Tag: hackers

West Pharmaceutical says hackers stole data encrypted systems
News

West Pharmaceutical says hackers stole data encrypted systems

West Pharmaceutical Services revealed that company was the victim of a hack that led to system encryption and data exfiltration. On May 4th, the business claimed to have discovered a compromise. The intruder stole data from the network, according to an examination into the incident. In a filing with the U.S. Securities and Exchange Commission (SEC) on May 7, 2026, West Pharmaceutical Services, Inc. states that […it] has experienced a material cybersecurity attack, in which certain systems were encrypted and certain data was exfiltrated by an unauthorized party. When the corporation first discovered an attack on May 4, 2026, it quickly triggered its incident response procedures, which included proactively shutting down systems worldwide for containment, alerting law authorities, a...
Hackers use pixel-large SVG trick to hide credit card stealer
News

Hackers use pixel-large SVG trick to hide credit card stealer

Credit card-stealing code is concealed in a pixel-sized Scalable Vector Graphics (SVG) graphic in a large campaign that affects almost 100 online retailers that use the Magento e-commerce platform. The victim is presented with a convincing overlay that can verify billing information and card details when they click the checkout button. Sansec, an eCommerce security company, found the campaign. According to their study, the attacker most likely obtained access by taking advantage of the PolyShell vulnerability that was made public in mid-March. All installations of Adobe Commerce stable version 2 and Magento Open Source are affected by PolyShell, which permits unauthenticated code execution and account takeover. Sansec cautioned that PolyShell attacks, which in some cases used cre...
Hackers Exploit CVE-2025-32975 (CVSS 10.0) to Hijack Unpatched Quest KACE SMA Systems
News

Hackers Exploit CVE-2025-32975 (CVSS 10.0) to Hijack Unpatched Quest KACE SMA Systems

Arctic Wolf reports that a maximum-severity security vulnerability affecting Quest KACE Systems Management Appliance (SMA) may be being exploited by threat actors. The cybersecurity firm claimed to have seen malicious activity in client environments beginning the week of March 9, 2026, which is consistent with the exploitation of CVE-2025-32975 on unpatched SMA systems that are online. The attack's ultimate objectives are yet unknown. An authentication bypass vulnerability known as CVE-2025-32975 (CVSS score: 10.0) enables attackers to pretend to be authentic users without having the right credentials. If the vulnerability is successfully exploited, administrative accounts could be fully taken over. Quest fixed the problem in May 2025. Threat actors are thought to have exploited ...
Canada Goose investigating as hackers leak 600K customer records
News

Canada Goose investigating as hackers leak 600K customer records

According to the well-known data extortion organization ShinyHunters, over 600,000 Canada Goose client records containing payment and personal information were taken. Canada Goose told BleepingComputer that it has not discovered any indication of a breach of its own systems and that the dataset seems to be related to previous client transactions. Established in 1957, Canada Goose is a performance premium outerwear company headquartered in Toronto that employs close to 4,000 people worldwide. Canada Goose informed BleepingComputer that it is aware of the recent online publication of a historical dataset pertaining to previous client transactions. We don't currently have any evidence of a system compromise. We are now examining the just made public dataset to determine its scope...
Hackers Exploit Metro4Shell RCE Flaw in React Native CLI npm Package
News

Hackers Exploit Metro4Shell RCE Flaw in React Native CLI npm Package

Threat actors have been seen taking advantage of a serious security vulnerability in the well-known "@react-native-community/cli" npm package that affects the Metro Development Server. According to cybersecurity firm VulnCheck, exploitation of CVE-2025-11953, also known as Metro4Shell, was first noticed on December 21, 2025. The vulnerability, which has a CVSS score of 9.8, enables remote unauthenticated attackers to run arbitrary operating system commands on the underlying host. JFrog originally reported the flaw's specifics in November 2025. It further stated that the "activity has yet to see broad public acknowledgment," even after it was first exploited in the wild more than a month ago. The threat actors have exploited the vulnerability in the attack that was discovered agai...
Critical jsPDF flaw lets hackers steal secrets via generated PDFs
News

