<?xml version="1.0" encoding="UTF-8" standalone="no"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:media="http://search.yahoo.com/mrss/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" version="2.0"><channel><title>The Hacker News</title><link>https://thehackernews.com</link><description>Most trusted, widely-read independent cybersecurity news source for everyone; supported by hackers and IT professionals — Send TIPs to admin@thehackernews.com</description><language>en-us</language><lastBuildDate>Thu, 25 Jun 2026 01:05:08 +0530</lastBuildDate><sy:updatePeriod>hourly</sy:updatePeriod><sy:updateFrequency>1</sy:updateFrequency><atom:link href="https://feeds.feedburner.com/TheHackersNews" rel="self" type="application/rss+xml"/><item><title>CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited</title><description><![CDATA[The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation of a critical security flaw impacting Lantronix EDS5000 Series devices, urging Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by June 26, 2026.

The vulnerability in question is CVE-2025-67038 (CVSS score: 9.8), a code injection flaw that could result in the execution]]></description><link>https://thehackernews.com/2026/06/cisa-warns-critical-lantronix-eds5000.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/cisa-warns-critical-lantronix-eds5000.html</guid><pubDate>Wed, 24 Jun 2026 22:49:18 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgjZtIkR9YS2fMY5MvIzgyEShmJAP1bgHqhBdU115iSY7WZ2EcBAbFKb1OQP6Nq8hoF4HlnRifxW890ztCcnezyAivPNWZjVsyJrhoNe8BVnZgSfcRo1Jbl4XilQM9bcQTU9nOeDgfWXSzh9sBru4RH6mDhwa1IijucDmj-l1gVI8NAiQRzu0IJ8d2AIVh9/s1600/1000085210.jpg"/></item><item><title>Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered</title><description><![CDATA[A coordinated law enforcement operation, in partnership with private sector companies, including Bitdefender, Bitsight, ESET, and Microsoft, has resulted in the takedown of criminal infrastructure powering Amadey and StealC.

"The main common goal was to disrupt the 'assembly lines' cybercriminals use to launch ransomware, financial fraud, and attacks on critical infrastructure," Europol said in]]></description><link>https://thehackernews.com/2026/06/amadey-and-stealc-malware-network.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/amadey-and-stealc-malware-network.html</guid><pubDate>Wed, 24 Jun 2026 21:29:50 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjBVSibdiZdJ1tNYJFrsHtZ8Vr1EG28rqKLY4E7HvAtuax2i3vgpcaMZjEAcGDRxUVu5aa_BHzCAahpw5l2RP2HNw9t7PF6zknNICdw0iuW5jozt5fzqsSfb3Lw55MIvStq2vh5W0139JychUhhJHvchyphenhyphenm7tT2oTS555CkVZrBYSkhmlMKWaXMLtO4OcSp6/s1600/cybercrime-ms.jpg"/></item><item><title>Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks</title><description><![CDATA[Cybersecurity researchers have flagged a new class of CI/CD workflow weakness that allows attackers to hijack workflows and compromise open-source supply chains.

The "critical exploitable pattern" has been codenamed Cordyceps by Novee Security. The issue can allow full attacker control of repositories at dozens of the largest organizations worldwide, including Microsoft, Google, Apache, and]]></description><link>https://thehackernews.com/2026/06/cordyceps-cicd-flaws-expose-300-github.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/cordyceps-cicd-flaws-expose-300-github.html</guid><pubDate>Wed, 24 Jun 2026 18:18:11 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjl_D6QzBWfQRZAXbjo9RhhLXSedzJR2Q2sUQoQYnDxpC7yETzJgn3KnpT8CcoqlfXdqkcnTCNcEpR1QKphy77NvG_9PIO57hHNF27x8pBb1pLf_4n3A6pTBs3qXQMsz81rvzpGIOqHZn7VqvJoJoB98o7COHOxi5wfkQvxhL4LcOxBkziY4MLxVCEOljX8/s1600/1000085115.jpg"/></item><item><title>Dawn of the Apex Agentic Adversary</title><description><![CDATA[We are standing at the end of an era we never thought to mourn: the era of human-speed threats.

For years, cybersecurity moved to a rhythm organizations could follow. A researcher found a bug, a CVE was cataloged, a vendor navigated a patch cycle, and weeks or even months later, a fix was deployed. In this era, dwell time was measured in days, sometimes weeks. We are now approaching an]]></description><link>https://thehackernews.com/2026/06/dawn-of-apex-agentic-adversary.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/dawn-of-apex-agentic-adversary.html</guid><pubDate>Wed, 24 Jun 2026 17:00:00 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjuQ2GvCcnjBgMTXoXBXqazE9MU3nbNgeccOlWELBQOL9WcHHH4uXS1BKCrrmv6iWWAn6vu1LZJzpHl1MGetv8EfnylIM48MlBK91Gyiz5zCL6cMFr6sJd5x0qdSvjPkwm-V5ON79TgMNPHdOuGQIqSWwTdQcmBnEjehYuDoKMllm9Xray6dVy2uqexoas/s1600/apex.jpg"/></item><item><title>DoJ Seizes Huione Cloud Account Tied to Cyber Scam Money Laundering</title><description><![CDATA[The U.S. Department of Justice (DoJ) on Tuesday announced the seizure of a cloud computing account put to use by subsidiaries of Cambodia-based corporate conglomerate HuiOne Group, as the Treasury unveiled fresh sanctions against nine individuals and 26 entities linked to Prince Group.

"These subsidiaries are alleged to have assisted individuals and organizations in transferring proceeds of]]></description><link>https://thehackernews.com/2026/06/doj-seizes-huione-cloud-account-tied-to.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/doj-seizes-huione-cloud-account-tied-to.html</guid><pubDate>Wed, 24 Jun 2026 14:25:12 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgwWpkKj6KRX5Q7jeH07PFaANRRfRbl_CdrBEZ0cypjUg2UBsy49GSGNAOXF74dDez1H9xz_FXTMWh1lziO6f1Q0xrhjZRICtxmzQQJruQoQ8fk33kgTacTn5Y0BrNHmkHfLy3iC4s2oEL7H2CRCaBTcbLBqCbg3jcSFfHTSYiIa_RZV49sE58GCHOWorXJ/s1600/cybercrime.jpg"/></item><item><title>Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root</title><description><![CDATA[Threat actors have begun to exploit a recently disclosed critical security flaw impacting Cisco Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME).

The vulnerability, tracked as CVE-2026-20230 (CVSS score: 8.6), is a case of improper input validation for specific HTTP requests that could allow an unauthenticated, remote]]></description><link>https://thehackernews.com/2026/06/cisco-unified-cm-flaw-exploited-after.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/cisco-unified-cm-flaw-exploited-after.html</guid><pubDate>Wed, 24 Jun 2026 12:20:38 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEivauBSNOsDqBHvUFSnF1NdlWJ8BAt2JVgIo_ZUQhBkVppSz0PvkEmrc9RP1hMf2-oFFRgr5PNm7pxLmPngAJHcxV6-F3e43bEqmdEg38013JmlUKDlGVOLQTj6bYbyk_R7WXBqbW3o2yPHdosqz7nncLivqDqXGAuiTFcHkPqiVPBJuDHlsvYWtEreVmk_/s1600/cc.jpg"/></item><item><title>FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation</title><description><![CDATA[A Russian-speaking initial access broker (IAB) driven by financial gain is assessed to be behind a large-scale credential-harvesting operation known as FortiBleed that has targeted over 430,000 FortiGate firewalls globally.

