Hackread.com
banner
hackread.bsky.social
Hackread.com
@hackread.bsky.social
The official Bluesky account of the most reliable cybersecurity news platform brings exclusive dark web, tech, hacking news, and much more. Contact: [email protected].
Pinned
Thank you. 🙏🏽
The official #Bluesky account of the most reliable cybersecurity news platform brings exclusive dark web, tech, hacking news, and much more. Contact: [email protected]. #CyberSecurityNews #Technology #HackingNews #CyberCrime #infosec

#FF
@hackread.bsky.social
⚠️📢🪝Revolut customers are receiving phishing texts featuring a fake video identity check and password request, days after sensitive customer data was exposed.

Listen/Read: hackread.com/revolut-cust...

#Revolut #Phishing #Cybersecurity #DataBreach #Scam
Revolut Customers Targeted by Phishing Campaign After Data Breach
Revolut customers are being targeted with phishing texts days after a social engineering attack exposed sensitive customer data, including IDs and selfies.
hackread.com
September 18, 2026 at 8:04 PM
A 3-person cybersecurity team used #ClaudeAI to help hack OpenAI during authorized research, taking over employee accounts and reaching an internal code repository in under 72 hours. The reward? A $6,500 bug bounty.

Listen/Read: hackread.com/cybersecurit...

#Cybersecurity #OpenAI #BugBounty #AI
Cybersecurity Startup Uses Claude AI to Hack OpenAI, Earns $6,500 Bug Bounty
Hacktron AI used Anthropic's Claude to help exploit OpenAI flaws, compromise employee accounts and reach an internal code repository, earning a $6,500 bounty.
hackread.com
September 18, 2026 at 1:45 PM
⚠️📢🪝Fake OpenAI billing emails are sending ChatGPT users to convincing phishing pages designed to steal account credentials and payment information.

Listen/Read: hackread.com/openai-billi...

#Cybersecurity #ChatGPT #OpenAI #Phishing #Scam
Fake OpenAI Billing Emails Target ChatGPT Users in Credential Harvesting Phishing Scam
Cofense researchers identified phishing emails impersonating OpenAI billing notices to steal ChatGPT credentials and payment information.
hackread.com
September 18, 2026 at 10:30 AM
The new GhostCode turns Microsoft’s legitimate device authentication flow against its users, stealing valid tokens after MFA and registering attacker-controlled devices in minutes.

Listen/Read: hackread.com/ghostcode-ph...

#Cybersecurity #GhostCode #Phishing #Microsoft365
New GhostCode Phishing Kit Hijacks Microsoft Accounts Despite MFA
eSentire uncovers the GhostCode phishing kit abusing Microsoft OAuth to steal tokens, register attacker devices and access Microsoft 365 accounts.
hackread.com
September 17, 2026 at 3:11 PM
FBI and RCMP have seized domains linked to #NightmareStresser, a DDoS-for-hire service used to launch hundreds of thousands of attacks and attempted attacks worldwide since 2022.

Listen/Read: hackread.com/operation-po...

#Cybersecurity #DDoS #FBI #OperationPowerOFF #CyberCrime
FBI Seizes NightmareStresser DDoS-for-Hire Domains in Operation PowerOFF
FBI and RCMP seize NightmareStresser domains after the DDoS-for-hire service was linked to hundreds of thousands of attacks and attempted attacks worldwide.
hackread.com
September 16, 2026 at 9:35 PM
Two critical flaws in The Events Calendar WordPress plugin put 600,000+ installations at risk, allowing unauthenticated attackers to execute code or take over sites.

Listen/Read: hackread.com/critical-cal...

#Cybersecurity #WordPress #RCE #Vulnerability #Wordfence
2 Critical Calendar WordPress Plugin Flaws Put 600K Sites at Risk of Takeover
Two critical RCE flaws in The Events Calendar expose 600,000+ WordPress installations to unauthenticated attacks, with CVSS scores of 9.8.
hackread.com
September 16, 2026 at 5:13 PM
#CrowdStrike has linked AI-generated PhantomRaven malware to a self-described bug bounty hunter accused of using malicious npm packages to compromise company systems.

Listen/Read: hackread.com/crowdstrike-...

#Cybersecurity #PhantomRaven #Malware #BugBounty #AI
CrowdStrike Links AI-Generated PhantomRaven Malware to Bug Bounty Hunter
CrowdStrike links PhantomRaven malware to a bug bounty hunter, finding LLM-generated code, malicious npm packages and attempts to compromise company IT systems.
hackread.com
September 16, 2026 at 2:20 PM
Oleksii Lytvynenko, a Ukrainian member of the Conti ransomware operation, has been sentenced to four years in a US prison after admitting his role in attacks that harmed at least 12 companies.

Listen/Read: hackread.com/ukrainian-co...

