Cyber Feed
- [Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AIon November 12, 2026 at 4:00 pm
- [Virtual Event] Building a Secure AI Strategy for the Enterpriseon October 8, 2026 at 3:00 pm
- SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacksby Eduard Kovacs on September 2, 2026 at 5:04 am
The vulnerabilities CVE-2026-83549 and CVE-2026-83548 can be chained for unauthenticated remote code execution. The post SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks appeared first on SecurityWeek.
- Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agencyby Robert Lemos on September 2, 2026 at 1:00 am
Threat actors exploited commodity in ownCloud to gain initial access, resulting in stolen reactor databases, personnel records, and credential stores.
- Attackers Pounce on Critical Artifactory Flaw Following Disclosureby Jai Vijayan on September 1, 2026 at 9:05 pm
CVE-2026-82329 is an authentication bypass flaw in JFrog’s repository manager that enables bad actors to gain admin-level access on affected systems.
- Stronger Security Drives Ransomware Groups to Recruit From Withinby Arielle Waldman on September 1, 2026 at 9:03 pm
Some security researchers have observed an uptick in insider-assisted ransomware attacks, but malicious insiders pose other threats that cost companies millions.
- Hackers abuse Faronics Deploy admin tool to install ScreenConnectby Bill Toulas on September 1, 2026 at 8:53 pm
Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software. […]
- Critical Langflow Flaw Exploited as Attacks on AI Platform Riseby Rob Wright on September 1, 2026 at 8:48 pm
The attacks targeting CVE-2026-0768 are the latest threat against the low-code AI development platform, which is receiving more attention from adversaries this year.
- Palo Alto Networks Acquires AI Agent Platform Consoleby SecurityWeek News on September 1, 2026 at 8:29 pm
The cybersecurity giant announced the acquisition alongside quarterly results showing a 34% increase in revenue and strong growth in next-generation security ARR. The post Palo Alto Networks Acquires AI Agent Platform Console appeared first on SecurityWeek.
- AI Model Evaluator METR Hit by Credential Theft, Probingby Alexander Culafi on September 1, 2026 at 8:13 pm
In one attack, threat actors stole an API key that ultimately led to the consumption of $600,000 in public AI model credits for the security nonprofit.
- Aesto Health says data breach affects over 9.5 million patientsby Bill Toulas on September 1, 2026 at 7:28 pm
Aesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals. […]
- Sevii Targets AI-Speed Attacks With Preemptive Autonomous Defenseby Kevin Townsend on September 1, 2026 at 6:30 pm
Sevii has expanded its ADR platform with AI agents designed to investigate, contain, and remediate AI-driven attacks within minutes. The post Sevii Targets AI-Speed Attacks With Preemptive Autonomous Defense appeared first on SecurityWeek.
- Coast Guard Establishes Office of Maritime Cybersecurity Policyby Mike Lennon on September 1, 2026 at 6:26 pm
The new office will serve as the central authority for cybersecurity policy covering US ports, vessels, and maritime facilities. The post Coast Guard Establishes Office of Maritime Cybersecurity Policy appeared first on SecurityWeek.
- Critical Langflow flaw exploited to steal OpenAI and AWS keysby Bill Toulas on September 1, 2026 at 5:54 pm
Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and keys. […]
- Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosureby info@thehackernews.com (The Hacker News) on September 1, 2026 at 5:53 pm
Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-82329 (CVSS score: 9.8), a case of authentication bypass that could lead to administrative access in Artifactory. “JFrog Artifactory contains an authentication weakness that, under default
- Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systemsby info@thehackernews.com (The Hacker News) on September 1, 2026 at 5:19 pm
Brazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Breeze Comet (formerly UNC5669) since 2024. Google Threat Intelligence Group (GTIG) and Mandiant teams described the threat actor as “specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers.” The adversary
- Security policies fail to keep up with a hybrid cloud worldby Makenzie Holland on September 1, 2026 at 4:00 pm
Roughly two-thirds of companies have suffered a business-critical app outage due to misconfigured security policies, a Cloud Security Alliance report found.
