Storm-2570 is a ransomware affiliate that uses consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware, and provides guidance to ...
China-linked UNC3569 exploited a Sogou Input Method flaw to deploy GRAYRABBIT; Tencent fixed the issue in version 16.3.0.3498.
By compromising BIG-IP APM systems, attackers may gain access to credentials, SSO tokens and trusted pathways into downstream applications.
We describe the technical details of the MikroTrick chain, which combines the CVE-2026-67279 and CVE-2026-86060 ...
Windows PowerShell offers an open-source administrative tool that allows IT professionals to automate tasks on a computer network for a more efficient system.
IntroductionIn June 2026, Zscaler ThreatLabz identified a new malware family, tracked as SloppyRAT, that is likely leveraged by a ransomware-related threat actor. ThreatLabz observed SloppyRAT being ...
Explore the latest news, real-world incidents, expert analysis, and trends in Telegram — only on The Hacker News, the leading ...
Hackers exploit a critical cPanel flaw to bypass logins and deploy Mirai malware, turning exposed servers into botnet ...
A Chinese-speaking threat actor tracked as Red Heron has exploited a remote-code-execution vulnerability in Gitea to steal source code, establish persistence, and deploy a previously undocumented ...
FamousSparrow uses SparroWocky backdoor to target public-facing Microsoft Exchange servers and government networks in Latin ...