The Wire
Curated cybersecurity and tech news — AI-summarized, source attributed.
Simple Tool Exposes GitHub Repo Sizes via Public API
Simon Willison built a small web tool that reveals the size of any GitHub repository - information GitHub doesn't surface in its own UI. The tool works by query
Smart Slider 3 Pro update system compromised, backdoors pushed to 900K+ sites
Attackers compromised the update distribution system for Smart Slider 3 Pro, a popular WordPress and Joomla plugin, and used it to push a trojanized version (3.
Storm-2755 hijacks Canadian payroll via AiTM phishing of Microsoft 365 sessions
Microsoft is tracking Storm-2755, a financially motivated crew rerouting Canadian employees' salary payments by stealing Microsoft 365 session tokens. Victims l
VENOM PhaaS targets C-suite Microsoft accounts with QR-based AiTM phishing
A previously undocumented phishing-as-a-service operation dubbed VENOM has been running since November against CEOs, CFOs, and VPs across industries. Abnormal r
Weekly Threat Roundup: Masjesu IoT Botnet and 13-Year Apache ActiveMQ RCE
The Hacker News' weekly ThreatsDay bulletin highlights 20 security stories, led by the Masjesu botnet and a long-dormant Apache ActiveMQ remote code execution f
Adobe Reader zero-day exploited since December via weaponized PDFs
EXPMON founder Haifei Li disclosed an unpatched Adobe Reader vulnerability that attackers have been exploiting in the wild since at least December. The exploit
AI-Assisted Research Surfaces 13-Year-Old RCE in Apache ActiveMQ Classic
A high-severity remote code execution flaw (CVE-2026-34197, CVSS 8.8) has been patched in Apache ActiveMQ Classic after sitting undetected for over a decade. Ho
Artemis II Returned Stunning Moon Photos - But Robots Already Mapped It
NASA's Artemis II crew completed a crewed lunar flyby this week, the first in over 53 years, transmitting high-resolution imagery via a laser communications lin
Atomic Stealer Evades macOS ClickFix Protections via Script Editor Abuse
A new Atomic Stealer campaign bypasses macOS Tahoe's ClickFix terminal warnings by pivoting to Script Editor instead. Attackers drive victims to fake Apple-bran
Bitcoin Depot loses 50.9 BTC after attackers pivot through corporate IT
Bitcoin Depot, operator of more than 25,000 crypto ATMs, disclosed in an SEC filing that intruders breached its corporate IT environment on March 23, 2026 and m
BPO Supply Chain Pivot: UNC6783 Tunnels Through Help Desks to Reach Enterprise Data
A newly tracked threat actor, UNC6783, is exploiting business process outsourcing providers as an entry point into high-value corporate targets across multiple
Chaos Botnet Evolves: New Variant Hits Misconfigured Cloud Servers With SOCKS5 Proxy
A new variant of the Chaos botnet malware has expanded its targeting to include misconfigured Linux cloud servers, a shift from its earlier focus on routers and