
News Feed from The Hacker News
The Hacker News Most trusted, widely-read independent cybersecurity news source for everyone; supported by hackers and IT professionals — Send TIPs to admin@thehackernews.com
- ScarCruft Hacks Gaming Platform to Deploy BirdCall Malware on Android and Windowsby info@thehackernews.com (The Hacker News) on May 5, 2026 at 9:07 AM
The North Korea-aligned state-sponsored hacking group known as ScarCruft has compromised a video game platform in a supply chain espionage attack, trojanizing its components with a backdoor called BirdCallto likely target ethnic Koreans residing in China. While prior versions of the backdoor have primarily targeted Windows users only, the supply chain attack is assessed to have enabled the
- Weaver E-cology RCE Flaw CVE-2026-22679 Actively Exploited via Debug APIby info@thehackernews.com (The Hacker News) on May 5, 2026 at 7:37 AM
A critical security vulnerability in Weaver (Fanwei) E-cology, an enterprise office automation (OA) and collaboration platform, has come under active exploitation in the wild. The vulnerability (CVE-2026-22679, CVSS score: 9.8) relates to a case of unauthenticated remote code execution affecting Weaver E-cology 10.0 versions prior to 20260312. The issue resides in the "/papi/esearch/data/devops/
- Microsoft Details Phishing Campaign Targeting 35,000 Users Across 26 Countriesby info@thehackernews.com (The Hacker News) on May 5, 2026 at 6:35 AM
Microsoft has disclosed details of a large-scale credential theft campaign that has leveraged a combination of code of conduct-themed lures and legitimate email services to direct users to attacker-controlled domains and steal authentication tokens. The multi-stage campaign, observed between April 14 and 16, 2026, targeted more than 35,000 users across over 13,000 organizations in 26 countries,
- Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Toolsby info@thehackernews.com (The Hacker News) on May 4, 2026 at 6:06 PM
An active phishing campaign has been observed targeting multiple vectors since at least April 2025 with legitimate Remote Monitoring and Management (RMM) software as a way to establish persistent remote access to compromised hosts. The activity, codenamed VENOMOUS#HELPER, has impacted over 80 organizations, most of which are in the U.S., according to Securonix. It shares overlaps with clusters
- Progress Patches Critical MOVEit Automation Bug Enabling Authentication Bypassby info@thehackernews.com (The Hacker News) on May 4, 2026 at 4:34 PM
Progress Software has released updates to address two security flaws in MOVEit Automation, including a critical bug that could result in an authentication bypass. MOVEit Automation (formerly Central) is a secure, server-based managed file transfer (MFT) solution used to schedule and automate file movement workflows in enterprise environments without requiring any custom scripts. The




