Sign in

Hackread.com

@hackread.bsky.social
1.8K followers 14 following 1.6K posts

The official Bluesky account of the most reliable cybersecurity news platform brings exclusive dark web, tech, hacking news, and much more. Contact: admin@hackread.com.

PostsRepliesMedia
Hackread.com @hackread.bsky.social · 1h
⚠️📢 Global Group ransomware is abusing the legitimate WinMerge application to retrieve its encryptor after victims are lured through payment-themed phishing emails and malicious ISO files. Listen/Read: hackread.com/global-group... #Ransomware #GlobalGroup #WinMerge #Phishing #Cybersecurity
hackread.com
Global Group Ransomware Abuses WinMerge to Deploy Encryptor
Cofense researchers reveal how Global Group uses payment-themed phishing, malicious ISO files and WinMerge to deploy ransomware and extort large enterprises.
000
Hackread.com @hackread.bsky.social · 6h
⚠️📢🪝Amazon Prime users, watch out! A convincing phishing scam uses fake billing alerts and a multi-step Amazon lookalike site to steal login credentials, personal information and complete payment card details. More: hackread.com/amazon-prime... #Amazon #AmazonPrime #Phishing #Cybersecurity #Scam
hackread.com
Amazon Prime Phishing Scam Uses Fake Billing Alert to Steal Logins and Card Details
An Amazon Prime phishing campaign is using fake payment alerts to steal account logins, personal data and complete credit or debit card details from unsuspecting customers.
000
Hackread.com @hackread.bsky.social · 19h
⚠️📢 Dutch police say a 24-year-old suspect in the #ShinyHunters investigation is also suspected of trying to arrange two murders abroad. Police clarified the murder case is separate from the cybercrime investigation. Listen/Read: hackread.com/dutch-shinyh... #Cybercrime #Cybersecurity #DutchPolice
hackread.com
Dutch ShinyHunters Suspect Investigated for Trying to Arrange 2 Murders
Dutch police say a ShinyHunters suspect is also suspected of trying to arrange two murders abroad, a case separate from the cybercrime investigation.
001
Hackread.com @hackread.bsky.social · 29/09/2026
⚠️📢 Students, job seekers, and university staff, watch out as hackers are hijacking university accounts to scam students, steal personal data, run advance-fee scams, and even impersonate an FBI agent. Listen/Read: hackread.com/hackers-hija... #Cybersecurity #Phishing #Scam #FBI #JobScam
hackread.com
Hackers Use Hijacked University Emails to Scam Students, Pose as FBI Agent
Proofpoint uncovers hackers using compromised university accounts for fake job offers, credential theft and gift card scams, including FBI impersonation.
000
Hackread.com @hackread.bsky.social · 29/09/2026
A 16-year-old hacker found an authentication flaw in Microsoft’s Titan analytics service, gaining admin-level SQL access to an environment whose metadata indicated 17.3 trillion stored data rows. Listen/Read: hackread.com/teen-hacker-... #Microsoft #Cybersecurity #Hacking #BugBounty #Azure
hackread.com
Teen Hacker Finds Auth Flaw in Microsoft System With 17.3 Trillion Data Rows
A teen hacker found an authentication flaw in Microsoft’s Titan analytics service, where metadata indicated an estimated 17.3 trillion stored rows.
030
Hackread.com @hackread.bsky.social · 28/09/2026
📢 Exclusive: ShinyHunters tells Hackread it will not publish or sell the FBI data it claims to have stolen when its ultimatum ends, saying a data leak was never planned. Listen/Read: hackread.com/exclusive-sh... #ShinyHunters #FBI #Cybersecurity #Cybercrime #DataBreach
hackread.com
Exclusive: ShinyHunters Says FBI Data Won’t Be Leaked When Ultimatum Ends
ShinyHunters tells Hackread it never planned to publish or sell stolen FBI data and says its ultimatum was part of a marketing campaign to counter FBI claims.
012
Hackread.com @hackread.bsky.social · 28/09/2026
⚠️📢 Dutch police have arrested a 23-year-old suspect in the ShinyHunters investigation into the Odido breach. Sources identify him as a previously convicted hacker, Pepijn van der Stap. Listen/Read: hackread.com/convicted-du... #ShinyHunters #Odido #Cybersecurity #Cybercrime #Netherlands
hackread.com
Previously Convicted Dutch Hacker Arrested in ShinyHunters Odido Probe
Dutch police arrested convicted hacker Pepijn van der Stap in the ShinyHunters probe into the Odido breach, which exposed data belonging to millions of customers.
