Hackread.com
Mastodon account of the most reliable cybersecurity news platforms bringing exclusive dark web, tech, and hacking news. Contact: admin@hackread.com.
📣 🔐 Fake #Interpol investigation emails are pressuring employees to open malicious files disguised as criminal complaints. In reality, the files infect devices with ransomware in a targeted campaign against small businesses globally.
Read or listen to this news https://hackread.com/fake-interpol-investigation-emails-ransomware-small-businesses/
🚨 International law enforcement has arrested an alleged member of the pro-Russia hacker group Cyber Army of Russia Reborn (aka Z-Pentest).
The operation, led by the FBI and Spain's National Police under #OperationRiptide, is part of ongoing efforts to disrupt cyberattacks targeting critical infrastructure.
Listen to or read this news: https://hackread.com/fbi-spanish-police-arrest-cyber-army-russia-reborn-member/
#CyberSecurity #CyberCrime #Hacking #FBI #Spain #Russia #CyberArmyOfRussiaReborn
📣🚨 #FortiBleed is now linked to ransomware activity, with SOCRadar connecting Fortinet credential theft to INC Ransom and Lynx. A Nextcloud zero-day is also under review.
Listen to or read this news: https://hackread.com/fortibleed-credential-theft-in-lynx-ransomware/
📣 🔐 WhatsApp is adding usernames so you can start chats without sharing your phone number. Users can reserve a username now, with the full feature expected later this year.
Read or listen to this news: https://hackread.com/whatsapp-usernames-chat-without-sharing-phone-number/
#Cyberbit is shutting down its Israel operations and laying off local staff as the cybersecurity training firm continues growing mainly in the US after its RangeForce acquisition.
Listen/read more: https://hackread.com/cybersecurity-firm-cyberbit-shuts-down-israel-op/
📣🚨 Anonymous-linked Canadian hacktivist #AubreyCottle, known as Kirtaner, has been jailed for 18 months over the 2021 Texas GOP website cyberattack.
Listen or read: https://hackread.com/anonymous-hacktivist-aubrey-cottle-gop-cyberattack/
#Anonymous #Hacktivist #CyberAttack #Cybersecurity #TexasGOP
Researchers say #Fiverr left user files on Cloudinary open to Google Search, exposing sensitive documents like IDs and tax records.
Read: https://hackread.com/fiverr-left-user-files-open-to-google-search/
📢⚠️ Bluesky is back online after a roughly 24-hour DDoS attack disrupted services, with the Iran-linked 313 Team claiming responsibility.
Read: https://hackread.com/bluesky-online-ddos-attack-iran-313-team/
#CyberSecurity #CyberAttack #DDoSAttack #Bluesky #Iran #313Team
📢⚠️ Hackers are now using hidden website instructions to manipulate AI assistants through indirect prompt injection (IPI) - New research shows these attacks are already happening on real websites.
Read: https://hackread.com/hackers-hidden-site-instruction-attack-ai-assistants/
📣🚨 Researchers spotted 212 new websites registered after the #Venezuela earthquake, prompting donation scam warnings over fake relief pages, crypto requests, and missing person forms.
Listen or read: https://hackread.com/venezuela-earthquake-domains-donation-scam-warnings/
📣🚨 Woodgnat hackers are using a new backdoor called #Mistic to let brokers compromise networks and sell entry points to ransomware groups.
Listen/Read: https://hackread.com/woodgnat-hackers-mistic-rat-access-ransomware-gangs/
📣🚨 #GTA6 scams are luring fans with fake early access, crypto payments, and malware downloads targeting both Android and PC users.
Listen or Read: https://hackread.com/gta-6-early-access-websites-gamers-malware-crypto-scam/
New #GhostShell hacking group is targeting Ukraine’s drone defense sector with fake Besomar-themed documents, spyware, and Vidar malware.
Listen or read: https://hackread.com/ghostshell-hacking-group-ukraine-drone-defense-sector/
📢⚠️ Vercel confirms breach linked to #ContextAI as a hacker listed alleged data for $2M. ShinyHunters denies involvement and flags impostors.