#Cybersecurity #Ransomware #Conti #Cybercrime #Ukraine
Ukrainian Conti Ransomware Member Gets 4 Years in US Prison
Ukrainian national Oleksii Lytvynenko gets four years in US prison for his role in the Conti ransomware operation, which targeted over 1,000 victims.
hackread.com
September 15, 2026 at 3:56 PM
⚠️📢🪝Hackers are posing as IT support and using fake passkey requests to hijack Microsoft 365 accounts, capture authentication tokens and access corporate cloud data.

Listen/Read: hackread.com/hackers-it-s...

#Cybersecurity #Microsoft365 #Phishing #Passkeys #Microsoft
Hackers Pose as IT Support, Use Fake Passkey Lures to Steal Microsoft 365 Access
Microsoft warns of fake passkey and IT support attacks targeting Microsoft 365 accounts to steal authentication tokens and access corporate cloud data.
hackread.com
September 15, 2026 at 12:28 PM
Hackers are actively exploiting the critical #StyleSmuggler zero-day to compromise Adobe Commerce and Magento stores, with researchers finding Linux backdoors and PHP web shells on affected systems.

Listen/Read: hackread.com/stylesmuggle...

#Cybersecurity #Magento #Adobe #0Day #Vulnerability
StyleSmuggler 0-Day Exploited to Hack Adobe Commerce and Magento Stores
A critical Adobe Commerce and Magento zero-day dubbed StyleSmuggler is under active attack, allowing hackers to execute PHP code without authentication.
hackread.com
September 15, 2026 at 11:26 AM
Florida has confirmed a DMV data breach after #ShinyHunters claimed access. Our review found 612,982 ZIP archives containing SSN cards, licenses, immigration docs and other sensitive records.

Listen/Read: hackread.com/florida-dmv-...

#Cybersecurity #DataBreach #FloridaDMV #Privacy
Florida Confirms DMV Breach as ShinyHunters Leak Exposes SSN Cards and Licenses
Florida DMV confirms breach after ShinyHunters claimed access, while leaked files contain SSN cards, licences, immigration records and government documents.
hackread.com
September 14, 2026 at 4:59 PM
Trellix’s latest threat-hunting report traces state-backed phishing, the #DarkSword iPhone exploit kit, a Node.js-based crypto stealer, and poisoned Axios npm packages across five covert campaigns.

Listen/Read: hackread.com/trellix-dark...

#Cybersecurity #ThreatResearch #Malware #APT28
Trellix Report Details DarkSword, JSCeal, Axios npm Attack and APT28 Campaigns
DarkSword, JSCeal, Axios, Bitter APT, and APT28 campaigns reveal evolving tactics targeting iPhones, Southeast Asia, software supply chains, diplomatic organizations, and European governments.
hackread.com
September 14, 2026 at 2:06 PM
Thousands of suspicious Android apps found abusing Google Play Early Access to push fake rewards, deepfake promotions, misleading utilities, and fraudulent ad clicks.

Listen/Read: hackread.com/google-play-...

#Cybersecurity #Android #GooglePlay #Scams #Deepfake
Google Play Early Access Abused by Thousands of Suspicious Android Apps
Bitdefender finds thousands of suspicious Android apps abusing Google Play Early Access with fake rewards, deepfake ads, misleading utilities and brand impersonation.
hackread.com
September 14, 2026 at 11:58 AM
⚠️📢 🫴🤝 Revolut handed sensitive customer data to scammers after fraudulent government requests were sent through a legitimate government agency email domain.

Listen/Read: hackread.com/revolut-gave...

#Cybersecurity #Revolut #DataBreach #Privacy #Bitcoin
Revolut Gave Customer Data to Scammers After Fake Government Requests
Revolut handed customer passports, verification selfies, IBANs and Bitcoin transaction records to scammers who used a legitimate government agency email domain.
hackread.com
September 12, 2026 at 12:10 PM
⚠️📢🪝Fake sexual misconduct and Title IX claims are being used in phishing emails targeting US universities, with victims directed through Google Drive to install Zoho RAT.

Listen/Read: hackread.com/fake-sexual-...

#Cybersecurity #Phishing #ZohoRAT #Universities #Malware
Fake Sexual Misconduct Emails Target Universities with Zoho RAT
Cofense details a phishing campaign targeting healthcare-linked universities through Google Drive links that lead recipients to install Zoho RAT.
hackread.com
September 11, 2026 at 1:16 PM
⚠️📢 Anthropic has disclosed a 4th Claude AI hacking incident after Opus 4.6 gained unauthorized access to a real third-party system during a cybersecurity test. The case was missed in an earlier review.

Listen/Read: hackread.com/anthropic-fi...

#Anthropic #ClaudeAI #Cybersecurity #AI #Hacking
Anthropic Finds 4th Claude AI Hacking Incident Missed in Earlier Review
Anthropic reveals a 4th Claude AI hacking incident after Opus 4.6 accessed a real system, leading to a review of 481 million evaluation transcripts.
hackread.com
September 10, 2026 at 9:54 PM
⚠️📢 Hackers are using hundreds of AI agents to exploit two PaperCut zero-days at scale, with at least 440 servers compromised across 395 organizations in 48 countries.

