<?xml version="1.0" encoding="UTF-8" standalone="no"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:media="http://search.yahoo.com/mrss/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" version="2.0"><channel><title>The Hacker News</title><link>https://thehackernews.com</link><description>Most trusted, widely-read independent cybersecurity news source for everyone; supported by hackers and IT professionals — Send TIPs to admin@thehackernews.com</description><language>en-us</language><lastBuildDate>Thu, 06 Aug 2026 01:43:55 +0530</lastBuildDate><sy:updatePeriod>hourly</sy:updatePeriod><sy:updateFrequency>1</sy:updateFrequency><atom:link href="https://feeds.feedburner.com/TheHackersNews" rel="self" type="application/rss+xml"/><item><title>Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures</title><description><![CDATA[A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks.

The server-side gate hides the malicious page from crawlers and sandboxes while presenting selected Mac users with a fake software download. Microsoft]]></description><link>https://thehackernews.com/2026/08/over-250-clickfix-domains-use-browser.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/over-250-clickfix-domains-use-browser.html</guid><pubDate>Thu, 06 Aug 2026 00:14:31 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgzEMAtBAmz-q78zPppsCxMiU-EtelOA3FQy_T6Qzb9KpWEsc9wNMT1f_dDjf65q2W_nrioQ033KClusfHFXexSM8V30mReU5V3nbRY4W0_F3cg2ehG51P1nnWa1iKiGX3hJ_yUUYLF92TanEEE0HifpkzdqRQeqe8qFYXq0SPRx6pW9IrfS7sK_lPzWRM/s1600/mackos-finger.jpg"/></item><item><title>OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes</title><description><![CDATA[OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes.

To that end, it banned a coordinated network of ChatGPT accounts likely originating from Southeast Asia and operating from the city of Poipet, a region with extensive]]></description><link>https://thehackernews.com/2026/08/openai-disrupts-poipet-scam-network.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/openai-disrupts-poipet-scam-network.html</guid><pubDate>Thu, 06 Aug 2026 00:03:47 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgmYzVApv7lLg_Qt67mGI-sC0vUGKZwkNmFsVgTykAPCHqVMsfGSSQRRaxVXuxx0RDd6wk18yEiVXXy3uPRpmLT_XLNMCI_0iuKbPtJ3z9CtuPtjBsIGDAsVTd5f8DE_z2yMfAsQFW66vvoe5MeQPWvfBM2CoSzi-xpgm_mTvXfqHERAr-1z9NYOUPGOgwP/s1600/chatgpt-scam.jpg"/></item><item><title>Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt</title><description><![CDATA[Cybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) models on underground cybercrime forums and messaging platforms.

One such service, Poison Claude, claims to offer access to Anthropic's large language models (LLMs), including Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6.

"Advertisements for Poison Claude]]></description><link>https://thehackernews.com/2026/08/poison-claude-sells-discounted-claude.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/poison-claude-sells-discounted-claude.html</guid><pubDate>Wed, 05 Aug 2026 21:06:03 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhp3V9f5UsiH1E6dHfRvy0DEOYvcK14BatMbbLVfdPjLbu3PMInRmVXDi4xoGw-pSIuxUjZS1rdv4X7N1V9xRoV9RRVfaYdAWI6OTxKZzOhAlHYh6dKZNeAWCPkaPdGAvwgcOwFQ0atoRBUxKfE_KfhJpnm1yV1tXr5_Wv2yqND0vZCMMEfRB0V220SZbne/s1600/ai-access.jpg"/></item><item><title>Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports</title><description><![CDATA[Two security flaws in Paperclip could let attackers execute commands on a network server or a developer's computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both paths rely on importing a malicious agent and starting it.

A third flaw could expose sensitive data and control-plane details through application programming interface (API) routes]]></description><link>https://thehackernews.com/2026/08/paperclip-ai-flaws-let-attackers-run.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/paperclip-ai-flaws-let-attackers-run.html</guid><pubDate>Wed, 05 Aug 2026 20:44:05 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgnNyDWyCEMrA99LxVQMqKNr188rBBjKa6Kg3nHdjVLxWCCVgfqa0cChHo_JWbHgbSLHgZVpcgWn0kw0FUySWhScczQi6LNme-wY9rkUAxE-IvoFLvfum-zWxEnppDBu6bAHBO0ObN39kCDwSK4jnsqdCAOhCPGG0FtoLX_2vvCi2DcoWPmzGUk6Hs_gB4/s1600/paperclipai.jpg"/></item><item><title>Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug</title><description><![CDATA[HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django.

The three most serious:


  An unauthenticated flaw in Veeam's console that hands over a managed agent's credentials, rated 9.5
  A cross-tenant flaw in HashiCorp's MCP server that lets one user's Terraform token be reused for later users']]></description><link>https://thehackernews.com/2026/08/veeam-terraform-mcp-django-patch.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/veeam-terraform-mcp-django-patch.html</guid><pubDate>Wed, 05 Aug 2026 19:57:30 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiGDed_n3TJGLHvhq2MkwkQTsKgIv_rOw24MRfYCoHnHiOK7r-VbitMrwXXF9H_Gwbegba20Dla1FLyK70-OQRVxiHfikBFrz6jei3QK5u4ApbR4aYuLikQj1YHU2IzA1V4fnR7Wgcp8H1NoYzSeTTOUd4dNTuE71jNUNq-P4yk0H9FkW55wivMDdNe0nE/s1600/veeam.jpg"/></item><item><title>Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain</title><description><![CDATA[Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer.

The new dead drop resolver approach, observed in two trojanized npm packages "bianira-ui" and "fluid-type-ui," has been codenamed NullReceiver by]]></description><link>https://thehackernews.com/2026/08/trojanized-npm-packages-decode-c2-ip.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/trojanized-npm-packages-decode-c2-ip.html</guid><pubDate>Wed, 05 Aug 2026 19:11:27 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_jFD4wUBf7wKq8NwAgGKeKgJ3XIR82d26D7t5fNRBoDTOHcK5i66j4VqtLNAvK7Lkocc3lbW4SK33Ialb3F4EuB_k59ahZItRVdPsZ3RceScz5lEyR7gQHqqw221WMj6ArtKDUashxvrkYSPaE0b7ue8v-TkkT0IB8sPhgcCGIqN3mtfsjQ2MKztu5DkV/s1600/npm-c2.jpg"/></item><item><title>New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch</title><description><![CDATA[A memory corruption flaw in the Linux kernel's Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured distributions, and a public exploit ships with pre-built records for roughly 800 kernel builds.