Critical jsPDF flaw lets hackers steal secrets via generated PDFs

A serious flaw in the jsPDF module for creating PDF documents in JavaScript programs enables an attacker to steal private information from the local disk by including it into created files. In jsPDF versions prior to 4.0, the weakness is a local file inclusion and path traversal that permits sending unsanitized paths to the file loading mechanism (loadFile). It has a severity score of 9.2 and is tracked as CVE-2025-68428. With over 3.5 million weekly downloads in the npm registry, the jsPDF library is a popular package. The local filesystem is read using the 'loadFile' function in jsPDF's Node.js builds. The issue is that when user-controlled input is supplied as the file path, jsPDF incorporates the file's content into the resulting PDF output. Since they can all call the loa...
Malicious LLMs empower inexperienced hackers with advanced tools
News

Malicious LLMs empower inexperienced hackers with advanced tools

Unrestricted large language models (LLMs) such as WormGPT 4 and KawaiiGPT are increasing their capacity to produce malicious code, providing useful scripts for lateral movement and ransomware encryptors. The two LLMs that hackers are increasingly using through paid subscriptions or free local instances were tested by researchers at Palo Alto Networks Unit42. Although the WormGPT model first appeared in 2023, the project was allegedly abandoned the same year. The brand made a comeback in September with WormGPT 4. It functions as an uncensored ChatGPT variation specifically trained for cybercrime activities and costs $50 per month or $220 for lifetime subscription. KawaiiGPT is a community-driven, free alternative that was discovered in July of this year. It can create well-written...
Hackers Hijack Blender 3D Assets to Deploy StealC V2 Data-Stealing Malware
News

Hackers Hijack Blender 3D Assets to Deploy StealC V2 Data-Stealing Malware

Cybersecurity experts have revealed information on a recent campaign that used Blender Foundation files to distribute StealC V2, an information stealer. Malicious implants are part of this continuous operation, which has been going on for at least six months.According to a revelation provided with The Hacker News by Morphisec researcher Shmuel Uzan, blend files on platforms such as CGTrader. These 3D model files, which are intended to run embedded Python scripts when opened in Blender—a free, open-source 3D creation suite—are downloaded by users without their knowledge. According to the cybersecurity firm, the activity is comparable to a previous effort connected to Russian-speaking threat actors that targeted the online gaming community by posing as the Electronic Frontier Found...
Iran-Linked Hackers Mapped Ship AIS Data Days Before Real-World Missile Strike Attempt
News

Iran-Linked Hackers Mapped Ship AIS Data Days Before Real-World Missile Strike Attempt

Amazon has dubbed this practice "cyber-enabled kinetic targeting." Threat actors with connections to Iran used cyberwarfare as a means of enabling and strengthening physical, real-world strikes. According to a research published with The Hacker News by the tech giant's threat intelligence team, the development indicates that the distinction between kinetic combat and state-sponsored cyberattacks is becoming more hazy, requiring the creation of a new category of warfare. According to CJ Moses, CISO of Amazon Integrated Security, nation-state threat actors are using cyber reconnaissance to enable kinetic targeting, despite the fact that traditional cybersecurity frameworks have treated digital and physical threats as distinct domains. These are organized campaigns where digital ope...
Hackers exploit WordPress plugin Post SMTP to hijack admin accounts
News

Hackers exploit WordPress plugin Post SMTP to hijack admin accounts

A serious flaw in the Post SMTP plugin, which is deployed on over 400,000 WordPress websites, is being actively exploited by threat actors to gain total access by taking over administrator accounts. A well-liked email distribution method called Post SMTP is promoted as a feature-rich and more dependable substitute for the built-in "wp_mail()" function. Researcher "netranger" reported an email log disclosure problem that might be used for account takeover attempts to WordPress security company Wordfence on October 11. With a critical-severity level of 9.8, the problem—tracked as CVE-2025-11833—affects all Post SMTP versions 3.6.0 and below. The "_construct" method of the plugin's "PostmanEmailLogs" flow lacks authorization checks which is the root of the vulnerability read more ab...