Login
HN Monitor

A critical security vulnerability in the Everest Forms Pro WordPress plugin, affecting approximately 4,000 active installations, is being actively exploited by threat actors to execute arbitrary code, leading to full website compromise. This remote code execution (RCE) flaw, identified as CVE-2026-3300, carries a severe CVSS score of 9.8 and impacts…

The cybersecurity landscape is constantly evolving, and a recent development concerning the last layer standing in network defense has caught the attention of IT professionals worldwide. A report released this week by the Global Cybersecurity Institute (GCI) highlights emerging threats and the increasing importance of multi-factor authentication (MFA) as a…

Flaw in Claude Code GitHub Action Uncovered, Posing Repository Takeover Risk A security vulnerability has been discovered in Anthropic’s Claude Code GitHub Action, allowing attackers to potentially hijack vulnerable public repositories. The flaw, reported by security researcher RyotaK of GMO Flatt Security, could enable a malicious actor to execute arbitrary…

The cybersecurity landscape continues to present complex challenges, with a persistent blend of evolving threats and persistent vulnerabilities. This ongoing dynamic highlights the critical importance of robust security practices and continuous vigilance for organizations across all sectors. As the digital realm expands, the intricate web of threats, from sophisticated nation-state…

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability affecting the Mirasvit Cache Warmer Magento extension to its Known Exploited Vulnerabilities (KEV) catalog. The move comes after reports of attackers actively exploiting the flaw, tracked as CVE-2026-45247, in the wild, posing a significant risk to e-commerce…

A sophisticated phishing campaign is actively targeting businesses worldwide by exploiting Meta’s legitimate Business Manager notifications. Cybercriminals are sending deceptive emails that are virtually indistinguishable from genuine Meta communications, leveraging the platform’s infrastructure to deliver malicious links. This tactic, identified by Trustwave SpiderLabs, bypasses standard email security checks by originating…

A sophisticated hack-for-hire campaign targeting journalists and activists in the Middle East and North Africa has been uncovered, utilizing advanced spyware and infrastructure linked to a group with suspected Indian government connections. This discovery, detailed in reports released Wednesday by three collaborating cybersecurity organizations, highlights the persistent threat faced by…

A sophisticated router compromise campaign orchestrated by Russian state-sponsored attackers has been neutralized after compromising over 18,000 routers in more than 120 countries. This extensive espionage network, identified as Forest Blizzard, aimed to gain deep access into sensitive networks before its recent shutdown by international law enforcement and cybersecurity firms.…

A novel supply chain attack has been uncovered, specifically targeting software developers who utilize artificial intelligence (AI) coding tools. On March 20, 2026, a threat actor released a malicious npm package named `gemini-ai-checker` under the `gemini-check` account. This package was deceptively presented as a utility for verifying Google Gemini AI…

Cybercriminals are increasingly exploiting misconfigurations within Kubernetes clusters to gain access to cloud accounts, moving beyond individual containers to target core infrastructure. Recent telemetry data reveals a significant surge in Kubernetes-related threat operations, particularly service account token theft, which saw a 282% increase over the past year, with the information…

A sophisticated and dangerous Linux backdoor known as BPFDoor has resurfaced with significant enhancements, making it exceedingly difficult to detect and eradicate. Researchers have identified new variants of this malware specifically engineered to infiltrate and persist within critical network infrastructure, particularly targeting Linux servers embedded in global telecommunications networks. This…

A new sophisticated cyber threat is emerging, targeting Windows users with a deceptive social engineering tactic dubbed “ClickFix.” This method lures victims into executing malicious code via a fake browser verification page, ultimately leading to the installation of a powerful Node.js-based Remote Access Trojan (RAT). This RAT leverages the anonymity…

Annual cybercrime losses climbed to nearly $20.9 billion last year, marking a significant 26% surge compared to 2024. This data comes from the FBI’s Internet Crime Complaint Center (IC3) annual report, released Tuesday, which paints a grim picture of escalating digital threats and their financial consequences. The report reveals that…

A sophisticated and prolonged malware campaign, identified as REF1695, has been actively deceiving users into downloading fake software installers. These deceptive applications secretly deploy potent remote access trojans (RATs) and Monero cryptocurrency miners, operating undetected for at least two years. The financially motivated threat actor behind this operation has been…

Organizations across the United States have become targets of a sophisticated multi-stage phishing campaign that leverages legitimate remote monitoring and management (RMM) tools, including LogMeIn Resolve and ScreenConnect, to bypass security measures and gain illicit access. The operation, which began as early as April 2025 with a surge in activity…