The vulnerability, tracked as CVE-2026-64531 (CVSS score: 7.8) and codenamed OVSwrap by its discoverer, was disclosed by security researcher Asim]]></description><link>https://thehackernews.com/2026/08/new-ovswrap-linux-kernel-flaw-lets.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/new-ovswrap-linux-kernel-flaw-lets.html</guid><pubDate>Wed, 05 Aug 2026 17:13:27 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjhWC9UfjMK9e0KvUrcCjymLYZzuDDgZpArW3oZPtcds7CJ1pr1GleT46Wlm2_aWWpoe6TpgYcdnz_jhVOgjK6mnW_gekJkMotmfRiQ0xcp5v7mdx6CvVvUID0IyfSplGHGX-8JGoMJ1OLyEA96qVMTWwhEjKf21thNfvkBCg2DSgNjSkVEDyAugdcyJfk/s1600/linux-exploit.jpg"/></item><item><title>Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk</title><description><![CDATA[Kali365 is turning a legitimate Microsoft login into a gateway to corporate data.

The phishing kit targets US organizations with attacker-controlled device codes that victims approve on Microsoft's real authentication page. Once access and refresh tokens are issued, attackers may retain access to email, documents, and cloud resources, creating a direct path to data exposure, financial fraud,]]></description><link>https://thehackernews.com/2026/08/kali365-weaponizes-microsoft.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/kali365-weaponizes-microsoft.html</guid><pubDate>Wed, 05 Aug 2026 17:13:19 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgW4SMtq8o2R4j-NiqM2jQTNNSKABhkghGsH1AkUpqHf7sms7KTAr63IKabEzV2vAfAFO3XxYjh6YH8rDNtNVuu41JePoUdB_WQB-WWtJt4A-FWfmT6rwyzKAL_scAorwzVMt5R_7LZp2qzmUAAKfAodH__3_HLwa-nFV6b6TEng-5Cjviybn07c-ZNKUoU/s1600/main-anyrun.jpg"/></item><item><title>Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup</title><description><![CDATA[An unauthenticated attacker can read any file the service account can access on Gitea, the self-hosted Git platform, in versions 1.22.1 through 1.27.0. No login, no repository write access. A public repository and crafted Org-mode markup are enough. The flaw is fixed in Gitea 1.27.1.

The file-read flaw is tracked as CVE-2026-59774, rated Critical with a CVSS score of 9.8, and received its]]></description><link>https://thehackernews.com/2026/08/critical-gitea-flaw-let-unauthenticated.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/critical-gitea-flaw-let-unauthenticated.html</guid><pubDate>Wed, 05 Aug 2026 16:34:23 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjwgShwk2piIWpgBCF7ikGum0q7QycFbG91NuOiXNj4iRw_Uya_1R53Mx53EcLELS4lEusFjCYxTZuD0vf1VbGdXJ6rM9zq2OuNMsP20bbATKOaMUYbu9vWRbAJUQX436hP4vWvwc-jy1sWdoIIph0Uf93XMVImu-OIKnOMBUOYptMtoK9nAsP4yo48AtM/s1600/gitea-lfi.jpg"/></item><item><title>Leaked n8n API Tokens Exposed Live Instances to Credential Theft</title><description><![CDATA[GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive data and downstream credentials without exploiting a software vulnerability.

We scanned public GitHub commits for exposed n8n API tokens and identified 4,576 unique credentials associated with 1,255 hostnames. Of the 896]]></description><link>https://thehackernews.com/2026/08/leaked-n8n-api-tokens-exposed-live.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/leaked-n8n-api-tokens-exposed-live.html</guid><pubDate>Wed, 05 Aug 2026 16:05:29 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhx1pOdsqya8FoeUfRoysn2429wQSGELUYOuuaDRT5-pJMERQc7DY042ndusTV0UriGHrR98oyPe_HnR845R1hxSxKBTvYGTilYobQhIIXOCEc08FiKbhDluP0UoR6g3sw8QK-X1aPEJDKe-EZbDNOtlXR6ltGBvxsqfB_bo-jO4t63OvT7_C1mD7Bf4rM/s1600/n8n-git.gif"/></item><item><title>Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data</title><description><![CDATA[A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed.

The "evil twin" extensions were uploaded to the repository between July 26 and August 1, 2026, according to Manifold Security. The packages have been removed from Open VSX as of]]></description><link>https://thehackernews.com/2026/08/open-vsx-removes-77-malicious-evil-twin.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/open-vsx-removes-77-malicious-evil-twin.html</guid><pubDate>Wed, 05 Aug 2026 14:53:03 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh28AJU8_kuimN9uKY5xj-0XMAMxfVP4rejHEWMJ_5FD99mAvt8dEsRuGhlCGb63VjWykzePg_-tuaTqNycmvhZy3oFRFAuVHbwpsAg6ae599Pl7bYQVb7Qo7fDuDjWMHmHZOLfWc9HZkQlyAis8LNMmkS_wnKbvliVNsOej4p6XV_KbiFHHzJp1SjGFU1G/s1600/vscode.jpg"/></item><item><title>Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself</title><description><![CDATA[An agent running Anthropic's Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project during a cyber evaluation by the UK's AI Security Institute.

When a bystander publicly warned that the code was malicious, the agent denied it, force-pushed a rewritten branch history to erase the evidence, and posted from a second account it controlled to vouch for]]></description><link>https://thehackernews.com/2026/08/claude-mythos-5-tried-to-backdoor-real.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/claude-mythos-5-tried-to-backdoor-real.html</guid><pubDate>Wed, 05 Aug 2026 13:23:50 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhyvip0I7Uu7TeEHOGkVi4gl93ktZtzWF1krMsS1XPlRcql2xIf9UU4rXjDvdrF0HPPQaFCgNhhrrp9IM0HBJgHEzweJM41lccFe19e2DYqzkk5Au2STfT_Bjzzdfp_-UibeQ2o19Rh3OTtj5nOpbEn61gKQR4w7dPpOJ_5gP4Ob8KqqYLfWwAnoZ59FCo/s1600/claude-ai-agent.jpg"/></item><item><title>CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited</title><description><![CDATA[The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild.

