News

The Hacker News
thehackernews. com > 2026 > 04 > threatsday-bulletin-hybrid-p2p-botnet. html

Threats Day Bulletin: Hybrid P2 P Botnet, 13-Year-Old Apache RCE and 18 More Stories

52+ min ago  (165+ words) Thursday. Another week, another batch of things that probably should've been caught sooner but'weren't. This'one's got some range " old vulnerabilities getting new life, a few "why was that even possible" moments, attackers leaning on platforms and tools you'd normally trust…...

The Hacker News
thehackernews. com > 2026 > 04 > the-hidden-security-risks-of-shadow-ai. html

The Hidden Security Risks of Shadow AI in Enterprises

2+ hour, 18+ min ago  (314+ words) Employees may use generative AI tools like Chat GPT or Claude in everyday workflows, and while this can improve productivity, it can result in sensitive data being shared externally without oversight. Whether or not the AI vendor uses that data…...

The Hacker News
thehackernews. com > 2026 > 04 > adobe-reader-zero-day-exploited-via. html

Adobe Reader Zero-Day Exploited via Malicious PDFs Since December 2025

2+ hour, 34+ min ago  (386+ words) Threat actors have been exploiting a previously unknown zero-day vulnerability in Adobe Reader using maliciously crafted PDF documents since at least December2025. The finding, detailed by EXPMON's Haifei Li, hasbeen described as a highly-sophisticated PDF exploit. The artifact ("Invoice540. pdf") first appeared…...

The Hacker News
thehackernews. com > 2026 > 04 > bitter-linked-hack-for-hire-campaign. html

Bitter-Linked Hack-for-Hire Campaign Targets Journalists Across MENA Region

3+ hour, 9+ min ago  (565+ words) An'apparent hack-for-hire campaign likely orchestrated by a threat actor with suspected ties to the Indian government targeted journalists, activists, and government officials across the Middle East and North Africa (MENA), according to findings'from Access'Now, Lookout,'and SMEX. "The attacks were…...

The Hacker News
thehackernews. com > 2026 > 04 > masjesu-botnet-emerges-as-ddos-for-hire. html

Masjesu Botnet Emerges as DDo S-for-Hire Service Targeting Global Io T Devices

21+ hour, 19+ min ago  (319+ words) Called Masjesu, the botnet has been advertised via Telegram as a DDo S-for-hire service since it first surfaced in 2023. It's capable of targeting a wide range of Io T devices, such as routers and gateways, spanning multiple architectures. "Built for…...

The Hacker News
thehackernews. com > 2026 > 04 > new-chaos-variant-targets-misconfigured. html

New Chaos Variant Targets Misconfigured Cloud Deployments, Adds SOCKS Proxy

19+ hour, 58+ min ago  (399+ words) "Chaos malware is increasingly targeting misconfigured cloud deployments, expanding beyond its traditional focus on routers and edge devices,"Darktrace said in a newreport. Chaoswas first documented by Lumen Black Lotus Labs in September 2022, describing it as a cross-platform malware capable…...

The Hacker News
thehackernews. com > 2026 > 04 > apt28-deploys-prismex-malware-in. html

APT28 Deploys PRISMEX Malware in Campaign Targeting Ukraine and NATO Allies

23+ hour, 59+ min ago  (492+ words) The Russian threat actor known'as APT28 (aka Forest Blizzard and Pawn Storm) has been linked to a fresh spear-phishing campaign targeting Ukraine and its allies to deploy a previously undocumented malware suite'codenamed PRISMEX. "PRISMEX combines advanced steganography, component object model (COM)…...

The Hacker News
thehackernews. com > 2026 > 04 > anthropics-claude-mythos-finds. html

Anthropic's Claude Mythos Finds Thousands of Zero-Day Flaws Across Major Systems

1+ day, 4+ hour ago  (366+ words) In one instance highlighted by the company, Mython Preview is said to have autonomously come'with a web browser exploit that chained together four vulnerabilities to escape the renderer and operating system sandboxes. Anthropic'also noted in the preview's system card that…...

The Hacker News
thehackernews. com > 2026 > 04 > n-korean-hackers-spread-1700-malicious. html

N. Korean Hackers Spread 1, 700 Malicious Packages Across npm, Py PI, Go, Rust

1+ day, 6+ hour ago  (489+ words) The North Korea-linked persistent campaign known'as Contagious'Interview has spread its tentacles by publishing malicious packages targeting the Go, Rust, and PHP ecosystems. The complete list of identified packages is as follows'- These loaders are designed to fetch platform-specific second-stage payloads,…...

The Hacker News
thehackernews. com > 2026 > 04 > iran-linked-hackers-disrupt-us-critical. html

Iran-Linked Hackers Disrupt U. S. Critical Infrastructure by Targeting Internet-Exposed PLCs

1+ day, 9+ hour ago  (730+ words) "These attacks have led to diminished PLC functionality, manipulation of display data and, in some cases, operational disruption and financial loss," the U. S. Federal Bureau of Investigation(FBI) said in a post on X. The agencies saidthe campaign is part ofa recent…...