Listen/Read: hackread.com/hackers-use-...

#Cybersecurity #PaperCut #AI #0Day #Vulnerability
Hackers Use Hundreds of AI Agents to Exploit PaperCut Zero-Days
Blackpoint Cyber and GreyNoise detail attacks exploiting two PaperCut zero-days, with hundreds of AI agents used to compromise servers across 48 countries.
hackread.com
September 10, 2026 at 3:51 PM
A newly uncovered Linux malware is targeting F5 BIG-IP APM systems and hiding a web shell in memory, allowing it to stay out of sight during normal file checks.

Listen/Read: hackread.com/f5-big-ip-ap...

#Cybersecurity #Malware #F5 #BIGIP #Linux #WebShell
F5 BIG-IP APM Linux Malware Hides PHP Web Shell in Apache Memory
Sophos found Linux malware targeting F5 BIG-IP APM that injects a PHP web shell into Apache memory, helping attackers evade file-based detection.
hackread.com
September 10, 2026 at 11:47 AM
A new AI workflow flaw dubbed Workflow Identity Hijacking could let outsiders access sensitive internal data simply by asking, without prompt injection or jailbreaks.

Listen/Read: hackread.com/ai-workflow-...

#Cybersecurity #AI #ArtificialIntelligence #Vulnerability
AI Workflow Flaw Could Let Attackers Access Sensitive Data by Simply Asking
Noma Labs has identified Workflow Identity Hijacking, an AI workflow flaw that can let attackers abuse privileged access to sensitive internal data without prompt injection.
hackread.com
September 9, 2026 at 5:00 PM
🖥️🩹 Microsoft’s September #PatchTuesday is its biggest yet, fixing 966 vulnerabilities, including 2 Windows 0-days already exploited in attacks. Critical RCE flaws also affect Office, networking services and Hyper-V.

Listen/Read: hackread.com/microsoft-pa...

#Microsoft #Windows #0Day #Cybersecurity
Microsoft Patch Tuesday Fixes 966 Vulnerabilities, Including 2 Exploited 0-Days
Microsoft Patch Tuesday fixes 966 vulnerabilities, including two exploited Windows zero-days, critical RCE flaws, and bugs in Office, networking and Hyper-V.
hackread.com
September 9, 2026 at 10:50 AM
⚠️📢 Mathspace says hackers exploited an unpatched Metabase flaw and downloaded account data belonging to 1.08 million students, parents, guardians and staff in Australia and New Zealand.

Listen/Read: hackread.com/mathspace-da...

#DataBreach #Cybersecurity #Mathspace #Metabase
Mathspace Data Breach Affects 1.08 Million Students, Parents and Staff
Mathspace says hackers exploited a Metabase flaw and downloaded account data belonging to 1.08 million students, parents and staff in Australia and New Zealand.
hackread.com
September 8, 2026 at 4:00 PM
⚠️📢 Fake Google Voice voicemail alerts are being sent from compromised accounts to lure victims into a live Google login relay. Attackers then intercept passwords, 2FA codes, and authenticated sessions.

Listen/Read: hackread.com/hackers-goog...

#Cybersecurity #Phishing #Google #2FA #Scam
Hackers Stream Real Google Login Pages to Steal Passwords and 2FA Codes
Researchers found a phishing service relaying live Google sign-in sessions to intercept passwords, 2FA codes, and active authenticated account sessions.
hackread.com
September 8, 2026 at 1:07 PM
ShinyHunters claims it breached Florida’s motor vehicle agency and has posted a detailed Jeffrey Epstein DAVID record as evidence.

Listen/Read: hackread.com/shinyhunters...

#ShinyHunters #FloridaDMV #DataBreach #Cybersecurity #Epstein
ShinyHunters Claims Florida DMV Breach, Posts Jeffrey Epstein Record as Proof
ShinyHunters claims access to Florida driver records and posts a Jeffrey Epstein DAVID screenshot, although FLHSMV has not confirmed any breach yet.
hackread.com
September 8, 2026 at 11:11 AM
Toy Ghouls hackers are targeting Russian organizations with two custom #Windows backdoors that use HiveMQ and an attacker-controlled Element server for command and control.

Listen/Read: hackread.com/toy-ghouls-r...

#Cybersecurity #Malware #Russia #ToyGhouls
Toy Ghouls Targets Russian Organizations With New Windows Backdoors
Kaspersky found 2 custom Toy Ghouls backdoors that use HiveMQ MQTT and an attacker-controlled Element server to execute commands on Windows systems.
hackread.com
September 7, 2026 at 5:55 PM
Reposted by Hackread.com
A massive win for global security! Sality’s 23-year run is finally over. Reminder: These threats often spread via removable drives, so keep your scanners active and systems patched! 🛡️
September 4, 2026 at 5:38 PM