The list of vulnerabilities is as follows -


  CVE-2026-9198 (CVSS score: 9.8) - A code injection vulnerability in Langflow that allows unauthenticated attackers to achieve full remote]]></description><link>https://thehackernews.com/2026/08/cisa-flags-langflow-rce-tomcat-and-n.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/cisa-flags-langflow-rce-tomcat-and-n.html</guid><pubDate>Wed, 05 Aug 2026 13:10:39 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjU9CZ3zh4mWF0SVRdcylBR7IyGB6j797LrHqyND8vcsBbiE6mcDlqaufSOBg2Av4Ej_HZ_gMxbzR-KS6GvXX0hLPgSFlh5gwxKwhjx3FvcdsQ7XP65x70cxeadgTM7uETFglAUoZrxwq9Rmx6i1T4yS-E7c7Szx9igRmM_GqG-8L5xfKYk2i3fhQGEHjez/s1600/cisa.jpg"/></item><item><title>QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer</title><description><![CDATA[Cybersecurity researchers have disclosed what has been described as a "long-standing supply chain attack" on QuickFox, a virtual private network (VPN) and network acceleration tool designed for overseas Chinese users.

According to Fortinet FortiGuard Labs, the supply chain attack has been ongoing since at least August 2025 and involves a trojanized version of the application to deliver FDMTP, a]]></description><link>https://thehackernews.com/2026/08/quickfox-supply-chain-attack-delivers.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/quickfox-supply-chain-attack-delivers.html</guid><pubDate>Wed, 05 Aug 2026 11:17:19 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiFQzlCdxoVUtdNgowwmPFaISlBF7Y2HsG1BQf3b-UJDQzRbPB249_W6rwU_-TSW1NES4OI-12R1z3tXQ-QlZv8cEaagpyLJVYz48Etb9W0MtuNp9BTL_13-5Wg95kz-Ey5iZ288mTkPt_5pbsxoh7Kv2KrmHqj_Tqb0KR9NSzz-jO2DuoTLthh6Dn3FUIh/s1600/quick.jpg"/></item><item><title>Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens</title><description><![CDATA[The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and seize control of user accounts.

"Greatness supports AiTM [adversary-in-the-middle] credential and]]></description><link>https://thehackernews.com/2026/08/greatness-phaas-adds-device-code.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/greatness-phaas-adds-device-code.html</guid><pubDate>Tue, 04 Aug 2026 22:57:39 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi8YRyOCSodUbPpWMicgOiuGbEQWDBmu_W-47PAUFkS7yKEQe4Do6svH4cQb-U0tC53C9mqq8ijjlG9gwuzyqYfNwtS61WxvNxIgk1dVC7wX598rncb_MgQ5t4yxc8NUYVdb6PT5cu7ZXJ7w3KaYG_7vtU5xixHel1jSADbtR-GC1bmngZPArXw-NjkTH1x/s1600/Greatness.jpg"/></item><item><title>Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks</title><description><![CDATA[A credential-stealing npm worm that first appeared in keyv@6.0.0 spread beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations on August 4, 2026.

SafeDep verified 353 poisoned versions across 79 package names in the npm registry. Its monitoring put the wider footprint at 442 versions across 353 names, while Aikido later reported at least 868 packages]]></description><link>https://thehackernews.com/2026/08/keyv-linked-npm-worm-poisons-hundreds.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/keyv-linked-npm-worm-poisons-hundreds.html</guid><pubDate>Tue, 04 Aug 2026 19:00:23 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjAb0f5sNdFs0uLbgh9_rBZ-SaCrUjv3c4mL7OLF7pFPxH5pusnFJyInc_7S-QqgMa0DsEm2fId6v2sWX7hJcaA0eHTHngKBXGOA3ysg7NYz1CyMAgwsrWnJ3FA1HGFkzglgj5pGsXeLWzXjCUhNGi5ecEsqIu2oOzz_koXsQAAC0EV5HkuAJGtAVvWotE/s1600/npmnpm.jpg"/></item><item><title>Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access</title><description><![CDATA[Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Monitoring and Management (RMM) programs like ConnectWise ScreenConnect.

The campaign has been codenamed SMOKE#SCREEN by Securonix Threat]]></description><link>https://thehackernews.com/2026/08/fake-adobe-and-zoom-updates-install.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/fake-adobe-and-zoom-updates-install.html</guid><pubDate>Tue, 04 Aug 2026 18:41:22 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi35nnI5-o_HtA0Eunk4tOFM1lg12NrqY7HrDNBbee-kPWR-BHHxXQtd-Tj3b7FrMlTOcWNC63XgVV9n0FEoD-G4ydCpmBv2g1PjvS-lzopLbMnODHbNL2bGMJ6nOYXST9M83vc9IYZaUOjkUqaa4Xo-LaAOtXu3bRhYAcVIUwxgDNMifc6xWI27VVca_B4/s1600/screenconnect.jpg"/></item><item><title>When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted</title><description><![CDATA[The cybersecurity industry has spent decades assuming that offensive capability scales with technical expertise.

That assumption is starting to break.

Security teams have long estimated risk by ranking attacker sophistication. Nation-state actors sat at one end. Organized criminal groups followed. Inexperienced attackers, dismissed as "script kiddies," sat at the other end, running public]]></description><link>https://thehackernews.com/2026/08/when-vibe-hacking-turns-ai-into-junior.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/when-vibe-hacking-turns-ai-into-junior.html</guid><pubDate>Tue, 04 Aug 2026 17:00:00 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgRUUATlzjkTMUxaFn2DI_qPw1WxQaqSvIY58hYRWrDQwnqyeDWgazdM0HarQoeNs9oXocZCMP__YqOZxnxyWz30-kEKzLZOFGyJ46GAuWyEj0ZfL69dqBd7OX1SdtiUoprog0-7JWYaYs1y2ceQGFT-GtTfsjiVFhyphenhyphend6WxYXV-1BYVhLRUIQ5hWqSyz2U/s1600/breachlock.jpg"/></item><item><title>Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent</title><description><![CDATA[Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue could manipulate a triage agent into triggering a privileged code-fixing agent.