The campaign, active since February 2026, involves collecting credential lists, searching for exposed services, brute-forcing accessible systems, and deploying bespoke]]></description><link>https://thehackernews.com/2026/06/fortibleed-targeted-fortigate-firewalls.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/fortibleed-targeted-fortigate-firewalls.html</guid><pubDate>Tue, 23 Jun 2026 23:50:49 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhJkhDD5qINhfAhBFXG2C13raQF6T6zAOmnHlArhnLUP5z0ifBzpyq6M_4n11cgynQfZW0mxJWnYU-TDYSpKQHYFHvXsZHCB7uoMFg0w02yZILY-JLMm2-uqm-CA_wIqZHhzl25FfO_lMd7dYm6VfprDP83bz_SoB3MWLEc059E4YCa554bba-qWHW5udHv/s1600/fortigate.jpg"/></item><item><title>Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents</title><description><![CDATA[Security firm&nbsp;AIR&nbsp;built a fake AI agent skill, pushed it through a popular skill marketplace and an Instagram ad, and says it reached roughly 26,000 agents, including some on corporate accounts.

Every skill security scanner the firm tested it against marked it safe. The payload was harmless by design: it collected the user's email address and did nothing else.

The point was to show]]></description><link>https://thehackernews.com/2026/06/fake-ai-agent-skill-passed-security.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/fake-ai-agent-skill-passed-security.html</guid><pubDate>Tue, 23 Jun 2026 20:46:43 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgb14v3ddlfpybc15jRbk-cwHI-0S8BAzdp8Ix83L5ZCZ4AB8gCySG7J4tZr4od9q3Jbuic1a4J29VAvRcdSQag_-ju1o9ae9yCcL6XV_jRDVhgd31E5BljiThpXcfHu_gdsmSySY8o0WyjuUoSQ5CGOyKO3cKXVDYeGKa1b1up2VM5ZJE6_PjPNCVOD_M/s1600/skills.jpg"/></item><item><title>Trump Order Sets 2030 Deadline for Federal Post-Quantum Crypto Migration</title><description><![CDATA[President Trump signed an&nbsp;executive order on June 22&nbsp;setting hard deadlines for federal agencies to move high-value assets and high-impact systems to post-quantum cryptography.

Key establishment must move by December 31, 2030; digital signatures by December 31, 2031. EO 14409 leaves national security systems on a separate track.

The deadlines matter because of a threat that does not]]></description><link>https://thehackernews.com/2026/06/trump-order-sets-2030-deadline-for.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/trump-order-sets-2030-deadline-for.html</guid><pubDate>Tue, 23 Jun 2026 20:46:40 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhoC7KFWoDGkSi-UzAyKNUkw-Ogs4oy2tCOAYXiYAAkqEUC1WMotLAE1GUwoWApfXK3prWVctTP05aLGjru0hDBfJkZ1NzPiFeI1VObgSNCx4egTrYhKIUt4m1S14eQ6_GpdffFBL4Ak3Mgjw7UiiBethv1lmyd_OaPIfhk_b-zuMjxCHLZtih8Tk6MtRg/s1600/unitedstates.jpg"/></item><item><title>GitHub Updates actions/checkout to Block Common Pwn Request Attack Patterns</title><description><![CDATA[GitHub is moving to strengthen software supply chain security by updating "actions/checkout" to block pwn request attacks that exploit the risky use of the "pull_request_target workflow" trigger to run malicious code with the workflow's full privileges.

Effective June 18, 2026, the latest version of "actions/checkout," the official GitHub action for checking out a repository into the]]></description><link>https://thehackernews.com/2026/06/github-updates-actionscheckout-to-block.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/github-updates-actionscheckout-to-block.html</guid><pubDate>Tue, 23 Jun 2026 19:52:03 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjcacTEKD_LZFda1wwX5aClbAVOb6mwah2lVUY-jUZwNsrSZGDOFL18LP5zYLX3M2DwKng0qknZ5qo_hMk4q-NExgZv1ozhCy7DJuZwvviZE0sv36PQ2k8Y2emv1KMDFplakFwVzulOFPteWkmVoLO6Le912KAbJGFW0nkqKWHEkwJQLbsGhz5npWO3aJaR/s1600/github-actions.jpg"/></item><item><title>Agentic AI: The Weapon That No Longer Needs a Warrior</title><description><![CDATA[Every weapon begins as an extension of the hand that holds it. The spear lengthened the reach of the arm. The bow sent the point flying without the throw. The rifle placed a man's death a quarter mile beyond his sight, and the aircraft carried that death across oceans. At each turn, the distance between the warrior and the wound grew wider, and yet one thing never moved: a human chose the target]]></description><link>https://thehackernews.com/2026/06/agentic-ai-weapon-that-no-longer-needs.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/agentic-ai-weapon-that-no-longer-needs.html</guid><pubDate>Tue, 23 Jun 2026 17:00:00 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg5YrdKJuy4ZmnWf_7L2RdXqS2QWC2BHJIbGsapJLmmYy1hBXfHxE7WMk-itWDkh-oCbAr8-CZOiUTyLftdM6191lDL8Iu2ENNU_i6Wfw2qy3lKY41iCrOnaLXHIl8cWDto42eqVlnsM4OetK0ymQUnwdpRXIniZQ-o7pBIDkqOYbm7o4CMlQTYFOeQyJI/s1600/ai-weapon.jpg"/></item><item><title>Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT</title><description><![CDATA[Cybersecurity researchers have discovered a set of malicious npm packages that are designed to deliver a Windows-based remote access trojan (RAT).

The list of identified packages, is below -


  aes-decode-runner-pro (145 downloads)
  postcss-minify-selector (256 downloads)
  postcss-minify-selector-parser (615 downloads)

All the packages were published over the past month by an npm user named]]></description><link>https://thehackernews.com/2026/06/malicious-npm-packages-pose-as-postcss.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/malicious-npm-packages-pose-as-postcss.html</guid><pubDate>Tue, 23 Jun 2026 14:24:32 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiENcFC1DFPXKuRCT_WmSwq-wpzC8IcZUdZzu5IHi597n77W8LFs9qSUdDPCuMK9QzkRZEBMbBh4p2xhnI1OXZu4akIgR5suIv_yRA7AtEkojDcyXaU5x0UiZKRDRvTn0n0wy9HIQnhJj9zUO0rpemNOFNZEmMl4NQsCj5aDEpDrqXUkivsOX1QoLRqeKZh/s1600/npmm.jpg"/></item><item><title>WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool</title><description><![CDATA[Direct messages sent via WhatsApp are being used to distribute malicious Visual Basic Script (VBScript) files that lead to the installation of legitimate Remote Monitoring and Management (RMM) software.