011
Hackread.com @hackread.bsky.social · 28/09/2026
⚠️📢 A fake email thread fooled an AI summarizer in all 60 tests, inserting fabricated dates and invoice amounts without hidden text or obvious instructions. Listen/Read: hackread.com/fake-email-t... #AI #Cybersecurity #PromptInjection #EmailSecurity #InfoSec
hackread.com
Fake Email Thread Tricks AI Summarizer Without Hidden Text
Forcepoint research shows fake email threads can manipulate AI email summarizers without hidden text or direct instructions, inserting fabricated details.
033
Hackread.com @hackread.bsky.social · 28/09/2026
⚠️📢 A tech support scam kit is abusing Google Ads to push fake security alerts that make browsers appear locked. Netskope observed exposure across 619 organizations. Listen/Read: hackread.com/tech-support... #GoogleAds #TechSupportScam #Cybersecurity #Scam
hackread.com
Tech Support Scam Kit Uses Google Ads to Deliver Fake Security Alerts
Google Ads deliver a tech support scam kit that shows fake security alerts, makes browsers appear locked and targets users across hundreds of organizations.
032
Hackread.com @hackread.bsky.social · 26/09/2026
⚠️📢 Placeholder domains referenced across 359,000 GitHub files and 349 AI agent skills were found redirecting some visitors to cloaked scams, including fake security alerts and investment schemes. Listen/Read: hackread.com/placeholder-... #AIAgents #Cybersecurity #GitHub #Scams #InfoSec
hackread.com
Placeholder Domains Used by 349 AI Agent Skills Found Redirecting to Scams
Manifold Security found placeholder domains cited in 359,000 GitHub files and 349 AI agent skills serving cloaked scam redirects observed on macOS.
011
Hackread.com @hackread.bsky.social · 26/09/2026
ShinyHunters is back, exploiting Oracle PeopleSoft, using URL encoding to bypass WAF rules on unpatched systems before deploying web shells and the SIDEEYE backdoor. Listen/Read: hackread.com/shinyhunters... #ShinyHunters #PeopleSoft #Oracle #Cybersecurity #WAF #CyberAttack
hackread.com
ShinyHunters Bypass WAF Rules to Resume Oracle PeopleSoft Attacks
ShinyHunters exploit CVE-2026-35273 in Oracle PeopleSoft using URL encoding to bypass WAF rules, deploy web shells and spread the SIDEEYE backdoor.
041
Hackread.com @hackread.bsky.social · 25/09/2026
⚠️📡📶🌐 Your phone could connect to a rogue 5G cell without a tap or warning. Researchers tested 5G-Shark on real devices, collecting identifiers and disrupting service without jamming mobile networks. Listen/Read: hackread.com/5g-shark-pho... #5G #MobileSecurity #Cybersecurity #Privacy
hackread.com
5G-Shark Lures Phones to Rogue 5G Cells Without Network Jamming
Researchers developed 5G-Shark to lure phones onto rogue base stations, collect subscriber IDs, force network downgrades and trigger service disruptions.
023
Hackread.com @hackread.bsky.social · 25/09/2026
⚠️📢 Attackers modified files from legitimate audio software to hide and launch SectopRAT. The malware steals passwords, cookies, card details and crypto wallet data while giving attackers remote control of the PC. Listen/Read: hackread.com/sectoprat-ab... #SectopRAT #Windows #Malware #Cybersecurity
hackread.com
SectopRAT Abuses Legitimate Audio Software Files to Steal PC Data
FortiGuard found SectopRAT hidden in modified audio software files, using staged loading to steal browser data and remotely control infected Windows PCs.
022
Hackread.com @hackread.bsky.social · 25/09/2026
⚠️📢 Just In: Attackers stole $351.6 million from #Bitget, forcing the exchange to suspend withdrawals. The company suspects North Korea’s Lazarus Group is behind the hack after it directly breached its servers. Listen/Read: hackread.com/bitget-hack-... #Crypto #Lazarus #Cybersecurity #Bitcoin
hackread.com
Bitget Confirms $351.6 Million Hack, Suspects North Korea’s Lazarus Group
Bitget confirms a $351.6 million theft, suspends withdrawals and says North Korea's Lazarus Group may be involved as investigators examine the breach in detail.
