<?xml version="1.0" encoding="UTF-8" standalone="no"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:media="http://search.yahoo.com/mrss/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" version="2.0"><channel><title>The Hacker News</title><link>https://thehackernews.com</link><description>Most trusted, widely-read independent cybersecurity news source for everyone; supported by hackers and IT professionals — Send TIPs to admin@thehackernews.com</description><language>en-us</language><lastBuildDate>Mon, 10 Aug 2026 23:31:13 +0530</lastBuildDate><sy:updatePeriod>hourly</sy:updatePeriod><sy:updateFrequency>1</sy:updateFrequency><atom:link href="https://feeds.feedburner.com/TheHackersNews" rel="self" type="application/rss+xml"/><item><title>Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development</title><description><![CDATA[AI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, prioritize fixes, and control risk at human speed.

When software output jumps 10 to 50 times, the problem is no longer just finding vulnerabilities. It is keeping security from becoming the bottleneck, or worse, losing control of what gets shipped.]]></description><link>https://thehackernews.com/2026/08/shipping-1050-more-code-watch-this.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/shipping-1050-more-code-watch-this.html</guid><pubDate>Mon, 10 Aug 2026 22:59:17 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhy3fcUJacnxspYO1ssk2-ESCQ9QYb5BBCB0-3Jk8UyWQFmKZxt8RCeYemwUlJ08y_hnkyVm4LaAq6a_oyz5BPmpuwkmephJ0K7iy6cFvPjAe-b3pQ4Q28jh3KzNqLhZ6qtecuG9jenDpeVsjpUrG9ZBEwe2WStxgh6RiOwhI_rlsxYelFv2BD31o9rhd8/s1600/chain-webinar.jpg"/></item><item><title>China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw</title><description><![CDATA[Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor.

The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware, the Microsoft Threat Intelligence Team said.

"StormEncryptor is written in C++ and appends the file name extension .encrypted]]></description><link>https://thehackernews.com/2026/08/china-linked-hackers-deploy-new.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/china-linked-hackers-deploy-new.html</guid><pubDate>Mon, 10 Aug 2026 22:08:37 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjNv5C82jT_6YlarerdXnoAR_tT3E8xP65ZWuJfpvOKU9baBT5UACUTb88XvDQgQA6RrYuqPK3FstaqwacR9gDjD0qwk3HUYl0wK848phyphenhyphenFuqRrOA1AqdISQaA6tpEqg0n2XJIA22NeNNbhei1bAgcyghnc2qaVfSvh4fd9J1oD4xVi-DQcNSOYWQovyUst/s1600/strom-ransomware.jpg"/></item><item><title>⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors</title><description><![CDATA[A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default.

That pretty much covers the mood this week. Old bugs are back, supply chains are getting stranger, and some exploit paths are so short you wonder what was supposed to stop them in the first place.

That’s only part of it. Here’s]]></description><link>https://thehackernews.com/2026/08/weekly-recap-ai-goes-rogue-metabase-0.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/weekly-recap-ai-goes-rogue-metabase-0.html</guid><pubDate>Mon, 10 Aug 2026 20:30:29 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjtXmkUOPD6prrNPMK9N1Rhu2dm3QFGQ2DUTiu3xrj2WWbauZ_IK2HemME36-4WBIqGh01SFOkNJuutFeXLgS_ZMUBFn5ZDzIP5_IeNrwJWDfKcOPQgZl3spOFVS8R84Hbthy6o3sx9IWJ1yRo4FiW5acGYGBrf2nljmx6yvSd55LWRrkX6JhJ9b5bHJX0g/s1600/recaps.jpg"/></item><item><title>Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development</title><description><![CDATA[North Korea's state hackers are no longer content to type prompts into public chatbots. One of the country's main espionage groups has begun running artificial intelligence (AI) offline on its own servers, connecting document-search tools to files in its possession, and collecting the software parts needed to build AI into its malware.

South Korean security firm Genians says it uncovered the]]></description><link>https://thehackernews.com/2026/08/kimsuky-builds-offline-ai-stack-that.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/kimsuky-builds-offline-ai-stack-that.html</guid><pubDate>Mon, 10 Aug 2026 18:49:58 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhDgatgimOxtzWBp5R0l6yiMeoFVAeLE-hn-RGePbOlgUMgb3Vj9cEKav3AadjZBcppLfoDs4o-oREZ0OimLYX9WDnIRwebA4P7nVa-wh8KwHW-z7HUALW_bj2B-53kotBjkGw-6QXx-Awo3OxBlhjIwEIuueFEXLOgpT7cPpz5e_MSlD4l_FHgJocN6QA/s1600/north.jpg"/></item><item><title>New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA</title><description><![CDATA[Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on.

Passkeys are designed to replace reusable passwords and resist phishing. The attacks instead reused signed authentication material that Windows had exposed, abused a cloud-synced passkey system from malware already on the victim's machine, and used a&nbsp;]]></description><link>https://thehackernews.com/2026/08/new-passkey-attacks-can-recover-synced.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/new-passkey-attacks-can-recover-synced.html</guid><pubDate>Mon, 10 Aug 2026 17:55:04 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjWKCkGCqH-c6Yaqkd_NnzFQijViu34tjAEsdl9tl2CmZLHL4m1rLhezO76zF6XFRTGS9Sr4R3jhMD7z15QV0BMqG948bjg8SoZb_j6HtQajd0PUDR8Tmw06GMqDwS6VhAtH-ZNtD06lzb9KMhJsHi-Vvkps0n6bl6C8n6rSBHCldBuc1cMczr30h11N-8/s1600/passkeys.jpg"/></item><item><title>TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore</title><description><![CDATA[The threat actor known as Head Mare has been observed weaponizing security flaws in unpatched TrueConf servers once again in attacks targeting Russian companies spanning instrumentation, electronics, transport, energy, IT, and software development sectors.

Russian cybersecurity vendor Kaspersky said it detected the attacks in July 2026.

