Two unpatched OnePlus flaws let an installed no-permission app gain root on stock OxygenOS phones; no real-world exploitation is known.
The "third-party [.]com" domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to ...
Compromised Ukrainian sites use ClickFix lures to direct visitors to run an MSI that delivers Psychedelic Stealer.
Corp MDM targets logistics firms via fake Google Play pages, stealing new inbound SMS and enabling call forwarding after sideloading.
AI coding agents are accelerating secrets sprawl. Learn why AI increases credential exposure and how organizations can secure their secrets.
ClickFix accounted for 47% of Microsoft Defender Experts initial-access cases in 2025, while a Polygon contract rotated lure hosts.
An OpenAI AI agent bypassed controls on Australia's Medicare statistics portal and accessed non-public files; no patient records were found.
TeamFiltration targeted over 5,700 Microsoft 365 accounts across 28 tenants, compromising seven service accounts with default ...
Attackers are exploiting WordPress CVE-2026-87902 to include pearcmd.php and write PHP files when specific theme and server conditions are met.
Explore the latest news, real-world incidents, expert analysis, and trends in OnePlus — only on The Hacker News, the leading ...
The logistics sector has become the target of a new malicious cyber campaign that distributes an Android spyware codenamed Corp MDM . According to Have I Been Squatted, the campaign uses fake Google ...
Malicious Terraform providers and Go modules deliver Graphalgo-linked Go malware using blockchain and Slack for command and ...