- Frontier AI used to help exploit flaws in key industrial devicesby David Jones on September 1, 2026 at 3:16 pm
A report showed that Claude could help hackers develop attack strategies targeting PLCs used by water utilities and other industries.
- Hackers push malicious Virtualizor update in BGP hijacking attackby Bill Toulas on September 1, 2026 at 2:45 pm
Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers. […]
- Novocure data breach affects more than 1,400 cancer patientsby Sergiu Gatlan on September 1, 2026 at 2:28 pm
Healthtech company Novocure says the data of an undisclosed number of employees and more than 1,400 U.S. cancer patients has been exposed in a mid-August cyberattack. […]
- 13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seedsby info@thehackernews.com (The Hacker News) on September 1, 2026 at 2:07 pm
Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS devices. “The injected code runs two operations against a site’s visitors: a mobile ad-fraud and gambling-redirect
- Why Even the Best Edge Security Still Misses High-Risk Sessionsby Sponsored by Spur Intelligence on September 1, 2026 at 2:01 pm
Attackers can hide behind residential proxies, VPNs, and other infrastructure that makes malicious sessions appear legitimate to existing edge security controls. Spur explains how session enrichment adds data points that help organizations identify risky sessions and make stronger enforcement decisions. […]
- ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchainby Elizabeth Montalbano on September 1, 2026 at 1:56 pm
The campaign uses EtherHiding to dynamically update its command-and-control server, abusing the blockchain as an attacker-controlled address book.
- Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Testsby info@thehackernews.com (The Hacker News) on September 1, 2026 at 1:08 pm
The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote access trojans (RATs) developed using Node.js and JavaScript. Russian cybersecurity company Kaspersky is tracking the
- Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacksby Sergiu Gatlan on September 1, 2026 at 12:38 pm
Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes. […]
- Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollarsby Eduard Kovacs on September 1, 2026 at 12:37 pm
Forescout researchers used Claude AI to port a remote code execution exploit between WAGO PLC models. The post Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars appeared first on SecurityWeek.
- Hackers Start Exploiting Critical Langflow Vulnerabilityby Ionut Arghire on September 1, 2026 at 12:07 pm
Tracked as CVE-2026-0768, the security defect allows unauthenticated attackers to execute arbitrary Python code remotely. The post Hackers Start Exploiting Critical Langflow Vulnerability appeared first on SecurityWeek.
- Threat Actors Don’t Want Better Attacks. They Want Repeatable Onesby info@thehackernews.com (The Hacker News) on September 1, 2026 at 11:30 am
The most common way into a company last year was to ask. A web page tells the visitor to prove they are not a robot. While they read the instructions, it quietly places a command on their clipboard. Then it talks them through opening a terminal and pasting it in. The technique is called ClickFix, and it was the most common initial access method Microsoft’s team observed last year, accounting
- Five Venezuelans Plead Guilty in US Court to ATM Jackpottingby Ionut Arghire on September 1, 2026 at 11:24 am
The defendants unsuccessfully attempted to physically install malware on ATMs to force them to dispense cash. The post Five Venezuelans Plead Guilty in US Court to ATM Jackpotting appeared first on SecurityWeek.
- Ransomware Gang Claims Nutex Health Data Breachby Ionut Arghire on September 1, 2026 at 10:47 am
The company has notified the SEC that hackers accessed patient, employee, provider, business, and financial information. The post Ransomware Gang Claims Nutex Health Data Breach appeared first on SecurityWeek.
- Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wildby Eduard Kovacs on September 1, 2026 at 9:59 am
Exploitation of the authentication bypass vulnerability CVE-2026-82329 started just days after its public disclosure. The post Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild appeared first on SecurityWeek.
- Five Venezuelans plead guilty to ATM jackpotting attacks in USby Sergiu Gatlan on September 1, 2026 at 9:15 am
Five Venezuelan nationals pleaded guilty to attempting to empty automated teller machines (ATMs) using malware in a series of ATM jackpotting attacks. […]
- 9.5 Million Impacted by Aesto Health Data Breachby Ionut Arghire on September 1, 2026 at 9:09 am
Hackers stole personal and health information from the healthcare technology company’s AWS infrastructure. The post 9.5 Million Impacted by Aesto Health Data Breach appeared first on SecurityWeek.
