HackWatch

Full archive

Latest cybersecurity alerts and incident archive

This page lists the full published alert archive for readers searching the latest cybersecurity alerts, phishing warnings, breach disclosures, malware campaigns and exploited vulnerability coverage in one place.

Use this archive when you want the complete flow of published incident reporting instead of the tighter homepage selection, including category filters, risk views and direct paths to response tools.

Filter the alert archive

Narrow the archive by category and risk level to review phishing alerts, data breach alerts, malware coverage, vulnerability updates and ransomware incidents faster.

Full alert archive

Showing 12 of 351 matching alerts. 351 published alerts are currently available in the archive.

Each alert card surfaces the threat type, documented summary and best next step so the listing itself can answer intent around latest cybersecurity alerts, phishing alerts, breach alerts and incident response without forcing every visitor to click through immediately.

Older alerts from 2021-2025 are still available, but stronger, documented and more recent reporting is ranked first so the archive stays aligned with current Google quality expectations.

HIGHVulnerability alerts

High-Severity Cross-Site Scripting Flaws Persist in Popular WordPress Plugins and Google Fonts

Human review: Marcin Pocztowski | Source date: Apr 30, 2026 | Sources: 1

Spain’s National Cybersecurity Institute (INCIBE) has flagged critical cross-site scripting vulnerabilities in several popular WordPress plugins and the Fontific Googl... Documented alert summary. Focus: affected products, exploit urgency and remediation guidance.

Best next step: Identity Theft Recovery Planner

HIGHMalware alerts

Backdoor Discovered in Popular WordPress Quick Page/Post Redirect Plugin

Human review: Marcin Pocztowski | Source date: Apr 30, 2026 | Sources: 1

A critical backdoor has been discovered in the Quick Page/Post Redirect WordPress plugin, exposing thousands of sites to unauthorized access and potential compromise.... Documented alert summary. Focus: infection path, likely payload impact and containment priorities.

Best next step: Identity Theft Recovery Planner

HIGHPhishing alerts

ClickUp Data Leak Exposes Enterprise Emails for Over a Year Due to Hardcoded API Key

Human review: Artur Ślesik | Source date: Apr 28, 2026 | Sources: 2

A hardcoded ClickUp API key exposed hundreds of corporate and government email addresses for more than a year, revealing critical vulnerabilities in SaaS security prac... Verified across 2 sources. Focus: lure pattern, spoofing signals and account-protection next steps.

Best next step: Identity Theft Recovery Planner

HIGHPhishing alerts

GlassWorm Malware Resurfaces via 73 Malicious OpenVSX Sleeper Extensions in 2026

Human review: Artur Ślesik | Source date: Apr 27, 2026 | Sources: 3

In 2026, the GlassWorm malware campaign has made a significant comeback by exploiting 73 dormant 'sleeper' extensions on the OpenVSX marketplace. These extensions init... Verified across 3 sources. Focus: lure pattern, spoofing signals and account-protection next steps.

Best next step: Identity Theft Recovery Planner

HIGHScam alerts

US Sanctions Target Cambodian Scam Network Leaders Involved in Crypto Fraud and Trafficking

Human review: Artur Ślesik | Source date: Apr 27, 2026 | Sources: 3

The US Treasury Department has sanctioned key leaders of a Cambodian-based criminal network involved in extensive cryptocurrency fraud and illegal trafficking. This de... Verified across 3 sources. Focus: fraud signals, pressure tactics and what to do before paying or replying.

Best next step: Crypto Scam Checker for Fake Investments and Recovery Fraud

HIGHPhishing alerts

North Korean Hackers Target Drug Companies with Weaponized Excel Malware Disguised as Income Tax Notices

Human review: Artur Ślesik | Source date: Apr 27, 2026 | Sources: 5

A sophisticated North Korean cyber espionage group is actively targeting pharmaceutical companies using weaponized Excel files disguised as urgent Income Tax Departmen... Verified across 5 sources. Focus: lure pattern, spoofing signals and account-protection next steps.

Best next step: Crypto Scam Checker for Fake Investments and Recovery Fraud

HIGHPhishing alerts

Vidar Infostealer 2026 Variant Spreads via Fake CAPTCHAs Embedded in JPEG and TXT Files

Human review: Artur Ślesik | Source date: Apr 27, 2026 | Sources: 6

The Vidar infostealer malware has reemerged in 2026 with sophisticated evasion methods, spreading through deceptive fake CAPTCHA prompts embedded within JPEG and TXT f... Verified across 6 sources. Focus: lure pattern, spoofing signals and account-protection next steps.

