Krebs on Security In-depth security news and investigation

  • Canadian Man Pleads Guilty in Snowflake Extortions
    by BrianKrebs on August 6, 2026 at 5:00 pm

    A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million AT&T customers.

  • Read This Before You Buy That TV Streaming Stick
    by BrianKrebs on July 30, 2026 at 4:49 pm

    Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

  • LG to Ban Residential Proxies from Smart TV Apps
    by BrianKrebs on July 22, 2026 at 1:10 am

    The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG's webOS store allow unknown third-parties to route their Internet traffic through a user's TV.

  • Microsoft Patches a Record 570 Security Flaws
    by BrianKrebs on July 14, 2026 at 7:22 pm

    Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.

  • Lessons Learned from CISA’s Recent GitHub Leak
    by BrianKrebs on July 13, 2026 at 3:03 pm

    The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almost six months before being notified by KrebsOnSecurity. Experts say the gaps identified in the agency's initial response provide important lessons that all security teams should absorb.



BleepingComputer BleepingComputer - All Stories



The Hacker News Most trusted, widely-read independent cybersecurity news source for everyone; supported by hackers and IT professionals — Send TIPs to admin@thehackernews.com

  • Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
    by info@thehackernews.com (The Hacker News) on August 7, 2026 at 6:48 pm

    A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems. "These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but all of them deliver a powerful RAT and infostealer payload," OpenSourceMalware researcher Paul

  • ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
    by info@thehackernews.com (The Hacker News) on August 7, 2026 at 6:29 pm

    ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The macOS-focused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that's compatible with the computer's CPU architecture. "

  • UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
    by info@thehackernews.com (The Hacker News) on August 7, 2026 at 6:16 pm

    A recent wave of cyber attacks targeting financial services, private equity, and professional services is attributed to a data extortion group known as UNC6671. "UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via their

  • New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
    by info@thehackernews.com (The Hacker News) on August 7, 2026 at 12:56 pm

    WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. pwn.ai demonstrated how the flaw can be chained into PHP code execution on the server when a logged-in administrator interacts with an attacker-controlled page. Tracked as CVE-2026-64638 (CVSS score: 8.9), the

  • Growing Up The Hard Way
    by info@thehackernews.com (The Hacker News) on August 7, 2026 at 11:55 am

    Open Source had a great childhood. For two decades it got to be a kid. It ran around barefoot, gave everything away, trusted strangers, and never once thought about who was watching. It ran the kind of lemonade stand that took IOUs from anyone who wandered up — take what you need, pay me back whenever, no need to leave a name. It was idyllic. It was also, in retrospect, a little feral. Then,