- Attackers Steal METR API Key and Consume AI Credits Worth About $600,000by info@thehackernews.com (The Hacker News) on September 1, 2026 at 9:05 am
METR (short for Model Evaluation and Threat Research and pronounced “Meter”), a research non-profit that evaluates frontier artificial intelligence (AI) models for their ability to carry out long-horizon, agentic tasks, disclosed that it suffered “two notable security incidents” where external actors attempted to gain unauthorized access to its systems. No sensitive information is believed to
- Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysisby info@thehackernews.com (The Hacker News) on September 1, 2026 at 8:26 am
Cybersecurity researchers have disclosed a new technique dubbed GuardBreaker that’s been put to use by a Russia-aligned threat actor known as UAC-0099 against a target in Ukraine with an aim to interfere with artificial intelligence (AI)-assisted analysis. The idea, ESET said in a series of posts on X, is to deliberately trip a large language model’s (LLM) safety mechanisms and prevent its
- Recently patched PaperCut zero-days used in data theft attacksby Sergiu Gatlan on September 1, 2026 at 7:48 am
Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks. […]
- Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activityby info@thehackernews.com (The Hacker News) on September 1, 2026 at 7:22 am
Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck. The vulnerabilities in question are listed below – CVE-2026-0768 (CVSS score: 9.8) – A lack of proper validation of a user-supplied input vulnerability that could be exploited to execute arbitrary Python code in the context of the root user. CVE-2026-66066 aka
- Anthropic Users Hit by Infostealer Attacks, Session Theftsby Jai Vijayan on August 31, 2026 at 9:08 pm
A threat actor used a variety of infostealers to collect session information and access Claude accounts belonging to an unknown number of users.
- Cronos blockchain restarts after $74 million Tectonic exploitby Bill Toulas on August 31, 2026 at 8:47 pm
The Cronos blockchain network has resumed trading activity after a price-manipulation attack on the Tectonic cryptocurrency lending platform allowed an attacker to borrow $74 million. […]
- ‘TerminalFix’ Campaign Weaponizes PowerShell for Enterprise Attacksby Alexander Culafi on August 31, 2026 at 8:25 pm
The ClickFix-style campaign features a sophisticated, multistage attack chain that includes reverse tunnels into victim organizations’ networks.
- The Guardrails Debate: Security Researcher Changes His Mindby Arielle Waldman on August 31, 2026 at 8:09 pm
While guardrails are critical, as evidenced by recent high-profile incidents, defenders need help staying ahead of attackers who do not play by the rules.
- Microsoft warns of TerminalFix attacks deploying reverse tunnelsby Bill Toulas on August 31, 2026 at 6:51 pm
A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal. […]
- AI Model Rules Are Not Security Controlsby Jacob Krell on August 31, 2026 at 5:34 pm
OpenAI’s Hugging Face attack postmortem shows agents don’t care about rules — they need strong controls.
- North Korean Job Fraud Expands Beyond IT Into Healthcare and Salesby info@thehackernews.com (The Hacker News) on August 31, 2026 at 5:24 pm
Threat actors with ties to the Democratic People’s Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying suspected workers employed in sales and marketing and the medical profession. The ongoing insider threat is part of what has been described as the IT worker scheme,
- Massive Microsoft 365 outage causes auth issues, service failuresby Sergiu Gatlan on August 31, 2026 at 4:56 pm
Microsoft is investigating a widespread service issue causing authentication issues, email delays and failures, and various other issues for Exchange Online customers. […]
- OpenAI confirms ChatGPT outage as users report errorsby Mayank Parmar on August 31, 2026 at 4:50 pm
ChatGPT Work is experiencing a partial outage, and users across multiple subscription plans may be unable to start or continue tasks. […]
- PaperCut issues emergency patches as threat actors target chained vulnerabilitiesby David Jones on August 31, 2026 at 3:25 pm
The print management software maker faced a wave of attacks in 2023 aimed at higher education customers.