The activity involves exploiting a vulnerability chain]]></description><link>https://thehackernews.com/2026/08/head-mare-exploits-trueconf-flaws-to.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/head-mare-exploits-trueconf-flaws-to.html</guid><pubDate>Mon, 10 Aug 2026 17:03:41 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhwaZH1uRwKD4SlLCwgb-7zVkEGjYYXdFxb21glBm3grBdwOZ_M-ECnOmNVFPPY6mg6wXUCf4R4xm9mI8mBiEm21Ixh6y9GXYvL9DKQgKEBkTN65AVQqFz9DJpMs6BRmrGWjGC5vDC-cFgx774ASr7j73D0wiRxrs9tKNdovUbwmLuGicKgcZeQR53z71bT/s1600/trueconf.jpg"/></item><item><title>Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials</title><description><![CDATA[Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro ("solidity-pro") that has been observed delivering a browser wallet and credential stealer.

The names of the extensions are below -


  helper-beeps.solidity-pro
  web3devtoolsx.solidity-pro

Although neither of the extensions is now available on Open VSX, the GitHub repository]]></description><link>https://thehackernews.com/2026/08/solidity-pro-vs-code-extensions-steal.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/solidity-pro-vs-code-extensions-steal.html</guid><pubDate>Mon, 10 Aug 2026 13:08:23 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjR5_Dx4heVYIxaujo8ybl0OFdVuLzMFe0qdEdr6-q_QTdhSVlgHdrP6MeooXamFpRNfHjoAqTquvk3CkkCKUw1TQDkQJCrZY1RTC9iYK_bsTLNvpj0BZfFKFcnlt1RAlBvfcsWeSuLAn6Gwh9lur7v9-HlH-6ZpSmw7npsn9TSZAEpwFSFE54_xcFPcuDi/s1600/pro.jpg"/></item><item><title>OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause</title><description><![CDATA[OpenAI has announced that it's pausing some "internal activities" involving its upcoming artificial intelligence (AI) model Astra after an internal evaluation found it had made significant advancements in agentic coding and cybersecurity.

In response to the discovery, the AI upstart said it's implementing security controls for higher-capability models and associated activities, such as isolated]]></description><link>https://thehackernews.com/2026/08/openais-next-ai-model-astra-shows-cyber.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/openais-next-ai-model-astra-shows-cyber.html</guid><pubDate>Mon, 10 Aug 2026 11:20:03 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgat4Wvo6Fpe6pNG66UengjFIWRohQUVp-khyphenhyphenxa57n9Ued3-mWlDeeTQkblpAP-OEjgSCbY0n1bC_MhI3a5_BF1bWq7rBohkS2DG1AXUtcDI8MuWPRMFKGNdteA7_Xkg-_6w-y-wao14ZPQWoRF8cnbibQYHUAGP1byqwYyBpcyvCBQd0h2fe6t94zvoa4j/s1600/openai-astra.jpg"/></item><item><title>Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers</title><description><![CDATA[Attacker-controlled instructions can make Atlassian's Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found that behavior independently, by different routes. Only one of those routes is confirmed closed.

PromptArmor, an AI security firm, hid the instructions in content Rovo reads. It said an uploaded file was]]></description><link>https://thehackernews.com/2026/08/atlassian-rovo-can-be-tricked-into.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/atlassian-rovo-can-be-tricked-into.html</guid><pubDate>Sat, 08 Aug 2026 14:24:50 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFYjJTxVoOMkR9DDRPZ5PkeR_EWAqmBScR3TPw3mlweipGlnQKq0OdfVqR2f26QIV3kBJWQIM65f8XwMSFq3zT6Bl4fsTvkPHxJiU2LilhK9s0tcreXt2gotEpE8sKoDrLQJ3SSVY9B-RS0FsS2dC480op8OV-caeaZvNyTiIipQbeNFJGMnAcjWEVq7g/s1600/rovo.jpg"/></item><item><title>New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens</title><description><![CDATA[New research shows content inside an email can escape its message boundary and interfere with the webmail interface.

Across attack chains spanning Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, take over third-party accounts, leak tokens, hijack trusted UI actions, and manipulate AI tools that read email.

PortSwigger researcher Gareth]]></description><link>https://thehackernews.com/2026/08/new-css-attacks-can-break-webmail.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/new-css-attacks-can-break-webmail.html</guid><pubDate>Sat, 08 Aug 2026 13:33:57 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiCUnWbFb6UGu3ML1MqcuVXYwk0yoD6WzgXIQmi8ijkZQjS6M3g1F3kgV-RanNgyP1bdpNxDOOqMJzJnutZGh4MUVyYCbbu98sNXtAp-GWxueyKH9fDo3z9HmBl4tL-rj91kb11bhdhRvWGAYe56YGYMEzJgGIZeUqj9eGH10Bynj0YE6WMLl0J7O-HhLc/s1600/css-bomb.jpg"/></item><item><title>Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication</title><description><![CDATA[Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day.

The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain]]></description><link>https://thehackernews.com/2026/08/metabase-zero-day-exploited-in-wild.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/metabase-zero-day-exploited-in-wild.html</guid><pubDate>Sat, 08 Aug 2026 12:28:31 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjv2q8ukeawl9ALLfPnkrRkD2a9umOrSxPHUJdclgLcKj5zM8k19y-NWuTGLrV1yIU4u0F2-QbAsD4zO-NkeEuWPwDqdUYbVFDG69EgOl0v55K0Brjp7lfIb6hExJGyVj9rj5KjeZPtoU97DwoaHAi_umLzQVqpedMMt08eas1akWBhNXUZ2WHOqVXczAf4/s1600/metabase.jpg"/></item><item><title>N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist</title><description><![CDATA[N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management (RMM) product.

"We are proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques," the company said.

"This is not a duplicate of our]]></description><link>https://thehackernews.com/2026/08/n-central-attackers-reach-managed.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/n-central-attackers-reach-managed.html</guid><pubDate>Sat, 08 Aug 2026 12:27:43 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhsaNpVaG83aDE1lJwcNllVSeS-ebafbbt4FgaKHH1_4dt1i4qvCtw-dYVrE_MiWf2GZ5vyGPhyphenhyphenCieChBz2IChMJew0I1Ze2HEYJpB-j3rB2VnfNrzbFpPDD7VFkWCkYBn2CJRLpOBIKNaeKPXlVPHpz7-1Wx9go7IfyUKSVNliDO644rNsoMmAk5a3Qf_W/s1600/nc.jpg"/></item><item><title>Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts</title><description><![CDATA[The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.

