Loading…

Whats The Hax?

Daily intelligence on threats, breaches, and defenders

Latest
BleepingComputerCOLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theftBleepingComputerGoogle Chrome may soon block New Tab hijacker extensions by defaultSecurity Latest8 Best Password Managers (2026), Tested and ReviewedThe Hacker NewsColdcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 MinutesBleepingComputerRails patches critical Active Storage flaw with RCE potentialSecurityWeekBalance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity InvestmentsSecurityWeekRuby on Rails Patches Critical VulnerabilitySecurity Latest7 States’ Water Systems Hit by Cyberattacks Likely Tied to IranSecurity LatestThe OpenAI and Anthropic AI Hacking Sprees Are a Messy New Legal FrontierThe Hacker NewsHackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer SitesThe Hacker NewsAdobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User InteractionThe Hacker NewsHijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance MalwareBleepingComputerAmgen says cloud data breach exposed patient health, proprietary infoBleepingComputerArch Linux disables AUR package adoption to stop malware floodBleepingComputerOnline ad firm Adform’s script compromised to steal cryptocurrencyCyberScoopTrump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber worldBleepingComputerOpenAI says its new GPT 5.6 models are becoming more cost-efficientThe Hacker NewsSuspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurkThe Record from Recorded Future NewsCISA warns of spike in attacks on water systems as Minnesota incidents probedBleepingComputerHacker uses DeepSeek AI to autonomously attack vulnerable serversBleepingComputerCOLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theftBleepingComputerGoogle Chrome may soon block New Tab hijacker extensions by defaultSecurity Latest8 Best Password Managers (2026), Tested and ReviewedThe Hacker NewsColdcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 MinutesBleepingComputerRails patches critical Active Storage flaw with RCE potentialSecurityWeekBalance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity InvestmentsSecurityWeekRuby on Rails Patches Critical VulnerabilitySecurity Latest7 States’ Water Systems Hit by Cyberattacks Likely Tied to IranSecurity LatestThe OpenAI and Anthropic AI Hacking Sprees Are a Messy New Legal FrontierThe Hacker NewsHackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer SitesThe Hacker NewsAdobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User InteractionThe Hacker NewsHijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance MalwareBleepingComputerAmgen says cloud data breach exposed patient health, proprietary infoBleepingComputerArch Linux disables AUR package adoption to stop malware floodBleepingComputerOnline ad firm Adform’s script compromised to steal cryptocurrencyCyberScoopTrump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber worldBleepingComputerOpenAI says its new GPT 5.6 models are becoming more cost-efficientThe Hacker NewsSuspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurkThe Record from Recorded Future NewsCISA warns of spike in attacks on water systems as Minnesota incidents probedBleepingComputerHacker uses DeepSeek AI to autonomously attack vulnerable servers

By Source

Feeds organized so you can skim by site.

Density Sort
BL
BleepingComputer
1h ago · 15 items
COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft 1h ago A vulnerability in COLDCARD hardware wallet firmware allowed attackers to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose seeds were generated using a flawed random number generator. Google Chrome may soon block New Tab hijacker extensions by default 7h ago Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing the default search engine. Rails patches critical Active Storage flaw with RCE potential 1d ago A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). Amgen says cloud data breach exposed patient health, proprietary info 1d ago Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers. Arch Linux disables AUR package adoption to stop malware flood 2d ago The Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of existing packages. Online ad firm Adform’s script compromised to steal cryptocurrency 2d ago Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors' clipboards with ones controlled by an attacker. OpenAI says its new GPT 5.6 models are becoming more cost-efficient 2d ago OpenAI says it has reduced the price of two GPT-5.6 models, cutting Luna's API price by 80% and Terra's by 20% as it works to make its models more efficient. Hacker uses DeepSeek AI to autonomously attack vulnerable servers 2d ago A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement. CISA warns of cyberattacks disrupting U.S. water utilities 2d ago The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a significant increase in attacks targeting internet-exposed programmable logic controllers (PLCs) in the water and wastewater systems sector. ESET tracks rise in malicious AI skills and adaptable malware 2d ago Attackers are adapting established techniques to AI platforms, emerging technologies, and changing user behavior. ESET's new threat report examines the rise of malicious AI skills, AI-assisted malware, ClickFix attacks, record quishing acti...
15 loaded
SL
Security Latest
10h ago · 20 items
20 loaded
TH
The Hacker News
1d ago · 20 items
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes 1d ago Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites 1d ago Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction 1d ago Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware 1d ago Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk 2d ago HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm 2d ago Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies 2d ago Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined 2d ago Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw 2d ago 6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026 2d ago
20 loaded
SE
SecurityWeek
1d ago · 10 items
CY
CyberScoop
2d ago · 165 items
Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world 2d ago What the Hugging Face breach reveals about defense in the age of agentic AI 2d ago Anthropic says its AI accidentally hacked three companies during safety tests 2d ago Anthropic revealed its Claude AI models accidentally breached three real companies during safety testing after a vendor configuration error exposed live systems. Okta’s deal for Permiso aims to close gaps in identity threat detection 3d ago CISA issues recommendations to federal agencies on open-source software security 3d ago We know how to protect our troops from telecom attacks. We’re just not doing it. 3d ago Ghanaian national sentenced to 7 years in prison for stealing $10M from romance scam victims 3d ago A little-known npm package was North Korea’s warm-up act for the axios hack 4d ago Supply chain challenges loom large in quantum race, White House official says 4d ago Huntress warns about attack spree that hit 30 SonicWall customers in 2 days 4d ago
165 loaded
KO
Krebs on Security
3d ago · 10 items
Read This Before You Buy That TV Streaming Stick 3d ago Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. ... LG to Ban Residential Proxies from Smart TV Apps 11d ago The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers… Microsoft Patches a Record 570 Security Flaws 19d ago Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesd... Lessons Learned from CISA’s Recent GitHub Leak 20d ago The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almos... Felons, Fraudsters Flog Offensive Cybersecurity Startup 25d ago A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intellige... FBI Seizes NetNut Proxy Platform, Popa Botnet 31d ago The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technolo... Scattered Spider Hackers Plead Guilty on Day 1 of Trial 40d ago Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The ... ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm 45d ago For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers ... Who Runs the Ransomware Group ‘The Gentlemen?’ 53d ago A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of... A Record-Breaking Patch Tuesday for June 2026 54d ago Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company's monthly Patch Tuesday cycle. Nearly three dozen of those bug...
DA
darkreading
9d ago · 144 items
CISOs vs. Boards: Myth or Misunderstanding? 9d ago Escape Artists: 'Incorrigible' AI Models Resist Rehabilitation 9d ago Vatican's Official Prayer App Leaks 700K+ Global Users' PII 9d ago Default Azure Automation Setting Enables Cross-Tenant Identity Takeover 9d ago Europe's Multilingual Reality Exposes AI Security Gaps 9d ago Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets 10d ago Agentic AI Challenges Progress in Confidential Computing 10d ago Brazilian Banking Trojan Actively Spreading in Portugal 10d ago Ransomware Attack Puts a Chill on Japanese Frozen-Food Chain 10d ago Flaws in Passkey Implementation Show Old Attacks Still Work 10d ago
144 loaded

No matching sources found.