001
Hackread.com @hackread.bsky.social · 24/09/2026
An OpenAI agent breached an Australian Medicare statistics portal. After its requests were blocked, it found another way in and accessed non-public files. hackread.com/openai-agent... #OpenAI #Cybersecurity #Medicare #Australia
hackread.com
OpenAI Agent Breached Australian Medicare Statistics Portal
An OpenAI agent bypassed controls on Australia's Medicare statistics portal, accessed non-public data and was not reported to officials for nearly 3 months.
000
Hackread.com @hackread.bsky.social · 24/09/2026
Microsoft’s password reset page can tell attackers more than it should, including which accounts exist, their recovery methods and, in some cases, which users may be administrators. Listen/Read: hackread.com/microsoft-pa... #Microsoft #Cybersecurity #AccountSecurity #Phishing
hackread.com
Microsoft Password Reset Portal Can Leak Account Verification Details
LevelBlue found Microsoft’s password reset portal can reveal valid accounts, recovery methods and likely administrator accounts without user authentication.
020
Hackread.com @hackread.bsky.social · 24/09/2026
Another day, another Windows malware - A fake DocuSign page tells victims to paste a command into their computer, quietly opening the door to AvisLoader malware Listen/Read: hackread.com/avisloader-w... #Cybersecurity #Malware #ClickFix #AvisLoader #Scam
hackread.com
New AvisLoader Windows Malware Uses ClickFix Lure and Tox P2P for C2
Varonis Threat Labs discovered AvisLoader, a Windows malware loader that uses the Tox peer-to-peer network for C2 and arrives through a malicious ClickFix lure.
010
Hackread.com @hackread.bsky.social · 23/09/2026
For about $25 per target, open-source AI agents scanned companies, exploited vulnerabilities, installed payment skimmers and destroyed database tables. At least 27 firms were breached and 600K credit card records stolen. Read: hackread.com/open-source-... #Cybersecurity #AIAgents #DataBreach #AI
hackread.com
Open-Source AI Agents Breach 27 Companies, Steal 600,000 Credit Card Records
Gambit Security found AI agents breached 27 companies, stole 600,000 credit card records and installed payment skimmers across compromised retail sites.
142
Hackread.com @hackread.bsky.social · 23/09/2026
#EvilTokens turned stolen inboxes into AI-assisted fraud operations - Microsoft has now seized 50 websites and disabled over 150 related domains, while 2 have been arrested. More: hackread.com/microsoft-di... #Microsoft #Phishing #Cybercrime #Cybersecurity
hackread.com
Microsoft Disrupts AI-Powered EvilTokens Service Linked to 12,000 Hacked Inboxes
Microsoft disrupted EvilTokens after the AI-powered phishing service compromised 12,000 inboxes across 10,000 organisations and enabled complex financial fraud.
010
Hackread.com @hackread.bsky.social · 22/09/2026
ShinyHunters defaced the official FBI Jobs portal and claims it obtained sensitive data on FBI agents, along with people who applied for jobs at the bureau. Listen/Read: hackread.com/shinyhunters... #FBI #ShinyHunters #Cybersecurity #DataBreach #Cybercrime #Hacking
hackread.com
ShinyHunters Hacks FBI Jobs Portal, Claims It Stole Agents' Data
ShinyHunters hacks the FBI Jobs portal and claims sensitive data on nearly all FBI agents and job applicants before the site is taken offline for security work.
010
Hackread.com @hackread.bsky.social · 22/09/2026
RatHat is not your typical Android banking malware. It uses generative #AI to navigate infected devices in real time, steal banking credentials, and intercept OTP codes, and can even reinstall itself after removal. Listen/Read: hackread.com/rathat-andro... #Cybersecurity #Android #Malware #RatHat
hackread.com
RatHat Android Malware Uses AI to Target Banking Credentials in Real Time
RatHat Android malware uses generative AI to navigate infected devices, steal banking credentials, intercept OTP codes and reinstall itself after removal again.
