<?xml version="1.0" encoding="UTF-8" standalone="no"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:media="http://search.yahoo.com/mrss/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" version="2.0"><channel><title>The Hacker News</title><link>https://thehackernews.com</link><description>Most trusted, widely-read independent cybersecurity news source for everyone; supported by hackers and IT professionals — Send TIPs to admin@thehackernews.com</description><language>en-us</language><lastBuildDate>Tue, 08 Sep 2026 19:46:39 +0530</lastBuildDate><sy:updatePeriod>hourly</sy:updatePeriod><sy:updateFrequency>1</sy:updateFrequency><atom:link href="https://feeds.feedburner.com/TheHackersNews" rel="self" type="application/rss+xml"/><item><title>Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC</title><description><![CDATA[Whoever took nearly 4,000 bitcoin from the Liquid Network on Sunday, September 6,&nbsp;returned 3,400 of it&nbsp;the next day, Bitcoin's public record shows. About 598.5 bitcoin has not come back.

Liquid is a Bitcoin sidechain that holds real bitcoin to back a token called L-BTC. The network is still paused, so holders cannot turn that token back into bitcoin.

The 3,400 bitcoin was sent to a&]]></description><link>https://thehackernews.com/2026/09/liquid-hackers-return-3400-bitcoin.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/liquid-hackers-return-3400-bitcoin.html</guid><pubDate>Tue, 08 Sep 2026 20:24:30 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhwlEWa8ED8DuOxP9Vi4gKvvtQeWC12LKU4yrjFMJYIczxkqLbjqcHpBHMu4hOHp7zjSLNzbQW8SXMR-3YS0PNgVlVEe-ZgYFfaOPdFYkduxEMls-mRWHx85_WNm8Xli0sGVifFjz4mZ1YjEzHs1DNHFZzzY16ZBZxvi77GmI-mtE3_xiilQo7pfRM_0g8M/s1600/liquid.jpg"/></item><item><title>ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account</title><description><![CDATA[Check Point Research said in a&nbsp;report published today&nbsp;that a single instruction planted in a ChatGPT conversation could cause ChatGPT to quietly work for an attacker while answering the user's question as usual.

In the company's proof of concept, that hidden work read data from the user's connected Gmail account and passed it to a second ChatGPT account through a hidden channel]]></description><link>https://thehackernews.com/2026/09/chatgpt-flaw-let-planted-prompt-send.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/chatgpt-flaw-let-planted-prompt-send.html</guid><pubDate>Tue, 08 Sep 2026 19:49:17 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi0jB-6O69dYNeqBTcSFXPcSQCqwabmHwmdGzC_ne5LyuUH-9v0MpLbJ1cgApFSqTuGG0Z_fKAD4A7gLcBcTdw6oUIv0nh_Pmyb5Obv7XhRY0jVGwPQ50S7rUnYZR8FUvYntVxL03GYJ010-iagkPkeZJ8oV6gvbEaVJPGw-L2rabD5pqOOu2HYW9g_nFcT/s1600/chatgpt-gmail.jpg"/></item><item><title>Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours</title><description><![CDATA[Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours.

Google Threat Intelligence Group (GTIG) said it has observed attackers with diverse motivations targeting proprietary AI]]></description><link>https://thehackernews.com/2026/09/autonomous-ai-agents-compromise.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/autonomous-ai-agents-compromise.html</guid><pubDate>Tue, 08 Sep 2026 19:18:16 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgdVKt_UmqEYNHNt0K516skza4MoV47hITqzcoC3WLLI3QkQ_jUEffHvaL7VHVtzRqvdt6k2bZwGAFVif-hRkoiTQva6JM95w3NgNRU_WpuTaZfhLGXAcOdLQXy_sMWU1dxAunMAsf7J8PEDG2AKvkFuXbOFyOmIQcaocMIBhNpaYscCUeJElKDXu6xGhkX/s1600/ai-agent.jpg"/></item><item><title>WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls</title><description><![CDATA[Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and&nbsp;demonstrated it spreading&nbsp;among three test phones.

