Hacking News Breaking Cybersecurity. No Filter.

Hacking News

Breaking Cybersecurity. No Filter.

Latest Articles

Someone Else Is Mining Crypto on Your Dime — And Your Cloud Dashboard Is Hiding It
Investigation

Someone Else Is Mining Crypto on Your Dime — And Your Cloud Dashboard Is Hiding It

Threat actors are quietly embedding cryptocurrency mining processes inside compromised cloud environments, racking up compute costs while evading conventional security tooling. The attack surface is broader than most IT teams realize, and the forensic trail is deliberately faint. Here's what's actually happening inside your AWS, Azure, or GCP environment right now.

Poison Pen: How Hackers Are Turning Your Internal Wiki Into a Slow-Burn Sabotage Machine
Investigation

Poison Pen: How Hackers Are Turning Your Internal Wiki Into a Slow-Burn Sabotage Machine

Threat actors have discovered that the most effective way into an organization isn't through a firewall — it's through a how-to guide. A growing wave of attacks is targeting internal knowledge bases like Confluence, Notion, and SharePoint, quietly rewriting company documentation to steer employees into installing backdoors and blowing up their own security configurations. The scariest part? Every victim thinks they're just following the rules.

The Last Line of Defense Just Became the First Point of Entry: How Attackers Are Living Inside Your Backup Infrastructure
Investigation

The Last Line of Defense Just Became the First Point of Entry: How Attackers Are Living Inside Your Backup Infrastructure

Ransomware crews and nation-state actors have quietly shifted their focus away from hardened production environments and toward the one system every organization trusts blindly: backups. By the time most security teams figure out what happened, the attackers have been camping in cold storage for months. Here's how they do it — and why your incident response playbook is probably missing the whole chapter.

One Template to Pwn Them All: The Quiet Crisis Unfolding Inside Your Infrastructure-as-Code Stack
Investigation

One Template to Pwn Them All: The Quiet Crisis Unfolding Inside Your Infrastructure-as-Code Stack

Reusable Terraform modules and CloudFormation templates have become the backbone of modern DevOps — and attackers know it. A single poisoned IaC template can silently backdoor hundreds of organizations at once, and most security teams have no idea it's happening. We dug into how this attack vector works, why it's spreading, and what the industry is doing (or not doing) about it.

One Wrong Letter, Millions of Compromised Machines: The Dark Art of Package Name Hijacking
Investigation

One Wrong Letter, Millions of Compromised Machines: The Dark Art of Package Name Hijacking

Attackers don't always need sophisticated exploits — sometimes a single mistyped package name is all it takes to hand over root access to an entire organization. Typosquatting in package managers has quietly become one of the most effective and underreported attack vectors in modern software supply chains. We dug into the economics, the real-world casualties, and why your automated scanners are probably missing it.

Your Boss Is on the Call — Except It Isn't: The Rise of Deepfake Executive Scams Targeting Corporate Employees
Investigation

Your Boss Is on the Call — Except It Isn't: The Rise of Deepfake Executive Scams Targeting Corporate Employees

Threat actors are now cloning the faces and voices of C-suite executives with off-the-shelf AI tools to run hyper-convincing social engineering attacks against corporate employees. The scam is frighteningly simple to execute, and your existing security training almost certainly won't catch it. We dug into how it works — and why it's spreading fast.

Here and Gone: The New Wave of Malware That Erases Itself Before You Even Know It Was There
Investigation

Here and Gone: The New Wave of Malware That Erases Itself Before You Even Know It Was There

A new class of malware is hitting enterprise networks and leaving behind absolutely nothing — no files, no logs, no evidence. Self-destructing code is turning traditional incident response into a ghost hunt, and most security teams aren't even close to ready for it.

Your Favorite Dev Tool Just Became a Backdoor: How Attackers Are Hiding Inside Your Debugging Workflow
Investigation

Your Favorite Dev Tool Just Became a Backdoor: How Attackers Are Hiding Inside Your Debugging Workflow

The tools developers trust most — REPLs, live code runners, and interactive debuggers — are quietly being turned into weapons. Attackers have figured out that the fastest way onto a developer's machine isn't a phishing email. It's a helpful utility that fits right into the daily grind.

When the Assembly Line Gets Hacked: Why Your Build Server Is the Most Dangerous Machine in Your Stack
Investigation

When the Assembly Line Gets Hacked: Why Your Build Server Is the Most Dangerous Machine in Your Stack

Attackers aren't bothering to crack your code anymore — they're going after the machines that compile it. A wave of sophisticated intrusions targeting CI/CD build infrastructure is quietly turning trusted software pipelines into delivery vehicles for enterprise-grade malware, and most security teams aren't even looking in the right direction.

Phantom Patches and Ghost CVEs: How AI Hallucinations Are Being Turned Into Cyber Weapons
Investigation

Phantom Patches and Ghost CVEs: How AI Hallucinations Are Being Turned Into Cyber Weapons

Security teams are getting played by convincing-but-fake threat intelligence generated by AI models that simply made things up. From fabricated CVEs to ghost advisories, attackers are learning to weaponize the one thing defenders trust most — their own tools.