Per findings from Kaspersky, the active campaign is targeting users of WhatsApp Desktop and WhatsApp Web across Malaysia, Brazil, India, Mexico, Singapore, the U.K., Spain, Taiwan, Australia,]]></description><link>https://thehackernews.com/2026/06/whatsapp-vbscript-campaign-uses-fake.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/whatsapp-vbscript-campaign-uses-fake.html</guid><pubDate>Tue, 23 Jun 2026 11:08:40 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgDqA3duB8U44C_MQ5PM061Wch2-j7uRvX_D52lK_2Dsm2lxcquuICTnFZ-dhQiQfxxKTnIJz4tf7ffCupdkoU1giCEGhHXLKJ0xC3dw7duptIHq15dD0E5XlkvB9JbKztGCTJOk2iJ53shzUQexv2So6rrFy8djOO1etfsolTM5UbvMUkKvNwNpHqFvS7V/s1600/whatsapp-main.jpg"/></item><item><title>OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws</title><description><![CDATA[OpenAI on Monday said it's releasing an improved version of its GPT‑5.5‑Cyber model to trusted defenders as part of the Daybreak initiative&nbsp;the artificial intelligence (AI) company announced last month.

Calling GPT‑5.5‑Cyber its "strongest model yet for finding and helping patch software vulnerabilities," OpenAI said the model can "sustain deeper analysis across large codebases" to]]></description><link>https://thehackernews.com/2026/06/openai-expands-daybreak-with-gpt-55.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/openai-expands-daybreak-with-gpt-55.html</guid><pubDate>Tue, 23 Jun 2026 09:26:58 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh5t7SN4kPSfgifNku4Z0eWG5x1Dd8CIb99OAHuktz4ZGAeIrwDEnLwD9DUkRj8nStBQjzxOgWO2hfsGYI07Yp8gQGtXiSBIqlQXtzDTc3bkveScQ2gd-WbUmBA0L1xVDXhbrukUIuWdLaMPyiDZO-5-tWlq-kwFdImdd-h7YVkO7oGDN08bv25RJ2TRDt8/s1600/opne.jpg"/></item><item><title>ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack</title><description><![CDATA[Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors managed to tamper with the official release channels and push backdoor code.

"Attackers compromised the vendor's build and distribution pipeline, injecting backdoor code into Pro plugin releases distributed through official licensed update channels," Wordfence said in an analysis]]></description><link>https://thehackernews.com/2026/06/shapedplugin-wordpress-pro-plugins.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/shapedplugin-wordpress-pro-plugins.html</guid><pubDate>Mon, 22 Jun 2026 23:30:48 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgd4DchiVkQLBMvGHgWrojoZUdyk2SwEhEj5q6cOYzKCUWF1Lz3Mxeizurg1O-SLVi2jg319ib4SJsSoVWixAkl5WLPu4rL1cMoYXUM6EziOVyt42ESt1zmMo_iLEfHx9XSAXpsDd1FEtRSgKk4AhDzA7DjJN8c__pUgogxTQgaGjsxM04WNiesgRnbEVHN/s1600/wordpress-plugin.jpg"/></item><item><title>29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests</title><description><![CDATA[A heap over-read in the Squid web proxy can leak another user's cleartext HTTP request, including any credentials or session tokens it carries, to anyone already allowed to send traffic through the same proxy.

The bug traces to a 1997 FTP-parsing change and is still live in Squid's default configuration. Researchers at Calif.io&nbsp;disclosed it in June&nbsp;and named it Squidbleed (]]></description><link>https://thehackernews.com/2026/06/29-year-old-squid-proxy-bug-squidbleed.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/29-year-old-squid-proxy-bug-squidbleed.html</guid><pubDate>Mon, 22 Jun 2026 21:59:00 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiA4IfKMjQxVhpOYdrcCC4ty0vlGBDg_qCZuuvSTvyVWXYPXQlli7qyCZkPdHHuGJp-HVH1s-HGmf_Zqn97o2Qz5JOHaZ-Mk1mecm4W4yUBiCaejJL5guczISx2Q8ZH7RvS_4fXiNdHemr1aWKwz0CcyBJI_4_jFjQhY5JedBz_-pSiSQ1eQCF_BPYEbRs/s1600/sq.jpg"/></item><item><title>Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants</title><description><![CDATA[Cybersecurity researchers have disclosed details of four vulnerabilities in Dify, an open-source agentic workflow platform with more than 146,000 GitHub stars, that could allow attackers to stealthily read artificial intelligence (AI) conversions from other customers' applications without requiring authentication.

The vulnerabilities have been collectively codenamed DifyTap by Zafran Security.]]></description><link>https://thehackernews.com/2026/06/researchers-detail-difytap-flaws-in.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/researchers-detail-difytap-flaws-in.html</guid><pubDate>Mon, 22 Jun 2026 21:43:28 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjrjCumekV1hjkgdgebp4RqfYc_Yt9Swv4lG7ds3XMDHG9f-JxSuJSWY3UcWIoivJoJkJjdlBvtiQAHKy7NNgApCoD8ADtOpicXvKf9RJwAZT1DEGUkgX87bmSR8cO75Ss__mnLn8MyDEddnzhyphenhyphenRfcf_gWEtoLiKu53yXNQJtT0DP7nZufqBhB3P8VmvV48/s1600/dify.png"/></item><item><title>New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer</title><description><![CDATA[Cybersecurity researchers have disclosed details of a new campaign that delivers CastleStealer by means of a previously unreported malware loader dubbed OXLOADER.

According to Elastic Security Labs, the campaign leverages malicious Google Ads as a starting point to distribute the malware. Evidence indicates that the threat actor is likely Russian-speaking and financially motivated, owing to the]]></description><link>https://thehackernews.com/2026/06/new-oxloader-loader-uses-malicious.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/new-oxloader-loader-uses-malicious.html</guid><pubDate>Mon, 22 Jun 2026 18:50:12 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi8sz7SHbQd4E8HNEKbvGGSYhPpJrUydP_gCRt_mWYYTr6QHLmChyphenhyphenca6BXhLBXA4OyKw-eS9xbqRqpKcYWFqDp4HoLBYKjVdWzhF0K1pqjX2bPtB91y1P1PZ8gh5r7Bpp-PIeUJVi_Hki91Qf6YjFAtFmf-qh7V9gNzmbEh_A2lISCvCDnNMALAuiqAlkL_/s1600/loader.jpg"/></item><item><title>Google Sets Sept. 30 Deadline for Android Developer Verification in Four Countries</title><description><![CDATA[Google has set September 30, 2026, as the day it begins enforcing&nbsp;Android developer verification&nbsp;in the first four countries, and the major device-maker app stores are in from the start.