Read: https://hackread.com/vercel-breach-context-ai-shinyhunters-not-involved/
📢⚠️ #OperationPowerOFF - Authorities identify and warn 75,000 users of DDoS-for-hire services worldwide, arresting 4, and seizing 53 domains.
Read: https://hackread.com/operation-poweroff-ddos-for-hire-services-identified/
📢⚠️ Fake CAPTCHA ClickFix campaign tricks users into running malicious commands, abusing native Windows tools to avoid detection.
Read: https://hackread.com/clickfix-variant-native-windows-tools-bypass-security/
New GoGra Linux Malware expands Harvester APT attacks, infecting systems via fake PDFs and using Microsoft APIs for stealthy control.
Read: https://hackread.com/harvester-apt-spying-new-gogra-linux-malware/
#CyberSecurity #GoGra #Linux #Malware #HarvesterAPT #Microsoft
📢⚠️ Discord-linked group accessed Claude Mythos Preview through a third-party vendor environment, prompting an investigation by Anthropic.
Read: https://hackread.com/discord-access-anthropic-claude-mythos-ai-breach/
#CyberSecurity #Anthropic #Mythos #Claude #AI #Discord #DataBreach
📢⚠️ Grinex crypto exchange collapses after $13.7M breach, blames Western spies as researchers flag possible exit scam.
Read: https://hackread.com/grinex-crypto-exchange-shuts-down-west-agency-breach/
📢⚠️ An ongoing malicious campaign called #StealTok is using browser extensions on Chrome and Microsoft Edge to steal user data and spy on their browser activity.
Read: https://hackread.com/fake-tiktok-downloaders-chrome-edge-spy-users/
📢⚠️ Critical RCE flaw in protobuf.js exposes apps to code execution via malicious schemas - 52M weekly downloads, patch now available.
Read: https://hackread.com/52m-download-protobuf-js-library-rce-schema-handle/
📢⚠️ Hackers are exploiting a 5-year-old #ShowDoc vulnerability (CVE-2025-0520) to deploy web shells, enabling RCE and full server takeover worldwide.
Read: https://hackread.com/showdoc-vulnerability-patch-2020-server-takeover/
📢⚠️ #Nexcorium, a new Mirai-based malware, is targeting DVR devices to turn them into a botnet for DDoS attacks worldwide.
Read: https://hackread.com/mirai-variant-nexcorium-dvr-devices-ddos-attacks/
A lone hacker exploited #ClaudeCode and GPT-4.1 to exfiltrate hundreds of millions of Mexican citizens' records from 9 government agencies.
Read: https://hackread.com/hacker-claude-code-gpt-4-1-mexican-records/
FBI Atlanta and Indonesian police have seized and taken down #W3LLSTORE, a notorious phishing marketplace linked to $20 million in fraud, seizing domains and detaining the developer.
Read: https://hackread.com/fbi-atlanta-indonesian-police-w3llstore-phishing-market/
⚠️🪝 Bluekit phishing kit is now active at scale, using Browser-in-the-Middle attacks, bot checks, and fake CAPTCHA pages to steal logins while evading detection.
Listen or read: https://hackread.com/bluekit-phishing-uses-browser-in-the-middle-attacks/
🚨 TeamPCP hijacks Bitwarden CLI in supply chain attack, abusing GitHub Dependabot to deploy Shai-Hulud malware and steal developer secrets, poison AI coding tools.
Read: https://hackread.com/teampcp-bitwarden-cli-dependabot-shai-hulud-malware/
#CyberSecurity #TeamPCP #Malware #Bitwarden #GitHub #Dependabot
A fake FIFA World Cup 2026 T-shirt giveaway spreads Voidrift malware through personalized emails using company logos and trusted websites to bypass security filters.
Listen to or read this news: https://hackread.com/hackers-fake-fifa-world-cup-2026-t-shirt-voidrift-malware/
📢⚠️ French police arrest 20-year-old HexDex hacker, caught as he prepared to leak more stolen data from multiple targeted organisations.