The vulnerability, tracked as CVE-2026-8037 (CVSS score: 9.6), is a command injection flaw that could be weaponized to achieve arbitrary]]></description><link>https://thehackernews.com/2026/08/progress-kemp-loadmaster-flaw-hits-cisa.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/progress-kemp-loadmaster-flaw-hits-cisa.html</guid><pubDate>Sat, 08 Aug 2026 12:22:16 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg_DF22WirQj4KZe5A4NxYmG3UhC2o4BRQ4AybyFlmr80n5Wkf15sbtMn11P0msoMyAe65WBqMpL2XBsqTiHdDNNH1i6qz11ydD9X4AIOoiaSfCYb1MCe7dfJD0n4TEIc5_83tsMq5zJ5zVpGbpCq7b8rACen1oMvW8XGBbz3T4hy_9J6igpOk0oCDp6vkA/s1600/progress.jpg"/></item><item><title>Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer</title><description><![CDATA[A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems.

"These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but all of them deliver a powerful RAT and infostealer payload," OpenSourceMalware researcher Paul]]></description><link>https://thehackernews.com/2026/08/nearly-800-malicious-npm-packages.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/nearly-800-malicious-npm-packages.html</guid><pubDate>Sat, 08 Aug 2026 00:18:17 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiIEXaa59LRblZ0rcBVbKDdH4w9Rszk27anNt20Onx7Li8D7FXbf3Ipod53uo3N2aa6Hj1QLJaNFDIBlrcgM3YZg0UJCsjI3maDKkFEdOeyhzis15St3QDg6WCXcYlbDRlw2WvgiOH-BL_v8I21QoSTE9kmJzzKqQwstqn11JWkAL1_9W41ZF04T-9ImaiL/s1600/npms.jpg"/></item><item><title>ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets</title><description><![CDATA[ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials.

The macOS-focused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that's compatible with the computer's CPU architecture.

"]]></description><link>https://thehackernews.com/2026/08/clickfix-attacks-deliver-macos-stealer.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/clickfix-attacks-deliver-macos-stealer.html</guid><pubDate>Fri, 07 Aug 2026 23:59:08 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiKQGTQ6AquoAvAeMWXXITPacYsdChgFUpg7MLwKkfb2AylEuwQTk9av5GqMSdgtsB_tr_6QC70DrJkEo02t-Wo67z1gumix6FKKlOPSWo4fLEUHCibBoTrf1zCdmn72ESzo5CzCKKEgyETZ0FeVD_3QLfCNit7vIwlMA7MmwGYg2JGbeYOBrjSHmOnfpWl/s1600/macos.jpg"/></item><item><title>UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data</title><description><![CDATA[A recent wave of cyber attacks targeting financial services, private equity, and professional services has been attributed to a data extortion group known as UNC6671.

"UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via]]></description><link>https://thehackernews.com/2026/08/unc6671-vishing-attacks-target-personal.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/unc6671-vishing-attacks-target-personal.html</guid><pubDate>Fri, 07 Aug 2026 23:46:13 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiL6-qu-cN6glV6XSy1IS7siHKdKPFmzqT3X8TQjGCa0RD33kfIQ8NfEBR5r8dbQvj1OS8L6T083igxfS1VO98xlg7MHIMysbfR_cVpdmPMcYibuMwDZ6SssIi3iryUznGL14zUByy7oRrTJe0AjgGMNti_Rcqezh7dtfyU31vyo-zft3fvR56SCsAfeHrm/s1600/vishing.jpg"/></item><item><title>New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP</title><description><![CDATA[WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. pwn.ai demonstrated how the flaw can be chained into PHP code execution on the server when a logged-in administrator interacts with an attacker-controlled page.

Tracked as&nbsp;CVE-2026-64638&nbsp;(CVSS score: 8.9), the high-severity]]></description><link>https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html</guid><pubDate>Fri, 07 Aug 2026 18:26:23 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjAXYZlxtz4bLTF4gNuVpVMMykRZpDR7IKjIFSR7jhL6CBKSsE1PZ7aIRpSGE57XGGb69NbrYV7wMJLjsRG_lP4SJzyvNZ0nUj9SHArph87e8bWBHKUsOGy1-9rymiMesSAcvUFrPP2Xrf_EuUXiOmKJC2MeBYFRcXmgxKhAv5UBcRzV0ku-_DLEONVLQuV/s1600/word.jpg"/></item><item><title>Growing Up The Hard Way</title><description><![CDATA[Open Source had a great childhood.

For two decades it got to be a kid. It ran around barefoot, gave everything away, trusted strangers, and never once thought about who was watching. It ran the kind of lemonade stand that took IOUs from anyone who wandered up — take what you need, pay me back whenever, no need to leave a name. It was idyllic. It was also, in retrospect, a little feral.

Then,]]></description><link>https://thehackernews.com/2026/08/growing-up-hard-way.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/growing-up-hard-way.html</guid><pubDate>Fri, 07 Aug 2026 17:25:26 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjz974dYXx9klEa_qhJoTHKqb5QNoQwTpxsMKoZeqsvQtvWZPgPKobw1QySvcNGgnFocbYaFaaBGsB4COPaw-fqqgOHERJEVc8sgRSjto5VCrQeIWr5Nz21r3PjMTIXmwUmvakUlP4sB3iYqF2qXiabCvrqKFyFBq3GzOUwqM7LGRV68q_Ib9zt1ilCBJo/s1600/open-source.jpg"/></item><item><title>18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers</title><description><![CDATA[A use-after-free bug in Linux's SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath.

The flaw has existed since 2008. The fix already shipped: stable kernels 7.1.6, 6.18.42, 6.12.101 and 6.6.148, released August 3, close it. Anyone running an older kernel with SCTP reachable should update.]]></description><link>https://thehackernews.com/2026/08/18-year-old-linux-sctp-flaw-could-let.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/18-year-old-linux-sctp-flaw-could-let.html</guid><pubDate>Fri, 07 Aug 2026 16:40:33 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjmTGemKyDLZPr_sBbt2AdOQMEBEcRFzic8_Ddtkx92vtPOfFdoiwxJ60b00usecTjHuIGUJuUIR2aB8MU2P7-GLc0NOuWsa3ctofrA2-wD38wgI4Fke3moSskWjiRJEXT8Yxl7Ye56NgGl9DZKr8zf974rHRsc1PtHie_iIPVyD18HMx49S02tGZ2EeDY/s1600/linux-sctp.jpg"/></item><item><title>New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables</title><description><![CDATA[Security researcher Malcolm Stagg has disclosed a new attack class called&nbsp;NatJack&nbsp;that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables.