The researchers said the public agent could be prompt-injected into posting /adk-issue-fix as adk-bot. They identified the bot as a collaborator, so that comment satisfied]]></description><link>https://thehackernews.com/2026/08/google-deletes-3-adk-ai-workflows-after.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/google-deletes-3-adk-ai-workflows-after.html</guid><pubDate>Tue, 04 Aug 2026 16:46:23 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhLUUlqxE9AYL9PyFAlWMsG9czDcrU9p2kMUsumVIYx5SnlMAO0z-n_weUWeX-CiMHQBbkGK1lV-78vp003-bAeRP4gQRyGXlq5blzx5dJdd9zFttd2tjhGlNUFLNk-6ro9GfXMkRCFVLs-ex3gWHoJh-87sZifOeTKohLNoypvvqLUUPLkGUsjKXfAj7A/s1600/google.gif"/></item><item><title>New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root</title><description><![CDATA[cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context, crossing the privilege boundary between a cPanel account and the server's administrative database identity. It shipped in a targeted security release that closes two other routes past account boundaries.

The database bug is tracked as CVE-2026-58048 (CVSS 4.0 score: 9.4) and affects]]></description><link>https://thehackernews.com/2026/08/new-cpanel-critical-flaw-could-let.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/new-cpanel-critical-flaw-could-let.html</guid><pubDate>Tue, 04 Aug 2026 16:06:27 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi2LFB09rf16kl1_PinOnHkAY4GiI38_azQ2t-EWYRicFndp5DX-5KSfwVVEJxwEKp07oouBfkFg71MxwilLY_M2i3clk82hs5-Xr-PgDj69JeYzTsPjp_8sdNZIminQFonHRq2GqWDXJuwGqpT4Na485_pILlvMSlBdSMqWYWqTHDrUC_9OdOW-kCdSeM/s1600/cpanel.jpg"/></item><item><title>DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT</title><description><![CDATA[A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims' browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager.

"The first stage drops a steganographic PNG image into the browser's cache, retrieves its hidden content, and executes the second]]></description><link>https://thehackernews.com/2026/08/doublecup-uses-clickfix-and-cached-pngs.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/doublecup-uses-clickfix-and-cached-pngs.html</guid><pubDate>Tue, 04 Aug 2026 14:33:23 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh0MM7WIz9TI9RxDFZ-toTt_tLMlGIJGGyqnPZ5m68ft2_h16hOepWgOlGkRdx7KdUaRjz7GxanOYCp3167ZvcaWo1MV9ihUjZb6dHyX4Ss8SV6X4GGpobunHDfXs83HKppsCR-TT8quPfiNmH1Z-7EvWRZ4cdyHsHRsmlVshEJpDa76yUCjaWy0-xXaeeS/s1600/double.jpg"/></item><item><title>CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises</title><description><![CDATA[The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog following reports of active exploitation in the wild.

The vulnerability, tracked as CVE-2026-18577 (CVSS score: 8.2), is a case of incomplete patching for CVE-2026-18556 (CVSS score: 8.2) that allows]]></description><link>https://thehackernews.com/2026/08/cisa-adds-exploited-n-able-n-central.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/cisa-adds-exploited-n-able-n-central.html</guid><pubDate>Tue, 04 Aug 2026 12:30:13 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhbA9omGpwD_xkaXsQD13QewwbHkZMx1FrBHBvsnFkbjkFTY6F679EEe_xtesc1R6ToZIZlHq4osq4AmGAI-74IHaagkIP7KhQp3X_QtlwaMx2ALTqs_sZTdtpmJNd1UHf_Mq2F9jfmz8viAlapY4gFUa5ZLAEtF_VjjzebWZApbU1VDElceFwS4sa2rR5C/s1600/cisa.png"/></item><item><title>18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users</title><description><![CDATA[Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments.

One of the packages in question is "lib-mtop," an unscoped package with the same name as a private Alibaba package]]></description><link>https://thehackernews.com/2026/08/18-malicious-npm-packages-deliver-cross.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/18-malicious-npm-packages-deliver-cross.html</guid><pubDate>Tue, 04 Aug 2026 00:13:53 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhb0HLXOvc5Gir8E_IXoYIRMQG7CsNL7gJEkPytfRRQ67OWrIoyrGAX78K0Ca0VJ7hhpyru2Vck7ntHKLyBLhGezuyOD_znWoB88KhAdEWu8MyhVbiEia2GfbRVeDPhaCEAHfhY637LqeIyso03edEkOGL3p0c3O6_Nn7oJ6rNmyve-6_pqziBCokfiKoKI/s1600/npm-git.jpg"/></item><item><title>Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts</title><description><![CDATA[Malware running as an ordinary user on a Windows machine can sign into a victim's passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim's screen.

Unit 42 detailed three attack paths against Chrome's Google Password Manager cloud authenticator, which it calls Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key; the strongest targets the master key]]></description><link>https://thehackernews.com/2026/08/google-password-manager-attacks-could.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/google-password-manager-attacks-could.html</guid><pubDate>Mon, 03 Aug 2026 21:54:47 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjNiuQky0C3uTOSaOEyGLg0O7h1B0VAP9nU8bwdZe-8DKD_pOBihrvWw-2ecGt03mmT0V1F0bg7xOQuv88cZlLcLqavDM9gWnZHku-skIzJMEWw3lBNvrVcDaeaezVTvt1yBCecBTQBT_SUsY1rTV-ygCEH1vUjttcAx8swmGljZPAXYRQ2APBwPrUhvPI/s1600/google-passkeys.jpg"/></item><item><title>INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws</title><description><![CDATA[The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances.

In a report published over the weekend, Resecurity said it observed the INC Ransomware accelerating its activity since the beginning of August 2026, listing multiple victims on its data leak site. Per]]></description><link>https://thehackernews.com/2026/08/inc-ransomware-emerges-as-dominant.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/inc-ransomware-emerges-as-dominant.html</guid><pubDate>Mon, 03 Aug 2026 21:45:13 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEghC22v1WIfuZutm_-lxuOPzdipffNmYvZ5KA9l_AUg-8EgQr9Gy0ouYijU_Vab5m5aIpGChViq6kpC4_h1fZfjBw415YHCINhU9GXTkil94vJv_Ct241xptfhjyt34cV348Q5VHlRVlKSj32-uj1u0PocPhDf9CBYuhFfPhvLjiHTqPYOPZBpXUyhiAe5Q/s1600/sonicwall-ransomware.jpg"/></item><item><title>⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks</title><description><![CDATA[This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended.