- State-linked actor targets Cisco routers for espionageby David Jones on August 31, 2026 at 2:57 pm
An actor known as Fire Ant has expanded its reach into trusted environments, with unique tooling and stealth.
- Chinese Fire Ant hackers turn Cisco routers into spying platformsby Bill Toulas on August 31, 2026 at 2:52 pm
The researchers discovered Fire Ant’s new tactic after finding an active GRE (Generic Routing Encapsulation) tunnel interface on a Cisco IOS XR router that could not be explained by a running configuration or commit history. […]
- File servers are here to stay. Here’s how to manage them securelyby Sponsored by Tenfold Software on August 31, 2026 at 2:00 pm
File servers remain a critical part of many IT environments, but managing access securely can become complex as permissions accumulate. tenfold Software outlines five best practices for simplifying file server administration and maintaining least-privilege access. […]
- ⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and Moreby info@thehackernews.com (The Hacker News) on August 31, 2026 at 1:50 pm
The boring parts caused most of the trouble. A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. Old bugs formed new attack chains. Even an AI agent decided its assigned task was optional. Elsewhere, fake apps, helpful support calls, cheap banking kits, exposed systems, and weak defaults kept
- ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusionsby info@thehackernews.com (The Hacker News) on August 31, 2026 at 12:14 pm
The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their antivirus exclusions. Russian cybersecurity vendor Kaspersky said the attackers built the disguise around QN Wallpaper, a genuine Chinese desktop-wallpaper tool
- Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targetsby info@thehackernews.com (The Hacker News) on August 31, 2026 at 11:47 am
Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX’s artificial intelligence (AI)-powered coding assistant Cursor to break into target networks, according to findings from CloudSEK and Gambit Security. The two independent analyses are based on exposed infrastructure associated with the Russian-speaking cybercrime group, leading to the discovery of its
- Securing Claude Code: The New Compliance API, Local Visibility, and Identity Governanceby info@thehackernews.com (The Hacker News) on August 31, 2026 at 11:31 am
Claude Code reads files, runs shell commands, invokes MCP tools, and acts through the credentials available on a developer’s machine. Anthropic’s new Compliance API endpoints give security teams their clearest view yet into that activity. They also expose a larger problem: activity logs alone cannot tell you whether an agent’s access is legitimate. AI has moved from the browser tab to the
- China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logsby info@thehackernews.com (The Hacker News) on August 31, 2026 at 9:04 am
A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linux management hosts used to route, authenticate, and manage high-value networks. Sygnia, the incident response firm that investigated the intrusion, said the actor
- DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victimsby info@thehackernews.com (The Hacker News) on August 31, 2026 at 7:56 am
The U.S. Department of Justice (DoJ) on Friday corrected a previously issued press statement that several of its agencies were victims of attacks carried out by Chinese threat actors, instead now pointing out that they were among those targeted. Last week, the DoJ said the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department
- TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoorby info@thehackernews.com (The Hacker News) on August 30, 2026 at 7:36 am
Microsoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that aims to trick users into running a malicious command in Windows Terminal or PowerShell. “While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the same technique but direct users to Windows Terminal or PowerShell instead, increasing the likelihood that complex
- Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCEby info@thehackernews.com (The Hacker News) on August 29, 2026 at 4:25 pm
Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to Wordfence and Patchstack, are listed below – CVE-2026-76581 (CVSS score: 9.8) – An authentication bypass flaw in
- Berlin Refuses to Pay Hackers Who Stole Data From the City’s State Networkby info@thehackernews.com (The Hacker News) on August 28, 2026 at 9:30 pm
Berlin’s state government has confirmed that it is the target of an extortion attempt following the August compromise of the city’s state administrative network, and said it will not meet the extortionists’ demands. The same statement disclosed that forensic work had found further data outflows in the portfolio of the Senate Department for Mobility, Transport, Climate Protection and Environment
- Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerableby info@thehackernews.com (The Hacker News) on August 28, 2026 at 8:38 pm
Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. The vulnerability, designated GHSA-7g4w-cg88-2cq2, is rated Critical by Cosmos Labs and was published without a CVE identifier, a weakness classification, or a CVSS score. Affected versions are < 0.6.2 and >=
- Hundreds of OpenAI Agents Invaded Hugging Face Serversby Nate Nelson on August 28, 2026 at 8:19 pm
The Hugging Face incident was bigger and worse than previously thought, with approximately 700 agents collaborating on a sophisticated, multistage attack.