On that date, certified Android phones in Brazil, Indonesia, Singapore, and Thailand will block normal installs of apps whose developers have not registered an identity with Google, whether the app]]></description><link>https://thehackernews.com/2026/06/google-sets-sept-30-deadline-for.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/google-sets-sept-30-deadline-for.html</guid><pubDate>Mon, 22 Jun 2026 18:15:08 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEisV9q8kKe0eopbInTHgwScUvzjKlnPTpk74j7M6F-6BH46hVr9wcadvztA2RYJdKDQDzpV89bN4wH0hEL9qTfIh2_4f3FEIT1OWwSeYehcOb-sVNNkEshTBBC6qviBMlFuwMXQL2iG_VVVBaT6NoGnbdcVBfcMm61T6NosKLtOdMgIebKCRh7hukQxIOk/s1600/playstore.jpg"/></item><item><title>Stop Your Legacy Infrastructure from Hijacking Your AI Agents</title><description><![CDATA[Earlier this month, I spoke at the Gartner Security &amp; Risk Management Summit about a blind spot most security programs are still not accounting for - how attackers are circumventing AI security programs by using legacy infrastructure to hijack AI agents.

AI adoption is moving faster than security programs can account for. Roughly 71% of organizations are piloting AI agents across their]]></description><link>https://thehackernews.com/2026/06/stop-your-legacy-infrastructure-from.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/stop-your-legacy-infrastructure-from.html</guid><pubDate>Mon, 22 Jun 2026 17:28:00 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSdS_7552zEvsn5xVfDcVMG2u8ponFIE1E65j5A8Wx-qUroU49h-f6qF7FPCABA063IjNnw-JntL-L1iZjHpiuqATqkDv-2vpi6lCVG1idXkg_elRJkyoUgASk4uYCTJ95EHfVQLJngVLKOxM2H5zLkdeFY7kpzveHUuKFoks0_ujNo9tJNQxm7XVgYb4/s1600/xmcyber.jpg"/></item><item><title>⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More</title><description><![CDATA[It’s Monday again.

This week’s threat list looks painfully familiar: abused integrations, fake tools, poisoned websites, ransomware crews trying to shut down security tools, and mobile malware asking for way too much control.

The annoying part is how little of this feels new. Weak credentials, sketchy downloads, browser extensions with too much access, and WordPress sites are used to push more]]></description><link>https://thehackernews.com/2026/06/weekly-recap-browser-bugs-edr-killers.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/weekly-recap-browser-bugs-edr-killers.html</guid><pubDate>Mon, 22 Jun 2026 16:25:10 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjWTle5JU3HMoV1yUzXt6nAYO-EtyfOp22bJldi9N4fwakWmzrwwjBKfQNkprStB3B9K5HyUchIUCoNpGs-Kn2EHwClO7xJOV-qZQeDKFllNQrZ-TYq6OiikJkwi65NdfFcR7XhMTuIpmwSdoglwRcMcI43rLGB1B462ZXhd7nkh-q-FNnpPKoeUyL7bUqs/s1600/recap-main.gif"/></item><item><title>Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices</title><description><![CDATA[Canada's spy service got a judge's permission to reach into infected servers, home routers, and IoT gear sitting on Canadian soil and neutralize two foreign-run botnets.

The Federal Court&nbsp;released a public version of the ruling on June 15. It is the first time the Canadian Security Intelligence Service has used its threat reduction warrant powers this way.

The warrant let CSIS alter,]]></description><link>https://thehackernews.com/2026/06/canadas-spy-agency-used-first-of-its.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/canadas-spy-agency-used-first-of-its.html</guid><pubDate>Mon, 22 Jun 2026 14:41:37 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgLwfeNp6y7paVA9a8F1NvROjNla494WBkRnt8JfQrDpxLCB-cEiewUAhyQeD9_xw1xL_KQkfXp5EnMImW7_js9HDTAjN5b-Sf5uIV4RghVuxpHYvd0YdAeJMXuRsm-xJldrNnBnoRK1lfZNT3aFUd-re2yS6X5Q05F2k7_RXQb1sPkhQp3_faoocFqayvj/s1600/cn.jpg"/></item><item><title>AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network</title><description><![CDATA[A new malware family is turning forgotten home routers into a distributed reconnaissance and proxy network, not the DDoS botnet these devices usually end up in. QiAnXin's&nbsp;XLab&nbsp;calls it AryStinger and counts at least 4,300 infected routers, a total it says is still rising.

The distinction matters. AryStinger exists for the stage of an attack that comes before the break-in. Infected]]></description><link>https://thehackernews.com/2026/06/arystinger-malware-infects-4300-legacy.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/arystinger-malware-infects-4300-legacy.html</guid><pubDate>Mon, 22 Jun 2026 12:27:44 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjr0TUOEuqak_4OJNaS9ogmGXQl1QWTMkdmvIDNy6mlYVxjA-Z5qfywF_6OwxaJRDuvrq9E106Cx9hqmsFMKMnVATj5uApKOILaXa3BeTojf-TBEqe80iUtz-dyqlLSxbgygqj-hE_rSeJMWAM40HIdWkY1YhGD5dYjzVSMwNAn4GbfaCijDUoudDau-DIj/s1600/router.jpg"/></item><item><title>INTERPOL Warns Phishing, Ransomware, and AI Scams Are Rising Across Asia-Pacific</title><description><![CDATA[A new report from INTERPOL has revealed a "dramatic increase" in cybercrime in Asia and the South Pacific, fueled by rapid digitalization, internet penetration, new technologies, organized criminal networks, and a disparity in cybersecurity maturity.

According to INTERPOL's 2025/2026 Asia and South Pacific Cyberthreat Assessment Report, phishing has emerged as the most widespread and]]></description><link>https://thehackernews.com/2026/06/interpol-warns-phishing-ransomware-and.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/interpol-warns-phishing-ransomware-and.html</guid><pubDate>Mon, 22 Jun 2026 11:36:53 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiCZyCo0qR6bFgeSdNHxD4d56tgq1YYTWI2aMHnDz63YlOYGrMbPnbpAumvGLNyZxxfLVTYEi7VBiVscqTpCC2sgfMtX-YFVAvy_flQZTKinHhT6qtKIc6boJfuGC4sbpNl9qYfblyZZizkaDRkMIScE3upxa-vBcGYeL6YqTBufD1ro3t0Mpwa6O8Ag4iU/s1600/asia.jpg"/></item><item><title>Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys</title><description><![CDATA[Threat actors are exploiting a recently patched security flaw impacting Gravity SMTP, a WordPress plugin that's installed on about 100,000 sites.