Some of it was clever. Most of it was just access left lying around: old bugs, exposed gear, poisoned dependencies, weak defaults, and tooling that moved from]]></description><link>https://thehackernews.com/2026/08/weekly-recap-rogue-ai-models-88m.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/weekly-recap-rogue-ai-models-88m.html</guid><pubDate>Mon, 03 Aug 2026 19:33:11 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgoiIM6TX9TShDQoVLnmGNE_LZPas3bK4cwsNviskgSjdFASOmzcJPOixde9rkt0uawGd5D5IRHc09j5etqie865lUafh95s-TggQm3PluElF3XhILbJUCkl6vJy6lAM5FSu0GBNu6eWHcVzH7d9X86fvxOjnhwylSgakxghEq_05FsWzZ8mSVMHWYr5HBS/s1600/weeklyrecap.jpg"/></item><item><title>FOMO in the SOC: Where AI Platforms like Claude Actually Fit</title><description><![CDATA[AI is moving incredibly fast, and every security leader is feeling the pressure to keep up.

AI platforms like Claude, Codex and Cursor are already helping security teams write detections, investigate alerts, summarize incidents, and automate repetitive work. The conversation has evolved from whether AI belongs in the SOC, to where each type of AI delivers the most value.

With so many new AI]]></description><link>https://thehackernews.com/2026/08/fomo-in-soc-where-ai-platforms-like.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/fomo-in-soc-where-ai-platforms-like.html</guid><pubDate>Mon, 03 Aug 2026 17:00:00 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgvsPqZrMBUJ3CH2LqsxL_1HWV6F-qs8FbnvytY_bz9ZlSUptj-3SPJ-BAlDBrF9V39V2F_D35LPU8BgSdDNfyPi2tqESWH_g2qzP2ospA36aF2CexX2_bRw7ee6qG4uqAyI24lavgb5wER2wuKWYd6rOUpdG0pbhlR4aAtEvSTuAQYmv8a5izEpv63mcA/s1600/phish-main.jpg"/></item><item><title>Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS</title><description><![CDATA[An unknown Chinese-speaking threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit.

Attack surface management platform Censys said it identified the threat actor running more than 100 web properties, most of which are fake Amazon Web Services (AWS) sign-in pages on a domain that also hosts the exploit]]></description><link>https://thehackernews.com/2026/08/chinese-threat-actor-uses-leaked.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/chinese-threat-actor-uses-leaked.html</guid><pubDate>Mon, 03 Aug 2026 16:19:06 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgvbg0AbgcDL8IouGo4deahk3vOuegzB-hxhUxAok05EuI5uuYJUDP-mUVS1w-gr9Oedf6JzF9qEB3l8MWVnsFGkmZ4ZorInHavwKWrQ7toTmv64uc4EnJdoFDqGlDPQsgcTwnJo8rlZyfG9yFu60fNE51Di00aVdZoiv5YMIvobc6xuWZhT_cKDk3ikV-P/s1600/apple.jpg"/></item><item><title>PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web</title><description><![CDATA[The Police National Legal Database (PNLD) has confirmed that police, government and customer contact information was compromised and published on the dark web.

The data included names, organisations and work email addresses belonging to police officers, police staff, criminal justice professionals, government partners and customers.

The incident, identified on July 26, also exposed some names]]></description><link>https://thehackernews.com/2026/08/pnld-breach-exposes-uk-police-and.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/pnld-breach-exposes-uk-police-and.html</guid><pubDate>Mon, 03 Aug 2026 14:43:56 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEguFnLbEr199EuLksobp-I8Z6liAUmM4EKRi94ttPtanQN2aiwvNh1qHK_kkGhOBfWTzLzANlQ3jd6FmJOHWbdn8rFfg1sHvYqmBaVM5kfak1JxRhqPEfNR94zY_pibMdsbWMIx8gqcZZjoYLhKk03Gw3PrYKF6JQzrNLV6HiE5U7UtYPSwmH-OmDmjl8c/s1600/exfilsquad.jpg"/></item><item><title>Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable</title><description><![CDATA[Thermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered before analysis software loads them.

The vendor's July 31 security bulletin says nearly undetectable changes to .fsa and .hid outputs could occur if laboratory controls are circumvented.

Thermo Fisher tracks the issue as CVE-2026-17583 and rates it]]></description><link>https://thehackernews.com/2026/08/thermo-fisher-patches-flaw-that-could.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/thermo-fisher-patches-flaw-that-could.html</guid><pubDate>Mon, 03 Aug 2026 13:35:30 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjMO8eh_7kmo0QAAphjdYIXsjfGspFVU9gV5XInqqhs4WnFNCm_hP-EBdmVln7vSrwWkmo9pdvoxAQbaC17M8sYg7VzBX8RJnRIb6E6pBr5euW9WweOeeZk9XpN8O5I5vF_OGypfqp9WO-SO_C81D4DDui3uTp0jBvV5_C7qIjuRgtoMd4bKQ1y8QEnC3c/s1600/dna.jpg"/></item><item><title>N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete</title><description><![CDATA[N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers.

Its first fix was incomplete. CVE-2026-18577 affects N-central builds prior to 2026.3.1.7. N-able shipped build 2026.3.1.7 on August 2 as the first unaffected version.

N-central is the remote monitoring and management platform]]></description><link>https://thehackernews.com/2026/08/n-able-says-attackers-take-over-n.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/n-able-says-attackers-take-over-n.html</guid><pubDate>Mon, 03 Aug 2026 12:11:46 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjs1H8Wx5_ZrUFksG2Tgb_6qho5XHULdP13qVeYXx1xWPPt8B2rH68XC6IhzBk-dczgsdWvpZ_dVTI7AIMsgK1EeU3B89WVUJu2N5B71FQ4GnlZDRlvNiD4pGO2hBCJGVowjUVDMSHAO_0CPlYthpa8jx-Af5OwB6ZMDr-PKTYDJKjP4pGCZZolbjbGi44/s1600/n-able.jpg"/></item><item><title>Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code</title><description><![CDATA[Three high-severity security flaws have been disclosed in Hugging Face's Diffusers library that could allow crafted model repositories to stealthily execute arbitrary code on machines that load it, opening the artificial intelligence (AI) supply chain to security risk.

