Whats The Hax? Signal / noise
All coverage

Threats, breaches, and defensive intelligence.

Security signals, without the noise. — page 1

Current feed archive. Entries come from the loaded publisher feeds and change as those feeds update. Search and saved-story filters apply to this page.

Complete index

Every loaded article, grouped by its original feed. Search scans source names and headlines.

Density
Sort
All coverage / Incidents darkreading

9 entries on this page

All coverage / Incidents BleepingComputer

15 entries on this page

ChatGPT Astra is now rolling out to $20 Plus subscription 1h ago OpenAI is now rolling out ChatGPT Astra, its most powerful model to date, to those with a $20 Plus subscription, but there's no word on when free users will get access.. Attackers conceal phishing lures using invisible Unicode characters 12h ago Threat actors have adopted the ASCII smuggling technique in phishing campaigns, using invisible Unicode characters to evade email security filters. Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain 1d ago A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC… OpenAI admits it didn't disclose rogue AI wiki hijacking incident 1d ago OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated… IDScan sued over alleged data breach affecting 153 million drivers 2d ago Multiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to sell more than 153 million driver's lice… Critical Citrix NetScaler auth bypass now leveraged in attacks 2d ago Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian. Microsoft says some users can’t open the Teams desktop client 2d ago Microsoft is working to resolve a known issue that causes delays or blocks some users from opening the Microsoft Teams desktop client on Windows systems. 39 New Methods That Compromise Passkey Authentication 2d ago Passkeys eliminate many password-based attacks, but researchers have documented 39 methods for compromising authentication built around them. Token explains how attackers can abus… New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges 2d ago An anonymous security researcher who uses the Exchange Online outage causes email delays, 'Server busy' errors 2d ago Microsoft is working to resolve an ongoing Exchange Online outage that is delaying email sent to and received from external domains. Google warns of new Chrome zero-day flaw exploited in attacks 2d ago Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities. French hospital fined €500,000 after breach exposes data of 727,000 3d ago France's data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 ($580,000) for failing to adequately protect patients' and their relatives' data. Coder's registry infrastructure compromised to push malicious modules 3d ago Attackers compromised Coder's Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code. HPE patches critical ArubaOS-CX remote code execution flaw 3d ago Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution. Microsoft: KB5120998 mouse reset bug affects only non-English PCs 3d ago Microsoft says a known issue that reverts mouse settings after installing the KB5120998 August 2026 preview update affects only non-English Windows 11 systems.
All coverage / Watch and listen DEFCONConference

15 entries on this page

All coverage / Watch and listen David Bombal

14 entries on this page

All coverage / Incidents The Hacker News

20 entries on this page

Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication 17h ago Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner 18h ago Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores 1d ago Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials 1d ago Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code 1d ago Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted 1d ago Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel 1d ago Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities 1d ago Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters 2d ago PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution 2d ago New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic 2d ago Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws 2d ago Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws 2d ago Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day 2d ago GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests 2d ago ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories 3d ago Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root 3d ago BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory 3d ago Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data 3d ago US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries 3d ago
All coverage Help Net Security

10 entries on this page

Week in review: Claude accounts compromised through infostealer, Patch Tuesday forecast 19h ago Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Anthropic locks out Claude users after infostealers Synology ActiveProtect Manager 2.0 improves AI-driven security 2d ago Synology ActiveProtect Manager 2.0 extends protection to Amazon EC2, Azure VM, Proxmox VE, Nutanix AHV, and Google Workspace. Google patches actively exploited Chrome zero-day (CVE-2026-85046) 2d ago Google has patched 12 vulnerabilities affecting its popular Chrome browser, among them CVE-2026-85046, which has been exploited in the wild. Microsoft Teams is about to make QR code phishing much harder 2d ago Microsoft is preparing a new Teams feature to help users stay safe from QR code phishing, with rollout set for October 2026. September 2026 Patch Tuesday forecast: All we need is more time 2d ago Todd Schell from Ivanti gives his overview of August 2026 and forecast for September 2026 Patch Tuesday. Are you ready to get patching? A five-part inventory for your AI agent credentials 2d ago Roy Katmor explains the review gap around AI agent credentials and what teams should inventory before an agent acts on its own. Scammers have figured out the best time to text you 2d ago Scam texts peak at noon and surge on Fridays, Malwarebytes data shows, while MrBeast, Google, and Roblox rank among scammers’ top targets. OpenAI is putting $1 billion behind Daybreak for defenders working without enterprise budgets 2d ago OpenAI Daybreak frontline defenders get $1B in subsidized access for water, grid and local government teams, with a six-month clock. Most of the bugs Claude Mythos found have never been checked by a human 2d ago Anthropic produced 23,019 Claude Mythos vulnerability findings. Outside firms reviewed 1,900, and 13 of 27 severity ratings were too high. New infosec products of the week: September 4, 2026 2d ago Here’s a look at the most interesting products from the past week, featuring releases from BugBase, F5 Networks, Ping Identity, and Superna.
All coverage / Incidents SecurityWeek

10 entries on this page

All coverage / Incidents Security Latest

12 entries on this page

All coverage / Watch and listen Black Hat

15 entries on this page

All coverage Security - Ars Technica

7 entries on this page

All coverage / Blogs Microsoft Security Blog

7 entries on this page

How to secure edge AI in customer-owned environments 2d ago As AI moves into customer-owned environments, organizations need new ways to verify the systems, software, and AI assets they trust before releasing sensitive data, credentials, a… ASCII smuggling crosses over from AI prompt injection to phishing evasion 3d ago Invisible Unicode characters popularized for hiding instructions from AI models are now being used to obfuscate words before email filters parse them. Impersonating IT support: how threat actors turn a remote session into enterprise-wide access 4d ago Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and de… Counterfeit installers to system compromise: Tracking a deceptive software download campaign 5d ago An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives. Microsoft Defender Experts… Cybersecurity IR Workshop: The workshop you shouldn’t miss 5d ago Cyber resilience starts before a crisis. Gain practical insights from DART to strengthen readiness and response. TerminalFix campaign deploys a reverse tunnel through multistage intrusion 8d ago Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance. ​​​​​​What’s new in Microsoft Security: August 2026 10d ago This month’s updates provide new capabilities to help organizations gain insights into agent activity, expand security coverage across supported environments, and enhance security…
All coverage / Community Technical Information Security Content & Discussion

15 entries on this page

All coverage / Alerts MSRC Security Update Guide

20 entries on this page

All coverage / Threat intel Securelist

3 entries on this page

All coverage / Threat intel Recorded Future

3 entries on this page

All coverage / Blogs Heimdal Security Blog

2 entries on this page

All coverage / Incidents CyberScoop

16 entries on this page

All coverage Cybersecurity News

16 entries on this page

All coverage / Alerts Cisco Security Advisory

4 entries on this page

No matching sources found.