Category: Uncategorized
-

LMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of Disclosure [email protected] (The Hacker News)
A high-severity security flaw in LMDeploy, an open-source toolkit for compressing, deploying, and serving LLMs, has come under active exploitation in the wild less than 13 hours after its public disclosure. The vulnerability, tracked as CVE-2026-33626 (CVSS score: 7.5), relates to a Server-Side Request Forgery (SSRF) vulnerability that could be exploited to access sensitive data.…
-
Deepfake era demands proof-based security, not just awareness
Deepfakes are reshaping social engineering attacks, and traditional security awareness training is falling short. Some experts say it’s time for proof-based verification policies.Read More
-

UNC6692 Impersonates IT Helpdesk via Microsoft Teams to Deploy SNOW Malware [email protected] (The Hacker News)
A previously undocumented threat activity cluster known as UNC6692 has been observed leveraging social engineering tactics via Microsoft Teams to deploy a custom malware suite on compromised hosts. “As with many other intrusions in recent years, UNC6692 relied heavily on impersonating IT helpdesk employees, convincing their victim to accept a Microsoft Teams chat invitation from…
-
Is SOAR dead or alive? Sort of
Orchestration and automation capabilities remain critical elements in effective cyber defense. Just don’t expect to hear much about SOAR anymore.Read More
-

Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign [email protected] (The Hacker News)
Bitwarden CLI has been compromised as part of the newly discovered and ongoing Checkmarx supply chain campaign, according to new findings from Socket. “The affected package version appears to be @bitwarden/[email protected], and the malicious code was published in ‘bw1.js,’ a file included in the package contents,” the application security company said. “The attack appears to…
-

ThreatsDay Bulletin: $290M DeFi Hack, macOS LotL Abuse, ProxySmart SIM Farms +25 New Stories [email protected] (The Hacker News)
You scroll past one incident and see another that feels familiar, like it should have been fixed years ago, but it still works with small changes. Same bugs. Same mistakes. The supply chain is messy. Packages you did not check are stealing data, adding backdoors, and spreading. Attacking the systems behind apps is easier than…
-
![[Webinar] Mythos Reality Check: Beating Automated Exploitation at AI Speed info@thehackernews.com (The Hacker News)](https://sekuritasit.com/wp-content/uploads/2026/04/miggo-webinar-34aOHW.jpg)
[Webinar] Mythos Reality Check: Beating Automated Exploitation at AI Speed [email protected] (The Hacker News)
Imagine a world where hackers don’t sleep, don’t take breaks, and find weak spots in your systems instantly. Well, that world is already here. Thanks to AI, attackers are now launching automated, large-scale exploits faster than ever before. The time you have to fix a vulnerability before it gets attacked is shrinking to zero. We…
-

Project Glasswing Proved AI Can Find the Bugs. Who’s Going to Fix Them? [email protected] (The Hacker News)
Last week, Anthropic announced Project Glasswing, an AI model so effective at discovering software vulnerabilities that they took the extraordinary step of postponing its public release. Instead, the company has given access to Apple, Microsoft, Google, Amazon, and a coalition of others to find and patch bugs before adversaries can. Mythos Preview, the model that…
-

China-Linked GopherWhisper Infects 12 Mongolian Government Systems with Go Backdoors [email protected] (The Hacker News)
Mongolian governmental institutions have emerged as the target of a previously undocumented China-aligned advanced persistent threat (APT) group tracked as GopherWhisper. “The group wields a wide array of tools mostly written in Go, using injectors and loaders to deploy and execute various backdoors in its arsenal,” Slovakian cybersecurity company ESET said in a report shared…
-

Vercel Finds More Compromised Accounts in Context.ai-Linked Breach [email protected] (The Hacker News)
Vercel on Wednesday revealed that it has identified an additional set of customer accounts that were compromised as part of a security incident that enabled unauthorized access to its internal systems. The company said it made the discovery after expanding its investigation to include an extra set of compromise indicators, alongside a review of requests…
