
News Feed from The Hacker News
The Hacker News Most trusted, widely-read independent cybersecurity news source for everyone; supported by hackers and IT professionals — Send TIPs to admin@thehackernews.com
- Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Databy info@thehackernews.com (The Hacker News) on September 13, 2026 at 10:11 AM
Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments.The first campaign, per the tech giant, involved sending over a million scam emails between August 3 and 5, 2026, by masquerading as chief executive officers
- CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEVby info@thehackernews.com (The Hacker News) on September 12, 2026 at 3:54 PM
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.Details of the vulnerabilities are as follows -CVE-2026-42016 (CVSS score: 8.1) - An incorrect authorization
- When the Whole Company Adopts AI: What It Does to Your SOCby info@thehackernews.com (The Hacker News) on September 12, 2026 at 10:24 AM
Over the past year, we watched a new class of alert appear in enterprise security operations centers and grow faster than anything else in the stream: alerts that were triggered by AI tools and agents. Not attacks against AI, but the ordinary, everyday footprint of an organization using it, from developers running coding agents and non-technical staff signing consumer AI tools into corporate
- OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Serversby info@thehackernews.com (The Hacker News) on September 12, 2026 at 9:07 AM
The "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx.On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, disclosed details of a coordinated cyber attack that targeted the package manager for the
- GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosureby info@thehackernews.com (The Hacker News) on September 11, 2026 at 4:30 PM
GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure.The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under