Presented at Black Hat USA 2026, the research found affected behavior across independently developed implementations, including Windows and]]></description><link>https://thehackernews.com/2026/08/new-natjack-attacks-hijack-tcp-sessions.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/new-natjack-attacks-hijack-tcp-sessions.html</guid><pubDate>Fri, 07 Aug 2026 16:28:38 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjx8dmEkj0rsX2NREBfPOczKn7zadWRaVVOyVPVeaCPzCDdBAPhocCwP1CVbX_p1pj4Q7DVYsdusvWc9u9G7lO4BGYihT6BXnXY099zIs1B1PBefH71cXCHZucxaG2gEzqKdf9B3FVr9MJ34SntVezm4gNXWSxIMF05DpYUNF6qmfhb0hMiyNpsWDOtuRE/s1600/NatJack.jpg"/></item><item><title>Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails</title><description><![CDATA[Cybersecurity researchers have called attention to an active "widespread email-driven phishing campaign" that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with an aim to identify key personnel involved in financial workflows and gather related email.

"The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic,]]></description><link>https://thehackernews.com/2026/08/microsoft-365-aitm-phishing-hijacks.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/microsoft-365-aitm-phishing-hijacks.html</guid><pubDate>Fri, 07 Aug 2026 16:08:27 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgH78NjDW1Q_sIk9dwQ1scYlCkNCMutfjGx_9flqrKbE42fEXqvHT8s5EeHTnWjbBGvzCuHPEWStR5r6wjwtIuuHF1hyphenhyphenot22E_Q98xedC1zXVhIhwglw6hLWQs45oSrPKPflK6Tt1BlHTj9iokMPpVaTehuemHGHDLL02cn2sqZJ5iIVstxiVf5IZ5Khodp/s1600/ms-phish.jpg"/></item><item><title>AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day</title><description><![CDATA[PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate desync vectors.

PortSwigger said a separate human-guided discovery cascade also exposed a zero-day in Apache Traffic Server. Kettle said HTTP Terminator tested 30,000 websites where]]></description><link>https://thehackernews.com/2026/08/ai-assisted-http-terminator-finds-novel.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/ai-assisted-http-terminator-finds-novel.html</guid><pubDate>Fri, 07 Aug 2026 15:39:54 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgynSSg0CZ1sssmMR8F0u09LmQ82liuj5nt2aor3klmi-xPcKTmalo4JLFQ7jd2mU9Ycnltsrnw2MiVVjmlT-wcYR74Ob7NMN31KNnny14lqVRdrmj30r3yqTSxapzCmQPk9lPG7v9GDSVKQwE4ufB-jWfsx1lc2O5GNd0bHd5M6FbMNah3dcLzu2EAFXo/s1600/Desync.jpg"/></item><item><title>Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access</title><description><![CDATA[Entra ID researcher Dirk-jan Mollema demonstrated that malware already running in a signed-in Windows session can silently use the victim's Windows Hello for Business key to authenticate to Microsoft Entra ID.

The attacker can then establish longer-term cloud access, register a device it controls, obtain a Primary Refresh Token (PRT), and add further authentication methods where tenant policies]]></description><link>https://thehackernews.com/2026/08/malware-can-abuse-windows-hello-for.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/malware-can-abuse-windows-hello-for.html</guid><pubDate>Fri, 07 Aug 2026 14:22:11 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj81b6_YckjrqqfRrJQNRdIf3nu4xfqLNScukFYEao4VeF5QNlt16sbEwrdutizdB9Q1nOWRQpqeSZg4gYZsL8cIhRSJ43XJqMKWKgdKF28oeTl19HQQ75dnOKVHsa6DtXr4zhlmIF43nbUWV5jyEh4D1TjIvBKjgoAX2MpUbjJH3cN4hd4zDvIu_t4Jec/s1600/windows-hello-keys.jpg"/></item><item><title>Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets</title><description><![CDATA[A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's own coding-agent repositories. On OpenAI's, it was enough to hijack the next agent run.

Novee Security ran the attack against each vendor's agent in the configuration that the vendor ships by default, and presented the work at Black Hat USA on August 5.]]></description><link>https://thehackernews.com/2026/08/claude-code-and-gemini-cli-flaws-let.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/claude-code-and-gemini-cli-flaws-let.html</guid><pubDate>Fri, 07 Aug 2026 13:48:35 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEguukj-eRhx9RtAq9X96hAxHi0IU3ZWgM_W5XkdWhF8ezevuBQygkpv-ku5PSri9Gt5hRkNVxe6HmJJr5Mg33X_PhOGziqaho9bwm-mkRZSBl2jo94XF3jRwTZOb_PocueKWJkEtvl7kG_YqmbVfUxNht8_ODzLOERIqQteMdPxnWpobM-c9-fHhn0cLMQ/s1600/claude-github.jpg"/></item><item><title>TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign</title><description><![CDATA[A new analysis has uncovered that the threat actor tracked as TeamPCP has been active on the cybercrime scene as far back as 2020, indicating the group has been compromising internet-facing infrastructure for years before training their sights on the software supply chain.

"The connection is supported by overlapping domains, malware deployment paths, staging techniques, backend infrastructure,]]></description><link>https://thehackernews.com/2026/08/teampcp-linked-to-redis-attacks-dating.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/teampcp-linked-to-redis-attacks-dating.html</guid><pubDate>Fri, 07 Aug 2026 12:20:05 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEicYXbdZUBG2jW8962nmphGWa0sWoq3jKe6HAT9wa6qlZdPPYBZRdw-uWjUbUv15BxaRgugcEAPXPZ2rMYx3RzM_vLVH18F6oTwwAklstzIRehnPJXwBs9b-d6NKjJZVhO5n1SRnBTlweRonaWCFogLrbJkyzs-F9K3lffy0tfqf2Vownwe9lj06rEe8Nn2/s1600/TeamPCP.jpg"/></item><item><title>New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts</title><description><![CDATA[Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests.

