NSA GRASSMARLIN
NSA's discontinued GRASSMARLIN tool has an XXE vulnerability (CVE-2026-6807) enabling local attackers to extract sensitive data. Though archived since 2017, legacy deployments remain at risk.
ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks • How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts • The US military just turned off ad tracking on its phones. Maybe you should too • Hackers exploit Tencent app flaw to deploy GrayRabbit malware • CRPx0 ransomware: what you need to know ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks • How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts • The US military just turned off ad tracking on its phones. Maybe you should too • Hackers exploit Tencent app flaw to deploy GrayRabbit malware • CRPx0 ransomware: what you need to know
The full HackWire archive — 3,892 stories, newest first.
NSA's discontinued GRASSMARLIN tool has an XXE vulnerability (CVE-2026-6807) enabling local attackers to extract sensitive data. Though archived since 2017, legacy deployments remain at risk.
Rival ransomware groups 0APT and KryBit breached each other's systems, exposing operational data, infrastructure details, and attack procedures. The leaked intelligence gave defenders rare visibility into how ransomware-as-a-service operations function.
VECT 2.0 ransomware contains a critical bug that permanently destroys files instead of properly encrypting them due to improper cryptographic nonce handling. Victims face irreversible data loss regardless of whether they pay the ransom, transforming what should be recoverable encryption into destruc
Enterprises deploy AI ad-hoc without governance, creating compliance and security risks. SecurityWeek's webinar outlines a practical roadmap for transitioning to controlled, scalable AI frameworks that align with emerging regulations.
Cyber insurance claims data shows financial losses from security gaps, giving CISOs concrete evidence to justify budgets—translating abstract technical risks into quantifiable bottom-line impact that boards understand.
Law enforcement takedowns of Lumma and Rhadamanthys infostealers fragmented the market. Vidar malware has now consolidated power as the primary credential-stealing tool for cybercriminals.
A critical RCE vulnerability (CVE-2026-3854, CVSS 8.7) in GitHub enables authenticated users to execute code via git push. The command injection flaw requires only push access, threatening supply chains with simple, weaponizable exploits.
Vimeo's user data was exposed through a breach at vendor Anodot, a third-party anomaly detection service. The incident demonstrates supply-chain vulnerability: even strong security is compromised when trusted third parties are breached.
Autonomous AI agents operating independently and learning from defenses represent a new cybersecurity threat. Enterprises must deploy AI-driven defenses to counter these threats at machine speed.
Vimeo confirmed a data breach as hacking group ShinyHunters demanded ransom for stolen user and customer data. The extortion attack underscores growing threats to major SaaS platforms relied on by millions of creators.
Brazilian cybercrime group LofyGang has resurfaced with LofyStealer malware disguised as a Minecraft mod. It targets players through social engineering to steal credentials, wallets, and system data.
A 19-year-old Scattered Spider member was arrested in Finland, marking law enforcement's escalation against the hacker collective. The group is linked to major data breaches and ransomware campaigns.
LAPSUS$ hacked Checkmarx and stole GitHub data, affecting a security platform trusted by enterprises. The breach is significant because LAPSUS$ is known for aggressive extortion of major tech companies.
A GlassWorm malware campaign deployed 70+ cloned extensions in Open VSX, deceiving developers with fake versions of legitimate VS Code tools. These dormant sleeper agents await remote activation to steal credentials, source code, and establish persistence in development environments.
Attackers exploited a Robinhood vulnerability to send phishing emails from legitimate platform servers. The active campaign stole credentials and account access from thousands of users.
GlassWorm distributes malicious VS Code extensions through Open VSX that self-propagate malware and compromise developer environments. Dozens of infected extensions have reached thousands.
VECT 2.0 ransomware's encryption flaw permanently destroys files over 131KB—making recovery impossible for all. The design failure transforms this extortion tool into a wiper affecting Windows, Linux, and ESXi.
Silk Typhoon hacker Xu Zewei extradited to US for targeting American universities to steal research. The case marks a rare diplomatic win against Chinese state-sponsored cyber espionage operations.
Zero Trust deployments commonly stall at data movement—the overlooked security gap. Organizations wrongly assume proper access controls complete the security equation, but research from the Cyber360 report shows secure data transit requires continuous oversight throughout the data lifecycle.
Threat actors are publishing OPSEC playbooks that democratize evasion techniques. This professionalization enables less-experienced operators to adopt sophisticated tradecraft while reducing attribution risk.
Microsoft deprecates legacy TLS in Exchange Online from July 2026 to fix security flaws. Older email clients lose compatibility, but organizations gain protection against email interception.
Microsoft Remote Desktop fails to display critical security warnings, risking unsafe connections to compromised systems and bypassing protections against man-in-the-middle attacks. This flaw creates a dangerous security gap for enterprises relying on RDP for administrative access.
PhantomRPC is an unpatched Windows privilege escalation technique that mimics legitimate RPC services to gain System-level access. It requires no Microsoft patch, forcing organizations to implement their own defenses against this attack that exploits legitimate Windows functionality.
Security researchers uncovered vulnerabilities in Zero Motorcycles and Yadea scooters enabling remote system attacks. These flaws threaten rider safety and enable vehicle theft or location tracking through compromised vehicle controls and GPS data.