home.social

Hackread.com

Mastodon account of the most reliable cybersecurity news platforms bringing exclusive dark web, tech, and hacking news. Contact: [email protected].

Posts
1,377
Followers
851
Following
2
Joined 2022-11-09 · View on mstdn.social →
  1. Watch out, hackers are hiding a new version of XWorm malware in files to bypass Windows security, steal data, and remotely control computers through ads!

    Read: hackread.com/hackers-pyinstall

  2. 📢⚠️🪝Watch out, hackers are using (Calendar Phishing) with the EvilTokens phishing kit to exploit calendar invites and device code phishing to steal session tokens and breach enterprise accounts.

    Read: hackread.com/calphishing-evilt

  3. Hackers are using fake job interview apps to spread new malware across macOS and Windows systems, stealing crypto, browser credentials, and more disguising itself as a video meeting app.

    Read more: hackread.com/fake-job-intervie

  4. 📢⚠️ China-linked hacking group targeted an oil and gas firm in using the ProxyNotShell exploit chain alongside Deed RAT and Terndoor malware across three persistent attack waves.

    Read: hackread.com/famoussparrow-oil

  5. 📢⚠️ A new China-linked hacking group is using fake Apple and Yahoo domains along with trusted tools to spy on organizations across Japan and the Asia-Pacific region.

    Read: hackread.com/chinatwill-typhoo

  6. Instructure has reached an agreement with the group to return and destroy stolen Canvas data, protecting millions of student records worldwide from being publicly leaked.

    Read: hackread.com/instructure-shiny

  7. Research reveals that hijacked OIDC tokens to poison hundreds of TanStack, Mistral AI, and UiPath packages with the self-propagating Mini Shai-Hulud worm.

    Read: hackread.com/teampcp-mini-shai

  8. 📢⚠️ A Slovakian administrator tied to the dark web Kingdom Market received a 16-year US prison sentence for drug trafficking and cybercrime activity.

    Read: hackread.com/slovakian-admin-d

  9. 📢⚠️ hackers say their official clearnet domain has been suspended after the Canvas LMS attacks, forcing the group to move fully to its onion site.

    Read: hackread.com/canvas-hackers-sh

  10. 📢⚠️ Hackers are now using to develop zero-day exploits, according to a new Google report. Researchers also uncovered AI-powered backdoors, phishing scams and automated supply chain attacks targeting GitHub and PyPI.

    Read: hackread.com/google-hackers-us

  11. 📢⚠️ Hackers tricked support staff into executing a malicious file, allowing attackers to obtain code-signing certificates later used to sign malware. DigiCert revoked 60 certificates after the breach was reported.

    Read: hackread.com/hackers-digicert-

  12. 📢⚠️ Researchers have uncovered , a vulnerability in Anthropic’s Claude for Chrome extension that could let hackers hijack the AI assistant, steal Google Drive files, access Gmail data, and bypass built-in security safeguards.

    Read more: hackread.com/claudebleed-vulne

  13. 📢⚠️ Google Chrome is reportedly downloading a 4GB AI model onto eligible devices without clearly notifying users, according to researcher Alexander Hanff. The report has triggered privacy, transparency, and concerns.

    Read more: hackread.com/google-chrome-ins

  14. 📢⚠️ Researchers revealed 20-year-old flaws at Wiz’s ZeroDay.Cloud hacking event, exposing critical pgcrypto vulnerabilities that could lead to code execution.

    Read: hackread.com/wiz-zeroday-cloud

  15. 📢⚠️ A critical cPanel vulnerability lets attackers bypass login and gain root access, with active exploitation reported before patches were released. Act now!

    Read: hackread.com/cpanel-vulnerabil

  16. A Cursor AI agent wiped ’ production database and backups in just 9 seconds after misusing a root API token, exposing serious risks in AI-driven coding and cloud setups.

    Read more: hackread.com/cursor-ai-agent-w

  17. 📢⚠️ , a new AI-powered phishing-as-a-service kit, lets attackers bypass MFA using attacks and stolen session cookies. With 40+ fake templates and AI tools.

    Read: hackread.com/bluekit-phishing-

  18. 📢⚠️ US-Estonian suspect Peter Stokes was arrested in over alleged ties to Scattered Spider, facing US charges for cyberattacks, fraud, and data breaches.

    Read: hackread.com/us-estonian-suspe

  19. 📢⚠️ Cursor AI IDE hit by a high-severity flaw that lets attackers execute code via hidden Git hooks in cloned repos, no clicks needed. A routine dev action can trigger a full system compromise. Patch now.

    Read: hackread.com/cursor-ai-ide-vul

  20. 📢⚠️ exposes a 12-year-old flaw in Linux’s PackageKit, letting unprivileged users gain root access in seconds. Affects major distros, patch now

    Read: hackread.com/pack2theroot-linu

  21. 🚨 TeamPCP hijacks Bitwarden CLI in supply chain attack, abusing GitHub Dependabot to deploy Shai-Hulud malware and steal developer secrets, poison AI coding tools.

    Read: hackread.com/teampcp-bitwarden

  22. 📢⚠️ Grinex crypto exchange collapses after $13.7M breach, blames Western spies as researchers flag possible exit scam.

    Read: hackread.com/grinex-crypto-exc

  23. 📢 Tyler Robert Buchanan, a 24-year-old British hacker linked to Scattered Spider, admits to a multi-year US hacking scheme involving at least $8M in crypto theft.

