The Hacker News
Most trusted, widely-read independent cybersecurity news source for everyone; supported by hackers and IT professionals.
- FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malwareby info@thehackernews.com (The Hacker News) on July 20, 2026 at 6:23 pm
Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a malware family known as SmartLoader as part of an ongoing campaign codenamed FakeGit. “FakeGit uses copied projects, lookalike developer profiles, convincing READMEs, and malicious ZIP
- Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaignby info@thehackernews.com (The Hacker News) on July 20, 2026 at 5:29 pm
A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering an infostealer through a fake government ID-lookup site over WebDAV. What makes it more than a
- HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050by info@thehackernews.com (The Hacker News) on July 20, 2026 at 2:33 pm
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050. Group-IB, which named the malware HollowGraph, says the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic, so the activity looks
- ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and Moreby info@thehackernews.com (The Hacker News) on July 20, 2026 at 1:32 pm
A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being used before defenders had time to patch. Here is the full
- Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraineby info@thehackernews.com (The Hacker News) on July 20, 2026 at 12:13 pm
At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops. That is the finding of a cybersecurity advisory published July 10 by the AIVD and MIVD, the Netherlands’ civilian and military intelligence
Security Magazine
Security magazine provides security industry news and trends on video surveillance, cyber security, physical security, security guards, access management and more for security executives and the security industry.
- Cyberattack Halts Coca-Cola’s Fairlife Productionson July 21, 2026 at 5:00 am
A company owned by Coca-Cola paused operations following a cyberattack.
- Hugging Face Confirms Data Breach Caused by Autonomous AI Agenton July 20, 2026 at 4:16 pm
A host platform for AI models and datasets confirmed it had experienced a data breach.
- Security’s 2026 Women in Securityon July 20, 2026 at 1:30 pm
Recognized for their achievements and influence, this year’s honorees drive progress throughout their organizations.
- Dr. Jazma Mekelle Parker — Women in Security 2026on July 20, 2026 at 9:00 am
Dr. Jazma Mekelle Parker began her security career as a contract background investigator for the U.S. Office of Personnel Management (OPM).
- Hannah Behnke — Women in Security 2026on July 20, 2026 at 9:00 am
At the age of 18, Hannah Behnke took her first step into the security world in a classic way: she got a job as a “mall cop.”
Threatpost
The first stop for security news.
- Student Loan Breach Exposes 2.5M Recordsby Nate Nelson on August 31, 2022 at 12:57 pm
2.5 million people were affected, in a breach that could spell more trouble down the line.
- Watering Hole Attacks Push ScanBox Keyloggerby Nate Nelson on August 30, 2022 at 4:00 pm
Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.
- Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firmsby Nate Nelson on August 29, 2022 at 2:56 pm
Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system.
- Ransomware Attacks are on the Riseby Nate Nelson on August 26, 2022 at 4:44 pm
Lockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group.
- Cybercriminals Are Selling Access to Chinese Surveillance Camerasby Nate Nelson on August 25, 2022 at 6:47 pm
Tens of thousands of cameras have failed to patch a critical, 11-month-old CVE, leaving thousands of organizations exposed.
Security Weekly
Connecting the Security Industry with the Security Community