The vulnerability, tracked as CVE-2026-4020 (CVSS score: 5.3), is a medium-severity information disclosure flaw that can allow unauthenticated attackers to extract sensitive data, such as configuration data, API keys, secrets, and OAuth tokens]]></description><link>https://thehackernews.com/2026/06/hackers-exploit-gravity-smtp-wordpress.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/hackers-exploit-gravity-smtp-wordpress.html</guid><pubDate>Sat, 20 Jun 2026 15:26:04 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjL1kN23KhnFjdjHcR0i-iySK1Zv-kkApPs6yBq11670ubXx0NiAbgDMoYSfwQNyq9asso5AG9KcPRXEL4LU8-BmcsC0Q_1YIYDfY89hIFd_hSNJ2yZJRAO5l6JaQbpItuI8cpwIvNDBOqNfc-0d1DMv_DOh04J5_2EvpEcxCtoQUziipbjfNod-tzdH1__/s1600/1000082862.jpg"/></item><item><title>Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain</title><description><![CDATA[Security researchers at&nbsp;Paradigm Shift&nbsp;have published a working exploit, dubbed&nbsp;usbliter8, that achieves arbitrary code execution inside the SecureROM of Apple's A12 and A13 chips.

That code is burned into the silicon at manufacture. No software update can reach it. Affected devices will carry this flaw for as long as they stay in use.

This is not a remote attack. It requires]]></description><link>https://thehackernews.com/2026/06/unpatchable-usbliter8-exploit-breaks.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/unpatchable-usbliter8-exploit-breaks.html</guid><pubDate>Sat, 20 Jun 2026 00:07:41 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgIM725Ni41-PBwM_6zXNdsydP1eZO7oSsWIlAqpwdOu9dOcZM6ZI1iaqwSsL3yZKT4lbFRM-eZVq3ARKDbLRnid1pJ0Us3XX135nD0tV71gb1lnADzig_vE9c6CAiJdlJ-Wco11InBKUyGX9V5nRFn9qZxuxeJKCzsCV4tQTfFIgU3F05Wnp2VfsxyTPs/s1600/apple-chip.jpg"/></item><item><title>The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes</title><description><![CDATA[The Gentlemen ransomware-as-a-service (RaaS) operation is actively developing and maintaining a suite of endpoint detection and response (EDR) killers that it hands out to affiliates for impairing system defenses before deploying the encryptor.

This mature portfolio of EDR-terminating tools is centered around a framework that's known as GentleKiller.

"They also incorporate third-party or]]></description><link>https://thehackernews.com/2026/06/the-gentlemen-raas-uses-gentlekiller.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/the-gentlemen-raas-uses-gentlekiller.html</guid><pubDate>Sat, 20 Jun 2026 00:03:07 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgjNWtaK_WkFnKnaLTIwg043i_I6YVi5XuZGVzh30SGeK-iutwr6t2Ed3S6Qk0V9uykYueDD5WETtQ4sW1QwG4jldPXW_IM2woF1Dk1PXcNxbwv6sgoprJ6m8pmogRc0vblucj3nf6Tox_ptxOX9bib6iO4bV4SXVVFoVzUGw0C8cSiJEvq3nDgUZ36G9xp/s1600/edr-killer.jpg"/></item><item><title>AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution</title><description><![CDATA[Microsoft researchers have detailed an exploit chain, named&nbsp;AutoJack, that turns an AI browsing agent into a delivery vehicle for remote code execution.

Steer the agent to load an attacker's web page, and that page's JavaScript can reach a privileged local service on the same machine and spawn a process on the host.

No credentials, no sign-in screen, and no further user interaction once]]></description><link>https://thehackernews.com/2026/06/autojack-attack-lets-one-web-page.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/autojack-attack-lets-one-web-page.html</guid><pubDate>Fri, 19 Jun 2026 21:00:47 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg3wJOg5Y5vAn_dM0DcIB6SwV2B34iO0H-moeyuWLJ_DF1KgEEZMBGtKPDXYk0pL4wclWbnSmOB74sqReSZoGI2_SwUSzKSscUxEdvuJFx_sCIfU7UplU2k5s4UA0cOVAZT_s80PDTek6OGfrsnE8f6QxrQU58rBqPiuk_J__Yja3YNzZLzd-6s8Ji1PBhc/s1600/agent.jpg"/></item><item><title>Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites</title><description><![CDATA[Dutch law enforcement authorities, along with counterparts from  Canada  , Germany, and the U.S., have disrupted malicious infrastructure associated with  SocGholish  and cleaned up nearly 15,000 infected WordPress websites.

"With these actions we deprive cybercriminals of access to infected computer systems," Maikel Rollman of the Netherlands National High Tech Crime Unit said.

"This prevents]]></description><link>https://thehackernews.com/2026/06/operation-endgame-disrupts-socgholish.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/operation-endgame-disrupts-socgholish.html</guid><pubDate>Fri, 19 Jun 2026 20:37:54 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg1-D7cu6ZQpoZXfPa_eYHuQijjkt6mJRjmoIS9eSnCGPPgyXNz-AChti_zkCGmlefTdBm5bvbyxXbrJVbpVJIneqvDmIMR8t7gXEyBn2JJFrZLW-hTbo_e8UHBFuh9tfki-QyVk2g5_XqbbSX52HYTNSpNzJng8lMfZiIHT3pMQBTjTeZwSqx2khJt2uAk/s1600/endgame.jpg"/></item><item><title>CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices</title><description><![CDATA[The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday urged Fortinet customers with FortiGate appliances to take steps to secure against ongoing malicious activity aimed at thousands of internet-accessible devices.

The sweeping campaign, believed to be the work of Russian-speaking threat actors, has been codenamed FortiBleed. The number of compromised devices stands at]]></description><link>https://thehackernews.com/2026/06/cisa-warns-fortinet-customers-as.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/cisa-warns-fortinet-customers-as.html</guid><pubDate>Fri, 19 Jun 2026 19:30:21 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg0NmhjowFYAIQws_hl2u1bMpkeyma6TUk8UumS90AdqbBjW_NJ5h97i1yV9uJ_GT6zT8A9jaruiGkhqvn0jb4LuaHDDbGtjZbB7tQQibuQmH4WTDeAI898xZnyDuUQOAvzPHooO7C2S2PQFPIvkmwZ8LTLO4xLUP5ygQVuZI3E0quggcAEvtOqKzx4zKdw/s1600/cisa-fortinet.jpg"/></item><item><title>From Assistive to Agentic: The AI Shift That's Redefining Threat Management</title><description><![CDATA[Introduction

The average enterprise security team has 40 or more security tools, giving a lot of visibility into internal telemetry and asset data. But often, these tools are working in siloes, generating (overlapping) alerts and data. And yet, breach dwell times remain stubbornly long (~43 days), response windows keep closing before teams can act, and analysts burn out triaging noise instead]]></description><link>https://thehackernews.com/2026/06/from-assistive-to-agentic-ai-shift.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/from-assistive-to-agentic-ai-shift.html</guid><pubDate>Fri, 19 Jun 2026 17:28:00 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiaBfyINQL8sJZiLP4VnJgWMBOmH-8zY01vQ3E7OWZM9sdPvFQzOrFgaEpJOcRqODwrKDMXjt1HiKZmYYKF4pr22BBcbVBqx31coqBTKsgsf43CPEoW430X177toxpnfpVBTogjlrBMOrsLJgpERpCliEP4h5_2gyu3h2Dy_hJwiV6AI3nbKyp5NvNVgzQ/s1600/filigran-main.png"/></item><item><title>Forget Data Leakage: Shadow AI's Real Threat Is Access Control</title><description><![CDATA[The first wave of enterprise AI concern was straightforward. It was simply employees pasting sensitive data into public AI tools. Security teams responded with usage policies, domain blocks, and data loss prevention rules. That response made sense at the time.

