$290M DeFi Hack, macOS LoL Abuse, ProxySmart SIM Farms +25 New Stories

Ravie LakshmananApr 23, 2026Hacking News / Cybersecurity News You scroll past one incident and see another that feels familiar, like it should have been fixed years ago, but it still works with small changes. Same bugs. Same mistakes. The supply chain is messy. Packages you did not check are stealing data, adding backdoors, and spreading. […]

Defeat automated exploits at the speed of AI

hacker newsApril 23, 2026Artificial Intelligence/Enterprise Security Imagine a world where hackers don’t sleep, don’t take breaks, and find weaknesses in systems instantly. Well, that world is already there. Thanks to AI, attackers can now execute large-scale, automated exploits faster than ever before. The time to remediate vulnerabilities before being attacked has been reduced to zero. […]

Project Glasswing proved that AI can find bugs. Who will fix it?

Last week, Anthropic announced Project Glasswing, an AI model so effective at finding vulnerabilities in software, that it took the unusual step of delaying its public release. Instead, the company granted access to Apple, Microsoft, Google, Amazon, and other allied companies so they could find and patch bugs before adversaries did. Mythos Preview, the model […]

China-linked GopherWhisper infects 12 Mongolian government systems with Go backdoor

Ravi LakshmananApril 23, 2026Threat Intelligence/Malware Mongolian government agencies have emerged as targets of a previously undocumented China-aligned Advanced Persistent Threat (APT) group tracked as GopherWhisper. “The group leverages a wide range of tools, primarily written in Go, and uses injectors and loaders to deploy and execute various backdoors in its arsenal,” Slovak cybersecurity firm ESET […]

Vercel finds more compromised accounts in breach related to Context.ai

Ravi LakshmananApril 23, 2026Artificial Intelligence / SaaS Security Vercel said Wednesday that it has identified a set of additional customer accounts that were compromised as part of a security incident that allowed unauthorized access to its internal systems. The company said it made the discovery after expanding its investigation to include an additional set of […]

Apple patches iOS flaw that saved Signal notifications deleted in FBI investigation

Ravi LakshmananApril 23, 2026Vulnerabilities/Encryption Apple has released a software fix for iOS and iPadOS to address a flaw in the Notifications service that stores notifications marked for deletion on the device. This vulnerability is tracked as CVE-2026-28950 (CVSS score: N/A) and is described as a logging issue that is resolved with improved data redacting. “Notifications […]

Malicious KICS Docker image and VS Code extension impact Checkmarx supply chain

Ravi LakshmananApril 22, 2026Cloud security/software security Cybersecurity researchers have warned about malicious images being pushed to the official “checkmarx/kics” Docker Hub repository. Socket, a software supply chain security company, revealed in an alert published today that an unknown attacker was able to successfully overwrite existing tags, including v2.1.20 and alpine, while simultaneously introducing a new […]

Self-propagating supply chain worm hijacks npm packages and steals developer tokens

Cybersecurity researchers have flagged a new set of packages that have been compromised by malicious parties to distribute a self-propagating worm that spreads through stolen developer npm tokens. The supply chain worm has been detected by both Socket and StepSecurity, and both companies are tracking the activity under the name CanisterSprawl because it used ICP […]

Harvester uses Microsoft Graph API to bring Linux GoGra backdoor to South Asia

Ravi LakshmananApril 22, 2026Cyber ​​espionage/malware The attacker, known as Harvester, is believed to have originated from a new Linux version of the GoGra backdoor, possibly introduced as part of an attack targeting organizations in South Asia. “This malware uses the legitimate Microsoft Graph API and Outlook mailboxes as covert command-and-control (C2) channels, allowing it to […]

Lotus Wiper Malware Destroys Venezuelan Energy Systems

Ravi LakshmananApril 22, 2026Malware/Critical Infrastructure Cybersecurity researchers have discovered a previously undocumented data wiper used in attacks targeting Venezuela between late last year and early 2026. According to Kaspersky Lab’s findings, this novel file wiper, called Lotus Wiper, was used in a destructive campaign targeting Venezuela’s energy and utilities sector. “The two batch scripts are […]