021
Hackread.com @hackread.bsky.social · 22/09/2026
Watch out: MovieReaper is infecting users through compromised torrents disguised as "The Odyssey", with Kaspersky identifying several hundred victims across multiple countries. Listen/Read: hackread.com/moviereaper-... #Cybersecurity #MovieReaper #Malware #Torrents #TheOdyssey
hackread.com
MovieReaper Malware Uses The Odyssey Torrents to Infect Users Worldwide
MovieReaper malware spreads through compromised Odyssey torrents, infecting hundreds of victims while using Solana to locate command-and-control infrastructure.
000
Hackread.com @hackread.bsky.social · 22/09/2026
TASK#STOMP backdoor is built to keep stealing business documents, watch for new or modified files, and give attackers continued access to infected Windows systems. Listen/Read: hackread.com/taskstomp-wi... #Cybersecurity #Malware #TASKSTOMP #Windows
hackread.com
New TASK#STOMP Windows Backdoor Enables Continuous Document Theft
TASK#STOMP Windows backdoor uses PowerShell, scheduled tasks and runtime C# compilation to steal business documents and maintain remote access.
011
Hackread.com @hackread.bsky.social · 21/09/2026
Clop has resurfaced on its own onion site with a message for ShinyHunters after the group hijacked its leak site and demanded an eight-figure payment, interest and a public apology. Listen/Read: hackread.com/clop-ransomw... #Cybersecurity #Clop #ShinyHunters #Ransomware #Cybercrime #DarkWeb
hackread.com
Clop Ransomware Responds to ShinyHunters Amid Eight-Figure Demands
Clop responds to ShinyHunters after its leak site takeover as the group demands an eight-figure payment, interest and a public apology in their escalating feud.
032
Hackread.com @hackread.bsky.social · 21/09/2026
China-linked FamousSparrow is targeting government organizations across Latin America with SparroWocky, a new C++ backdoor built for espionage and stealth. Listen/Read: hackread.com/china-famous... #Cybersecurity #FamousSparrow #SparroWocky #Malware #China #LatinAmerica
hackread.com
China-Linked FamousSparrow Deploys SparroWocky Backdoor in Latin America
FamousSparrow is targeting Latin American governments with SparroWocky, a new C++ backdoor that exfiltrates files, takes screenshots and evades security tools.
031
Hackread.com @hackread.bsky.social · 21/09/2026
Fake Spotify, Zoom and Teams installers are being used in ClickFix attacks to spread ChainScript, a Node.js RAT that uses Polygon smart contracts to locate its C2 server. Listen/Read: hackread.com/clickfix-cha... #Cybersecurity #Malware #ClickFix #ChainScript #NodeJS #Polygon
hackread.com
ClickFix Attacks Spread ChainScript RAT via Fake Spotify and Teams Installers
Blackpoint Cyber found ChainScript, a Node.js RAT spread through fake Spotify, Zoom and Teams installers that uses Polygon smart contracts to locate its C2 server.
021
Hackread.com @hackread.bsky.social · 19/09/2026
ShinyHunters hacked and defaced Clop's ransomware leak site, replacing its content with ShinyHunters branding as its own onion site goes offline. Listen/Read: hackread.com/shinyhunters... #CyberSecurity #CyberCrime #ShinyHunters #Cl0p #Ransomware
hackread.com
ShinyHunters Hacks and Defaces Clop Ransomware Leak Site
ShinyHunters hacked and defaced Clop's ransomware leak site, replacing its content with ShinyHunters branding as its own onion site goes offline.
012
Hackread.com @hackread.bsky.social · 18/09/2026
⚠️📢🪝Revolut customers are receiving phishing texts featuring a fake video identity check and password request, days after sensitive customer data was exposed. Listen/Read: hackread.com/revolut-cust... #Revolut #Phishing #Cybersecurity #DataBreach #Scam
hackread.com
Revolut Customers Targeted by Phishing Campaign After Data Breach
Revolut customers are being targeted with phishing texts days after a social engineering attack exposed sensitive customer data, including IDs and selfies.
010
Hackread.com @hackread.bsky.social · 18/09/2026
A 3-person cybersecurity team used #ClaudeAI to help hack OpenAI during authorized research, taking over employee accounts and reaching an internal code repository in under 72 hours. The reward? A $6,500 bug bounty. Listen/Read: hackread.com/cybersecurit... #Cybersecurity #OpenAI #BugBounty #AI
hackread.com
Cybersecurity Startup Uses Claude AI to Hack OpenAI, Earns $6,500 Bug Bounty
Hacktron AI used Anthropic's Claude to help exploit OpenAI flaws, compromise employee accounts and reach an internal code repository, earning a $6,500 bounty.
