
News Feed from The Hacker News
The Hacker News Most trusted, widely-read independent cybersecurity news source for everyone; supported by hackers and IT professionals — Send TIPs to admin@thehackernews.com
- Trapdoor Android Ad Fraud Scheme Hit 659 Million Daily Bid Requests Using 455 Appsby info@thehackernews.com (The Hacker News) on May 19, 2026 at 4:38 PM
Cybersecurity researchers have disclosed details of a new ad fraud and malvertising operation dubbed Trapdoor targeting Android device users.The activity, per HUMAN's Satori Threat Intelligence and Research Team, encompassed 455 malicious Android apps and 183 threat actor-owned command-and-control (C2) domains, turning the infrastructure into a pipeline for multi-stage fraud."Users
- DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerabilityby info@thehackernews.com (The Hacker News) on May 19, 2026 at 2:56 PM
Proof-of-concept (PoC) exploit code has now been released for a recently patched security flaw in the Linux kernel that could allow for local privilege escalation (LPE). Dubbed DirtyDecrypt (aka DirtyCBC), the vulnerability was discovered and reported by the Zellic and V12 security team on May 9, 2026, only to be informed by the maintainers that it was a duplicate of a vulnerability that had
- The New Phishing Click: How OAuth Consent Bypasses MFAby info@thehackernews.com (The Hacker News) on May 19, 2026 at 11:30 AM
In February 2026, a phishing-as-a-service (PhaaS) platform called EvilTokens went live. Within five weeks, it had compromised more than 340 Microsoft 365 organizations across five countries. The targets of the platform received a message asking them to enter a short code at microsoft.com/devicelogin and complete their normal MFA challenge, then walked away believing they had verified a
- Drupal to Release Urgent Core Security Updates on May 20, Sites Told to Prepareby info@thehackernews.com (The Hacker News) on May 19, 2026 at 10:44 AM
Drupal has issued an alert stating that it intends to release a "core security release" for all supported branches on May 20, 2026, from 5-9 p.m. UTC."The Drupal Security Team urges you to reserve time for core updates at that time because exploits might be developed within hours or days," the maintainers of the PHP-based content management system (CMS) said."Not all configurations are
- SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Accessby info@thehackernews.com (The Hacker News) on May 19, 2026 at 9:23 AM
Critical security vulnerabilities have been disclosed in SEPPMail Secure E-Mail Gateway, an enterprise-grade email security solution, that could be exploited to achieve remote code execution and enable an attacker to read arbitrary mails from the virtual appliance. "These vulnerabilities could have been exploited to read all mail traffic or as an entry vector into the internal network,"