The person being called does not have to answer or touch their phone for it to work, but the caller must already be one of their WeChat contacts. Calif reported the flaw to Tencent in July and says the company has since]]></description><link>https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over.html</guid><pubDate>Tue, 08 Sep 2026 17:24:29 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiMjSG5iYgxvsWLWeFe2E-z5UDx0S4Q6zBQjkFEiKuFxcfplz39pE90jWcuiV7NcYqT6t2l8j5WWVBHdV-upHuzQVoy-pt4nL4WP7l-Uz_9AYFqOw1Pn0yI8LzM6OThlXJZY8_b4RVK0WzZYIsjWL96-2O-HHY1SH2FCtrE5c6nV0QJ0aU1X8FVlIvOs3g/s1600/wechat.jpg"/></item><item><title>What It Took to Reach 1 Billion Build Manifests</title><description><![CDATA[In the last six months, Chainguard doubled its output from 500 million to more than 1 billion container build manifests. We also surpassed 3,000 unique container images and 675,000 image versions in our catalog. Those are the headline numbers, but I want to share what's actually behind them. The number itself is less interesting than the system that produced it, and why we had to fundamentally]]></description><link>https://thehackernews.com/2026/09/what-it-took-to-reach-1-billion-build.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/what-it-took-to-reach-1-billion-build.html</guid><pubDate>Tue, 08 Sep 2026 17:19:02 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiqJEqJ_CCrFzLtmEtLrrIWQv80hyY6xtGfdsad0NgYCYSs-ur2ObfnMgE8uBWlZ7idJHbjDcOwpo8_ESTMpCAWAUHUwbqhVr-zqxV-oxUWmR3PMwBD_vrDziQFaeL0VTzX8NUQRFGRzVQCuTPrvflnepbKlCgqH84MRNTJUhZRNfqwEtmBUxhIB5a8MfeE/s1600/chainguard.jpg"/></item><item><title>FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials</title><description><![CDATA[A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says.

FreeIPA is the system that determines who may log in across a Linux domain and maintains all identities in a 389 Directory Server database accessed via LDAP. The attack needs a second flaw in that database software.

The]]></description><link>https://thehackernews.com/2026/09/freeipa-flaw-chain-lets-anonymous.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/freeipa-flaw-chain-lets-anonymous.html</guid><pubDate>Tue, 08 Sep 2026 16:52:07 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSKAVaHcAsULrGXPVkGXRyf94eoG7Kv3X0wwK2lRC64l3Em-S4_H5iE8-poK04yzrAC18tuHqpZyHhJvFTgliu_z8jo4QR78Mi4ghhCA-cUVL4oj2zjoLGiWKmD16oV4i44VfY45DYll0Uij_Exf4U2JMSLJEyH8jZk_xXKq7O_7D73q7vTYCCc4hrTnQ/s1600/freeipa.jpg"/></item><item><title>Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell</title><description><![CDATA[Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild.

The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026.

"This update resolves a critical]]></description><link>https://thehackernews.com/2026/09/adobe-patches-magento-zero-day.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/adobe-patches-magento-zero-day.html</guid><pubDate>Tue, 08 Sep 2026 14:43:47 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg_xdakttovno7kFgFYIw5XGFGcSZibVvXYB64vih4iZpc4_WY_t7oe1X3igSPGXBa8UTkf4z4xn_GzZ_n7PmuFFvYC8Wsmb04PxYP5z-XHjZZFe_SASihwZNg1dxHXQzz8hBRo-6LhvQmwyo_MA9Kj6hrcci6ouvOX1D4f-0dNvs57M6WneQHC61yZkF_o/s1600/magento.jpg"/></item><item><title>BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams</title><description><![CDATA[Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams.

