HackWatch

Full archive

Latest cybersecurity alerts and incident archive

This page lists the full published alert archive for readers searching the latest cybersecurity alerts, phishing warnings, breach disclosures, malware campaigns and exploited vulnerability coverage in one place.

Use this archive when you want the complete flow of published incident reporting instead of the tighter homepage selection, including category filters, risk views and direct paths to response tools.

Filter the alert archive

Narrow the archive by category and risk level to review phishing alerts, data breach alerts, malware coverage, vulnerability updates and ransomware incidents faster.

Full alert archive

Showing 12 of 351 matching alerts. 351 published alerts are currently available in the archive.

Each alert card surfaces the threat type, documented summary and best next step so the listing itself can answer intent around latest cybersecurity alerts, phishing alerts, breach alerts and incident response without forcing every visitor to click through immediately.

Older alerts from 2021-2025 are still available, but stronger, documented and more recent reporting is ranked first so the archive stays aligned with current Google quality expectations.

HIGHMalware alerts

Dragos Analysis: ZionSiphon AI-Powered Malware Targeting Water Plants Is Overhyped

Human review: Marcin Pocztowski | Source date: Apr 23, 2026 | Sources: 1

Despite alarming headlines about ZionSiphon, a new AI-assisted malware aimed at Israeli water infrastructure, cybersecurity firm Dragos finds the threat largely overst... Documented alert summary. Focus: infection path, likely payload impact and containment priorities.

Best next step: Phishing Recovery Center and Account Takeover Guides

HIGHData breach alerts

Apple Fixes iOS Vulnerability Exploited by FBI to Access Deleted Signal Messages

Human review: Artur Ślesik | Source date: Apr 23, 2026 | Sources: 12

Apple's iOS 26.4.2 update patches a critical vulnerability that allowed the FBI to retrieve deleted messages from the Signal app. This article details the flaw, its ex... Verified across 12 sources. Focus: exposed data, who may be affected and breach-response priorities.

Best next step: Identity Theft Recovery Planner

HIGHVulnerability alerts

Discontinued D-Link DIR-823X Routers Exploited by Mirai Botnet via CVE-2025-29635 Command Injection

Human review: Marcin Pocztowski | Source date: Apr 23, 2026 | Sources: 1

Since early 2025, discontinued D-Link DIR-823X routers have been actively targeted by the Mirai botnet exploiting a known command injection vulnerability (CVE-2025-296... Documented alert summary. Focus: affected products, exploit urgency and remediation guidance.

Best next step: Identity Theft Recovery Planner

LOWData breach alerts

Checkmarx Supply-Chain Breach Compromises KICS Analysis Tool Docker Images and Extensions

Human review: Artur Ślesik | Source date: Apr 23, 2026 | Sources: 1

In April 2026, Checkmarx disclosed a supply-chain breach impacting its KICS analysis tool's Docker images and VSCode/Open VSX extensions. Attackers injected malicious... Documented alert summary. Focus: exposed data, who may be affected and breach-response priorities.

Best next step: Crypto Scam Checker for Fake Investments and Recovery Fraud

LOWMalware alerts

UK Intelligence Reveals Surge in Government Access to Commercial Spyware Across 100 Nations

Human review: Marcin Pocztowski | Source date: Apr 23, 2026 | Sources: 1

The UK National Cyber Security Centre (NCSC) has disclosed that over 100 countries now have access to commercial spyware tools, marking a significant rise from 80 nati... Documented alert summary. Focus: infection path, likely payload impact and containment priorities.

Best next step: Identity Theft Recovery Planner

HIGHPhishing alerts

UK Ransomware Attacks Shift to Targeted 'Big Game Hunting' Methods, Small Businesses at Greatest Risk

Human review: Marcin Pocztowski | Source date: Apr 23, 2026 | Sources: 1

Recent cybersecurity research reveals a significant shift in ransomware attack strategies within the UK, moving from broad, indiscriminate campaigns to highly targeted... Documented alert summary. Focus: lure pattern, spoofing signals and account-protection next steps.

Best next step: Identity Theft Recovery Planner

HIGHVulnerability alerts

UAT-4356 Exploits Critical Vulnerabilities in Cisco Firepower Devices FXOS

Human review: Artur Ślesik | Source date: Apr 23, 2026 | Sources: 1

The threat actor UAT-4356 has been actively exploiting two n-day vulnerabilities, CVE-2025-20333 and CVE-2025-20362, in Cisco Firepower devices running the Firepower e... Documented alert summary. Focus: affected products, exploit urgency and remediation guidance.

