home.social
  1. Hackers are using fake job interview apps to spread new malware across macOS and Windows systems, stealing crypto, browser credentials, and more disguising itself as a video meeting app.

    Read more: hackread.com/fake-job-intervie

  2. 📢⚠️ China-linked hacking group targeted an oil and gas firm in using the ProxyNotShell exploit chain alongside Deed RAT and Terndoor malware across three persistent attack waves.

    Read: hackread.com/famoussparrow-oil

  3. 📢⚠️ A new China-linked hacking group is using fake Apple and Yahoo domains along with trusted tools to spy on organizations across Japan and the Asia-Pacific region.

    Read: hackread.com/chinatwill-typhoo

  4. Research reveals that hijacked OIDC tokens to poison hundreds of TanStack, Mistral AI, and UiPath packages with the self-propagating Mini Shai-Hulud worm.

    Read: hackread.com/teampcp-mini-shai

  5. 📢⚠️ Hackers are now using to develop zero-day exploits, according to a new Google report. Researchers also uncovered AI-powered backdoors, phishing scams and automated supply chain attacks targeting GitHub and PyPI.

    Read: hackread.com/google-hackers-us

  6. 📢⚠️ Researchers revealed 20-year-old flaws at Wiz’s ZeroDay.Cloud hacking event, exposing critical pgcrypto vulnerabilities that could lead to code execution.

    Read: hackread.com/wiz-zeroday-cloud

  7. 📢⚠️ A critical cPanel vulnerability lets attackers bypass login and gain root access, with active exploitation reported before patches were released. Act now!

    Read: hackread.com/cpanel-vulnerabil

  8. A Cursor AI agent wiped ’ production database and backups in just 9 seconds after misusing a root API token, exposing serious risks in AI-driven coding and cloud setups.

    Read more: hackread.com/cursor-ai-agent-w

  9. 📢⚠️ Cursor AI IDE hit by a high-severity flaw that lets attackers execute code via hidden Git hooks in cloned repos, no clicks needed. A routine dev action can trigger a full system compromise. Patch now.

    Read: hackread.com/cursor-ai-ide-vul

  10. 🚨 TeamPCP hijacks Bitwarden CLI in supply chain attack, abusing GitHub Dependabot to deploy Shai-Hulud malware and steal developer secrets, poison AI coding tools.

    Read: hackread.com/teampcp-bitwarden

  11. 📢⚠️ New malware is being sold on Telegram, targeting Android and iOS devices with real-time monitoring, location tracking, surveillance and crypto theft tools.

    Read: hackread.com/zerodayrat-malwar

  12. tricked Cognizant's helpdesk with fake calls, gaining admin access and crippling Clorox in a $380M ransomware attack. New analysis breaks down how it happened:

    Read: hackread.com/how-scattered-spi