HackRead

HackRead

Publication
0 followers

UK-based news site focusing on infosec, cybercrime, and hacking.

Iran’s Nimbus Manticore Used Trojanized Zoom Installers Against US Firms
NewsMay 27, 2026

Iran’s Nimbus Manticore Used Trojanized Zoom Installers Against US Firms

Check Point Research uncovered a campaign by Iran‑linked Nimbus Manticore that used trojanized Zoom installers and SEO‑poisoned sites to deliver AI‑assisted malware to U.S. aviation and software firms. Between February and April 2026 the group shifted from fake job offers...

By HackRead
How Can MSSPs Scale Threat Detection Without Burning Out Their Analysts?
NewsMay 27, 2026

How Can MSSPs Scale Threat Detection Without Burning Out Their Analysts?

Managed security service providers (MSSPs) face a talent bottleneck that limits analyst capacity as client demand surges. To avoid burnout, they are adopting AI‑driven threat intelligence, automated enrichment, and AI‑assisted triage from vendors like ANY.RUN. Integrated feeds, YARA‑based custom detection,...

By HackRead
Trojanized Gemini and Claude Installers Target Developers Via SEO Poisoning
NewsMay 26, 2026

Trojanized Gemini and Claude Installers Target Developers Via SEO Poisoning

Cybercriminals are leveraging SEO poisoning to promote typosquatted domains that mimic official AI tool installers such as Google Gemini CLI and Anthropic Claude Code. When developers follow the fake pages, a PowerShell script downloads a file‑less infostealer that silently installs...

By HackRead
FBI Chief Kash Patel’s Clothing Store Hacked in ClickFix Infostealer Attack
NewsMay 25, 2026

FBI Chief Kash Patel’s Clothing Store Hacked in ClickFix Infostealer Attack

An online clothing store tied to FBI Director Kash Patel, Based Apparel, was taken offline after a click‑fix attack distributed a macOS infostealer. The hack presented a counterfeit Cloudflare CAPTCHA that instructed visitors to paste malicious code into Terminal, enabling...

By HackRead
5,561 GitHub Repositories Hit by Megalodon Supply Chain Attack in Six Hours
NewsMay 22, 2026

5,561 GitHub Repositories Hit by Megalodon Supply Chain Attack in Six Hours

Cybersecurity firm SafeDep uncovered a rapid supply‑chain attack dubbed Megalodon that compromised 5,561 GitHub repositories within six hours on 18 May 2026, injecting 5,718 malicious code updates. The attackers created fake accounts and inserted hidden workflow files (.github/workflows/ci.yml) that act as dormant...

By HackRead
Deleted Google API Keys Remain Active up to 23 Minutes, Study Finds
NewsMay 21, 2026

Deleted Google API Keys Remain Active up to 23 Minutes, Study Finds

Aikido Security discovered that Google API keys remain functional for up to 23 minutes after deletion, with an average lag of 16 minutes. The delay stems from eventual consistency across Google’s global authentication servers, allowing attackers to continue accessing enabled...

By HackRead
Fake Word Phishing Reveals Enterprise Blind Spot in Trusted Remote Access Tools
NewsMay 20, 2026

Fake Word Phishing Reveals Enterprise Blind Spot in Trusted Remote Access Tools

A fake Word Online phishing page is being leveraged to deliver a silent MSI installer that launches ScreenConnect remote‑access software, then hides its activity with HideUL. The attack chain—email, fake preview, installer, remote tool—uses trusted enterprise utilities, allowing it to...

By HackRead
AI Agent Security: Automating Workflow Without Creating Prompt Injection or Data Leak Risks
NewsMay 19, 2026

AI Agent Security: Automating Workflow Without Creating Prompt Injection or Data Leak Risks

Enterprises are rapidly deploying AI agents to automate tasks such as ticket triage, data summarization, and CRM updates. While these agents boost efficiency, their elevated authority creates new attack surfaces, notably prompt injection and data‑leak risks. The article outlines how...

By HackRead
New Reaper Malware Uses Fake Microsoft Domain to Steal macOS Passwords
NewsMay 18, 2026

New Reaper Malware Uses Fake Microsoft Domain to Steal macOS Passwords

SentinelOne’s research team has uncovered a new macOS infostealer, dubbed Reaper, that masquerades as legitimate updates for apps like WeChat and Miro. The malware leverages a typo‑squatted domain (mlcrosoft.co.com) to deliver a malicious Script Editor link that runs hidden AppleScript...

By HackRead
Government Backed Hackers Abuse Cloudflare in Malaysian Espionage Campaign
NewsMay 18, 2026

Government Backed Hackers Abuse Cloudflare in Malaysian Espionage Campaign

Oasis Security uncovered a multi‑year espionage campaign tied to the Malaysian government that uses hidden command‑and‑control servers cloaked behind Cloudflare’s CDN and storage services. The operators rotate and repurpose infrastructure to stay invisible, while malicious payloads and phishing pages are...

By HackRead
Continuous Detection, Continuous Response: Mate Security Redefines the Modern SOC
NewsMay 18, 2026

Continuous Detection, Continuous Response: Mate Security Redefines the Modern SOC

Mate Security unveiled its Continuous Detection, Continuous Response (CD/CR) model, which fuses detection and investigation into a single, self‑reinforcing loop. At the core is a Security Context Graph that aggregates real‑time organizational data from distributed sources, eliminating the need for...

By HackRead
The Gentlemen Ransomware Gang Hit by Internal Breach, Operations Exposed
NewsMay 18, 2026

The Gentlemen Ransomware Gang Hit by Internal Breach, Operations Exposed

The Gentlemen ransomware gang suffered an internal breach in May 2026, exposing its backend infrastructure, affiliate communications, and victim‑management tools. Check Point Research uncovered leaked chats, databases, and evidence of over 1,570 probable victims, far exceeding the gang’s public leak counts....

By HackRead
Closing the Gap: The Regulatory and Structural Maturation of Digital Assets
NewsMay 17, 2026

Closing the Gap: The Regulatory and Structural Maturation of Digital Assets

Digital assets have moved from a niche experiment to a $2.66 trillion market, driven by structural reforms that separate custody, execution, and clearing. The U.S. GENIUS Act, enacted in July 2025, imposes a 100 % reserve requirement on stablecoins, turning them into transparent,...

By HackRead
Scammers Send Physical Phishing Letters to Steal Ledger Wallet Seed Phrases
NewsMay 17, 2026

Scammers Send Physical Phishing Letters to Steal Ledger Wallet Seed Phrases

Scammers are sending forged Ledger‑branded letters that include QR codes to trick hardware‑wallet owners into revealing their 24‑word seed phrases. The campaign is localized, with versions in Italian and other languages, indicating attackers may have accessed customer shipping data from...

By HackRead
HackRead | Pulse