Best next step: Free Phishing Link Checker and Domain Intelligence Report

HIGHPhishing alerts

How AI Empowered North Korean Hackers to Launch a Near-Undetectable Cyberattack

Human review: Artur Ślesik | Source date: Apr 23, 2026 | Sources: 1

North Korean state-sponsored hackers, notably the group HexagonalRodent, have leveraged generative AI tools to execute sophisticated, near-undetectable cyberattacks ta... Documented alert summary. Focus: lure pattern, spoofing signals and account-protection next steps.

Best next step: Phishing Recovery Center and Account Takeover Guides

MEDIUMPhishing alerts

China Employs ‘Covert Network’ Botnets to Mask Cyberattacks, Warn US and Allies

Human review: Marcin Pocztowski | Source date: Apr 23, 2026 | Sources: 1

A joint advisory from the US and allied cybersecurity agencies reveals China’s use of sophisticated ‘covert network’ botnets to disguise cyberattacks. These stealthy b... Documented alert summary. Focus: lure pattern, spoofing signals and account-protection next steps.

Best next step: Phishing Recovery Center and Account Takeover Guides

HIGHPhishing alerts

Three Trees Data Leak Exposes Personal Information of Over 40,000 Customers and Delivery Drivers

Human review: Artur Ślesik | Source date: Apr 23, 2026 | Sources: 4

A misconfigured MongoDB database belonging to California-based marijuana delivery service Three Trees exposed sensitive data of at least 40,000 individuals, including... Verified across 4 sources. Focus: lure pattern, spoofing signals and account-protection next steps.

Best next step: Identity Theft Recovery Planner

HIGHPhishing alerts

French Hacker ‘HexDex’ Arrested for Targeting Sports Institutions in Major Data Breaches

Human review: Artur Ślesik | Source date: Apr 23, 2026 | Sources: 2

A 20-year-old French hacker known as ‘HexDex’ has been arrested for orchestrating multiple data breaches targeting national sports federations. The leaks exposed sensi... Verified across 2 sources. Focus: lure pattern, spoofing signals and account-protection next steps.

Best next step: Identity Theft Recovery Planner

HIGHRansomware alerts

CISA Adds CVE-2026-39987 Marimo Remote Code Execution Vulnerability to Known Exploited Vulnerabilities Catalog

Human review: Marcin Pocztowski | Source date: Apr 23, 2026 | Sources: 2

On April 23, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) expanded its Known Exploited Vulnerabilities (KEV) Catalog by adding CVE-2026-39987, a h... Verified across 2 sources. Focus: extortion context, containment timing and recovery options.

Best next step: Identity Theft Recovery Planner

Alerts archive SEO topics

Latest cybersecurity alerts

This archive is built for users searching latest cybersecurity alerts, active threat coverage and incident reporting beyond the curated homepage selection.

Open archive view

Phishing alerts

Review suspicious-domain incidents, fake login campaigns, credential-theft operations and account-takeover lures from one focused phishing archive.

Open archive view

High-risk phishing alerts

Open the stronger landing page built for urgent phishing campaigns, fake login portals and rapid account-recovery next steps.

Open archive view

Data breach alerts

Track exposed-record incidents, breach disclosures, affected-account coverage and immediate response guidance through the dedicated breach view.

Open archive view

Latest breach alerts

Jump into the breach landing page optimized for fresh disclosures, exposed-record coverage and identity-theft response journeys.

Open archive view

Malware alerts

Follow infostealer, spyware and trojan campaigns with stronger context around infection paths, payload behavior and containment priorities.

Open archive view

Vulnerability alerts

Monitor exploited CVEs, zero-day disclosures, patch timing and remediation guidance in a dedicated vulnerability landing page.

Open archive view

Actively exploited vulnerabilities today

Open the exploit-focused landing page tuned for urgent CVE coverage, patch-now incidents and operational remediation intent.

Open archive view

Ransomware alerts

Track extortion campaigns, encrypted-environment incidents and decryptor-related reporting tied directly to ransomware response workflows.

Open archive view

Scam alerts

Review fake support, payment fraud, impersonation and delivery scam coverage designed for rapid verification and next-step action.

Open archive view

Fake support alerts

Open the scam landing page focused on malicious support popups, fake helplines, remote-access fraud and tech support scam recovery.

Open archive view

Payment fraud alerts

Jump into invoice scams, fake payment requests, bank impersonation and wire-fraud coverage with stronger identity-risk next steps.

Open archive view

Archive maintenance and remediation tracking. HackWatch does not treat alerts as one-time posts. We continue checking whether vendors have issued patches, workarounds or final remediation updates, then refresh the article with the latest incident status so readers can see whether a threat is still active, mitigated or already resolved.