Read: https://hackread.com/french-police-arrest-hexdex-hacker-data-leak-leaks/
#CyberSecurity #CyberCrime #France #BreachForums #DarkForums
📢⚠️ Hackers are exploiting a 5-year-old #ShowDoc vulnerability (CVE-2025-0520) to deploy web shells, enabling RCE and full server takeover worldwide.
Read: https://hackread.com/showdoc-vulnerability-patch-2020-server-takeover/
📣🚨 Spotted: #JADEPUFFER, the first documented agentic ransomware operation in which an LLM agent abused a Langflow flaw, stole credentials, reached production MySQL, and destroyed Nacos config data.
Listen/Read: https://hackread.com/sysdig-jadepuffer-first-agentic-ransomware-operation/
Authorities seized domains linked to Israeli proxy provider NetNut after Google reported disrupting the company’s residential proxy network, which it says drew on at least 2 million devices, including smart TVs and streaming boxes.
Read: https://hackread.com/fbi-seizes-netnut-domains-google-disrupts-proxy-network/
#CyberSecurity #Botnet #Malware #CyberCrime #Android #ProxyNetwork
📣🚨 A #GoogleNotes browser extension is being spread through malicious sites, replacing copied crypto payment details and putting wallet transfers at risk for Chrome, Brave, and Microsoft Edge users.
Listen/Read: https://hackread.com/fake-google-notes-browser-extension-swap-crypto-wallets/
📣🚨 Brazil’s alert system was taken offline after a fake emergency warning reached phones, with officials investigating a suspected cyberattack and security failure.
Read: https://hackread.com/cyberattack-sends-fake-emergency-alert-phones-brazil/
📢 Tyler Robert Buchanan, a 24-year-old British hacker linked to Scattered Spider, admits to a multi-year US hacking scheme involving at least $8M in crypto theft.
Read: https://hackread.com/british-hacker-tyler-buchanan-guilty-hacking-scheme/
📢⚠️ Watch out as China-linked #MustangPanda is deploying an updated LOTUSLITE backdoor to target Indian banks and South Korean diplomats.
Read: https://hackread.com/mustang-panda-india-s-korea-lotuslite-backdoor/
📣🚨 A #macOS XPC flaw let regular users disable CrowdStrike and Kandji tools, exposing security gaps that vendors patched after being reported.
Listen or Read: https://hackread.com/macos-flaw-users-disable-crowdstrike-kandji-security-tools/
#CyberSecurity #InfoSec #EndpointSecurity #CrowdStrike #Kandji
📢⚠️ #Microsoft vulnerabilities fall, but critical flaws double. BeyondTrust report highlights rising risk in Microsoft Office, Azure, and cloud systems.
Read: https://hackread.com/microsoft-vulnerabilities-drop-critical-flaws-double/
Watchout as new #PamStealer malware is targeting macOS users through a fake #Maccy clipboard app, using AppleScript and a Rust payload to steal passwords, browser data, and clipboard content.
Listen to or read this news: https://hackread.com/pamstealer-malware-macos-fake-maccy-clipboard-app/
📣🚨 Fake Google and Cloudflare verification pages are being abused in new ClickFix campaigns that deliver seven malware families, including some of the most notorious infostealers seen in recent months.
Listen or Read: https://hackread.com/clickfix-scam-google-cloudflare-7-malware-families/
📢⚠️ Watch out as 4 new Android malware families, RecruitRat, SaferRat, Astrinox, and Massiv, have been found targeting 800 banking and crypto apps.
Read: https://hackread.com/recruitrat-saferrat-astrinox-massiv-android-malware/
📣🚨 #OperationEndgame disrupts StealC malware infrastructure, seizing millions of stolen credentials and targeting servers used in global cybercrime campaigns.
Listen or Read: https://hackread.com/operation-endgame-stealc-amadey-socgholish-malware/




















