# Archive

Browse past daily curated stories

May 08 May 05 May 03 May 02 May 01 Apr 30 Apr 28 Apr 26 Apr 25 Apr 24 Apr 23 Apr 22 Apr 21 Apr 20 Apr 19 Apr 18 Apr 17 Apr 16 Apr 15 Apr 14 Apr 12 Apr 11 Apr 10 Apr 09 Apr 08 Apr 07 Apr 05 Apr 04 Apr 03 Apr 02

Saturday, April 04, 2026

  1. 1
    0
    BleepingComputer general
    LinkedIn secretely scans for 6,000+ Chrome extensions, collects data

    Microsoft's LinkedIn is secretly scanning visitors' browsers for over 6,000 Chrome extensions using hidden JavaScript and collecting device data. The "BrowserGate" report reveals how LinkedIn bypasses user consent to profile browser configurations and potentially identify security tools or privacy extensions.

  2. 2
    0
    The Record threat-intel
    CISA gives agencies two weeks to patch video conferencing bug exploited by Chinese hackers

    CISA ordered federal agencies to patch a video conferencing vulnerability within two weeks after Chinese hackers actively exploited it. The directive targets a bug in TrueConf's video conferencing platform that allows privilege escalation and reconnaissance on Asian government systems.

  3. 3
    0
    SecurityWeek general
    North Korean Hackers Drain $285 Million From Drift in 10 Seconds

    North Korean hackers stole $285 million from Drift Protocol in just 10 seconds by taking control of admin keys and draining five vaults. The attackers prepared nonce-based transactions and infrastructure beforehand, executing a sophisticated social engineering attack against the Security Council.

  4. 4
    0
    The Record threat-intel
    EU cyber agency attributes major data breach to TeamPCP hacking group

    The EU cybersecurity agency CERT-EU attributed a massive data breach at the European Commission to the TeamPCP hacking group. The breach compromised cloud infrastructure and exposed data from at least 29 additional EU entities beyond the Commission itself.

  5. 5
    0
    The Hacker News general
    UNC1069 Social Engineering of Axios Maintainer Led to npm Supply Chain Attack

    North Korean threat actors from UNC1069 compromised the Axios npm package through targeted social engineering of maintainer Jason Saayman. The supply chain attack demonstrates sophisticated DPRK capabilities to infiltrate widely-used JavaScript libraries through personalized social manipulation campaigns.

  6. 6
    0
    SecurityWeek general
    Critical ShareFile Flaws Lead to Unauthenticated RCE

    Critical vulnerabilities in Citrix ShareFile can be chained together to achieve unauthenticated remote code execution by bypassing authentication and uploading arbitrary files. The flaws allow attackers to completely compromise ShareFile servers without any credentials.

  7. 7
    0
    The Hacker News general
    China-Linked TA416 Targets European Governments with PlugX and OAuth-Based Phishing

    China-linked TA416 (also tracked as DarkPeony, RedDelta, SmugX) has targeted European government and diplomatic organizations since mid-2025 using PlugX malware and OAuth-based phishing. The campaign marks a return to European targeting after a two-year hiatus in the region.

  8. 8
    0
    The Hacker News general
    Microsoft Details Cookie-Controlled PHP Web Shells Persisting via Cron on Linux Servers

    Microsoft discovered threat actors using HTTP cookies as control channels for PHP web shells on Linux servers to achieve remote code execution. The attackers use cookie values to gate execution rather than URL parameters, persisting through cron jobs for stealthier command and control.

  9. 9
    0
    BleepingComputer general
    Hims & Hers warns of data breach after Zendesk support ticket breach

    Telehealth company Hims & Hers suffered a data breach after attackers stole support tickets from Zendesk's customer service platform. The breach exposed patient information stored in third-party support systems, highlighting risks in healthcare companies' vendor ecosystems.

  10. 10
    0
    BleepingComputer general
    Die Linke German political party confirms data stolen by Qilin ransomware

    German political party Die Linke confirmed that the Qilin ransomware group stole sensitive data during an attack that forced IT systems offline. The breach affects one of Germany's major left-wing political parties and threatens to expose confidential political communications and member data.