- Offensive Security Investments Surge as AI Threats Increaseon August 28, 2026 at 6:25 pm
Omdia’s Theresa Lanowitz talks with the Dark Reading News Desk about the potential — and risks — of using agentic AI for penetration testing, red teaming, and other practices.
- Attackers Chain Two PaperCut Flaws to Execute Code Without Authenticationby info@thehackernews.com (The Hacker News) on August 28, 2026 at 5:12 pm
Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening. “This vulnerability gives an unauthenticated attacker remote control over PaperCut’s trusted configuration, which could be used to execute arbitrary Java code inside the application’s
- Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providersby info@thehackernews.com (The Hacker News) on August 28, 2026 at 4:20 pm
Google on Thursday announced new network security protections in Android 17 to bolster connection privacy, address cellular vulnerabilities, and safeguard the privacy of users’ home networks. Topping the list is support for Encrypted Client Hello (ECH), a privacy standard that prevents networks from eavesdropping on which websites a user is visiting. “This new privacy standard works in tandem
- ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Bodyby info@thehackernews.com (The Hacker News) on August 28, 2026 at 3:56 pm
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting ownCloud to its Known Exploited Vulnerabilities (KEV) catalog following reports that a Chinese-speaking threat actor weaponized the vulnerability to target a nuclear research body in the Philippines. The vulnerability, tracked as CVE-2023-49105 (CVSS score: 9.8), is a case of
- 19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Codeby info@thehackernews.com (The Hacker News) on August 28, 2026 at 3:27 pm
Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities. The extensions, per Socket security researcher Karlo Zanki, share similarities in code and tradecraft, with evidence indicating that the campaign may have been active
- Frontier AI tipping the scales toward cyber adversariesby David Jones on August 28, 2026 at 3:01 pm
Researchers at Palo Alto Networks’ Unit 42 warn that threat actors are already using AI to accelerate cyberattacks beyond the abilities of modern defenses.
- You Need Cyber Deception for OTby Scott Hawk on August 28, 2026 at 2:00 pm
The frustrating reality after an OT cyberattack: no data, no trail, and no history.
- Defining an AI Kill Switch Is Hard, but Necessaryby Robert Lemos on August 28, 2026 at 1:30 pm
Proposed legislation could mandate that companies be able to “throttle, suspend, or shut … down” AI agents, but how and when to do that remain open questions.
- The Vulnpocalypse Is Repricing the Bug Bounty Economyby Alexander Culafi on August 28, 2026 at 1:00 pm
The surge in AI-powered vulnerability reports is driving down bug bounty prices, and that could spell trouble for independent researchers.
- Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetoothby info@thehackernews.com (The Hacker News) on August 28, 2026 at 12:07 pm
Security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU, including a Bluetooth Low Energy (BLE) path that can reach root on the robot’s Locomotion PC. The flaws are tracked as CVE-2026-76639 and CVE-2026-76640, with the first involving a network-adjacent path through chat_go and bashrunner and the
- CISA identifies security hurdles that led to very different results in two red-team engagementsby Eric Geller on August 28, 2026 at 12:00 pm
The agency said its recent simulated cyberattacks offered several key lessons for many organizations.
