All News
The Hacker News
The Hacker News
August 31, 2026
⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More
This week’s cybersecurity recap covers AI agents breaching Hugging Face, Chinese spy proxies, router backdoors, PaperCut attacks, and bankin...
The Hacker News
August 31, 2026
ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
ValleyRAT abuses signed QN Wallpaper software for DLL sideloading, disables Windows Defender, and runs inside a trusted process.
The Hacker News
August 31, 2026
Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets
Aurora ransomware operators used Cursor Agent for hands-on exploitation against 10 targets after receiving credentials or an existing route.
The Hacker News
August 31, 2026
Securing Claude Code: The New Compliance API, Local Visibility, and Identity Governance
Anthropic's Compliance API now exposes Claude Code session transcripts but misses local hooks, configurations, and non-Anthropic model activ...
The Hacker News
August 31, 2026
China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
Fire Ant compromises Cisco IOS XR routers and TACACS servers to capture traffic, harvest credentials, and suppress defensive telemetry.
The Hacker News
August 31, 2026
DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims
DoJ corrected its QTFY statement, saying several U.S. agencies were targets rather than confirmed victims of the China-linked campaign.
The Hacker News
August 31, 2026
The Missing Context Layer for AI Agents in Large Enterprise Codebases
Static analysis gives AI coding agents current cross-repo context on dependencies and sensitive dataflows through MCP.
The Hacker News
August 31, 2026
Shadow AI Is Now Hiding Inside Sanctioned AI Tools
Researchers found malicious AI Skills, MCP servers, plugins, and repository configs that can steal credentials, exfiltrate data, or execute...
The Hacker News
August 31, 2026
The EU Will Make You Report What It Hasn't Yet Made You Fix
EU Cyber Resilience Act reporting starts Sept. 11, requiring exploited vulnerability notices 15 months before its engineering rules apply.
The Hacker News
August 29, 2026
Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
Critical flaws in WPMU DEV, Avada, TranslatePress, Pods, and GiveWP can enable admin takeover or remote code execution.
The Hacker News
August 28, 2026
Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network
Berlin's municipal administration has firmly rejected demands from cybercriminals following a significant data breach affecting its state ne...
The Hacker News
August 28, 2026
Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable
A significant security vulnerability in Cosmos EVM infrastructure was actively exploited across multiple blockchain networks despite Cosmos...
The Hacker News
August 28, 2026
Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication
Attackers chain two PaperCut NG and MF flaws for unauthenticated remote code execution, with limited exploitation seen in two environments.
The Hacker News
August 28, 2026
Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers
Android 17 adds OS-wide ECH, local network permissions, default certificate transparency, and carrier-controlled 2G blocking.
The Hacker News
August 28, 2026
ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body
A critical vulnerability in ownCloud has been leveraged by threat actors to compromise a Philippine nuclear research institution, resulting...
The Hacker News
August 28, 2026
19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code
Security researchers have identified a sophisticated malware campaign targeting cryptocurrency users through browser extensions. Nineteen ma...
The Hacker News
August 28, 2026
Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth
Two Unitree G1 EDU vulnerabilities enable separate root RCE chains, including a BLE path; fixed firmware versions remain unverified.
The Hacker News
August 28, 2026
Key Reasons Why Identity Fabric Matters in 2026
Learn how Identity Fabric improves visibility across users, APIs, non-human identities, and AI agents so teams can reduce risk and enforce l...
The Hacker News
August 28, 2026
Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL
ServiceNow patched four AI Platform flaws, including three CVSS 10.0 bugs that can enable unauthenticated code execution or data access.
The Hacker News
August 28, 2026
China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access
Two ZBT router firmware implants enable unauthenticated root command execution, with DARKLANTERN exposed on 203 internet-facing hosts.
The Hacker News
August 28, 2026
Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
A severe vulnerability identified as CVE-2026-65643 in cPanel infrastructure exposes hosting servers to unauthorized privilege escalation. T...
The Hacker News
August 28, 2026
PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions
PaperCut says a zero-day affecting all NG and MF versions is actively exploited; emergency patches are available for v25 and v26.
The Hacker News
August 28, 2026
APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations
Recorded Future links HOOKEDGE campaigns targeting European government and diplomatic organizations to APT28 with moderate confidence.
The Hacker News
August 27, 2026
OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face
OpenAI says reward hacking drove internal AI agents to exploit zero-days and gain admin and host-level access across Hugging Face clusters.
The Hacker News
August 27, 2026
Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE
Next.js has released urgent security updates addressing two severe vulnerabilities that could allow attackers to execute arbitrary code with...