Always Listening, Always Selling: The Hidden Data Economy Living Inside Your Smart Speaker
Investigation

Always Listening, Always Selling: The Hidden Data Economy Living Inside Your Smart Speaker

Your Amazon Echo and Google Nest aren't just waiting for wake words — they're part of a sprawling data pipeline that funnels behavioral audio signals to brokers you've never heard of. We dug into the technical reality of what these devices actually capture, which companies have the worst records, and the legal loopholes that make all of it completely above board.

The Blinking Light on Your Desk Is Watching You: How Office Printers Became the Perfect Hacker Entry Point
Investigation

The Blinking Light on Your Desk Is Watching You: How Office Printers Became the Perfect Hacker Entry Point

Security teams spend millions locking down endpoints, firewalls, and cloud infrastructure — then leave the $400 multifunction printer in the corner completely unpatched for three years. Attackers have noticed. Here's how they're walking through that open door and what your team can do before the next breach audit finds it first.

Your Face Is No Longer Your Password: The Rise of AI-Cloned Identities Cracking Biometric Gates
Investigation

Your Face Is No Longer Your Password: The Rise of AI-Cloned Identities Cracking Biometric Gates

Attackers are no longer just guessing passwords — they're synthetically rebuilding your face. A new wave of AI-generated video attacks is quietly dismantling the biometric authentication systems that enterprises and consumers were told were unbreakable. Here's what's actually happening on the front lines.

Turned Against the Team: How Attackers Are Quietly Converting Your Security Staff Into Their Best Asset
Investigation

Turned Against the Team: How Attackers Are Quietly Converting Your Security Staff Into Their Best Asset

The people you've hired to protect your organization may already be compromised — not through malware, but through manipulation. A growing body of evidence shows threat actors are deliberately studying security team dynamics, access privileges, and internal culture to flip defenders into unwitting accomplices. Here's how it happens, and why most companies never see it coming.

Ghost Sessions: How Hackers Are Raiding Your Browser's Memory Without Touching Your Password
Investigation

Ghost Sessions: How Hackers Are Raiding Your Browser's Memory Without Touching Your Password

You changed your password. You enabled MFA. You did everything right — and they still got in. The dirty secret of modern authentication is that your password is often the least interesting thing an attacker wants. What they're really after is already sitting in your browser's memory, waiting to be scooped up.

Hunting the Hunters: The Calculated Playbook Threat Actors Use to Flip Security Pros Into Victims
Opinion

Hunting the Hunters: The Calculated Playbook Threat Actors Use to Flip Security Pros Into Victims

Security engineers spend their careers learning to spot manipulation — and attackers know it. The most dangerous social engineering campaigns aren't aimed at the receptionist or the new hire anymore. They're precision-crafted for the people who are supposed to stop them, and they're working.

They Read Your Slack Before They Phished You: How Attackers Are Mastering Your Company's Culture to Walk Right Through the Front Door
Opinion

They Read Your Slack Before They Phished You: How Attackers Are Mastering Your Company's Culture to Walk Right Through the Front Door

Modern social engineering attacks aren't just spoofing email addresses anymore — they're spoofing entire corporate identities. Threat actors are spending weeks studying org charts, internal lingo, office politics, and team dynamics before making a single move. The result is attacks so culturally fluent that even security-aware employees get fooled, and the playbook is getting more sophisticated by the month.

Trojan Weights: The Hidden Threat Lurking Inside Every Pre-Trained Model You Pull from the Internet
Investigation

Trojan Weights: The Hidden Threat Lurking Inside Every Pre-Trained Model You Pull from the Internet

Researchers are sounding the alarm on a new class of supply chain attack that doesn't target your code — it targets the AI models you're plugging directly into production. Poisoned neural networks are quietly making their way through Hugging Face, GitHub, and other popular repositories, carrying malicious behaviors that no antivirus on earth will catch. Here's what's actually happening, and why the security community is only beginning to understand the scope.

Passwordless Was Supposed to Save Us. So Why Are We Still Typing 'Password123'?
Opinion

Passwordless Was Supposed to Save Us. So Why Are We Still Typing 'Password123'?

The security industry declared passwords dead years ago. FIDO2, WebAuthn, and passkeys were supposed to bury them for good. But walk into almost any American enterprise in 2024 and you'll find the same sticky notes on monitors, the same quarterly password resets, and the same help desk tickets about forgotten credentials. Here's why the post-password future is taking forever to arrive.

The Phishing Email That Knows Your Boss's Writing Style — AI Did That
Investigation

The Phishing Email That Knows Your Boss's Writing Style — AI Did That

Generative AI didn't just make phishing emails better-written — it made them personal, scalable, and nearly impossible to catch with traditional filters. Security researchers are documenting a new generation of AI-assisted social engineering attacks that can clone communication styles, adapt in real time, and defeat the defenses most organizations have spent years building. This is what that looks like from the inside.