Category: TheHackerNews

The Hidden Risk of Orphan Accounts
20
Jan
2026

The Hidden Risk of Orphan Accounts

The Hacker NewsJan 20, 2026Enterprise Security / AI Security The Problem: The Identities Left Behind As organizations grow and evolve,…

Why Secrets in JavaScript Bundles are Still Being Missed
20
Jan
2026

Why Secrets in JavaScript Bundles are Still Being Missed

Leaked API keys are no longer unusual, nor are the breaches that follow. So why are sensitive tokens still being…

Cloudflare Fixes ACME Validation Bug Allowing WAF Bypass to Origin Servers
20
Jan
2026

Cloudflare Fixes ACME Validation Bug Allowing WAF Bypass to Origin Servers

Ravie LakshmananJan 20, 2026Web Security / Vulnerability Cloudflare has addressed a security vulnerability impacting its Automatic Certificate Management Environment (ACME)…

Tudou Guarantee Marketplace
20
Jan
2026

Tudou Guarantee Marketplace Halts Telegram Transactions After Processing Over $12 Billion

Ravie LakshmananJan 20, 2026Cryptocurrency / Artificial Intelligence A Telegram-based guarantee marketplace known for advertising a broad range of illicit services…

Google Gemini Prompt Injection Flaw Exposed Private Calendar Data via Malicious Invites
19
Jan
2026

Google Gemini Prompt Injection Flaw Exposed Private Calendar Data via Malicious Invites

Cybersecurity researchers have disclosed details of a security flaw that leverages indirect prompt injection targeting Google Gemini as a way…

New StackWarp Hardware Flaw Breaks AMD SEV-SNP Protections on Zen 1–5 CPUs
19
Jan
2026

New StackWarp Hardware Flaw Breaks AMD SEV-SNP Protections on Zen 1–5 CPUs

Ravie LakshmananJan 19, 2026Hardware Security / Vulnerability A team of academics from the CISPA Helmholtz Center for Information Security in…

The High (and Hidden) Costs for Cloud-First Businesses
19
Jan
2026

The High (and Hidden) Costs for Cloud-First Businesses

Just a few years ago, the cloud was touted as the “magic pill” for any cyber threat or performance issue….

CrashFix Chrome Extension Delivers ModeloRAT Using ClickFix-Style Browser Crash Lures
19
Jan
2026

CrashFix Chrome Extension Delivers ModeloRAT Using ClickFix-Style Browser Crash Lures

Cybersecurity researchers have disclosed details of an ongoing campaign dubbed KongTuke that used a malicious Google Chrome extension masquerading as…

Security Bug in StealC Malware Panel Let Researchers Spy on Threat Actor Operations
19
Jan
2026

Security Bug in StealC Malware Panel Let Researchers Spy on Threat Actor Operations

Ravie LakshmananJan 19, 2026Malware / Threat Intelligence Cybersecurity researchers have disclosed a cross-site scripting (XSS) vulnerability in the web-based control…

Black Basta Ransomware Leader Added to EU Most Wanted and INTERPOL Red Notice
17
Jan
2026

Black Basta Ransomware Leader Added to EU Most Wanted and INTERPOL Red Notice

Ravie LakshmananJan 17, 2026Law Enforcement / Cybercrime Ukrainian and German law enforcement authorities have identified two Ukrainians suspected of working…

OpenAI to Show Ads in ChatGPT for Logged-In U.S. Adults on Free and Go Plans
17
Jan
2026

OpenAI to Show Ads in ChatGPT for Logged-In U.S. Adults on Free and Go Plans

Jan 17, 2026Ravie LakshmananArtificial Intelligence / Data Privacy OpenAI on Friday said it would start showing ads in ChatGPT to…

GootLoader Malware Uses 500–1,000 Concatenated ZIP Archives to Evade Detection
16
Jan
2026

GootLoader Malware Uses 500–1,000 Concatenated ZIP Archives to Evade Detection

Jan 16, 2026Ravie LakshmananMalvertising / Threat Intelligence The JavaScript (aka JScript) malware loader called GootLoader has been observed using a…