000
Hackread.com @hackread.bsky.social · 18/09/2026
⚠️📢🪝Fake OpenAI billing emails are sending ChatGPT users to convincing phishing pages designed to steal account credentials and payment information. Listen/Read: hackread.com/openai-billi... #Cybersecurity #ChatGPT #OpenAI #Phishing #Scam
hackread.com
Fake OpenAI Billing Emails Target ChatGPT Users in Credential Harvesting Phishing Scam
Cofense researchers identified phishing emails impersonating OpenAI billing notices to steal ChatGPT credentials and payment information.
020
Hackread.com @hackread.bsky.social · 17/09/2026
The new GhostCode turns Microsoft’s legitimate device authentication flow against its users, stealing valid tokens after MFA and registering attacker-controlled devices in minutes. Listen/Read: hackread.com/ghostcode-ph... #Cybersecurity #GhostCode #Phishing #Microsoft365
hackread.com
New GhostCode Phishing Kit Hijacks Microsoft Accounts Despite MFA
eSentire uncovers the GhostCode phishing kit abusing Microsoft OAuth to steal tokens, register attacker devices and access Microsoft 365 accounts.
023
Hackread.com @hackread.bsky.social · 16/09/2026
FBI and RCMP have seized domains linked to #NightmareStresser, a DDoS-for-hire service used to launch hundreds of thousands of attacks and attempted attacks worldwide since 2022. Listen/Read: hackread.com/operation-po... #Cybersecurity #DDoS #FBI #OperationPowerOFF #CyberCrime
hackread.com
FBI Seizes NightmareStresser DDoS-for-Hire Domains in Operation PowerOFF
FBI and RCMP seize NightmareStresser domains after the DDoS-for-hire service was linked to hundreds of thousands of attacks and attempted attacks worldwide.
033
Hackread.com @hackread.bsky.social · 16/09/2026
Two critical flaws in The Events Calendar WordPress plugin put 600,000+ installations at risk, allowing unauthenticated attackers to execute code or take over sites. Listen/Read: hackread.com/critical-cal... #Cybersecurity #WordPress #RCE #Vulnerability #Wordfence
hackread.com
2 Critical Calendar WordPress Plugin Flaws Put 600K Sites at Risk of Takeover
Two critical RCE flaws in The Events Calendar expose 600,000+ WordPress installations to unauthenticated attacks, with CVSS scores of 9.8.
011
Hackread.com @hackread.bsky.social · 16/09/2026
#CrowdStrike has linked AI-generated PhantomRaven malware to a self-described bug bounty hunter accused of using malicious npm packages to compromise company systems. Listen/Read: hackread.com/crowdstrike-... #Cybersecurity #PhantomRaven #Malware #BugBounty #AI
hackread.com
CrowdStrike Links AI-Generated PhantomRaven Malware to Bug Bounty Hunter
CrowdStrike links PhantomRaven malware to a bug bounty hunter, finding LLM-generated code, malicious npm packages and attempts to compromise company IT systems.
033
Hackread.com @hackread.bsky.social · 15/09/2026
Oleksii Lytvynenko, a Ukrainian member of the Conti ransomware operation, has been sentenced to four years in a US prison after admitting his role in attacks that harmed at least 12 companies. Listen/Read: hackread.com/ukrainian-co... #Cybersecurity #Ransomware #Conti #Cybercrime #Ukraine
hackread.com
Ukrainian Conti Ransomware Member Gets 4 Years in US Prison
Ukrainian national Oleksii Lytvynenko gets four years in US prison for his role in the Conti ransomware operation, which targeted over 1,000 victims.
033
Hackread.com @hackread.bsky.social · 15/09/2026
⚠️📢🪝Hackers are posing as IT support and using fake passkey requests to hijack Microsoft 365 accounts, capture authentication tokens and access corporate cloud data. Listen/Read: hackread.com/hackers-it-s... #Cybersecurity #Microsoft365 #Phishing #Passkeys #Microsoft
hackread.com
Hackers Pose as IT Support, Use Fake Passkey Lures to Steal Microsoft 365 Access
Microsoft warns of fake passkey and IT support attacks targeting Microsoft 365 accounts to steal authentication tokens and access corporate cloud data.