"These vulnerabilities are bypassing trust_remote_code, the safeguard designed to stop unreviewed code from running in the]]></description><link>https://thehackernews.com/2026/08/hugging-face-diffusers-flaws-could-let.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/hugging-face-diffusers-flaws-could-let.html</guid><pubDate>Mon, 03 Aug 2026 12:10:31 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiWQmUt2QHxTfiXiolir9akmVh8dT5di3UBDtD7H2IJlkWQ4x4VmeTUEZo8CUvz2q2FXCvxTJDHenWPzqPeSbnlCYSRTNGULKdWRJnsmVg7SVJT_BBPABxqRuvr22Z9V2C6P51fRjSGzgAlHMzEn-MjA4yTMfCaM91ujVajF8GJqYg9ZaZELXsCc-GMnYq8/s1600/hugging.jpg"/></item><item><title>Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes</title><description><![CDATA[An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite.

A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG]]></description><link>https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html</guid><pubDate>Sat, 01 Aug 2026 22:47:22 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiea5Kw_2TLtPI4Ts3s3anmPIQr3S8VxO0G9yL-UV1dSlRrW1Z_L41XoHcSFuk2ThCBDKLFy-xZl_y7DnA0FM2nWHk4G1TpV2iMx6-X6EDT3gK7s0pJu6e1wMUoEsuPifcXseXuqOIHL3W9voWoD_se5gKJPyii4X0mJY7sxJ3uOPlTWVfAyrKs4ixa-18/s1600/coldcard.jpg"/></item><item><title>Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites</title><description><![CDATA[Attackers modified a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses.

Adform detected the incident on July 27, 2026, removed the malicious code, notified affected clients, and reported it to authorities.

Anyone who visited a site carrying the affected script on July 27 and copied a Bitcoin,]]></description><link>https://thehackernews.com/2026/08/hackers-poison-adform-script-to-swap.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/hackers-poison-adform-script-to-swap.html</guid><pubDate>Sat, 01 Aug 2026 14:33:07 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiX-el4ovGAmKfllRfhupL0SzdEoZKlouDb1_YmhCOl3owxN1ks0Do-WphuD77rka_3ukbqvPxSmFYMdBKBirYyw0DJpvSxVP5riGBR_vd7wKwnpgZfNm0RFEDLTzsvzzQB7qGtawMvpccd700dfNM2zZeFTy9cyHf4oFyHSASKRU3gmxbMgTJRtDFsSNs/s1600/adform.jpg"/></item><item><title>Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction</title><description><![CDATA[Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution.

The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system.

It has been described as a case of incorrect authorization that could result in]]></description><link>https://thehackernews.com/2026/08/adobe-campaign-classic-cvss-100-flaw.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/adobe-campaign-classic-cvss-100-flaw.html</guid><pubDate>Sat, 01 Aug 2026 12:42:42 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgL4TR-PlW4MehiF4iAbWafpNUQrSuhhTuEZwgwba7Gi0mF-PfixGSlFmpsBm51WbJYfkA69ZYNjO2aWl8eE8tqdSPdJL7mvLOaYL9O6VWkfxw96YFF0Qxt1ggCurqVd2J2muf6SAjW0cCrt2UwnOO3rK76X-mBWHW1e8-2Mk6FERpS1yPrSVScImJ0TmKW/s1600/adobe-flaw.jpg"/></item><item><title>Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware</title><description><![CDATA[A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report.

Researchers track the operation as CaptiveCrunch and attribute it to Storm-2945. It assesses Storm-2945 to be an operational sub-cluster of Midnight Blizzard, also known as]]></description><link>https://thehackernews.com/2026/08/hijacked-hotel-wi-fi-pushes-fake.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/hijacked-hotel-wi-fi-pushes-fake.html</guid><pubDate>Sat, 01 Aug 2026 11:59:05 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEglJ30Q0_3tS3R4yrNdyR3sDdvBam1plVfmenBAFVPGmaVMErJ_oq_zXoIpeAjrFrkkFkudKUSHI-h82FGoiIJlkT2JghjQKrO2p7VmzpduPGv26gGgJ8I04b-U7eY1sihmIer0bGTtIof3CwH1vKmQOYLDvhNsYICoALOLhehhaLC65fPmAH_fpT0BrKk/s1600/hotel-wifi.jpg"/></item><item><title>Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk</title><description><![CDATA[A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, since January 2025.

These targeted organizations operate across several sectors, such as healthcare, research, government offices,]]></description><link>https://thehackernews.com/2026/08/suspected-chinese-speaking-hackers.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/suspected-chinese-speaking-hackers.html</guid><pubDate>Sat, 01 Aug 2026 00:22:04 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjmBagWdesuJqVgNAHPh7t75IGrajY_oJeL9HHI7r23AK7CuLUN22-GBwDCWJWTlIutBApsdhSGproqxtR6kV_Dg04FT2zc6vZXZCQed8Kx3bD-jw-VXkYfAHlJsNgcQOcqRFW8TTh1kyN34MisnGx3ImU9vejv_oNy4jN0sPNcPM7jclq7klrMmGrnROjk/s1600/chinese-hackers.jpg"/></item><item><title>HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm</title><description><![CDATA[Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka.

According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a link to an encrypted archive, which holds a Windows Shortcut (LNK). Executing the file triggers a multi-stage chain that]]></description><link>https://thehackernews.com/2026/07/hollowframe-loader-deploys-matryoshka.html</link><guid isPermaLink="false">https://thehackernews.com/2026/07/hollowframe-loader-deploys-matryoshka.html</guid><pubDate>Fri, 31 Jul 2026 22:09:31 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgjOaqDYzKWLfOEp56DfMjSmDMudw7Y3DBFUY_xOhGNTnzRYlKw9YCNNbjLvepf-vDHB_KVSSA-KZjx2dNXjJR3ZpTpS_IgGSfhLRjyR2P8ocr_uWQ1w5UcYpuXnycnyv2tPtDqXoZMvD9pqgCNCPDrYMwAup0ftaycFLYzxHvdoOWhEA1ZXffc9ahBpkj5/s1600/law-firm.jpg"/></item><item><title>Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies</title><description><![CDATA[Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators.

Researchers named the operation Fuyao and attributed it to Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China company founded in 2019.