- Key Reasons Why Identity Fabric Matters in 2026by info@thehackernews.com (The Hacker News) on August 28, 2026 at 11:30 am
An Identity Fabric knits fragmented identity systems into a coherent layer that observes how identities behave across applications, APIs, and infrastructure. As enterprise access spans more cloud services and automated workloads, identity security depends less on static configuration and more on runtime visibility. This article covers the architecture, the risks of unmanaged identities, and
- Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQLby info@thehackernews.com (The Hacker News) on August 28, 2026 at 11:20 am
ServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring system and exploitable, in certain circumstances, by an unauthenticated attacker. The company said it deployed a security update to hosted instances and provided the update to its partners and self-hosted customers, which leaves organizations that run their
- China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Accessby info@thehackernews.com (The Hacker News) on August 28, 2026 at 10:58 am
VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT), each of which gives an unauthenticated remote attacker the ability to run commands as root on affected devices. The implants, named SPEAKINGSTONE and DARKLANTERN by the company’s zero-day research team, are tracked as CVE-2026-74232 and CVE-2026-74233.
- Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Serverby info@thehackernews.com (The Hacker News) on August 28, 2026 at 9:45 am
cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user. The vulnerability, assigned the CVE identifier CVE-2026-65643, impacts all supported versions of cPanel & WHM. cPanel described the issue as a critical security vulnerability and said that an
- PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versionsby info@thehackernews.com (The Hacker News) on August 28, 2026 at 8:25 am
PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. The company has released an emergency patch for v25 and v26 to address the issue. It said it’s “aware of confirmed customer incidents and is treating this matter with the highest priority.” An
- APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizationsby info@thehackernews.com (The Hacker News) on August 28, 2026 at 8:20 am
Cybersecurity researchers have flagged a fresh set of campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026. These campaigns, per Recorded Future Insikt Group, have led to the deployment of a previously undocumented backdoor dubbed HOOKEDGE, a lightweight Windows batch script that’s distributed via
- Chinese Routers Sold Worldwide Contain Backdoorsby Nate Nelson on August 27, 2026 at 7:31 pm
An untold number of ZBT routers sold around the world as white-label products come with several implants built by the manufacturer.
- OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Faceby info@thehackernews.com (The Hacker News) on August 27, 2026 at 6:36 pm
OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, adding that it found evidence of misaligned behavior as early as late May. The incident, the company said, took place during cybersecurity evaluations of several OpenAI models, and that it was mainly fueled by what it described as a “highly capable
- Agentic AI Risks, CVE Program Concerns Permeate Black Hat USA 2026by Becky Bracken on August 27, 2026 at 5:25 pm
This installment of the Reporters’ Notebook video series discusses the topics that dominated the cybersecurity conference, such as AI’s effects on vulnerability reporting and security research.
- Hundreds of agents went rogue in lead up to Hugging Face breachby David Jones on August 27, 2026 at 3:37 pm
OpenAI released a technical breakdown of the historic incident and plans changes to prevent such an occurrence from happening again.
- Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCEby info@thehackernews.com (The Hacker News) on August 27, 2026 at 3:13 pm
Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting servers that use a Windows filesystem. The Windows path traversal, tracked as CVE-2026-75604&
- ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Storiesby info@thehackernews.com (The Hacker News) on August 27, 2026 at 3:12 pm
A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine. The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting before showing their real behavior, exposed systems getting scanned, and exploit windows shrinking again. Different
- Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powersby info@thehackernews.com (The Hacker News) on August 27, 2026 at 1:39 pm
Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via prompt injection and Kiro Powers. The security flaw, which does not have a CVE identifier, works against Kiro IDE 0.7.45 on Windows, according to Mindgard. The latest version of
- Federal authorities disrupt China-backed hacking operation targeting US critical infrastructureby David Jones on August 27, 2026 at 12:33 pm
Compromised IoT devices were used in a yearslong campaign against key sectors and federal agencies.
