could allow a remote authenticated attacker to gain full control of the device. The flaw, CVE-2025-65606...
Lire l'article →
Fake Booking Emails Redirect Hotel Staff to Fake BSoD Pages Delivering DCRat
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 06/01/2026 12:13
Source: Securonix Cybersecurity researchers have disclosed details of a new campaign dubbed PHALT#BLYX that has leveraged ClickFix-style lures to display fixes for fake blue screen of death (BSoD) errors in attacks targeting the European hospitality...
Lire l'article →
What is Identity Dark Matter?
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 06/01/2026 11:30
The Invisible Half of the Identity Universe Identity used to live in one place - an LDAP directory, an HR system, a single IAM portal. Not anymore. Today, identity is fragmented across SaaS, on-prem, IaaS, PaaS, home-grown, and shadow applications....
Lire l'article →
VS Code Forks Recommend Missing Extensions, Creating Supply Chain Risk in Open VSX
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 06/01/2026 11:25
Popular artificial intelligence (AI)-powered Microsoft Visual Studio Code (VS Code) forks such as Cursor, Windsurf, Google Antigravity, and Trae have been found to recommend extensions that are non-existent in the Open VSX registry, potentially...
Lire l'article →
New n8n Vulnerability (9.9 CVSS) Lets Authenticated Users Execute System Commands
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 06/01/2026 05:08
A new critical security vulnerability has been disclosed in n8n, an open-source workflow automation platform, that could enable an authenticated attacker to execute arbitrary system commands on the underlying host. The vulnerability, tracked as...
Lire l'article →
Critical AdonisJS Bodyparser Flaw (CVSS 9.2) Enables Arbitrary File Write on Servers
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 06/01/2026 03:30
Users of the "@adonisjs/bodyparser" npm package are being advised to update to the latest version following the disclosure of a critical security vulnerability that, if successfully exploited, could allow a remote attacker to write arbitrary files...
Lire l'article →
Russia-Aligned Hackers Abuse Viber to Target Ukrainian Military and Government
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 05/01/2026 17:56
The Russia-aligned threat actor known as UAC-0184 has been observed targeting Ukrainian military and government entities by leveraging the Viber messaging platform to deliver malicious ZIP archives. "This organization has continued to conduct...
Lire l'article →
Kimwolf Android Botnet Infects Over 2 Million Devices via Exposed ADB and Proxy Networks
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 05/01/2026 16:41
The botnet known as Kimwolf has infected more than 2 million Android devices by tunneling through residential proxy networks, according to findings from Synthient. "Key actors involved in the Kimwolf botnet are observed monetizing the botnet through...
Lire l'article →
⚡ Weekly Recap: IoT Exploits, Wallet Breaches, Rogue Extensions, AI Abuse & More
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 05/01/2026 12:53
The year opened without a reset. The same pressure carried over, and in some places it tightened. Systems people assume are boring or stable are showing up in the wrong places. Attacks moved quietly, reused familiar paths, and kept working longer...
Lire l'article →
The State of Cybersecurity in 2025: Key Segments, Insights, and Innovations
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 05/01/2026 11:55
Featuring: Cybersecurity is being reshaped by forces that extend beyond individual threats or tools. As organizations operate across cloud infrastructure, distributed endpoints, and complex supply chains, security has shifted from a collection of...
Lire l'article →
Bitfinex Hack Convict Ilya Lichtenstein Released Early Under U.S. First Step Act
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 05/01/2026 09:42
Ilya Lichtenstein, who was sentenced to prison last year for money laundering charges in connection with his role in the massive hack of cryptocurrency exchange Bitfinex in 2016, said he has been released early. In a post shared on X last week, the...
Lire l'article →
New VVS Stealer Malware Targets Discord Accounts via Obfuscated Python Code
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 05/01/2026 07:48
Cybersecurity researchers have disclosed details of a new Python-based information stealer called VVS Stealer (also styled as VVS $tealer) that's capable of harvesting Discord credentials and tokens. The stealer is said to have been on sale on...
Lire l'article →
Transparent Tribe Launches New RAT Attacks Against Indian Government and Academia
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 02/01/2026 13:52
The threat actor known as Transparent Tribe has been attributed to a fresh set of attacks targeting Indian governmental, academic, and strategic entities with a remote access trojan (RAT) that grants them persistent control over compromised hosts....
Lire l'article →
The ROI Problem in Attack Surface Management
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 02/01/2026 11:30
Attack Surface Management (ASM) tools promise reduced risk. What they usually deliver is more information. Security teams deploy ASM, asset inventories grow, alerts start flowing, and dashboards fill up. There is visible activity and measurable...
Lire l'article →
Cybercriminals Abuse Google Cloud Email Feature in Multi-Stage Phishing Campaign
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 02/01/2026 09:14
Cybersecurity researchers have disclosed details of a phishing campaign that involves the attackers impersonating legitimate Google-generated messages by abusing Google Cloud's Application Integration service to distribute emails. The activity,...
Lire l'article →
ThreatsDay Bulletin: GhostAd Drain, macOS Attacks, Proxy Botnets, Cloud Exploits, and 12+ Stories
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 01/01/2026 15:52
The first ThreatsDay Bulletin of 2026 lands on a day that already feels symbolic — new year, new breaches, new tricks. If the past twelve months taught defenders anything, it’s that threat actors don’t pause for holidays or resolutions. They just...
Lire l'article →