Best next step: Crypto Scam Checker for Fake Investments and Recovery Fraud

HIGHPhishing alerts

Microsoft Teams Exploited for Phishing Attacks Distributing SNOWBELT Malware

Human review: Artur Ślesik | Source date: Apr 27, 2026 | Sources: 2

Cybercriminals are increasingly exploiting Microsoft Teams to execute sophisticated phishing campaigns that deliver the SNOWBELT malware. Utilizing social engineering... Verified across 2 sources. Focus: lure pattern, spoofing signals and account-protection next steps.

Best next step: Identity Theft Recovery Planner

HIGHMalware alerts

Attackers Exploit Chained Vulnerabilities to Backdoor CODESYS Applications, Gaining Full Control

Human review: Marcin Pocztowski | Source date: Apr 27, 2026 | Sources: 2

Multiple vulnerabilities in the widely used CODESYS Control runtime enable attackers to chain exploits, replacing legitimate industrial control applications with backd... Verified across 2 sources. Focus: infection path, likely payload impact and containment priorities.

Best next step: Identity Theft Recovery Planner

HIGHPhishing alerts

FBI and Indonesian Authorities Collaborate to Shut Down W3LLStore Marketplace Defrauding Users of Millions

Human review: Artur Ślesik | Source date: Apr 27, 2026 | Sources: 1

In a coordinated international law enforcement operation, the FBI and Indonesian authorities successfully dismantled the W3LLStore marketplace, a phishing and fraud pl... Documented alert summary. Focus: lure pattern, spoofing signals and account-protection next steps.

Best next step: Identity Theft Recovery Planner

MEDIUMData breach alerts

Safe Vulnerability Disclosure for UK SMEs: A Practical Guide for 2026

Human review: Marcin Pocztowski | Source date: Apr 27, 2026 | Sources: 1

This comprehensive guide explains safe vulnerability disclosure tailored for UK SMEs, demystifying the process and highlighting actionable steps to protect businesses... Documented alert summary. Focus: exposed data, who may be affected and breach-response priorities.

Best next step: Identity Theft Recovery Planner

HIGHData breach alerts

Firefox and Tor Browser IndexedDB Vulnerability Exposed Hidden User Identifiers

Human review: Marcin Pocztowski | Source date: Apr 27, 2026 | Sources: 2

A medium-risk vulnerability affecting Firefox and Tor Browser allowed malicious actors to access hidden identifiers stored via IndexedDB, potentially compromising user... Verified across 2 sources. Focus: exposed data, who may be affected and breach-response priorities.

Best next step: Identity Theft Recovery Planner

Alerts archive SEO topics

Latest cybersecurity alerts

This archive is built for users searching latest cybersecurity alerts, active threat coverage and incident reporting beyond the curated homepage selection.

Open archive view

Phishing alerts

Review suspicious-domain incidents, fake login campaigns, credential-theft operations and account-takeover lures from one focused phishing archive.

Open archive view

High-risk phishing alerts

Open the stronger landing page built for urgent phishing campaigns, fake login portals and rapid account-recovery next steps.

Open archive view

Data breach alerts

Track exposed-record incidents, breach disclosures, affected-account coverage and immediate response guidance through the dedicated breach view.

Open archive view

Latest breach alerts

Jump into the breach landing page optimized for fresh disclosures, exposed-record coverage and identity-theft response journeys.

Open archive view

Malware alerts

Follow infostealer, spyware and trojan campaigns with stronger context around infection paths, payload behavior and containment priorities.

Open archive view

Vulnerability alerts

Monitor exploited CVEs, zero-day disclosures, patch timing and remediation guidance in a dedicated vulnerability landing page.

Open archive view

Actively exploited vulnerabilities today

Open the exploit-focused landing page tuned for urgent CVE coverage, patch-now incidents and operational remediation intent.

Open archive view

Ransomware alerts

Track extortion campaigns, encrypted-environment incidents and decryptor-related reporting tied directly to ransomware response workflows.

Open archive view

Scam alerts

Review fake support, payment fraud, impersonation and delivery scam coverage designed for rapid verification and next-step action.

Open archive view

Fake support alerts

Open the scam landing page focused on malicious support popups, fake helplines, remote-access fraud and tech support scam recovery.

Open archive view

Payment fraud alerts

Jump into invoice scams, fake payment requests, bank impersonation and wire-fraud coverage with stronger identity-risk next steps.

Open archive view

Archive maintenance and remediation tracking. HackWatch does not treat alerts as one-time posts. We continue checking whether vendors have issued patches, workarounds or final remediation updates, then refresh the article with the latest incident status so readers can see whether a threat is still active, mitigated or already resolved.