    Read: hackread.com/british-hacker-ty

  24. Fake Claude AI installer mimicking Anthropic spreads PlugX RAT on Windows, using DLL sideloading to gain persistent remote access to infected systems.

    Read: hackread.com/fake-claude-ai-in

  25. The FBI recovered deleted Signal messages from an iPhone even after the app was removed. Here’s how to change your notification settings to keep chats private.

    Read: hackread.com/fbi-recover-delet

    iPhone

  26. ⛶ 𝄃𝄂🪝“Quish Splash” QR phishing campaign hits 1.6M users, hiding malicious links inside images to bypass email security and steal credentials undetected.

    Read: hackread.com/quish-splash-qr-c

  27. Watch out, as Microsoft has uncovered a Storm-2561 campaign using SEO poisoning to push fake Fortinet and Ivanti VPN sites that deliver infostealer malware.

    Read: hackread.com/storm-2561-fake-f

  28. China-linked hackers targeted using fake war news to spread PlugX backdoors and launch cyber-espionage attacks on military and energy sectors.

    hackread.com/china-hackers-qat

  29. 📢⚠️-linked APT36 is flooding Indian government networks with AI-generated “”, disposable malware built with AI. The campaign abuses trusted platforms like Google Sheets, Slack, and Discord for C&C

    Read: hackread.com/pakistan-apt36-in

  30. 📢🪝⚠️ Watch out as scammers are using Fake Zoom and Google Meet pages to trick users into installing monitoring software on Windows systems through phishing links and fake updates.

    Read: hackread.com/zoom-google-meet-

  31. 📢⚠️ New malware is being sold on Telegram, targeting Android and iOS devices with real-time monitoring, location tracking, surveillance and crypto theft tools.

    Read: hackread.com/zerodayrat-malwar

  32. 📢🚫⛔ Firefox will add a global AI kill switch, letting users block all AI features and manage individual tools for better control and privacy.

    Read: hackread.com/firefox-users-ai-

  33. Iranian TV transmission was hacked to broadcast protest footage and a message from exiled Prince Reza Pahlavi urging security forces not to fire on civilians 📺

    Read: hackread.com/iranian-tv-transm

  34. Watch out as a new report reveals a widespread Magecart skimmer campaign targeting users of all major credit cards at online checkout.

    Read more: hackread.com/magecart-targets-

  35. Watch out as the Astaroth banking Trojan is now spreading via messages in a Brazil focused campaign, using friendly-looking ZIP files to auto-infect contacts and steal banking credentials and data.

    Read: hackread.com/astaroth-banking-

  36. Ilya Lichtenstein, the 2016 hack mastermind behind a theft now valued at roughly 10 billion dollars, has been released early to home confinement under the after serving about 14 months of a 5-year sentence.

    Read: hackread.com/bitfinex-hack-mas

  37. Watch as researcher Martha Root infiltrates and wipes white supremacist dating sites like, leaks thousands of profiles on .lol after a live demo at CCC 2025.

    Read: hackread.com/white-supremacist

  38. Korean Air confirms 30,000 of its employee records have been stolen after the Cl0p ransomware gang leaked the data online, following exploitation of an Oracle EBS vulnerability.

    Read: hackread.com/30000-korean-air-

  39. 🪝 Scammers sent 40,000 phishing emails spoofing SharePoint and DocuSign to target 6,000 firms in 2 weeks, hiding malicious links behind trusted redirects 📧🔒

    Read more: hackread.com/scammers-e-signat

  40. ⚠️ Alert: A flaw (CVE-2025-12443) affected Chrome, Edge, Brave, Opera and other Chromium browsers - over 4 billion devices at risk. Patch pushed - update your browser now! 🔐

    Read: hackread.com/webxr-flaw-chromi

  41. ⚠️ Watch out! A new Android backdoor called is spreading through a fake Telegram X app, hijacking Telegram accounts on thousands of devices.

    Read: hackread.com/baohuo-android-ma

  42. 🚔 Spanish police have busted the GXC Team, one of the most active cybercrime networks led by , a 25-year-old Brazilian.

    Read: hackread.com/police-bust-gxc-t

  43. The Astaroth Trojan is back, targeting Windows devices and hiding its C2 data in GitHub images to stay active after takedowns. 🎯

    Read: hackread.com/astaroth-trojan-g

  44. Hackers are using fake Ukrainian police emails to spread new malware, giving ransomware gangs like LockBit and Qilin initial access to victims.

    Read: hackread.com/fake-ukrainian-po

  45. Europol and authorities from 18 countries tracked and protected 51 child victims in global online abuse cases, leading to 60 arrests.

    Read: hackread.com/ai-forensics-euro

  46. Watch out as hackers are using FileFix phishing with fake Facebook warnings to drop StealC Infostealer, hiding the payload inside images with .

    Read: hackread.com/filefix-attack-st

  47. 🚨 SEO poisoning alert! Watch what you download as users are being targeted with fake search results that lead to installers containing Hiddengh0st and Winos malware

    Read: hackread.com/seo-poisoning-att

  48. 🚨 Hackers are exploiting a CrushFTP Zero-Day (CVE-2025-54309) to gain admin access and take over servers. Update to v10.8.5 or v11.3.4 now!

    Read: hackread.com/hackers-exploit-c