Category archive
Scam alerts
Track the latest scam alerts, fake support incidents, delivery fraud, payment scams and rapid verification guidance in one archive.
This landing page groups scam alerts into one indexable archive so users and Google can navigate the incident stream by topic instead of only by date, with stronger internal links into the right tools and recovery paths.
Filter the alert archive
Narrow the archive by category and risk level to review phishing alerts, data breach alerts, malware coverage, vulnerability updates and ransomware incidents faster.
Full alert archive
Showing 12 of 241 matching alerts.
Each alert card surfaces the threat type, documented summary and best next step so the listing itself can answer intent around latest cybersecurity alerts, phishing alerts, breach alerts and incident response without forcing every visitor to click through immediately.
Older alerts from 2021-2025 are still available, but stronger, documented and more recent reporting is ranked first so the archive stays aligned with current Google quality expectations.
Critical Vulnerabilities in Hardy Barth Salia EV Charge Controller Expose Energy Infrastructure to Remote Attacks
Human review: Marcin Pocztowski | Source date: Apr 21, 2026 | Sources: 3Multiple critical vulnerabilities (CVE-2025-5873 and CVE-2025-10371) have been identified in the Hardy Barth Salia EV Charge Controller firmware version 2.3.81 and ear... Verified across 3 sources. Focus: affected products, exploit urgency and remediation guidance.
Best next step: Identity Theft Recovery Planner
CISA Adds Critical Linux Local Privilege Escalation Bug CVE-2026-31431 to Known Exploited Vulnerabilities List
Human review: Marcin Pocztowski | Source date: May 03, 2026 | Sources: 4CISA has added CVE-2026-31431 to the KEV catalog after evidence of active exploitation. Linux administrators should verify affected kernel or distribution packages, pr... Verified across 4 sources. Focus: affected products, exploit urgency and remediation guidance.
Best next step: Identity Theft Recovery Planner
Attackers Exploit Microsoft Teams to Impersonate IT Helpdesk in Sophisticated Enterprise Intrusion Playbook
Human review: Artur Ślesik | Source date: Apr 20, 2026 | Sources: 1In 2026, attackers have increasingly abused Microsoft Teams’ cross-tenant communication feature to impersonate IT helpdesk personnel, persuading employees to grant rem... Documented alert summary. Focus: lure pattern, spoofing signals and account-protection next steps.
Best next step: Identity Theft Recovery Planner
New High-Risk Cisco Catalyst SD-WAN Manager Vulnerability Added to CISA’s Known Exploited List
Human review: Marcin Pocztowski | Source date: Apr 21, 2026 | Sources: 2A newly discovered vulnerability in Cisco Catalyst SD-WAN Manager has been added to the CISA Known Exploited Vulnerabilities Catalog amid active exploitation in the wi... Verified across 2 sources. Focus: affected products, exploit urgency and remediation guidance.
Best next step: Identity Theft Recovery Planner
109 Fake GitHub Repositories Used to Deliver SmartLoader and StealC Malware: detailed reporting and Protection Guide
Human review: Marcin Pocztowski | Source date: Apr 22, 2026 | Sources: 6A sophisticated malware campaign involving 109 counterfeit GitHub repositories has been uncovered, distributing SmartLoader and StealC malware by mimicking legitimate... Verified across 6 sources. Focus: lure pattern, spoofing signals and account-protection next steps.
Best next step: Crypto Scam Checker for Fake Investments and Recovery Fraud
High-Severity Cross-Site Scripting Flaws Persist in Popular WordPress Plugins and Google Fonts
Human review: Marcin Pocztowski | Source date: Apr 30, 2026 | Sources: 1Spain’s National Cybersecurity Institute (INCIBE) has flagged critical cross-site scripting vulnerabilities in several popular WordPress plugins and the Fontific Googl... Documented alert summary. Focus: affected products, exploit urgency and remediation guidance.
Best next step: Identity Theft Recovery Planner
Critical Weak Authentication Vulnerability in Yadea T5 Electric Bicycle Enables Theft Risk
Human review: Artur Ślesik | Source date: Apr 23, 2026 | Sources: 1A high-severity vulnerability (CVE-2025-70994) affecting all versions of the Yadea T5 Electric Bicycle has been publicly disclosed by CISA in April 2026. The flaw allo... Documented alert summary. Focus: affected products, exploit urgency and remediation guidance.
Best next step: Identity Theft Recovery Planner
Operation TrueChaos Exploits TrueConf Zero-Day to Target Southeast Asian Governments
Human review: Artur Ślesik | Source date: Mar 31, 2026 | Sources: 2In January 2026, Operation TrueChaos exploited a zero-day vulnerability (CVE-2026-3502) in TrueConf software, compromising Southeast Asian government agencies' communi... Verified across 2 sources. Focus: affected products, exploit urgency and remediation guidance.
Best next step: Identity Theft Recovery Planner
ClickUp Data Leak Exposes Enterprise Emails for Over a Year Due to Hardcoded API Key
Human review: Artur Ślesik | Source date: Apr 28, 2026 | Sources: 2A hardcoded ClickUp API key exposed hundreds of corporate and government email addresses for more than a year, revealing critical vulnerabilities in SaaS security prac... Verified across 2 sources. Focus: lure pattern, spoofing signals and account-protection next steps.
Best next step: Identity Theft Recovery Planner
Supply Chain Compromise Hits Axios NPM Package: What Developers and Organizations Must Do
Human review: Artur Ślesik | Source date: Apr 20, 2026 | Sources: 1In March 2026, the Axios npm package was compromised with a malicious dependency that installed a remote access trojan, impacting countless Node.js projects worldwide. Documented alert summary. Focus: infection path, likely payload impact and containment priorities.
Best next step: Crypto Scam Checker for Fake Investments and Recovery Fraud
Hypersonic Supply Chain Attacks: How AI Stopped Zero-Day Threats Without Payload Insight
Human review: Marcin Pocztowski | Source date: Apr 22, 2026 | Sources: 2In 2026, SentinelOne's AI-driven defense successfully thwarted three zero-day hypersonic supply chain attacks by detecting malicious behavior without needing to know t... Verified across 2 sources. Focus: lure pattern, spoofing signals and account-protection next steps.
Best next step: Identity Theft Recovery Planner
9 Identity-Based Threats Redefining Cybersecurity in 2026 (Beyond Credential Stuffing)
Human review: Artur Ślesik | Source date: Apr 25, 2026 | Sources: 1In 2026, identity-based cyber threats have evolved far beyond traditional credential stuffing attacks. This detailed reporting uncovers nine critical threats reshaping... Documented alert summary. Focus: lure pattern, spoofing signals and account-protection next steps.
Best next step: Crypto Scam Checker for Fake Investments and Recovery Fraud
Alerts archive SEO topics
Archive maintenance and remediation tracking. HackWatch does not treat alerts as one-time posts. We continue checking whether vendors have issued patches, workarounds or final remediation updates, then refresh the article with the latest incident status so readers can see whether a threat is still active, mitigated or already resolved.