HackenPost blogs HackenPost blogs
0
99
5
90
12
189
0
0
HackenPost blogs HackenPost blogs
dark
HackenPost blogs HackenPost blogs
Hand-Picked Top-Read Stories
New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs
World’s Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent
Trending Tags
  • Vulnerability
  • Unauthorized access risks
  • Two-factor authentication best practices
  • Tech
  • System vulnerability patches
  • System security tips
  • Strong password guidelines
  • Stealer
  • Staying informed on cyber threats
  • Security software updates importance
  • Data Breaches

New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction

Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw,…
July 20, 2026
  • Data Breaches

Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs

A solo Russian-speaking threat actor known as “bandcampro” outsourced a chunk of their operations to Google’s open-source Gemini…
July 20, 2026
  • Data Breaches

World’s Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent

In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of…
July 20, 2026
  • Data Breaches

SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three…
July 20, 2026
  • Data Breaches

Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap…
July 19, 2026
  • Data Breaches

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a…
July 17, 2026
  • Data Breaches

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests

Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a…
July 17, 2026
  • Data Breaches

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT

Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as…
July 17, 2026
  • Data Breaches

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator’s own…
July 17, 2026
  • Data Breaches

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft

Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel,…
July 17, 2026

Posts pagination

1 2 … 135 Next
Featured Posts
  • New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction

    July 20, 2026
  • Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs

    July 20, 2026
  • World’s Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent

    July 20, 2026
  • SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

    July 20, 2026
  • Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

    July 19, 2026
Recent Posts
  • ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files

  • New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage

Categories
  • Cyber Attacks (5)
  • Data Breaches (1,334)
  • News (4)
  • Technology (3)
  • Vulnerabilities (2)
HackenPost blogs HackenPost blogs
Designed & Developed by Hackenpost
0
99
5
90
12
189
0
0