It doesn't fit the problem anymore.

Shadow AI has shifted from a data leakage concern to an access control problem. The threat isn't]]></description><link>https://thehackernews.com/2026/06/forget-data-leakage-shadow-ais-real.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/forget-data-leakage-shadow-ais-real.html</guid><pubDate>Fri, 19 Jun 2026 16:00:00 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh6R48ZeaNtIzMVc6atNjuxbNYFUfiFCJ_cE1qE_85yGOOavsX0ijvQGdv9QZ2-4Lky8mTOPhrNIydUvLS2DtGkkFXYJFRTT99Vbb03s3Rtk9pTariHdQ2on2RGxiAsMQnySj7AJfxUtBxO1aJTupjkQvDvt5jp1klznY9_WHckqm64F-BbCtCR2UoJ968/s1600/tines-main.jpg"/></item><item><title>Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data</title><description><![CDATA[Salesforce has revealed that it disabled the Klue Battlecards app integration within its platform in response to a security incident impacting the competitive intelligence company on June 11, 2026.

To that end, organizations will be unable to connect to Salesforce via the app until further notice, the American cloud-based software company noted in an alert published this week.

"Salesforce took]]></description><link>https://thehackernews.com/2026/06/salesforce-disables-klue-app.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/salesforce-disables-klue-app.html</guid><pubDate>Fri, 19 Jun 2026 14:33:57 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgI7q_DYP5ExkNSDd8Y10rOfYtTIs6sNXxdE6X55nsvKVllZZ14U9mqUY23nzGGPhXx515NVPMI5Btp4MM5qUx0V1lKDvURtKBICbblPPYuN1VSCN12-J0RmpBKCSM0veZc_9hNt1TnD9PdkNTQi8x337E9cPmLn7uyHOPw0_HshcbxKqVnmgOAjJHOOw6g/s1600/salesforce.jpg"/></item><item><title>Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone</title><description><![CDATA[Apple has updated its Beats Studio Buds wireless earbuds to patch a high-severity vulnerability that could be exploited by nearby hackers to eavesdrop on users.

The vulnerability, tracked as CVE-2025-20701 (CVSS score: 8.8), refers to a case of incorrect authorization impacting the Airoha Bluetooth audio SDK that makes it possible to pair a Bluetooth audio device without user consent.]]></description><link>https://thehackernews.com/2026/06/apple-patches-beats-studio-buds-flaw.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/apple-patches-beats-studio-buds-flaw.html</guid><pubDate>Fri, 19 Jun 2026 12:06:09 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhvlr0i44MWKmuHJKLS1V3uKSMse7tVsRFBTpyD1VGLaRZy24qq4bIb6K3Db1s0eKtuh3TkLCYFWn6eJ-uEkVnkO9CbPHHUlD3j8Z-SEFFr9A1X6ndd-fQd6UKTAyXO0DhUI2ZTe1sc4Eq7NLoGUyjQUkKmhHp99QGz3WTcFAnucAnfiioLDFiGaTbI8Wvx/s1600/apple.jpg"/></item><item><title>F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution</title><description><![CDATA[F5 has released security updates to address two critical security flaws in NGINX Open Source that could be exploited to achieve code execution on affected systems.

The vulnerabilities are listed below -


  CVE-2026-42530 (CVSS v4 score: 9.2) - A use-after-free vulnerability in the ngx_http_v3_module that could be triggered by a remote unauthenticated attacker when NGINX Open Source is]]></description><link>https://thehackernews.com/2026/06/f5-patches-two-critical-nginx-open.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/f5-patches-two-critical-nginx-open.html</guid><pubDate>Thu, 18 Jun 2026 23:02:14 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhxYclMMaAOBe1jlW_s0S1SfdX3sPrGB9MZ7R9Hfo2ktoF9DiLqPA5ZYmFAyGmzws5eNmqopdPw7bBV7TTO8KgS2C8CJU8cgHNXw0ERAvk8sGRLYXH7M98eqxDM9c-rQTU0Hlj8ISEmSWMCnw6OqJMyhgxxLHCFPwP1JugZ3bCJow7AfTZ40kOo8XpY3WdF/s1600/f5.jpg"/></item><item><title>Orphaned AI Agents: How to Find Hidden Access Risks Inside Your Network</title><description><![CDATA[If an autonomous AI agent interacts with your company's core intellectual property today, can your security team instantly name the person who authorized it?

For most enterprises, the answer is a simple no.

The rush to adopt internal AI tools has left a massive trail of administrative debt: orphaned agents (AI tools left running after their creator leaves the company) and standing privileges (]]></description><link>https://thehackernews.com/2026/06/orphaned-ai-agents-how-to-find-hidden.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/orphaned-ai-agents-how-to-find-hidden.html</guid><pubDate>Thu, 18 Jun 2026 21:03:49 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj_nqjviAfaPP-eOuhtQKNwdvOGLaN-rOmxVnoQPMOruaJvDcw5rsCi-kIKxAhOpxjCggRXt7bfwyRAKMzVKdwIPlRAJpXLl4OReBnbVtOSZYGS4Bsf9EvU71bMIkWdpDwjydNWe22WCdjgqX6b_TrPtXptekJc3N8BH5m56-wauHl5KX0DePQmv2gIoNks/s1600/webinar.jpg"/></item><item><title>ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories</title><description><![CDATA[The internet did not break this week. It got used exactly as designed, which is worse.

Searches were siphoned through shady browser add-ons. AI chat links turned into malware delivery paths. macOS attacks ran in memory and left almost nothing behind. Cloud agents looked like helpers until attackers treated them like open shells.

Add exposed edge gear, poisoned packages, cash courier scams,]]></description><link>https://thehackernews.com/2026/06/threatsday-bulletin-claude-chat-abuse.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/threatsday-bulletin-claude-chat-abuse.html</guid><pubDate>Thu, 18 Jun 2026 20:57:54 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh6k3CSWsyKHS6UdXmxX-w92fdsWjTSL7JR7xeaPBPh8d5G6rkZbMhmJHr9o3gxF5G2I2GojubOJnzhRqxjtKYxlXTrmlgrdRFRrmmyEEIi_zXAQXT3zpq5KNQqOFHrfGKhUFHzsMx1E2Eqs7S_jvTFfN3Jnz1YO58Ryvk0urKEDUZggoQgI07lKFWQDMfw/s1600/threatss.jpg"/></item><item><title>Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2</title><description><![CDATA[Microsoft has disclosed details of a Windows-based cryptocurrency clipper campaign codenamed CryptoBandits that has
 targeted users since February 2026 with clipboard-intercepting malware with self-spreading capabilities and using the Tor anonymity network to hide communication.
"The clipper in this campaign relies on Windows Script Host and ActiveX-driven logic to launch a bundled Tor proxy and]]></description><link>https://thehackernews.com/2026/06/microsoft-details-windows-clipper.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/microsoft-details-windows-clipper.html</guid><pubDate>Thu, 18 Jun 2026 20:00:42 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjvKWONrjyxy3cGsc9xfw7n-6izVRjMImK2DpiOv4JDrtutcENRgX6JxsFQhsEMHDhZx9fGfeoj_mAQSVk9SoJumNREvmLtbWOjWaTlYn3c25sH_paaeZk-Xw08k3ckerv19Ax9stFCURiV321W7vh0f6qQbrmSHnuvPeNBeW6Grb7o6TU4s5dhJNkXyIon/s1600/clipper-malware.jpg"/></item><item><title>INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023</title><description><![CDATA[Cybersecurity researchers have charted the evolution of INC from an nascent ransomware-as-a-service (RaaS) operation to one of the most prolific cybercrime groups in 2026, claiming no less than 830 victims since August 2023.