The flaw is tracked as&nbsp;CVE-2026-64561&nbsp;and affects KVM/x86's shadow memory management unit (MMU), which manages shadow page]]></description><link>https://thehackernews.com/2026/08/new-zapscape-kvm-flaw-could-let.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/new-zapscape-kvm-flaw-could-let.html</guid><pubDate>Thu, 06 Aug 2026 23:28:30 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj5BBX-j7uA7NqPF9tVWhx3y09F3whJ3zweRoWGyI2kJDxhW6ymOG1oumq5Oz0sZWtCAKSCALcd9TTl7Kf5Mo3aqE3aWKH8jfKWt2uUD-CUa6tmid-3MvMTM08EAEhg5iLQ2mlEgFkVeuVKv1QkRqr2T0Ya9JcNtMYheggInGndCG0n-N7BPjyH9vbKCg8/s1600/Zapscape.gif"/></item><item><title>Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.9 CVSS Score Bugs</title><description><![CDATA[Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of a comprehensive internal security review.

The security issues affect Cisco Catalyst SD-WAN Software, regardless of device configuration, and Cisco IOS XE Software when it is running in autonomous or controller mode.

"These vulnerabilities were found]]></description><link>https://thehackernews.com/2026/08/cisco-patches-12-sd-wan-and-ios-xe.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/cisco-patches-12-sd-wan-and-ios-xe.html</guid><pubDate>Thu, 06 Aug 2026 22:43:15 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgzkSwdiUeH8rB-KgSkEXrT-oNL19IyghM7Ks8UDOedxPYB5czgwO8pXNf0YUt7OHqAbRRDJkRvJffzJ0lfpEdqfLn-w-Bc9pwOa_1FNJjJkrVbD-diaZu9HRFqAlOBWogXEsZ4sSFRDW-HYmsaUmVD98QGQoyq2rHep_dwDa5ueafTUO0Lh6zsA-Czd3he/s1600/cisco-flaws.jpg"/></item><item><title>New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs</title><description><![CDATA[An unprivileged Linux program can time a hardware interrupt to land in the gap between a processor sanitizing its branch predictor and the kernel using it, re-poisoning the predictor after the defense has run.

MIT CSAIL researchers Daniël Trujillo and Mengjia Yan named the technique INTERRUPT INJECTION. On an AMD Zen 2 machine running Linux 6.14 with every default Spectre v2 mitigation on,]]></description><link>https://thehackernews.com/2026/08/new-interrupt-injection-attack-can.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/new-interrupt-injection-attack-can.html</guid><pubDate>Thu, 06 Aug 2026 21:47:13 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiA_BgCPUTlxOgmh4ljCoOazIkcoSA_BHUGZmfAuhxD8TiUzui2nhB5b5KV_lv50ocFWI14FG5RIe8rqrm6D8ZC8ACR7mY1bXE4JADKcTRIY1bfIeXtnYs07yXk2T9Jsv0-vcxPkKbl6FuNXxXylv5BQQQLTDSpJ2XSyqxvIsxYy5d2X1Kwt_2CSJegj9Tv/s1600/place.jpg"/></item><item><title>ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories</title><description><![CDATA[Apparently, opening the thing is now enough. A repo can run before the first prompt, a package can hide among hundreds, and a harmless-looking PDF can finish the job.

This week runs on cheap leverage: exposed servers, recycled bugs, poisoned agent instructions, remote-access tools dressed as support software, and trusted defaults doing attackers a favor.

Nothing here is especially mystical.]]></description><link>https://thehackernews.com/2026/08/threatsday-odysseus-rce-samsung-one.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/threatsday-odysseus-rce-samsung-one.html</guid><pubDate>Thu, 06 Aug 2026 20:54:31 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhl0f74Tyvl6NQ4TAbPMIpgYWuHQN8THsYSQ77D9qmHuZdKsK2ZDrTLyWshLPV-UfSYW6Rbtfj866jP0X_D1QHmOFYIoEDZG90G3cy7JGFJrKsq0m7VeGqa0CCDygB9F3ttryPRQm-6MY50zIOsGFBdnwZZgAf31swGo5dOIa0noWuIoEk7rPrUkdfoddIj/s1600/threatsd.jpg"/></item><item><title>Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities</title><description><![CDATA[Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network.

Its August 3 scan counted 4,407 exposed Rockwell controllers worldwide, including 2,844 in the United States, but Forescout could not confirm any were compromised. That figure counts exposed]]></description><link>https://thehackernews.com/2026/08/over-4400-rockwell-plcs-exposed-online.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/over-4400-rockwell-plcs-exposed-online.html</guid><pubDate>Thu, 06 Aug 2026 17:46:58 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhUzp-V2FqPXO6jQl0K2Qnn-2Ys6UG168FNhA0TcFv7CGHtBIgWuD66JsjhDiQhf_DkSTBo_YpVGTY3wcLe3SITSszBT0XAD01P6_nFLkXOHNNoKmp6VTsQ-zB9oKR6qYU2tCpf5RwHZ_u35lJiF41Sa3T7zuGfXujh_Ums9snpXTUAJIbcL6LfF9a5bIw/s1600/power.jpg"/></item><item><title>CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps</title><description><![CDATA[Coinspect has identified CryptoJS.lib.WordArray.random() as the weak random number generator behind the Ill Bloom wallet drains.

Introduced in the JavaScript cryptography library 12 years ago, the function supplied weak entropy that affected wallet apps used to generate recovery phrases. Coinspect's on-chain analysis puts the measured theft across two sweeps since late May at a lower bound of]]></description><link>https://thehackernews.com/2026/08/cryptojs-weak-rng-behind-57-million-in.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/cryptojs-weak-rng-behind-57-million-in.html</guid><pubDate>Thu, 06 Aug 2026 17:19:48 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhOLyOOoRbj7XXsr5asbHmKbRetYhjWcAZap4b6VUBQ3ENWpeB46A78vztXFJGUDMDHNskXyUMH6yu9Quv-WLut657FS4Dk4-SICypcAVTLuI7fYUxC7Y4qEUI6A8NMIS-GZ8KkzjRULoNZAPD1TIamWyp-T5vgrjMDQKMD0lmR6pZU8P4VeOwWEo7KxWA/s1600/CRYPTOJS.jpg"/></item><item><title>Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses</title><description><![CDATA[Cybersecurity researchers have disclosed a security issue with Apple's iCloud Private Relay tool that can expose a user's real IP address.

