News
27, 000-Download Codex UI Tool Secretly Stole Open AI Refresh Tokens
7+ hour, 33+ min ago (198+ words) A popular software tool used by thousands of mobile developers has been found stealing authentication tokens. On 27 May 2026, Aikido Security shared research with Hackread. com about a malicious npm package called codexui-android. For context, it is a highly popular remote…...
Iran's Nimbus Manticore Used Trojanized Zoom Installers Against US Firms
4+ day, 4+ hour ago (257+ words) If you installed Zoom from unofficial sites earlier this year, your device may have been exposed to malware linked to Iran's Nimbus Manticore hackers. Check Point Research (CPR) recently exposed a series of cyberattacks carried out by an Iranian group…...
Rondo Dox Botnet Exploits Critical 2018 Vulnerability to Hijack ASUS Routers
1+ week, 1+ day ago (424+ words) Cybersecurity firm Vuln Check's latest research reveals that cybercriminals are now targeting old models of ASUS routers by exploiting a software vulnerability from 2018, tracked as CVE-2018-5999. This is a critical unauthenticated configuration update vulnerability with a CVSS score of 9. 8/10 that…...
Git Hub Breach: Team PCP Steals 3, 800 Repositories via VS Code Extension
1+ week, 4+ day ago (483+ words) Git Hub is the newest target of a data breach in which hackers from the infamous Team PCP hackers bypassed its security to gain access to internal systems and steal proprietary source code. This widely used software hosting platform detected…...
Pwn2 Own Berlin 2026 Closes With $1. 3 Million in Zero-Day Payouts
1+ week, 5+ day ago (406+ words) The highly anticipated Pwn2 Own Berlin 2026 hacking competition concluded on 16 May 2026, following three days of intense activity at the Offensive Con conference, and we have all the results. The event saw massive financial payouts, with researchers receiving around $1, 298, 250 in total for…...
Hackers Actively Exploit "Nginx Rift" Vulnerability Affecting NGINX, F5 Products
1+ week, 5+ day ago (851+ words) Discovered by researchers at Depthfirst using an AI-assisted detection platform, CVE-2026-42945 is a heap-based buffer overflow (CWE-122) found inside the ngx_http_rewrite_module and affects NGINX Open Source versions 0. 6. 27 through 1. 30. 0, NGINX Plus versions R32 through R36, and several tied-in F5 products, including the NGINX Ingress Controller…...
Pwn2 Own Berlin 2026 Reportedly Hits Capacity as Rejected Hackers Release 0-Days
2+ week, 5+ day ago (335+ words) The world's most famous hacking contest is facing a crisis it didn't see coming. For the first time in 19 years, Pwn2 Own Berlin 2026 has reportedly run out of space. The event, run by Trend Micro's Zero Day Initiative (ZDI), hit a…...
Google Says Hackers Used AI to Develop a Zero-Day Exploit
2+ week, 6+ day ago (425+ words) Google researchers have discovered the first evidence of hackers using AI to develop zero-day exploits, autonomous Android backdoors, and automated supply chain attacks against Git Hub and Py PI. Hackers have long used AI models to create phishing pages and…...
9-Year-Old Dirty Frag Vulnerability Enables Root Access on Linux Systems
2+ week, 6+ day ago (533+ words) Dirty Frag is the collective name researchers assigned to two Linux vulnerabilities that existed in the Linux kernel for around nine years before being discovered. Red Hat, a major American software firm, has released a report on two Linux kernel…...
Best OSINT Tools for Investigations and Threat Intelligence in 2026
3+ week, 4+ day ago (1023+ words) OSINT tools help people collect and analyze publicly available data from across the internet. In 2026, these tools play a bigger role in tracking digital footprints, identifying security threats, and supporting investigations. From social media platforms to DNS server records, open-source…...