avatar
The Hacker News
@thehackernews
07.04.2026 21:53
�� WARNING - APT28 ran a global router hijack to steal credentials.

The group compromised MikroTik and TP-Link devices, rewrote DNS settings, and redirected traffic for credential theft at scale -- impacting 18,000+ IPs across 120 countries, including government and cloud targets.

�� Read here → https://thehackernews.com/2026/04/russian-state-linked-apt28-exploits.html
🔥 6
😱 2
👍 1
26 2.8K
avatar
The Hacker News
@thehackernews
07.04.2026 21:33
--- ⚠️ WEBINAR ALERT ---

The biggest identity risk in 2026 isn’t inside your IAM. It’s everything outside it.

Hundreds of unmanaged apps are now being accessed by AI agents, expanding risk beyond what your team can see or control.

�� Join the WEBINAR for data and practical steps to close the gaps → https://thehackernews.com/2026/04/webinar-how-to-close-identity-gaps-in.html
👍 6
🔥 1
11 2.9K
avatar
The Hacker News
@thehackernews
07.04.2026 17:51
Most attacks don’t start with exploits anymore. They start with access.

Across thousands of real-world incidents analyzed in the 2026 Annual Threat Report, one pattern is clear:

Attackers aren’t breaking in.
They’re logging in.

Here’s what we’re seeing:
↳ Legitimate credentials are the #1 entry point
↳ Remote access tools are being used against you
↳ Traditional detection is missing what looks “normal”

This isn’t theory. This is what actually worked for attackers in 2025.

If your security strategy is still built around stopping malware, you’re already behind.

Download the Blackpoint Cyber 2026 Annual Threat Report and see how modern attacks are actually unfolding.

Download the report: https://thn.news/blackpoint-threat-2026
👍 5
🔥 1
👏 1
15 4.2K
avatar
The Hacker News
@thehackernews
07.04.2026 14:39
Ilan Nacmias at Sygnia shares a case where AI security tools worked, but no decisions were made.

Risks were clear, but teams disagreed and leaders saw things as under control. Progress came only after linking risk to business impact.

�� Why AI didn’t fix execution in cybersecurity → https://thehackernews.com/expert-insights/2026/04/ai-will-change-cybersecurity-humans.html
🔥 6
1
10 4.5K
avatar
The Hacker News
@thehackernews
06.04.2026 23:39
⚠️ Iran-linked actors targeted Microsoft 365 accounts in 3 attack waves in March 2026, hitting 300+ orgs in Israel and 25+ in the UAE.

They used password spraying via Tor/VPNs to access mailboxes.

At the same time, Pay2Key ransomware resurfaced with stronger evasion and log wiping.

�� Read → https://thehackernews.com/2026/04/iran-linked-password-spraying-campaign.html
👏 16
🔥 9
😁 5
🤯 5
👍 1
29 6.7K
avatar
The Hacker News
@thehackernews
06.04.2026 21:07
�� Attackers now move across Windows, macOS, Linux, and mobile in one campaign.

Multi-OS attacks break SOC workflows, splitting one threat into many investigations and slowing validation.

That delay gives attackers time to spread and persist.

�� Why fragmented triage increases risk → https://thehackernews.com/2026/04/multi-os-cyberattacks-how-socs-close.html
🤯 7
👍 1
🔥 1
🤔 1
19 6.1K
avatar
The Hacker News
@thehackernews
06.04.2026 19:32
Automated pentesting evaluates environments through chained attack paths. If step A fails, steps B through Z never execute.

One blocked step near the top = cascading blind spot across every downstream technique.

Picus Security mapped these two other structural gaps in a new whitepaper.

Download now → https://thn.news/automated-blind-spots
5
🔥 4
👍 2
11 6K
avatar
The Hacker News
@thehackernews
06.04.2026 18:11
⚠️ A compromised AI library exposed developer machines.

1,705 packages pulled infected LiteLLM versions, harvesting SSH keys and cloud creds from local systems via dependencies.

It worked because secrets sit in plaintext across files and tools.

�� How one dependency exposed thousands of environments → https://thehackernews.com/2026/04/how-litellm-turned-developer-machines.html
🤯 8
🔥 6
👍 1
15 5.8K
avatar
The Hacker News
@thehackernews
06.04.2026 18:08
Everything hit at once this week ...

�� Supply-chain: Axios hack
�� Exploits: Chrome 0-day, TrueConf, Fortinet
�� Patches: Apple DarkSword fixes
�� Malware: ClickFix, DeepLoad, Mirax, Venom
�� Leak: Claude code exposure
�� Phishing: device code surge, banking scams
��️ Privacy: LinkedIn tracking claims
��️ Spyware: Paragon use confirmed
�� Infra: residential proxy abuse
�� Targeting: crypto org attacks
�� Policy: India SIM-binding
�� APT: access regain attempts
�� Insider: extortion case
❤️ Data: OkCupid settlement
�� Trend: stealer surge, malicious extensions

Read the full recap → https://thehackernews.com/2026/04/weekly-recap-axios-hack-chrome-0-day.html
🔥 8
6
😱 3
👏 2
👍 1
26 5.6K
avatar
The Hacker News
@thehackernews
06.04.2026 16:16
AI isn’t making attacks smarter, says Martin Zugec, Technical Solutions Director at Bitdefender. It’s making them cheaper and easier to scale.

Current AI malware is often unreliable and less advanced, but it can hit thousands of standardized systems fast.

�� Why scale matters more than sophistication in AI threats → https://thehackernews.com/expert-insights/2026/04/why-ai-does-not-need-to-be-innovative.html
😁 7
👍 3
👏 2
🔥 1
20 5.8K
avatar
The Hacker News
@thehackernews
06.04.2026 15:10
�� Qilin and Warlock #ransomware are disabling defenses before attacks using BYOVD techniques.

Qilin uses a side-loaded DLL to kill 300+ EDR drivers via vulnerable kernel drivers. Warlock exploits SharePoint and uses similar drivers to bypass kernel-level security, often delaying ransomware execution.

�� Find the technique disabling EDR tools → https://thehackernews.com/2026/04/qilin-and-warlock-ransomware-use.html
🤯 7
👏 5
🔥 3
25 6.2K
avatar
The Hacker News
@thehackernews
05.04.2026 23:26
�� North Korea-linked hackers spent 6 months building trust before stealing $285M from Drift.

They posed as a trading firm, met contributors in person, deposited $1M+, then used malicious code and a fake wallet app to gain access.

�� How social engineering enabled the Drift crypto theft → https://thehackernews.com/2026/04/285-million-drift-hack-traced-to-six.html
😱 22
🤯 12
🔥 10
😁 6
👍 5
👏 2
49 7.9K

The Hacker News

162.3K
⭐ Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

📨 Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Открыть в Telegram