033
Hackread.com @hackread.bsky.social · 15/09/2026
Hackers are actively exploiting the critical #StyleSmuggler zero-day to compromise Adobe Commerce and Magento stores, with researchers finding Linux backdoors and PHP web shells on affected systems. Listen/Read: hackread.com/stylesmuggle... #Cybersecurity #Magento #Adobe #0Day #Vulnerability
hackread.com
StyleSmuggler 0-Day Exploited to Hack Adobe Commerce and Magento Stores
A critical Adobe Commerce and Magento zero-day dubbed StyleSmuggler is under active attack, allowing hackers to execute PHP code without authentication.
010
Hackread.com @hackread.bsky.social · 14/09/2026
Florida has confirmed a DMV data breach after #ShinyHunters claimed access. Our review found 612,982 ZIP archives containing SSN cards, licenses, immigration docs and other sensitive records. Listen/Read: hackread.com/florida-dmv-... #Cybersecurity #DataBreach #FloridaDMV #Privacy
hackread.com
Florida Confirms DMV Breach as ShinyHunters Leak Exposes SSN Cards and Licenses
Florida DMV confirms breach after ShinyHunters claimed access, while leaked files contain SSN cards, licences, immigration records and government documents.
022
Hackread.com @hackread.bsky.social · 14/09/2026
Trellix’s latest threat-hunting report traces state-backed phishing, the #DarkSword iPhone exploit kit, a Node.js-based crypto stealer, and poisoned Axios npm packages across five covert campaigns. Listen/Read: hackread.com/trellix-dark... #Cybersecurity #ThreatResearch #Malware #APT28
hackread.com
Trellix Report Details DarkSword, JSCeal, Axios npm Attack and APT28 Campaigns
DarkSword, JSCeal, Axios, Bitter APT, and APT28 campaigns reveal evolving tactics targeting iPhones, Southeast Asia, software supply chains, diplomatic organizations, and European governments.
021
Hackread.com @hackread.bsky.social · 14/09/2026
Thousands of suspicious Android apps found abusing Google Play Early Access to push fake rewards, deepfake promotions, misleading utilities, and fraudulent ad clicks. Listen/Read: hackread.com/google-play-... #Cybersecurity #Android #GooglePlay #Scams #Deepfake
hackread.com
Google Play Early Access Abused by Thousands of Suspicious Android Apps
Bitdefender finds thousands of suspicious Android apps abusing Google Play Early Access with fake rewards, deepfake ads, misleading utilities and brand impersonation.
032
Hackread.com @hackread.bsky.social · 12/09/2026
⚠️📢 🫴🤝 Revolut handed sensitive customer data to scammers after fraudulent government requests were sent through a legitimate government agency email domain. Listen/Read: hackread.com/revolut-gave... #Cybersecurity #Revolut #DataBreach #Privacy #Bitcoin
hackread.com
Revolut Gave Customer Data to Scammers After Fake Government Requests
Revolut handed customer passports, verification selfies, IBANs and Bitcoin transaction records to scammers who used a legitimate government agency email domain.
012
Hackread.com @hackread.bsky.social · 11/09/2026
⚠️📢🪝Fake sexual misconduct and Title IX claims are being used in phishing emails targeting US universities, with victims directed through Google Drive to install Zoho RAT. Listen/Read: hackread.com/fake-sexual-... #Cybersecurity #Phishing #ZohoRAT #Universities #Malware
hackread.com
Fake Sexual Misconduct Emails Target Universities with Zoho RAT
Cofense details a phishing campaign targeting healthcare-linked universities through Google Drive links that lead recipients to install Zoho RAT.
023
Hackread.com @hackread.bsky.social · 10/09/2026
⚠️📢 Anthropic has disclosed a 4th Claude AI hacking incident after Opus 4.6 gained unauthorized access to a real third-party system during a cybersecurity test. The case was missed in an earlier review. Listen/Read: hackread.com/anthropic-fi... #Anthropic #ClaudeAI #Cybersecurity #AI #Hacking
hackread.com
Anthropic Finds 4th Claude AI Hacking Incident Missed in Earlier Review
Anthropic reveals a 4th Claude AI hacking incident after Opus 4.6 accessed a real system, leading to a review of 481 million evaluation transcripts.