Introduced with iOS 15, iCloud Private Relay employs a dual-hop architecture to ensure users' privacy by routing their Safari web traffic through two relays so that no single third-party, including Apple, can determine where the request is originating from]]></description><link>https://thehackernews.com/2026/08/webkit-proxy-bypasses-can-expose-real.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/webkit-proxy-bypasses-can-expose-real.html</guid><pubDate>Thu, 06 Aug 2026 17:03:08 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi53VbynsVNPTCihg9qrqybX7Yu90yM3Tm7KlJnJCHz2_MOUQPyJys1uK6H5QkVqxGekck8qe-pA55tcy19IDYQ4_ndOKasvoaFiPJCI_NJClfHv6G14Ga5P_FPr0zyNijjRMBM-GBlt-XYRqCGAcrZxm9ETsAAu4kPh829ZKABQonHDlx2GuWG9-B-V383/s1600/apple-relay.jpg"/></item><item><title>AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory</title><description><![CDATA[A new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and no zero-day exploit. It abuses a standard feature built into almost every major AI assistant: pre-filled deep links.

We observed production websites embedding hidden prompt injection payloads inside "Ask AI" buttons on marketing and competitor comparison pages. When a user]]></description><link>https://thehackernews.com/2026/08/ai-recommendation-poisoning-how-ask-ai.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/ai-recommendation-poisoning-how-ask-ai.html</guid><pubDate>Thu, 06 Aug 2026 17:00:00 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgERF89TJZsy7Kq1JhEcPKC5ynyCNMv1JAObXj4W415ZbGwE-ZZplLbq5HEiBWi3ULKifDI7Tl440UrQvLFEmngeAHL4o2XfWKxTgb7CEsHmBqBt-w5qePo-BGmlDcu_vJtyfsh1CV5COMXpIUHRiw8WmPeitZAzEu3ugQJ90mDtOhlU0BzTaRDogTHg2Y/s1600/ask-ai.jpg"/></item><item><title>Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access</title><description><![CDATA[Attackers broke into an organization's Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit without writing an executable to disk. They fed Java source code to the database, let Oracle compile it into stored schema objects, and ran commands from inside the database engine.

Huntress, which tracks the toolkit as khunt,]]></description><link>https://thehackernews.com/2026/08/attackers-compile-khunt-inside-oracle.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/attackers-compile-khunt-inside-oracle.html</guid><pubDate>Thu, 06 Aug 2026 14:49:23 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgWGMHYrRkDGf3XV_lOoUbE1UCSjvcN9x-XNpNGpX_f45JqZzd2FrxJ-metvu-U5VyDqH2PGNaY9MiSeShhH-YVN3O4ryN5lh4ICsuXtz0-DuCSAgnywXUifDOf_qZS81AtjRGNQWgs1QnL4Eu54icswla_ZK7qGoZqWDaVzPX46pmcTrvj_ec0yQwrt9k/s1600/oracle-root.jpg"/></item><item><title>AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model</title><description><![CDATA[Security flaws in agent infrastructure from Amazon Web Services (AWS), Google, and Vercel let untrusted or forged instructions reach an agent's tools with no check that a model turn had authorized them.

In several of the attack paths, the model never ran at all, so system prompts, content filters, and model-level guardrails never got a chance to intervene.

The affected products include Amazon]]></description><link>https://thehackernews.com/2026/08/aws-google-and-vercel-patch-agent-flaws.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/aws-google-and-vercel-patch-agent-flaws.html</guid><pubDate>Thu, 06 Aug 2026 14:27:30 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhNMtOKfZBxSDQ1928IVtFay3f8_6go4rnTY6yFaQYCzAdGt3e6uBkZfZkoFtHbS_cEbTCri3ZNVVO7BbuvoVpjGCLSpdphneotNbiXRT3vciQT6dzPa0K81_ee8Al2rxx7GlT5qTS3_B2MKjCCUcHut1pdIeqaLBRjoD5ZqttMcHxZ5AwKea3eL-wruta7/s1600/agent-sdk.jpg"/></item><item><title>Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells</title><description><![CDATA[Cybersecurity researchers have disclosed details of a "factory-shipped backdoor" implanted in at least 20 Chinese router models from Zbtlink.

According to a new report from VulnCheck, the implant appears in all 21 firmware images currently available from Zbtlink that span more than 2 years. The backdoors are designed such that they start automatically and attempt to beacon to Chinese]]></description><link>https://thehackernews.com/2026/08/chinese-made-zbtlink-routers-ship-with.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/chinese-made-zbtlink-routers-ship-with.html</guid><pubDate>Thu, 06 Aug 2026 13:35:22 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg3VqhMa79pNymspvzHhSpHG4HCDAGn4nAD-7ZwQgDuSOELhM0xxHASqfnd2ThEv8XJ0tM58bPsGPHcobfoaEEWW4Am9H-Wd9bpb-QqYRQfFcFKrvbLjwEGYu0VfIAclBcVn9PpMWS02ZAtOa7hhwg8e45cYcgYYX0C1_yQptZh7-ZvqFHpf-9uqq5csbCj/s1600/router-hacking.jpg"/></item><item><title>Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service</title><description><![CDATA[A federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison on August 5 for creating and running Ransom Cartel, the ransomware-as-a-service operation he stood up in 2021.

Between 2021 and 2023, Ransom Cartel conspirators attacked at least 18 companies, including firms in California, New York and Nebraska, and others abroad, according to the Justice Department.]]></description><link>https://thehackernews.com/2026/08/ransom-cartel-creator-gets-16-years-in.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/ransom-cartel-creator-gets-16-years-in.html</guid><pubDate>Thu, 06 Aug 2026 12:49:54 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgsIRDdzzjtJRcq3kiouQy7I8wwCFvWIKA5VHAKEVdGC2OJL3WCGnKPZUvAHUi-Jrz9yLN5pfTtS0QI8MRUuSbGOlbg_3jNktHGZSb4wsOKvjcwehZYqL671hB0UgjVjUPnKju5QFDO4BXhjePhJuvGDw_mJs1scXXI_veItNxCej7uEwjKfTHzc9Nkm90/s1600/Ransom-Cartel.jpg"/></item><item><title>CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild</title><description><![CDATA[A newly patched security flaw impacting on-premise versions of JetBrains TeamCity has come under active exploitation in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).