"The disruption of LockBit and the shutdown of BlackCat created opportunities for INC to expand as affiliates migrated to alternative ransomware operations," Acronis]]></description><link>https://thehackernews.com/2026/06/inc-ransomware-claims-830-victims-since.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/inc-ransomware-claims-830-victims-since.html</guid><pubDate>Thu, 18 Jun 2026 19:42:48 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh2MOms1DiyvYE-L_zXvrgrL_4cDaNBZwrhVFPq7ee58uPMORAF9v60xW8_QZbjJ05C34E2F5u9xKXBal4_DbVvUjcg8aDAvQ9iKSgWss6vnvlk4f1tgLYwb3a5xNc6T3lbGeE1pcTf35vf320No6XzS4mkw_5dTTILKfc0w6VpcTHX5VitEodFJBKMWzjA/s1600/ransomware-malware.jpg"/></item><item><title>The Scripts on Your Checkout Page Are Now a PCI DSS Problem</title><description><![CDATA[An independent PCI assessor tested Reflectiz against the new PCI DSS rules. Here is the verdict: See the full QSA assessment here →

When a customer types their card number into your checkout, their browser is running far more than your code. Analytics tags, a tag manager, a support widget, a payment iframe: a modern checkout loads dozens of third-party scripts, and any one of them can be turned]]></description><link>https://thehackernews.com/2026/06/the-scripts-on-your-checkout-page-are.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/the-scripts-on-your-checkout-page-are.html</guid><pubDate>Thu, 18 Jun 2026 19:28:39 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjHJHzi-rQqSIiD4wXw_HQpgvXGNTNgvJnxt42OupMrchYSmQPyeXbtsuH62zLqPHDq3bywvirdcqKSq9VQ-pZyL02RAw2IYYh1f4qcpUH4NZu50XLSDsQSSYvyqMAEwSN-8PQMcpwXZMtLC_pVYzqZMYm7qkygfMQeZEIHVWpIkYfUifJvX3oUMSBs3w0/s1600/reflectiz.jpg"/></item><item><title>DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic</title><description><![CDATA[Threat actors associated with the DragonForce ransomware have been observed using a custom Go-based remote access trojan (RAT) called Backdoor.Turn to conceal command-and-control (C2) traffic inside Microsoft Teams relay infrastructure.

According to findings from Broadcom-owned Symantec and Carbon Black, the backdoor was deployed against a major U.S. services firm. The name of the company was]]></description><link>https://thehackernews.com/2026/06/dragonforce-hackers-abuse-microsoft.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/dragonforce-hackers-abuse-microsoft.html</guid><pubDate>Thu, 18 Jun 2026 19:00:07 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEidEg1Q-FcDTwCPci3OMxGy0TghiI1dbWJoaJVc88gpGgO2ia6bgne18KfS3A9qAzBnMX2rGY9H78ewtofXQO22RRpzHxWXmvQJvRZ1nsvwj37aZBtLOXXltzd1KkNRKhu2N5LpIro5Fi0BBkftPqP_IO6B3HCKx5WPtFXZKA1bfbP3xV71CpEqpT7H6RPN/s1600/teams.jpg"/></item><item><title>Crypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal Comments</title><description><![CDATA[An unknown threat actor has been observed leveraging paid or promoted posts on legitimate news websites to drum up buzz for their warez, according to new findings from Check Point Research.

The threat actor also has at their disposal a dedicated WordPress phishing page that acts as the central hub, alongside GitHub and SourceForge projects promoted by fake accounts, a YouTube channel, and a]]></description><link>https://thehackernews.com/2026/06/crypto-clipper-campaign-abuses-fake.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/crypto-clipper-campaign-abuses-fake.html</guid><pubDate>Wed, 17 Jun 2026 23:44:24 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjbbJOofP7P7zruPGvktMERgtQqGnu5msB1iDGyfukJA9g72QHXmHx9eJNbQaF7VIGcUqB76e5bGpnBnfg9AE4-F5kJQnY2fKtfHoi9zggEgteLN6rpYJeYE2nPlHFHWfj58a_DmklTT0x0GcWmRAxJsVGeysX9CUadCIygZTpDzBxCWZ4HvrPqhPwQy6Ng/s1600/scam.jpg"/></item><item><title>Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development</title><description><![CDATA[Microsoft has formally disclosed that it's working to release a patch to address a Defender zero-day codenamed RoguePlanet.

The vulnerability has now been assigned the CVE identifier CVE-2026-50656 (CVSS score: 7.8), with the tech giant describing it as a privilege escalation flaw.

"Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender]]></description><link>https://thehackernews.com/2026/06/microsoft-confirms-rogueplanet-defender_02022423645.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/microsoft-confirms-rogueplanet-defender_02022423645.html</guid><pubDate>Wed, 17 Jun 2026 23:06:28 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgy3ayOlDb3vsL747G9hStxxjTd3N5i2u8hegcT_hTs4RlNqylS_HyYH4mGLQEavD-QwH3G4l-p2tE5xrXoeK-Btj5YjbENpZcnqRZ7mXCjnJgqHKaoqyE3I3yqy3tYxafbDGNOMrDsvTnJ8UKkn7DDQ8PY_sQNZI6TsNTV0lOmSqs1uxUKm3pgpmkSDpeZ/s1600/ms-patch.jpg"/></item><item><title>Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline</title><description><![CDATA[A French-speaking attacker broke into a small French automotive business, planted a keylogger, and stole banking and email credentials.

Ordinary stuff, until one move near the end.

Before his command-and-control server went dark, he installed OpenSSH and Tailscale on a victim's machine, building a way back in that did not run through the C2 at all. When the Havoc server went offline the next]]></description><link>https://thehackernews.com/2026/06/junior-hacker-used-tailscale-and.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/junior-hacker-used-tailscale-and.html</guid><pubDate>Wed, 17 Jun 2026 21:30:56 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhN4ptzzF7u-dzNyOc4F1HsCUbEszvkkeD1ZVl7MHQNXXcUtgqb40Wgodu3aj61QDzaNsX0eJjRDGK1eNJLCbud-4iWHJjnpHPuCfTak2m9UydSW4DEJErr5L2V_KwD39P__6iVxgaOhH8mYtY2LhPFnyCavP8eJ_1N3QpGo4NkZaFJYVRc-LX0droem8Q/s1600/cyber.jpg"/></item><item><title>Adversarial Exposure Validation Turns Security Visibility into Confident Prioritization</title><description><![CDATA[For security teams, the findings never stop, but confidence in knowing which ones matter is becoming harder to maintain.