022
Hackread.com @hackread.bsky.social · 10/09/2026
⚠️📢 Hackers are using hundreds of AI agents to exploit two PaperCut zero-days at scale, with at least 440 servers compromised across 395 organizations in 48 countries. Listen/Read: hackread.com/hackers-use-... #Cybersecurity #PaperCut #AI #0Day #Vulnerability
hackread.com
Hackers Use Hundreds of AI Agents to Exploit PaperCut Zero-Days
Blackpoint Cyber and GreyNoise detail attacks exploiting two PaperCut zero-days, with hundreds of AI agents used to compromise servers across 48 countries.
031
Hackread.com @hackread.bsky.social · 10/09/2026
A newly uncovered Linux malware is targeting F5 BIG-IP APM systems and hiding a web shell in memory, allowing it to stay out of sight during normal file checks. Listen/Read: hackread.com/f5-big-ip-ap... #Cybersecurity #Malware #F5 #BIGIP #Linux #WebShell
hackread.com
F5 BIG-IP APM Linux Malware Hides PHP Web Shell in Apache Memory
Sophos found Linux malware targeting F5 BIG-IP APM that injects a PHP web shell into Apache memory, helping attackers evade file-based detection.
011
Hackread.com @hackread.bsky.social · 09/09/2026
A new AI workflow flaw dubbed Workflow Identity Hijacking could let outsiders access sensitive internal data simply by asking, without prompt injection or jailbreaks. Listen/Read: hackread.com/ai-workflow-... #Cybersecurity #AI #ArtificialIntelligence #Vulnerability
hackread.com
AI Workflow Flaw Could Let Attackers Access Sensitive Data by Simply Asking
Noma Labs has identified Workflow Identity Hijacking, an AI workflow flaw that can let attackers abuse privileged access to sensitive internal data without prompt injection.
022
Hackread.com @hackread.bsky.social · 09/09/2026
🖥️🩹 Microsoft’s September #PatchTuesday is its biggest yet, fixing 966 vulnerabilities, including 2 Windows 0-days already exploited in attacks. Critical RCE flaws also affect Office, networking services and Hyper-V. Listen/Read: hackread.com/microsoft-pa... #Microsoft #Windows #0Day #Cybersecurity
hackread.com
Microsoft Patch Tuesday Fixes 966 Vulnerabilities, Including 2 Exploited 0-Days
Microsoft Patch Tuesday fixes 966 vulnerabilities, including two exploited Windows zero-days, critical RCE flaws, and bugs in Office, networking and Hyper-V.
022
Hackread.com @hackread.bsky.social · 08/09/2026
⚠️📢 Mathspace says hackers exploited an unpatched Metabase flaw and downloaded account data belonging to 1.08 million students, parents, guardians and staff in Australia and New Zealand. Listen/Read: hackread.com/mathspace-da... #DataBreach #Cybersecurity #Mathspace #Metabase
hackread.com
Mathspace Data Breach Affects 1.08 Million Students, Parents and Staff
Mathspace says hackers exploited a Metabase flaw and downloaded account data belonging to 1.08 million students, parents and staff in Australia and New Zealand.
000
Hackread.com @hackread.bsky.social · 08/09/2026
⚠️📢 Fake Google Voice voicemail alerts are being sent from compromised accounts to lure victims into a live Google login relay. Attackers then intercept passwords, 2FA codes, and authenticated sessions. Listen/Read: hackread.com/hackers-goog... #Cybersecurity #Phishing #Google #2FA #Scam
hackread.com
Hackers Stream Real Google Login Pages to Steal Passwords and 2FA Codes
Researchers found a phishing service relaying live Google sign-in sessions to intercept passwords, 2FA codes, and active authenticated account sessions.
010
Hackread.com @hackread.bsky.social · 08/09/2026
ShinyHunters claims it breached Florida’s motor vehicle agency and has posted a detailed Jeffrey Epstein DAVID record as evidence. Listen/Read: hackread.com/shinyhunters... #ShinyHunters #FloridaDMV #DataBreach #Cybersecurity #Epstein
hackread.com
ShinyHunters Claims Florida DMV Breach, Posts Jeffrey Epstein Record as Proof
ShinyHunters claims access to Florida driver records and posts a Jeffrey Epstein DAVID screenshot, although FLHSMV has not confirmed any breach yet.
000