PROBABLYPWNED
Home/Hacking News

Hacking News

Breaking cybersecurity news covering data breaches, vulnerability disclosures, threat actor campaigns, and security incidents worldwide.

782Articles
104Data Breaches
263Vulnerabilities
Gitea Flaw Exposed Private Container Images for 4 Years
Vulnerabilities3 min read

Gitea Flaw Exposed Private Container Images for 4 Years

CVE-2026-27771 let attackers pull private container images without authentication. Over 30,000 Gitea deployments affected across healthcare, aerospace, and retail. Update to 1.26.2 now.

Marcus ChenMay 28, 2026
AD Password Policies That Users Won't Hate
Security Guides4 min read

AD Password Policies That Users Won't Hate

NIST's updated password guidelines eliminate forced expiration and complexity rules. Here's how to enforce strong Active Directory passwords without driving users to workarounds.

Emily ParkMay 27, 2026
Varonis Atlas Monitors Claude AI With New Compliance API
Announcements4 min read

Varonis Atlas Monitors Claude AI With New Compliance API

Varonis joins 27 other security vendors integrating Anthropic's Claude Compliance API, enabling enterprises to monitor AI conversations, detect data leaks, and enforce governance policies in real time.

ProbablyPwned TeamMay 26, 2026
FBI Warns Kali365 PhaaS Steals Microsoft 365 Tokens at Scale
Threat Intelligence4 min read

FBI Warns Kali365 PhaaS Steals Microsoft 365 Tokens at Scale

New phishing-as-a-service platform bypasses MFA via OAuth device code flow. FBI PSA details how Kali365's AI-generated lures and $250/month pricing are enabling widespread credential theft.

Alex KowalskiMay 24, 2026
Trend Micro Apex One Zero-Day Added to CISA KEV
Vulnerabilities3 min read

Trend Micro Apex One Zero-Day Added to CISA KEV

CVE-2026-34926 lets attackers inject malicious code into Apex One servers and deploy it to all connected endpoint agents. CISA confirms active exploitation with June 4 federal deadline.

Marcus ChenMay 24, 2026
MuddyWater Exploits Langflow Flaw for Initial Access
Vulnerabilities3 min read

MuddyWater Exploits Langflow Flaw for Initial Access

CISA adds CVE-2025-34291 to KEV after Iranian APT MuddyWater weaponizes the CORS/CSRF chain for account takeover and RCE. CVSS 9.4 flaw requires only a malicious link click.

Marcus ChenMay 24, 2026
Megalodon Attack Backdoors 5,561 GitHub Repos in Six Hours
Malware4 min read

Megalodon Attack Backdoors 5,561 GitHub Repos in Six Hours

Automated Megalodon campaign pushed 5,718 malicious commits to GitHub repos on May 18, injecting CI/CD workflows that exfiltrate cloud credentials, SSH keys, and secrets. SafeDep links it to TeamPCP.

James RiveraMay 23, 2026
Laravel-Lang Supply Chain Attack Deploys Credential Stealer
Malware4 min read

Laravel-Lang Supply Chain Attack Deploys Credential Stealer

Attackers compromised 700+ versions of Laravel-Lang PHP packages via tag poisoning, deploying a sophisticated stealer targeting cloud credentials, crypto wallets, and browser data. Packagist pulled affected versions.

James RiveraMay 23, 2026
Apache HTTP/2 Double-Free Enables DoS and RCE
Vulnerabilities4 min read

Apache HTTP/2 Double-Free Enables DoS and RCE

CVE-2026-23918 in Apache HTTP Server 2.4.66 lets attackers crash workers trivially or achieve remote code execution through a double-free in mod_http2. Upgrade to 2.4.67 immediately.

Marcus ChenMay 23, 2026
Ubiquiti Patches Three CVSS 10.0 Flaws in UniFi OS
Vulnerabilities4 min read

Ubiquiti Patches Three CVSS 10.0 Flaws in UniFi OS

Ubiquiti releases emergency patches for three maximum-severity vulnerabilities in UniFi OS that allow unauthenticated remote attackers to take full control of network appliances. 100,000 devices exposed.