The vulnerability in question is CVE-2026-63077 (CVSS score: 9.8), a case of deserialization of untrusted data that could allow an unauthenticated attacker with access to a TeamCity server]]></description><link>https://thehackernews.com/2026/08/cisa-flags-teamcity-cve-2026-63077-rce.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/cisa-flags-teamcity-cve-2026-63077-rce.html</guid><pubDate>Thu, 06 Aug 2026 12:21:43 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiaatZ2xKx3CMoWOXqKbIp1Sd-rMbET1_QE2Lh10XAVc_g_Z18UUlW_RyR8BR0Nj-gqy9SZhnEq0ZBv_z63FfCBu-XGfH5yEzUsKBLicrlfXK2-iMsgZYkDDTW-HiEPV29TEjFSFF1PYXyDkZcyfe6LuUKkgu2nRe4E_XFNPOcxSrBmUZwi3tX_GgHafeZ9/s1600/cisa-teamcity.jpg"/></item><item><title>Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People</title><description><![CDATA[Connor Riley Moucka pleaded guilty in Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft and a related conspiracy over the 2024 breaches of Snowflake customer accounts.

The intrusions reached at least 165 organizations and exposed records belonging to at least 100 million people. Moucka, 26, of Kitchener, Ontario, personally took at least $495,000 from]]></description><link>https://thehackernews.com/2026/08/snowflake-hacker-pleads-guilty-over.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/snowflake-hacker-pleads-guilty-over.html</guid><pubDate>Thu, 06 Aug 2026 11:34:30 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEimtSQSbHZnqrcub_RlfzViiiKRKyucYCIYf0nqt0aWqcYJgY122xGjIRDGnvpYukopZM9DuEPjN6Lax97qyYIghxfFb_faULxhabuOJHBOVbyycVBNUVHAbb5Z8LRfnG_5xrwH__9Jbs6qmPEdopvRysLduoAn0hoANFRnNd2g24zqBTfCUK4WXtDx7eg/s1600/snowflake-hacker.jpg"/></item><item><title>Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures</title><description><![CDATA[A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks.

The server-side gate hides the malicious page from crawlers and sandboxes while presenting selected Mac users with a fake software download. Microsoft]]></description><link>https://thehackernews.com/2026/08/over-250-clickfix-domains-use-browser.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/over-250-clickfix-domains-use-browser.html</guid><pubDate>Thu, 06 Aug 2026 00:14:31 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgzEMAtBAmz-q78zPppsCxMiU-EtelOA3FQy_T6Qzb9KpWEsc9wNMT1f_dDjf65q2W_nrioQ033KClusfHFXexSM8V30mReU5V3nbRY4W0_F3cg2ehG51P1nnWa1iKiGX3hJ_yUUYLF92TanEEE0HifpkzdqRQeqe8qFYXq0SPRx6pW9IrfS7sK_lPzWRM/s1600/mackos-finger.jpg"/></item><item><title>OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes</title><description><![CDATA[OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes.

To that end, it banned a coordinated network of ChatGPT accounts likely originating from Southeast Asia and operating from the city of Poipet, a region with extensive]]></description><link>https://thehackernews.com/2026/08/openai-disrupts-poipet-scam-network.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/openai-disrupts-poipet-scam-network.html</guid><pubDate>Thu, 06 Aug 2026 00:03:47 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgmYzVApv7lLg_Qt67mGI-sC0vUGKZwkNmFsVgTykAPCHqVMsfGSSQRRaxVXuxx0RDd6wk18yEiVXXy3uPRpmLT_XLNMCI_0iuKbPtJ3z9CtuPtjBsIGDAsVTd5f8DE_z2yMfAsQFW66vvoe5MeQPWvfBM2CoSzi-xpgm_mTvXfqHERAr-1z9NYOUPGOgwP/s1600/chatgpt-scam.jpg"/></item><item><title>Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt</title><description><![CDATA[Cybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) models on underground cybercrime forums and messaging platforms.

One such service, Poison Claude, claims to offer access to Anthropic's large language models (LLMs), including Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6.

"Advertisements for Poison Claude]]></description><link>https://thehackernews.com/2026/08/poison-claude-sells-discounted-claude.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/poison-claude-sells-discounted-claude.html</guid><pubDate>Wed, 05 Aug 2026 21:06:03 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhp3V9f5UsiH1E6dHfRvy0DEOYvcK14BatMbbLVfdPjLbu3PMInRmVXDi4xoGw-pSIuxUjZS1rdv4X7N1V9xRoV9RRVfaYdAWI6OTxKZzOhAlHYh6dKZNeAWCPkaPdGAvwgcOwFQ0atoRBUxKfE_KfhJpnm1yV1tXr5_Wv2yqND0vZCMMEfRB0V220SZbne/s1600/ai-access.jpg"/></item><item><title>Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports</title><description><![CDATA[Two security flaws in Paperclip could let attackers execute commands on a network server or a developer's computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both paths rely on importing a malicious agent and starting it.

A third flaw could expose sensitive data and control-plane details through application programming interface (API) routes]]></description><link>https://thehackernews.com/2026/08/paperclip-ai-flaws-let-attackers-run.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/paperclip-ai-flaws-let-attackers-run.html</guid><pubDate>Wed, 05 Aug 2026 20:44:05 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgnNyDWyCEMrA99LxVQMqKNr188rBBjKa6Kg3nHdjVLxWCCVgfqa0cChHo_JWbHgbSLHgZVpcgWn0kw0FUySWhScczQi6LNme-wY9rkUAxE-IvoFLvfum-zWxEnppDBu6bAHBO0ObN39kCDwSK4jnsqdCAOhCPGG0FtoLX_2vvCi2DcoWPmzGUk6Hs_gB4/s1600/paperclipai.jpg"/></item><item><title>Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug</title><description><![CDATA[HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django.

The three most serious:


  An unauthenticated flaw in Veeam's console that hands over a managed agent's credentials, rated 9.5
  A cross-tenant flaw in HashiCorp's MCP server that lets one user's Terraform token be reused for later users']]></description><link>https://thehackernews.com/2026/08/veeam-terraform-mcp-django-patch.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/veeam-terraform-mcp-django-patch.html</guid><pubDate>Wed, 05 Aug 2026 19:57:30 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiGDed_n3TJGLHvhq2MkwkQTsKgIv_rOw24MRfYCoHnHiOK7r-VbitMrwXXF9H_Gwbegba20Dla1FLyK70-OQRVxiHfikBFrz6jei3QK5u4ApbR4aYuLikQj1YHU2IzA1V4fnR7Wgcp8H1NoYzSeTTOUd4dNTuE71jNUNq-P4yk0H9FkW55wivMDdNe0nE/s1600/veeam.jpg"/></item><item><title>Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain</title><description><![CDATA[Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer.