The same apps have a second job. When a box]]></description><link>https://thehackernews.com/2026/07/cheap-android-tv-boxes-pose-as-phones.html</link><guid isPermaLink="false">https://thehackernews.com/2026/07/cheap-android-tv-boxes-pose-as-phones.html</guid><pubDate>Fri, 31 Jul 2026 20:15:01 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjhxfc7_NuArKSujgjgzPzENagYVTlBxcvnFBXSbptnFs_TI1o-Zt5SINHtPEO5MNkJ3vwkKUTX68vwmCzVxRQVFcgnb9eXwAsLKayCtzMLVRuqwV3RDaWTgQNOm0CVXcV_jX1v4x4mgEthTDjAsZdF4BSPSuTTRqKnM6qbIhPVjZP38dHmpptNurSmXRM/s1600/android-tv.jpg"/></item><item><title>Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined</title><description><![CDATA[Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined.

Both versions were released last month. In its latest patch for Chrome 151, released Wednesday, the tech giant resolved 370 flaws, out of which 349 were reported by Google itself. Seven of the]]></description><link>https://thehackernews.com/2026/07/three-recent-chrome-releases-fix-1442.html</link><guid isPermaLink="false">https://thehackernews.com/2026/07/three-recent-chrome-releases-fix-1442.html</guid><pubDate>Fri, 31 Jul 2026 18:21:52 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiqUoKsOzzL1DJubfk79p5F7EfcWUNP-tPwTMNDt329zqRohKeX2tE3qxMCciII-FZEHofHM72OihyAfF_7Eqs48MRmxxVOcGZyKML5LHynh5Akf1fWeNSsDlY2D-EaGLx2T9wy6y2jNfOGx-5xmKNhf0koUmkpIGcuShRA47RVW_207PVhnxdlPijMUmkx/s1600/chrome.jpg"/></item><item><title>Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw</title><description><![CDATA[An academic study has disclosed a "widespread class" of security vulnerabilities impacting 4G and 5G core networks that, if successfully exploited, could trigger denial-of-service (DoS) attacks and even session hijacking, allowing an attacker to seize control of a user's network session.

The findings have been released by a group of researchers from Singapore's Nanyang Technological University]]></description><link>https://thehackernews.com/2026/07/researchers-report-84-flaws-in-4g-and.html</link><guid isPermaLink="false">https://thehackernews.com/2026/07/researchers-report-84-flaws-in-4g-and.html</guid><pubDate>Fri, 31 Jul 2026 17:25:00 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhx5Qzkfu4WC4nW5n_nmFDP3CoZsw91wzaKcfKRZBx7DXHggnqqxqun757BOQey3jOUCGe4928DBU6fy4dPX04Cmp94xqWdNkZgkp1DuenVewYZFxSs9YSQdArKp1Ma3hAGkDAIA7zH8_7hXubNrJbP27r6XxIlCrzrYYoi3vAVFaLVdu1tnN6blLhE61xE/s1600/ifinder.jpg"/></item><item><title>6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026</title><description><![CDATA[Device code phishing - the abuse of the OAuth 2.0 device authorization grant to steal access tokens - has evolved from a niche red-team technique to an industrial-scale threat in under six months.

Designed for input-constrained devices like smart TVs, printers, and so on, the device authorization login flow has been adopted by a wide range of apps and use-cases that it wasn't originally]]></description><link>https://thehackernews.com/2026/07/6-reasons-why-device-code-phishing-is.html</link><guid isPermaLink="false">https://thehackernews.com/2026/07/6-reasons-why-device-code-phishing-is.html</guid><pubDate>Fri, 31 Jul 2026 16:54:59 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiamJN4Z-p-XmpB_1nwgfCMj2JvWAmGP4avhjI3pBYb11kgANQy4wQf2DQ4VGJEXom4eZCFoqVozP4aJPPtpGufYrEe5E9xkebmctud6KO7NZEfNCiT14ln7CmZA1bB3m6HYNdiUnShVsIpr03SYa7jlZWnbml9R1HbqECSbnUH0DTqyETz1fpiNIqhExw/s1600/push-main.jpg"/></item><item><title>Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks</title><description><![CDATA[Palo Alto Networks' Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously.

After an initial Telegram instruction, the agent found internet-facing systems and selected public exploits. The researchers recovered no further operator input in the session.

The operator, tracked through the aliases knaithe and KnYuan,]]></description><link>https://thehackernews.com/2026/07/chinese-hacker-commands-deepseek-via.html</link><guid isPermaLink="false">https://thehackernews.com/2026/07/chinese-hacker-commands-deepseek-via.html</guid><pubDate>Fri, 31 Jul 2026 16:51:27 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi2dGysHIR6yJWx6hMxq6lAct7fi4YTury_WDkrcenDv-psd-fU7I8K3RbM6Blox_5OE3MQojew5bnPamtI_DPzdBX6fOk295hhQh6rBkA2f9a1sN7t7ZbSyU-kWdLoIb7XnseOHKPmLOGRb9wRRvmV0scVZ4rhMtxSmqOLZmZIUjtg_IHT4FBg5gzeX50/s1600/deepseek-telegram.jpg"/></item><item><title>Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations</title><description><![CDATA[Anthropic on Thursday became the latest artificial intelligence (AI) company to reveal that three of its models, including Claude Opus 4.7, Mythos 5, and an unnamed research model, had breached three unnamed organizations during cybersecurity testing without its knowledge.

The AI firm said the earliest incidents date back to April 2026, adding it made the discoveries after launching a "]]></description><link>https://thehackernews.com/2026/07/anthropic-says-claude-mistook-open.html</link><guid isPermaLink="false">https://thehackernews.com/2026/07/anthropic-says-claude-mistook-open.html</guid><pubDate>Fri, 31 Jul 2026 12:11:44 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjJ3hIjH82iCzMILnA0uACotjW9waDLj4siTRhyphenhyphenBSiVyis0Ul0j7-7FcWyDzmCAzZPLJ72iYRezpbd9dUAB_UMw5G4eMBRwph0Sb_aQr9yCRXeLXAkjGiNFekM_qDtOZNFsSk6LLC81Ef74JaqIrcJN58-5p2ShHmUuhKC1IYeVgpQ7D76NWXLnR44RN6G6/s1600/claude.jpg"/></item><item><title>DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware</title><description><![CDATA[Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Contagious Interview campaign.

