Trending: hackersAll contenthive-129948hive-196917krhive-150122zzanhive-180932steemhive-185836hive-183959photographyhive-183397hive-166405hive-188619hive-144064hive-101145uncommonlabhive-109690hive-139150hive-103599hive-145157photohive-180301hive-193637hive-170554hive-184714TrendingNewHotLikersninda (43)in hacknews • 8 hours ago🔄 Update on LAMEHUG malware →🔄 Update on LAMEHUG malware → Russian hackers used ~270 Hugging Face tokens to run AI-powered attacks — sending prompts to a coding LLM to generate system-hacking commands. The kicker? It’s…ninda (43)in hacknews • 3 days agoManual IAM processes slow down IT and introduce risk.Manual IAM processes slow down IT and introduce risk. In this upcoming webinar, join Black Rifle Coffee Company and Tines for practical advice on automating identity lifecycles, reducing tickets…ninda (43)in hacknews • yesterday⚠️ A China-linked group breached VMware ESXi & vCenter in a stealthy, years-long cyberespionage camp⚠️ A China-linked group breached VMware ESXi & vCenter in a stealthy, years-long cyberespionage campaign. They killed logs, mimicked forensic tools—and stayed hidden for years. Most orgs still…ninda (43)in hacknews • 2 days ago🚨 New malware CastleLoader is hijacking systems through fake GitHub repos and phishing sites—469 co🚨 New malware CastleLoader is hijacking systems through fake GitHub repos and phishing sites—469 confirmed infections. It spreads stealers and RATs, uses PowerShell, and mimics trusted dev…ninda (43)in hacknews • yesterday☠️ WARNING: A critical auth bypass flaw in Mitel MiVoice MX-ONE (CVSS 9.4) lets attackers hijack us☠️ WARNING: A critical auth bypass flaw in Mitel MiVoice MX-ONE (CVSS 9.4) lets attackers hijack user and admin accounts—no login needed. It affects versions still widely in use. Details +…ninda (43)in hacknews • 2 days ago🚨 Sophos & SonicWall just patched critical RCE flaws—some pre-auth, CVSS 9.8.🚨 Sophos & SonicWall just patched critical RCE flaws—some pre-auth, CVSS 9.8. One bug affects devices even after patching (via upgrade path). Another was used to plant a backdoor. Here’s what…ninda (43)in hacknews • 2 days ago🔥 AI is rewriting the rules of customer identity — and users are pushing back.🔥 AI is rewriting the rules of customer identity — and users are pushing back. From smoother logins to rising fraud threats, what used to work won’t cut it in 2025. This free webinar breaks it…ninda (43)in hacknews • 16 hours ago🔐 AI logins are breaking trust—73% of users say one bad experience, and they’re gone.🔐 AI logins are breaking trust—73% of users say one bad experience, and they’re gone. Want to keep them? Learn how top brands are using smart, secure CIAM to win loyalty in the AI era.…ninda (43)in hacknews • 3 days ago🚨 81% faster gap mitigation. 50% fewer critical vulns.🚨 81% faster gap mitigation. 50% fewer critical vulns. Annual pentests can’t keep up—your defenses change daily, and so do attackers. It’s time to stop playing defense once a year. Build an…ninda (43)in hacknews • 3 days ago🚨 Chinese hackers hijacked a Dalai Lama birthday tribute site to spy on Tibetans.🚨 Chinese hackers hijacked a Dalai Lama birthday tribute site to spy on Tibetans. Victims downloaded a fake encrypted chat app—actually a backdoored version of Element laced with Gh0st RAT. It…ninda (43)in hacknews • 3 days ago🚨 ALERT: China-linked hackers are exploiting unpatched SharePoint servers to drop Warlock ransomwar🚨 ALERT: China-linked hackers are exploiting unpatched SharePoint servers to drop Warlock ransomware. They’re using legit tools like PsExec, Mimikatz & IIS hijacking to stay hidden. Even…ninda (43)in hacknews • 4 days ago🚨 Hackers are hijacking WordPress sites with a backdoor hidden in plain sight—inside mu-plugins.🚨 Hackers are hijacking WordPress sites with a backdoor hidden in plain sight—inside mu-plugins. It gives them full admin access, evades detection, and locks out real users. It looks like a…ninda (43)in hacknews • 3 days ago🚨 Europol just took down XSS — a top Russian-speaking cybercrime forum with 50,000+ users.🚨 Europol just took down XSS — a top Russian-speaking cybercrime forum with 50,000+ users. Its admin made €7M running it like a darknet eBay for stolen data and hacking tools. He’s now in…ninda (43)in hacknews • 4 days agoA hacker group just pivoted from Craft CMS to Magento & Docker—using real pentest tools to hide malwA hacker group just pivoted from Craft CMS to Magento & Docker—using real pentest tools to hide malware in-memory. Even if you stop their crypto miner, they still profit off your bandwidth.…ninda (43)in hacknews • 6 days ago🚨 Hackers are bypassing FIDO keys—without breaking them.A new phishing trick fools users into scanning legit QR codes, handing attackers full access. The worst part? It abuses a real cross-device sign-in feature. How PoisonSeed pulls it off ↓ninda (43)in hacknews • 4 days ago🚨 Most Kerberoasting attacks still bypass detection—despite being a 10+ year-old threat.🚨 Most Kerberoasting attacks still bypass detection—despite being a 10+ year-old threat. Why? Legacy tools miss subtle, low-and-slow attacks. @BeyondTrust just built a statistical model that…ninda (43)in hacknews • 4 days ago🚨 This Windows trojan just became the first to weaponize Microsoft’s accessibility tools.🚨 This Windows trojan just became the first to weaponize Microsoft’s accessibility tools. The Coyote malware is stealing banking and crypto logins from 75+ institutions—by reading what’s on your…ninda (43)in hacknews • 4 days agoOverexposed to risk with public images?Overexposed to risk with public images? Get ActiveState's free secure containers—rebuilt, scanned, and now on Docker Hub. 🛡️ Cut out CVEs and patching hassle. Just pull, trust, and deploy:ninda (43)in hacknews • 4 days agoVegas, neon & next-level security insights. Don’t miss @BeyondTrust at #BHUSA.Vegas, neon & next-level security insights. Don’t miss @BeyondTrust at #BHUSA. Find their award-winning Outfitters booth at #5024, navigate the cybersecurity wilderness and take a free identity…ninda (43)in hacknews • 5 days ago🚨 Chinese hackers are actively exploiting new SharePoint flaws to bypass auth & run code remotely.Even Microsoft’s AMSI fix isn’t stopping them. The worst part? Many orgs aren’t patching. Details you can’t afford to miss →