Category: TheHackerNews

North Korean PurpleBravo Campaign Targeted 3,136 IP Addresses via Fake Job Interviews
21
Jan
2026

North Korean PurpleBravo Campaign Targeted 3,136 IP Addresses via Fake Job Interviews

As many as 3,136 individual IP addresses linked to likely targets of the Contagious Interview activity have been identified, with…

Zoom and GitLab Release Security Updates Fixing RCE, DoS, and 2FA Bypass Flaws
21
Jan
2026

Zoom and GitLab Release Security Updates Fixing RCE, DoS, and 2FA Bypass Flaws

Ravie LakshmananJan 21, 2026Vulnerability / Network Security Zoom and GitLab have released security updates to resolve a number of security…

How Smart MSSPs Using AI to Boost Margins with Half the Staff
21
Jan
2026

How Smart MSSPs Using AI to Boost Margins with Half the Staff

The Hacker NewsJan 21, 2026Artificial Intelligence / Automation Every managed security provider is chasing the same problem in 2026 —…

Exposure Assessment Platforms Signal a Shift in Focus
21
Jan
2026

Exposure Assessment Platforms Signal a Shift in Focus

Gartner® doesn’t create new categories lightly. Generally speaking, a new acronym only emerges when the industry’s collective “to-do list” has…

VoidLink Linux Malware Framework Built with AI Assistance Reaches 88,000 Lines of Code
21
Jan
2026

VoidLink Linux Malware Framework Built with AI Assistance Reaches 88,000 Lines of Code

The recently discovered sophisticated Linux malware framework known as VoidLink is assessed to have been developed by a single person…

Chainlit AI Framework Flaws Enable Data Theft via File Read and SSRF Bugs
21
Jan
2026

Chainlit AI Framework Flaws Enable Data Theft via File Read and SSRF Bugs

Ravie LakshmananJan 21, 2026Vulnerability / Artificial Intelligence Security vulnerabilities were uncovered in the popular open-source artificial intelligence (AI) framework Chainlit…

CERT/CC Warns binary-parser Bug Allows Node.js Privilege-Level Code Execution
21
Jan
2026

CERT/CC Warns binary-parser Bug Allows Node.js Privilege-Level Code Execution

Ravie LakshmananJan 21, 2026Open Source / Vulnerability A security vulnerability has been disclosed in the popular binary-parser npm library that,…

LastPass Warns of Fake Maintenance Messages Targeting Users' Master Passwords
21
Jan
2026

LastPass Warns of Fake Maintenance Messages Targeting Users’ Master Passwords

Ravie LakshmananJan 21, 2026Email Security / Malware LastPass is alerting users to a new active phishing campaign that’s impersonating the…

North Korea-Linked Hackers Target Developers via Malicious VS Code Projects
20
Jan
2026

North Korea-Linked Hackers Target Developers via Malicious VS Code Projects

The North Korean threat actors associated with the long-running Contagious Interview campaign have been observed using malicious Microsoft Visual Studio…

LinkedIn Messages to Spread RAT Malware
20
Jan
2026

Hackers Use LinkedIn Messages to Spread RAT Malware Through DLL Sideloading

Ravie LakshmananJan 20, 2026Malware / Threat Intelligence Cybersecurity researchers have uncovered a new phishing campaign that exploits social media private…

Three Flaws in Anthropic MCP Git Server Enable File Access and Code Execution
20
Jan
2026

Three Flaws in Anthropic MCP Git Server Enable File Access and Code Execution

Ravie LakshmananJan 20, 2026Vulnerability / Artificial Intelligence A set of three security vulnerabilities has been disclosed in mcp-server-git, the official…

Evelyn Stealer Malware Abuses VS Code Extensions to Steal Developer Credentials and Crypto
20
Jan
2026

Evelyn Stealer Malware Abuses VS Code Extensions to Steal Developer Credentials and Crypto

Ravie LakshmananJan 20, 2026Cloud Security / Developer Security Cybersecurity researchers have disclosed details of a malware campaign that’s targeting software…