The new dead drop resolver approach, observed in two trojanized npm packages "bianira-ui" and "fluid-type-ui," has been codenamed NullReceiver by]]></description><link>https://thehackernews.com/2026/08/trojanized-npm-packages-decode-c2-ip.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/trojanized-npm-packages-decode-c2-ip.html</guid><pubDate>Wed, 05 Aug 2026 19:11:27 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_jFD4wUBf7wKq8NwAgGKeKgJ3XIR82d26D7t5fNRBoDTOHcK5i66j4VqtLNAvK7Lkocc3lbW4SK33Ialb3F4EuB_k59ahZItRVdPsZ3RceScz5lEyR7gQHqqw221WMj6ArtKDUashxvrkYSPaE0b7ue8v-TkkT0IB8sPhgcCGIqN3mtfsjQ2MKztu5DkV/s1600/npm-c2.jpg"/></item><item><title>New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch</title><description><![CDATA[A memory corruption flaw in the Linux kernel's Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured distributions, and a public exploit ships with pre-built records for roughly 800 kernel builds.

The vulnerability, tracked as CVE-2026-64531 (CVSS score: 7.8) and codenamed OVSwrap by its discoverer, was disclosed by security researcher Asim]]></description><link>https://thehackernews.com/2026/08/new-ovswrap-linux-kernel-flaw-lets.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/new-ovswrap-linux-kernel-flaw-lets.html</guid><pubDate>Wed, 05 Aug 2026 17:13:27 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjhWC9UfjMK9e0KvUrcCjymLYZzuDDgZpArW3oZPtcds7CJ1pr1GleT46Wlm2_aWWpoe6TpgYcdnz_jhVOgjK6mnW_gekJkMotmfRiQ0xcp5v7mdx6CvVvUID0IyfSplGHGX-8JGoMJ1OLyEA96qVMTWwhEjKf21thNfvkBCg2DSgNjSkVEDyAugdcyJfk/s1600/linux-exploit.jpg"/></item><item><title>Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk</title><description><![CDATA[Kali365 is turning a legitimate Microsoft login into a gateway to corporate data.

The phishing kit targets US organizations with attacker-controlled device codes that victims approve on Microsoft's real authentication page. Once access and refresh tokens are issued, attackers may retain access to email, documents, and cloud resources, creating a direct path to data exposure, financial fraud,]]></description><link>https://thehackernews.com/2026/08/kali365-weaponizes-microsoft.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/kali365-weaponizes-microsoft.html</guid><pubDate>Wed, 05 Aug 2026 17:13:19 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgW4SMtq8o2R4j-NiqM2jQTNNSKABhkghGsH1AkUpqHf7sms7KTAr63IKabEzV2vAfAFO3XxYjh6YH8rDNtNVuu41JePoUdB_WQB-WWtJt4A-FWfmT6rwyzKAL_scAorwzVMt5R_7LZp2qzmUAAKfAodH__3_HLwa-nFV6b6TEng-5Cjviybn07c-ZNKUoU/s1600/main-anyrun.jpg"/></item><item><title>Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup</title><description><![CDATA[An unauthenticated attacker can read any file the service account can access on Gitea, the self-hosted Git platform, in versions 1.22.1 through 1.27.0. No login, no repository write access. A public repository and crafted Org-mode markup are enough. The flaw is fixed in Gitea 1.27.1.

The file-read flaw is tracked as CVE-2026-59774, rated Critical with a CVSS score of 9.8, and received its]]></description><link>https://thehackernews.com/2026/08/critical-gitea-flaw-let-unauthenticated.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/critical-gitea-flaw-let-unauthenticated.html</guid><pubDate>Wed, 05 Aug 2026 16:34:23 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjwgShwk2piIWpgBCF7ikGum0q7QycFbG91NuOiXNj4iRw_Uya_1R53Mx53EcLELS4lEusFjCYxTZuD0vf1VbGdXJ6rM9zq2OuNMsP20bbATKOaMUYbu9vWRbAJUQX436hP4vWvwc-jy1sWdoIIph0Uf93XMVImu-OIKnOMBUOYptMtoK9nAsP4yo48AtM/s1600/gitea-lfi.jpg"/></item><item><title>Leaked n8n API Tokens Exposed Live Instances to Credential Theft</title><description><![CDATA[GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive data and downstream credentials without exploiting a software vulnerability.

We scanned public GitHub commits for exposed n8n API tokens and identified 4,576 unique credentials associated with 1,255 hostnames. Of the 896]]></description><link>https://thehackernews.com/2026/08/leaked-n8n-api-tokens-exposed-live.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/leaked-n8n-api-tokens-exposed-live.html</guid><pubDate>Wed, 05 Aug 2026 16:05:29 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhx1pOdsqya8FoeUfRoysn2429wQSGELUYOuuaDRT5-pJMERQc7DY042ndusTV0UriGHrR98oyPe_HnR845R1hxSxKBTvYGTilYobQhIIXOCEc08FiKbhDluP0UoR6g3sw8QK-X1aPEJDKe-EZbDNOtlXR6ltGBvxsqfB_bo-jO4t63OvT7_C1mD7Bf4rM/s1600/n8n-git.gif"/></item><item><title>Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data</title><description><![CDATA[A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed.

The "evil twin" extensions were uploaded to the repository between July 26 and August 1, 2026, according to Manifold Security. The packages have been removed from Open VSX as of]]></description><link>https://thehackernews.com/2026/08/open-vsx-removes-77-malicious-evil-twin.html</link><guid isPermaLink="false">https://thehackernews.com/2026/08/open-vsx-removes-77-malicious-evil-twin.html</guid><pubDate>Wed, 05 Aug 2026 14:53:03 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh28AJU8_kuimN9uKY5xj-0XMAMxfVP4rejHEWMJ_5FD99mAvt8dEsRuGhlCGb63VjWykzePg_-tuaTqNycmvhZy3oFRFAuVHbwpsAg6ae599Pl7bYQVb7Qo7fDuDjWMHmHZOLfWc9HZkQlyAis8LNMmkS_wnKbvliVNsOej4p6XV_KbiFHHzJp1SjGFU1G/s1600/vscode.jpg"/></item></channel></rss>