Ethical Hacking Mission Control
This live lab is a safe space for defenders, red teamers, and curious hackers to sharpen their tradecraft using real tooling and real telemetry. Every article, lab module, and intel briefing is curated to help you practice responsible disclosure, grow your skill set, and support the security community.
FBI arrests another suspected ShinyHunters hacker after agency breach
TP-Link Sued by Four More U.S. States Over Router Security and China Ties
What We Missed: FBI Strikes Back at ShinyHunters
Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto
P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands
Security Threats Don't Stop at the Office: Why Executives' Families Need Training Too
Germany arrests alleged core Qilin ransomware member after extradition
How to keep AI agents within their permissions
Social Engineering AI Agents: The New BEC for 2026
Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access
Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects
Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge
Max severity SonicWall SMA1000 flaw now exploited in attacks
Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies
FBI Seizes 7 Domains, Disrupts Flax Typhoon Tools Used in Critical Infrastructure Intrusions
The AI Velocity Paradox: Why Security Is Decades Behind AI Ambition
Man admits to running network of 15,000 money mules for cybercriminals
Microsoft: Outdated Windows devices will stop receiving security updates
GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys
Citrix warns admins to patch new NetScaler RCE flaw immediately
Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own
Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments
Hackers get $1,262,000 for 98 zero-days at Pwn2Own Ireland
FBI disrupts Chinese hacking tools used to breach critical infrastructure
'AgentCorruption' Puts AWS Environments At Risk With Single Prompt
Ransomware attack disrupts Japan's IDCF Cloud used by govt clients
Low-cost Android phones ship with residential proxy malware
Venezuelan Cartel's Malware Honcho Nabbed for ATM Jackpotting
FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails
Russian Spies Give 'MatchBoil' Malware a Stealthy Facelift
ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories
FakeGit malware campaign returns with 17,610 malicious GitHub repos
Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks
UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML
Cisco warns of critical flaws allowing Nexus switch takeover
ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms
OAuth grants pile up faster than you can review them. Here's how to keep up.
Uranium crypto exchange hacker convicted for stealing $53 million
Microsoft Teams to get support for third-party deepfake detection tools
Writing the Next Chapter
ASOS links data breach to social engineering attack, credential theft
Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia
16 Malicious Firefox Extensions Pose as Rabby and OKX Wallets to Steal Recovery Phrases
U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks
MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt Data
Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm
Citizen Lab Slams Trump Administration, 'Techno-Fascist' Executives
Australian Gov't Weighs Mandatory AI Incident Reporting
Anthropic Gives Vetted Defenders Fewer Claude Guardrails
OpenAI Agent Escape Causes Wikimedia Service Outage
Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains
Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer
SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances
Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely
PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet
ShinyHunters Extorted Boeing Spin-off Prior to Arrests
The Sixth Voice of the CISO Data Shows Cyber Risk Has Moved Inside the Workflow
FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials
Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details
What Is Agentic Pentesting? What It Proves, and Where It Stops.
Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws
100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer
ClickFix Attacks Evolve to Better Hide Malicious Payloads
Critical Healthcare Systems Aren't Quantum-Ready
Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes
Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan
Google's PageBreak AI Agent Finds 500 Flaws in Its Web Apps
IANS' Kakolowski: How AI Is Reshaping CISO Budgets & Security Teams
'BigDiskBuster' Leaves Microsoft Defender Running While Blocking Updates
LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings
Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as Proxies
Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers
Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports
Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products
FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach
Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account
ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits
ClingSTUN Turns Vulnerable IoT Devices Into Proxy Nodes
Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes
Chinese Hackers Impersonate US Officials for AI Cyber Espionage
⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests
Need for Speed: AI-Driven Attacks Are Changing Security Strategies
The Credential Layer Is Expanding Faster Than Security Teams Can See It
Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2
Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access
Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline
ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members
China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing
RemoteThreat Bets Security Teams Need to Test What Happens After Defenses Fail
Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response
SWIFT Banking & Government Middleware Enables RCE
Is Your Organization Ready for 2027's AI Accountability Era?
Is It Fair to Blame 'Rogue' AI for Security Failures?
Vulnerability Backlogs Are an Ownership Problem
Malicious Linux Implants Mimic Asian Mail Security Products
Alleged KillSec Ransomware Mastermind a 16-Year-Old
Warlock Ransomware Hits Large Spanish, Portuguese Orgs
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation
U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions
Data Broker Radaris Loses Domains in Privacy Fight
Microsoft Plugs Nearly 1,000 Security Holes
FBI Probes Service Selling 153M+ Drivers Licenses
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
Who’s Tracking You? Use This New Service to Find Out
Microsoft Plugs Nearly 400 Security Holes
Canadian Man Pleads Guilty in Snowflake Extortions
Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure
Trump, Tech Giants Strike Voluntary AI Safety Accord
As AI Reshapes the SOC Career Ladder, Satisfaction Rises for 91%, but Entry Gets Harder for Nearly Half
Russia's Star Blizzard Ditches ClickFix to Widen Phishing Net
South Africa Seeks Help After Cyberattack Targets Air Traffic Control
Apple Zero-Day Vulnerability Weaponized in Targeted Attacks
Unsloth Studio Flaw Turns Routine Model Inspection Into Code Execution
Cloudflare Announces Public Certificate Authority for the Post-Quantum Web
'NeedyMantis' Provides Long-Term Access to Compromised Networks
Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers
Nvidia Launches AI Agent Safety Platform to Prevent Rogue Activities
One Packet Can Crash OT Servers in Industrial Sectors
Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts
AI Agents Are Privileged Users; Who Is Auditing Their Access?
Chrome Store Hosts 'Poper Blocker' Spyware Downloaded by Millions
JadePuffer AI Actor Compromises Azure Tenant in Destructive Cloud Attack
Why the CISO-CFO Relationship Is a Key to Cybersecurity Success
AI Sandbox Escapes: Why Forensic Readiness Matters More Than Containment
What We Missed: Google Gemini Joins the AI Escape Party
Stopping IT Worker Scams Requires Revamped HR Process
Russia's Hybrid Cyber-Physical War in Europe Heats Up
'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing
SectopRAT Returns, Hiding Inside a Legitimate Application
3 Cyber Threats That Defined the Summer of 2026
Bug Bounty Radar
Hand-picked programs with live scope and standout rewards to help you focus your next responsible disclosure run.
FastAPI Cloud
HackerOne • Updated 2024-05-18
Prototype pollution in async workers and GraphQL stitching flaws.
Scope: api.fastapicloud.com, *.fastapicloud.com
Program brief →Supply Chain Monitor
Bugcrowd • Updated 2024-05-22
Dependency confusion, pipeline breakout, and artifact poisoning.
Scope: *.scm.dev, api.scm.dev
Program brief →Secure Notes
Intigriti • Updated 2024-05-17
OAuth misconfigurations, storage isolation, and advanced XSS chains.
Scope: app.securenotes.io, api.securenotes.io
Program brief →OpenTelemetry Hub
YesWeHack • Updated 2024-05-20
Collector escapes, tenant isolation bugs, and SSRF via exporters.
Scope: *.otelhub.dev
Program brief →