The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO. It has operated out of the Indian state of Rajasthan since at least 2015, driven by two IT service providers named WeConnect]]></description><link>https://thehackernews.com/2026/09/bengalseo-poisons-bing-search-results.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/bengalseo-poisons-bing-search-results.html</guid><pubDate>Tue, 08 Sep 2026 14:13:51 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj_rKrsCwJpZOS1Cu2htzFszKn4OgjK2p5A43OUaQJsmlbjsaLfGHtgyqQPfOu3IFWqRBoj2J6hIiqv6CVr56ZLyyf73-E71iaDRB2nrO9qaGOg92EbOcutMu8M8i1uimwkC-GPcc9oGDgFNNLB4kkgfDB3MbcjPuAn_gsml3FyThlEyI3Pg8E-udYq175m/s1600/bing.jpg"/></item><item><title>Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing</title><description><![CDATA[Online dating app Grindr has opted to pay £26 million ($35.1 million) to settle a lawsuit in the U.K. over allegations that it shared users' personal information, including their HIV status, with third-parties.

Grindr, which is the largest LGBTQ+ dating app, was sued in April 2024, accusing it of violating U.K. privacy laws by sharing sensitive data for commercial purposes such as advertising.]]></description><link>https://thehackernews.com/2026/09/grindr-to-pay-26-million-to-settle-uk.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/grindr-to-pay-26-million-to-settle-uk.html</guid><pubDate>Tue, 08 Sep 2026 12:30:43 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjGUJMPbCbes7NM-EpNPWOUc7bYX5pznAZZjAl29ELdnhrIFzOBqkVtUsiDgxWvImd-yqpnCi5E4EaA1SCbnqY-_1qOwv2RnBTrjOHwn738A5TVUyZV6uX9TQyjF2EmPsJhyxHc1IcqV0jH3JraUU5s3Yw64WOCoE4WawhfajZhq7X-XvWQtVfw-S2QxbkU/s1600/grindr.jpg"/></item><item><title>PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution</title><description><![CDATA[Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser.

"Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium's own Secure Preferences]]></description><link>https://thehackernews.com/2026/09/peep-turns-chrome-and-edge-into-post.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/peep-turns-chrome-and-edge-into-post.html</guid><pubDate>Mon, 07 Sep 2026 23:42:09 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhA3-5bNylOMc_s8MAT2ibQnV33cnJXadwKPRXjYgAL0GcZWOXuwtM-s5HS4ryVu5ewnhfAqBtOiuSseLcUSyDIfxf5XKF6mAwrpyG-v3Y-siqjJY8I5zVEMXwfkKPwBNAqaO2sQFI-q2oA4MWiagZFUlknIPKADDfvOo8s2Ifsa_xBAojg1rD5ZGUErC85/s1600/chrome-malware.jpg"/></item><item><title>Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks</title><description><![CDATA[Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins.

The activity, which mainly singles out directors, vice presidents, and other executive staff]]></description><link>https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html</guid><pubDate>Mon, 07 Sep 2026 21:21:56 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjg-Zo4zgxCrVcz6-00WV2qAPHSD-av2Ed5hgRmR-2vUzkr9jVeph0NNb6gGsQfwSkFyuRfRcSsaISSpfysl_Xx5F48IM7HdBpO4F3CaVuLhk1v0a4vcH5xK_bxX6BxIjkfAjhDaNGcLG7_R9IcTjVGlFcW7y1ZV64imACHi9528LOjH1Flhk-cy9LFgrMv/s1600/phish-ms.jpg"/></item><item><title>⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More</title><description><![CDATA[Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on.

Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management]]></description><link>https://thehackernews.com/2026/09/weekly-recap-chrome-0-day-router.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/weekly-recap-chrome-0-day-router.html</guid><pubDate>Mon, 07 Sep 2026 20:06:07 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg3SJbgfzjY0QMdutDU1Lf8A1ZVh6S-hcQEwATiHIXXKIpYhh1mrojhkxootev2lhFxjehrTS8h3UNmZgHBwgxNUN0ho2r5Tzk2PRLqK_yO-4OetzmlaFE5V5z0G-Yp34y_RWR5ZlWoL51LWMOFh8YTZCKDADDnHFLhYZl5oQkqLFxJ9JHK1j35kxilIkyp/s1600/recaps.jpg"/></item><item><title>Your Cloud Security Checklist Doesn't Work the Way You Think It Does</title><description><![CDATA[If managing security across multiple cloud providers wasn't hard enough, each one fails in a different way. For the 2026 Cloud Security Index, Intruder analyzed misconfiguration data from 3,000 organizations across AWS, Azure, and Google Cloud and found that risk profiles across providers have almost nothing in common. Here’s what the data looks like.

