Please turn JavaScript on
The Hacker News | #1 Trusted Source for Cybersecurity News icon

The Hacker News | #1 Trusted Source for Cybersecurity News

Get updates from The Hacker News | #1 Trusted Source for Cybersecurity News via email, on your phone or read them on follow.it on your own custom news page.

You can filter the news from The Hacker News | #1 Trusted Source for Cybersecurity News that get delivered to you using tags or topics or you can opt for all of them. Unsubscription is also very simple.

See the latest news from The Hacker News | #1 Trusted Source for Cybersecurity News below.

Site title: The Hacker News | #1 Trusted Source for Cybersecurity News

Is this your feed? Claim it!

Publisher:  Unclaimed!
Message frequency:  6.87 / day

Message History

Threat actors are actively exploiting a critical security flaw in Everest Forms Pro, a WordPress plugin with about 4,000 active installations, to execute arbitrary code, leading to a complete site compromise. The vulnerability in question is CVE-2026-3300 (CVSS score: 9.8), a remote code execution bug impacting all versions of the plugin up to, and including, 1.9.12. A patch fo...

Read full story
Security researchers and the FBI are warning that a wave of FIFA-themed fraud is already hitting World Cup 2026 fans, days before the June 11 kickoff. Recent reports describe thousands of lookalike FIFA domains, banking malware hidden inside pirate streaming apps, and at least one operation that copies FIFA's login page well enough to take over real accounts. It is an obvious ...

Read full story
The threat actor known as PCPJack has hijacked cloud servers associated with Amazon Web Services (AWS), Google Cloud, and Microsoft Azure to create a covert SMTP email relay network. "Compromised business servers across the U.S., Europe, and Asia were quietly converted into SMTP proxies, verified for mail relay capability, and synced to a downstream consumer every five minutes,...

Read full story
Cisco has patched a bug in Unified Communications Manager that lets an unauthenticated attacker on the network write files to the box and, from there, climb to root. It is tracked as CVE-2026-20230, and proof-of-concept exploit code is already public. Cisco's PSIRT says it has not seen the flaw used in attacks yet. The PoC shortens that runway. The flaw is a server-side reques...

Read full story
Over the past several weeks, the cybersecurity community has been reminded how quickly frontier and agentic AI in defense networks can challenge our assumptions. When Anthropic's Claude Mythos model was made available to a limited set of organizations as a technical preview, it was reported that an unauthorized group claimed that it had gained access within hours. The incident, ...

Read full story