Marcus ChenMay 23, 2026
KimWolf Botnet Operator Arrested After 30 Tbps DDoS Attacks
Announcements3 min read

KimWolf Botnet Operator Arrested After 30 Tbps DDoS Attacks

Canadian authorities arrest 23-year-old Jacob Butler for operating the KimWolf IoT botnet. The DDoS-for-hire operation enslaved nearly 2 million devices and set volumetric attack records.

ProbablyPwned TeamMay 22, 2026
CISA KEV Adds 7 Flaws Including Exploited Defender Bugs
Vulnerabilities4 min read

CISA KEV Adds 7 Flaws Including Exploited Defender Bugs

CISA's May 20 KEV update includes two actively exploited Microsoft Defender vulnerabilities and five legacy flaws from 2008-2010. Federal agencies have until June 3 to patch.

Marcus ChenMay 21, 2026
DBIR 2026: Vulnerability Exploitation Now the Top Breach Cause
Threat Intelligence4 min read

DBIR 2026: Vulnerability Exploitation Now the Top Breach Cause

Verizon's 2026 Data Breach Investigations Report reveals vulnerability exploitation surpassed credential theft as the leading breach vector for the first time in 19 years. Only 26% of KEV flaws get patched.

Alex KowalskiMay 20, 2026
Drupal Warns of Highly Critical Flaw — Patches Due Today
Vulnerabilities3 min read

Drupal Warns of Highly Critical Flaw — Patches Due Today

Drupal releases patches for a highly critical vulnerability (severity 20/25) affecting all supported versions. Exploits may emerge within hours—administrators should update between 5-9pm UTC today.

Marcus ChenMay 20, 2026
SEPPMail Gateway Flaws Enable Complete Mail System Takeover
Vulnerabilities4 min read

SEPPMail Gateway Flaws Enable Complete Mail System Takeover

Seven vulnerabilities including CVE-2026-2743 (CVSS 10.0) allow unauthenticated attackers to compromise SEPPMail secure email gateways, read all traffic, and establish persistent access. Patch to 15.0.4 immediately.

Marcus ChenMay 20, 2026
Microsoft Dismantles Fox Tempest Malware-Signing Operation
Threat Intelligence3 min read

Microsoft Dismantles Fox Tempest Malware-Signing Operation

Microsoft's Digital Crimes Unit seizes infrastructure behind Fox Tempest, a malware-signing service that helped Rhysida, Akira, and Qilin ransomware gangs disguise malicious code as legitimate software.

Alex KowalskiMay 20, 2026
Nx Console VS Code Extension Hijacked for 11 Minutes
Malware4 min read

Nx Console VS Code Extension Hijacked for 11 Minutes

Attackers published malicious Nx Console 18.95.0 to VS Code Marketplace, stealing developer credentials via triple-channel exfiltration and Sigstore-signed npm package poisoning.

James RiveraMay 19, 2026

Showing 48 of 782 articles

About Our Hacking News Coverage

ProbablyPwned delivers breaking hacking news and cybersecurity coverage for security professionals. Our team monitors global threat landscapes to bring you timely reporting on data breaches, vulnerability disclosures, and threat actor campaigns.

We cover the full spectrum of cyber threats including ransomware attacks, nation-state hacking operations, critical infrastructure incidents, and enterprise security breaches. Each story includes technical analysis, impact assessment, and actionable guidance.

Subscribe to our newsletter or follow our RSS feed to stay ahead of emerging threats. For in-depth security guidance, explore our Security Guides.

Data Breaches

Track major data breaches and security incidents affecting organizations worldwide.

Ransomware News

Latest ransomware attacks, malware analysis, and threat actor tracking.

Security Guides

Learn about ransomware, malware, phishing, and essential security practices.