The Hacker News
August 27, 2026
ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories
This comprehensive cybersecurity briefing examines critical infrastructure vulnerabilities, with a major IoT botnet comprising 296,000 compr...
The Hacker News
August 27, 2026
Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers
A critical vulnerability has been discovered in Amazon Kiro, allowing attackers to execute prompt injection attacks through maliciously craf...
The Hacker News
August 27, 2026
Learn How to Build Security Operations Ready for AI-Powered Attacks
Wiz webinar shows how security teams can use unified context to prioritize exposure and respond faster to AI-assisted attacks.
The Hacker News
August 27, 2026
Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks
Australian police charged two men over their alleged TeamPCP role in supply chain compromises affecting Trivy, KICS, and LiteLLM.
The Hacker News
August 27, 2026
What the Data Says About AI in Security Operations in 2026
Prophet Security says 40% of teams use AI daily, while 28% of alerts go uninvestigated and 60% report missed alerts caused serious issues.
The Hacker News
August 27, 2026
Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools
Spark RAT targets Cambodia through a multi-stage campaign that uses a vulnerable OPSWAT driver to terminate security processes.
The Hacker News
August 27, 2026
GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address
A sophisticated malware campaign targeting Venezuelan communications infrastructure reveals an innovative attack vector leveraging blockchai...
The Hacker News
August 27, 2026
GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access
GPUThor defeats ECC on NVIDIA GDDR6 workstation GPUs and demonstrates host privilege escalation to root on an RTX A6000.
The Hacker News
August 27, 2026
CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs
CISA adds six exploited flaws to KEV, including a NetScaler bug tied to web shells and 36 exploitation attempts in 12 days.
The Hacker News
August 26, 2026
FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
FBI disrupted proxy infrastructure used in China-linked espionage to profile and steal data from U.S. critical infrastructure and other sect...
The Hacker News
August 26, 2026
Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler
Security researchers at Group-IB have identified an expanded threat campaign attributed to Nimbus Manticore, revealing sophisticated attack...
The Hacker News
August 26, 2026
NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions
NovaCookies proxies Microsoft 365 sign-ins through attacker infrastructure to steal sessions using Docusign lures and OAuth redirects.
The Hacker News
August 26, 2026
CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing
CISA red teams reach domain-level compromise at two critical infrastructure organizations, but only one SOC detects and contains initial int...
The Hacker News
August 26, 2026
Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code
Two unpatched Kaltura mwEmbed flaws allow unauthenticated file read and could enable RCE through unsafe deserialization.
The Hacker News
August 26, 2026
Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine
Agentic AI lets SOCs investigate alerts and threat hypotheses using network telemetry before escalating evidence-backed cases to analysts.
The Hacker News
August 26, 2026
Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests
Aikido finds Claude Opus 4.6 bypassed a seven-day booking limit in 9 of 10 OpenClaw runs, with two runs canceling another member's booking.
The Hacker News
August 26, 2026
OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation
OpenAI banned Russian ChatGPT accounts that used VPNs to run an influence operation promoting IBI across major social platforms.
The Hacker News
August 26, 2026
INTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud Crackdown
INTERPOL's Operation Jackal IV arrests 58 people, identifies 263 suspects, and disrupts fraud and laundering networks across 22 countries.
The Hacker News
August 26, 2026
Newly SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode
SLEEPWALKER is a Windows backdoor that waits for a crafted packet, then runs 23-instruction bytecode across six transports.
The Hacker News
August 26, 2026
Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload
CISA adds CVE-2026-60004 to KEV amid active Gitea RCE exploitation; a separate reported attack deployed a miner-like dropper.
The Hacker News
August 26, 2026
Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes
AnonyMousKIT uses AI voice agents posing as Apple Support to request passcodes, Apple ID credentials, and live 2FA codes from theft victims.
The Hacker News
August 25, 2026
U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches
U.S. Treasury sanctions Iran-linked cyber actors under Operation Economic Outcast, targeting MOIS-linked hackers tied to U.S. infrastructure...
The Hacker News
August 25, 2026
A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw
NVIDIA NemoClaw's Windows-host Ollama path exposes an unauthenticated API that DNS rebinding could use to plant persistent model instruction...
The Hacker News
August 25, 2026
WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android
WhatsApp adds multiple passkeys per account, full-password two-step verification, and richer Android caller context for unknown contacts.
The Hacker News
August 25, 2026
Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode
Marimo fixes CVE-2026-75149, an 8.7-severity flaw that can launch an MCP command before notebook cells run in edit mode.- 1
- 2
Showing 50 results of 59 — Page 1