The defining aspect of the attack is that bogus macOS software update screen stealthily]]></description><link>https://thehackernews.com/2026/07/dprk-linked-macos-malvertising-uses.html</link><guid isPermaLink="false">https://thehackernews.com/2026/07/dprk-linked-macos-malvertising-uses.html</guid><pubDate>Thu, 30 Jul 2026 23:48:24 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhCHbm6QCC9jjGwa-7P1N2PwhDjRvpC2hlS2hl09-DUZa5xdDeHt9qH1zISepl2ERqDzmDbdQ_zfE2vkHDsvE7G8QsetJHjzC45DpPr5-83lc1BGaLHfEwMfdYEA04d5xc7GL02_qkz1HjhIenSKBWF0FZqHnICaLn9agLEoEGnnN2n-smXxYFuQQaYNd8A/s1600/all-secure.jpg"/></item><item><title>ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories</title><description><![CDATA[A lot of security still comes down to trusting the wrong screen.

This week, that screen might be a login page, an install guide, a recruiter call, or a familiar service behaving slightly wrong. Behind it: reused credentials, exposed systems, quiet loaders, abused trust, and exploit paths that should have been harder.

Some defenses improved. The loose parts still got found first. Anyway,]]></description><link>https://thehackernews.com/2026/07/threatsday-ai-powered-hacking-370.html</link><guid isPermaLink="false">https://thehackernews.com/2026/07/threatsday-ai-powered-hacking-370.html</guid><pubDate>Thu, 30 Jul 2026 20:55:57 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgNfPEjoHY1NDIrmCVPaZ_dmWbOk0MZwMlh6Odxpqfchn-5rOvsj4PhaBZs4LJvoj5iXhgbBTZzKCNYOPbblXU6kSnVNxEfQER6bNIuhROsSBTrhS6P_mPySTbAS5CvbYgu7lOANl0C6YuLR92om_sS_-9skmNqYT4BDmy_07cTMVj75vUUES70gPicrgGW/s1600/threatsday.jpg"/></item><item><title>Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database</title><description><![CDATA[A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz.

Wiz, which codenamed the chain CosmosEscape, said the exploit chain began with a crafted query against a Gremlin database controlled by the attacker. From there, code execution on a]]></description><link>https://thehackernews.com/2026/07/azure-cosmos-db-flaw-exposed-platform.html</link><guid isPermaLink="false">https://thehackernews.com/2026/07/azure-cosmos-db-flaw-exposed-platform.html</guid><pubDate>Thu, 30 Jul 2026 19:04:09 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_dFT-y76kGOf4rFOAu6NYNsE2s57G-7dl0a03tULY-f2ZGTbpPeEvu-NUCLVh-bgEdBvecIt28BJLQXUHclBc_IfGP9tBSZyMIm971Myrp2_zhSPyXhCJkhYmSfvLWNRewSsCip2YJfBEWocEEKdXPUL-y_mK8ZcHbBAaTWt8SzXmDJeQoYc6r5ceC6A/s1600/wiz-cosmodb.jpg"/></item><item><title>Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents</title><description><![CDATA[Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file. Håkon Måløy disclosed the technique on July 28, 144 days after reporting it to Microsoft.

In his proof of concept, the internally generated file triggered the same behavior when it was used in a second Copilot drafting session.

Måløy's]]></description><link>https://thehackernews.com/2026/07/microsoft-copilot-for-word-can-copy.html</link><guid isPermaLink="false">https://thehackernews.com/2026/07/microsoft-copilot-for-word-can-copy.html</guid><pubDate>Thu, 30 Jul 2026 17:24:49 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi-BgxoTGLqXYzQh4HW0TUm-hbX0ApFizzFtFkKe5mb3fKS_yn6Zzpj_Uvivxi7VCwEUOuJx3Bg1XHpHWq9tbZh5xBrAHT4gBG2DYyqvFkVKmWIRiF_zCpXIG5bTs7HfsV1pjM2EsTm-e7WttN-iB57p0n4ki2Vs7vXyB6rTF9mSqlwPu3h7KHocg0mWcI/s1600/copilot-word.jpg"/></item><item><title>The Network Has Become the Control Plane for AI Security</title><description><![CDATA[Network firewalls are the workhorses of modern cybersecurity. They are trusted to protect the network, blocking malicious traffic and preventing intrusions and breaches. And for decades, network security teams have built controls around a relatively stable model: users connect to applications, applications exchange data, and security tools inspect packets, protocols, and destinations. Firewalls]]></description><link>https://thehackernews.com/2026/07/the-network-has-become-control-plane.html</link><guid isPermaLink="false">https://thehackernews.com/2026/07/the-network-has-become-control-plane.html</guid><pubDate>Thu, 30 Jul 2026 17:02:46 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhCMiEYFcCrvL7s-o_ZApEbF6gP4J5FpWseBSQN2iP5bBIXP51mVR8QDnUmxDHBrMr0ta6ucsouVsVnWg8mGPeRvwkx09PCddi0pWLYzOpeA7NnrKUaeVhypXKK9rBJSfminUSBH9cz4YTelqUFMU-VZU2G-mkKFhb1pMQsGcAqtuT4btXzbbgb4pD1Mdfi/s1600/checkpoint-main.jpg"/></item><item><title>Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts</title><description><![CDATA[South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally installed financial-security software and infect targeted visitors with SIGNBT or COPPERHEDGE backdoors.

A compromised page could infect a system running a vulnerable AnySign4PC version without a prompt or]]></description><link>https://thehackernews.com/2026/07/hackers-exploit-anysign4pc-via-hacked.html</link><guid isPermaLink="false">https://thehackernews.com/2026/07/hackers-exploit-anysign4pc-via-hacked.html</guid><pubDate>Thu, 30 Jul 2026 16:03:15 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjGU7u7ESWcaN4Xy7bCwiH5yVHsr1vMjqCu05UKJ7c4tsJ4gSRsQXwg-WOe69VD1dLiRuf9FC3HTcjp1ia1NZPPg85MUmHz2TCOplJKSC002w7OMu0X9KWtXTN0MljVt88tQlfABhP7p4pnndpOJoplI5fnqheI8LZwBp623A6gx1HyurT4ZBHRSSils1g/s1600/south-korea.jpg"/></item></channel></rss>