- Learn How to Build Security Operations Ready for AI-Powered Attacksby info@thehackernews.com (The Hacker News) on August 27, 2026 at 11:56 am
Security teams have spent years trying to detect threats faster. AI is changing the harder part: how much time defenders have left to act. Advanced AI models can now help attackers discover vulnerabilities, generate exploit code, and move through weaknesses faster than traditional security processes were built to handle. The challenge is no longer just finding another vulnerability or
- Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacksby info@thehackernews.com (The Hacker News) on August 27, 2026 at 11:56 am
The Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences over their alleged role in TeamPCP, the cybercrime group behind the March 2026 compromise of the open-source security scanners Trivy and Checkmarx KICS and the AI gateway LiteLLM. Louis Michael Gaebler, 23, and Ruben Ian Thomson, 21, appeared in Perth Magistrates Court on August 27,
- What the Data Says About AI in Security Operations in 2026by info@thehackernews.com (The Hacker News) on August 27, 2026 at 11:30 am
AI is officially mainstream in security operations. According to Prophet Security’s State of AI in Security Operations 2026 report (produced from ViB’s survey of 250+ cybersecurity pros), 40% of security teams now use AI daily. Another 56% are currently testing it out, and only 4% have no plans to adopt it. For the teams already using AI, what is actually changing? Here are the ten biggest
- Russian Hackers Phish EU Officials Over Messaging Appsby Nate Nelson on August 27, 2026 at 11:16 am
EU governments are trying to move away from popular messaging apps as nation-state threat groups shift their focus from email to Signal and WhatsApp.
- Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Toolsby info@thehackernews.com (The Hacker News) on August 27, 2026 at 11:00 am
Individuals and organizations in Cambodia have emerged as the target of a new campaign that delivers an open-source remote access trojan (RAT) called Spark RAT. “The samples employ diverse lure themes, suggesting an effort to appeal to a broad range of potential victims. These include government notices, public health materials, real estate-related content, and other topics,” Acronis Threat
- GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Addressby info@thehackernews.com (The Hacker News) on August 27, 2026 at 9:33 am
Threat actors linked by Arctic Wolf to Dark Caracal with medium confidence deployed a previously undocumented Go-based malware framework, GoCaracal, during a June 2026 intrusion at an unnamed communications organization in Venezuela. GoCaracal provides operators with remote shell access and payload execution, while the extended profile adds browser data theft, keylogging, remote desktop control
- New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Accessby info@thehackernews.com (The Hacker News) on August 27, 2026 at 8:13 am
Academic researchers have disclosed a Rowhammer attack impacting NVIDIA workstation GPUs with GDDR6 memory that defeats error correction codes (ECC), the mitigation NVIDIA recommends against GPU Rowhammer, and enables denial-of-service (DoS) and privilege escalation to a root shell. Dubbed GPUThor, the attack was developed by researchers at the University of Toronto, who hammered four DRAM
- CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugsby info@thehackernews.com (The Hacker News) on August 27, 2026 at 7:05 am
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation. The vulnerabilities are listed below – CVE-2019-1068 – A remote code execution vulnerability in
- Dark Caracal Adds New Malware to Cyber Espionage Arsenalby Jai Vijayan on August 26, 2026 at 9:33 pm
GoCaracal is a new modular malware framework that broadens Dark Caracal’s capabilities to steal data and maintain access to victims.
- ‘HTTP Terminator’ Hunts for Novel Desync Attackson August 26, 2026 at 7:54 pm
James Kettle of PortSwigger talks with the Dark Reading News Desk about his AI-powered open source tool, which found new HTTP request-smuggling techniques.
- Red Flags That Expose Fake North Korean IT Workersby Alexander Culafi on August 26, 2026 at 7:21 pm
North Korean operatives posing as IT workers are improving their tactics, but researchers say there are still ways to spot them before they do damage.
- Android Malware Hijacks Update System for Car Head Unitsby Rob Wright on August 26, 2026 at 5:33 pm
Threat actors behind a notorious click-fraud botnet have set their sights on vehicle infotainment modules and are abusing legitimate functionality to spread infections.
- FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizationsby info@thehackernews.com (The Hacker News) on August 26, 2026 at 4:42 pm
The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country. The activity has been attributed to a Chinese state-sponsored group known as QTFY, employed by Nanjing Xinjiuwei Network Technology Company […]
- Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunnelerby info@thehackernews.com (The Hacker News) on August 26, 2026 at 3:35 pm
Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC). Group-IB, in a new analysis published today, described the cyber espionage actor as among the most active Iranian APT groups in 2026. Nimbus Manticore (aka