The problem is no longer visibility. It's validation. Security teams must decide which findings warrant action while operating under constant pressure and incomplete information. Increasingly, the challenge is not discovering potential risks. It is determining which risks]]></description><link>https://thehackernews.com/2026/06/adversarial-exposure-validation-turns.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/adversarial-exposure-validation-turns.html</guid><pubDate>Wed, 17 Jun 2026 20:28:00 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg_8P-dioPWCAX94ha33KAWjvP0RvBHHCxI4ZAMnMHYY66XUQUFK_FZFkQJ3nW8XYlG6U5GxLL-o21CvZFNeOkZsHH41KlaVGYR3Ne26PZjeyK318yCFpZnxqFgp-e7qU1XitrcF7ODwc1znYAw2r2MioIePdJs4eQdHMmdBEmDqbq-YicStLUsU1_842g/s1600/breachlock.jpg"/></item><item><title>Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats</title><description><![CDATA[Cybersecurity researchers have flagged a "coordinated malware campaign" on the JetBrains Marketplace that has published no less than 15 malicious plugins capable of exfiltrating artificial intelligence (AI) provider keys.

"Every plugin poses as an AI coding assistant built on DeepSeek and other large language models, offering chat, commit messages, code review, bug finding, and unit tests,"]]></description><link>https://thehackernews.com/2026/06/malicious-jetbrains-plugins-steal-ai.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/malicious-jetbrains-plugins-steal-ai.html</guid><pubDate>Wed, 17 Jun 2026 19:21:58 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg2aRb82ydrk_lAXr6Yy-GmrPfQSaIuCNYTtB8dFm02DZWhJVj3bmjB3WLhWDUtiFmrGC3lHdeLfA2NtC6oHKJDAdW7ot4f3HQDyLw2Ep3q49BnOkuBWOPP2OuN1I1HNFknxPyQNpEZEnEt-8KhV2nx_HcaEiBm8Rdh7blevc3I1GjuBMLL1xOpJThFuJpE/s1600/hi.jpg"/></item><item><title>The Top 10 Attack Surface Exposures in 2026</title><description><![CDATA[Breaches don't always start with a zero-day. An exposed admin panel can get brute-forced, or credentials reused from a previous attack. But when a vulnerability does drop — like MongoBleed earlier this year, which let attackers pull credentials and session tokens from server memory without authentication — anything internet-facing is immediately at risk.

With time-to-exploit now down to a]]></description><link>https://thehackernews.com/2026/06/the-top-10-attack-surface-exposures-in.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/the-top-10-attack-surface-exposures-in.html</guid><pubDate>Wed, 17 Jun 2026 16:00:00 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiM2DfFAWIuQ6v6hyh32CXcT_wKU72aTUxixyWIcnjW04ydv40r8RtVXjDrxKJzksW6zzqYciPMxgYAwcDGRz8kahhZVZXoi0FySWg5o8LpWo_KkHdX4wRX4Qgk6ONxHqyb7_cF5TN5qQp-9B4hOQpB3WljI8sDbHMlOh6n2jyTjV30kxC-ccJVJHu4bTs/s1600/INTRUDER.jpg"/></item><item><title>145 Mastra npm Packages Compromised via Hijacked Contributor Account</title><description><![CDATA[As many as 145 npm packages associated with the Mastra namespace ("@mastra/*"), a popular open-source JavaScript and TypeScript framework for building artificial intelligence (AI) applications, have been compromised as part of a software supply chain attack codenamed easy-day-js, per findings from Endor Labs, JFrog, OX Security, SafeDep, Socket, StepSecurity, and Synk.

"A single npm account (]]></description><link>https://thehackernews.com/2026/06/144-mastra-npm-packages-compromised-via.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/144-mastra-npm-packages-compromised-via.html</guid><pubDate>Wed, 17 Jun 2026 13:08:24 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiKLWn0zHFuJ8rkb2bqILIyAGxt_-VJ13Ytmv1TRWtGJkI6Rva5Oag5LdLasE2rmenokuRvoEI2wH0Ayfe_P4_5q1Qc5FQ2MrQgUHrgD9wY6DTlYugAtj8CP7Fh0OPjKkU5LbeRKWvPEh0Ol0CmLTe4QVayeZiNlVFvU7MO5tWl-b8Lbn80hKd45q9Z1yOd/s1600/npms.jpg"/></item><item><title>CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution</title><description><![CDATA[The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting Widget Factory Joomla Content Editor (JCE) to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

The vulnerability, tracked as CVE-2026-48907 (CVSS score: 10.0), is a case of improper access control that could facilitate arbitrary]]></description><link>https://thehackernews.com/2026/06/cisa-warns-of-actively-exploited-joomla.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/cisa-warns-of-actively-exploited-joomla.html</guid><pubDate>Wed, 17 Jun 2026 11:20:46 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEisS71RYEu_1Sts3eqAt878RoohdLgeUzyTbRQgFqUYQcwBxzKB1ug6AvOBRXqZvWcChuLVj6KFbIt7nO9RX66ZJZyMEIADvIXe-fdNDrQIYXGtcMt3StDzbK4lF9ZLpF9pqCR1cGEa4lLkFFRVqIyD5w0JqwhVgr-C9ga7pZ6IQWpFmbsojcsGePBnzsGW/s1600/joomla.jpg"/></item><item><title>Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting</title><description><![CDATA[A flaw in the Google Cloud Vertex AI SDK for Python let an attacker with no access to a victim's project hijack the victim's machine learning model upload and run code inside Google's serving infrastructure.

Palo Alto Networks Unit 42, which found and reported the bug through Google's bug bounty program, calls the technique "Pickle in the Middle" and said it saw no exploitation in the wild.]]></description><link>https://thehackernews.com/2026/06/google-vertex-ai-sdk-flaw-let-attackers.html</link><guid isPermaLink="false">https://thehackernews.com/2026/06/google-vertex-ai-sdk-flaw-let-attackers.html</guid><pubDate>Wed, 17 Jun 2026 00:35:41 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgpiAGZTnvo43enaVYkna4ZSp217mwwW5kW8kZOhaSiLAxicjvHQY-3d8rdLN47bsRvxUIj6R0h_Ttr8NcIJrgz6k_mbcx94KLuPD29KdhFcYQsrV8htgg_iDYMV9aXbr21kv6BdYTzLNOOqQLpsCfpDC4XxDPnu77uVQ3oCYbIUfIpUKdmqx-rZZWj6P0/s1600/Google-Vertex-AI.jpg"/></item></channel></rss>