How risk differs across cloud providers]]></description><link>https://thehackernews.com/2026/09/your-cloud-security-checklist-doesnt.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/your-cloud-security-checklist-doesnt.html</guid><pubDate>Mon, 07 Sep 2026 17:15:00 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhAkHa8CDEfDzL0HknvyLE5eRK8r91iyhgzpCS1GmG3HRtriZYYFzCTP9_H433YsqJ80SAppgs9g6rOhsTWIzHPh_CFcZJS18DIj5ANgzFwSU0vfcyJofTEqEvjGGjNcqZdHU_54PENNzxawWHCZ2r_1K-A63x3P8CbuIiu8OHASjQV3OoglWTefAF2dZw/s1600/intruder.jpg"/></item><item><title>Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts</title><description><![CDATA[Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems.

According to Huntress, three unrelated incidents have been found to use diverse initial access methods, namely a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake]]></description><link>https://thehackernews.com/2026/09/rogue-screenconnect-clients-spread-four.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/rogue-screenconnect-clients-spread-four.html</guid><pubDate>Mon, 07 Sep 2026 17:06:39 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiWA_nxvqJuKkqq0ab1I-XR1YtpsM6BadhHDNOIheZmBflLWaQ018JFJsAUBVuyWWTYI4pyT8OQNXhui8Annde3SnOIScH9B0ohMq-OzXLjvPeAXQnz4mAUdEMS_07i7gLaWqPVpHaPvyLJdZQKUTs2MLGhjB9UZ0A83CGcSeDCJFKn7hNjiyf6dbzbHogp/s1600/screen.jpg"/></item><item><title>Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released</title><description><![CDATA[A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no confirmed reports of exploitation in the wild.

Security firm TantoSec has published a working exploit chain targeting vulnerabilities]]></description><link>https://thehackernews.com/2026/09/telerik-ui-padding-oracle-bug-chained.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/telerik-ui-padding-oracle-bug-chained.html</guid><pubDate>Mon, 07 Sep 2026 16:50:14 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiOwlnNFKd-mH5uyY-AjtXSVx57m9MDT4WRtoQStPY9HoNxOP3ps7znRzENJAK7ZzF4homlCzVGVPFuFZ1sXYGciKyA3rZN_NYewwTXhwpRxCUFaPmUmdgP_TdJQtf57falTD12A0GJewAS23pnxttANQ1meOeRFnr_IqZqAngg0rc9ov998VwQlANB0cE/s1600/tel.jpg"/></item><item><title>N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw</title><description><![CDATA[Every on-premises N-central build below 2026.3.1.14 — including servers updated to Hotfix 3 a day earlier — needs Hotfix 4. N-able's incident notice says the flaw has been exploited in the wild; its release notes say that is unconfirmed.

N-able has released its&nbsp;fourth hotfix&nbsp;in five weeks for the N-central remote monitoring and management (RMM) platform, this time for a]]></description><link>https://thehackernews.com/2026/09/n-able-issues-fourth-n-central-hotfix.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/n-able-issues-fourth-n-central-hotfix.html</guid><pubDate>Mon, 07 Sep 2026 14:01:12 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgOtysh_bb-hej1pQzey0RUhPD2w29ONlPDQMzE9Nc4lM529hKaHhuLKfGXEnqVZyUkMKhJchEeoN1clSKo3-opm2_BQkN6FJ72xBZOZwxX6sTwU4Zzk_j6taOwBpioZOnolR9idUjpydUlQ84TQ9pdWUlUm61JH0Xh8-6_0fo3VieeW3xVQwk4UvXcSu4/s1600/nable.jpg"/></item><item><title>JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies</title><description><![CDATA[Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities.

"The payloads are protected with javascript-obfuscator, using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers," Check Point Research said in a]]></description><link>https://thehackernews.com/2026/09/jsceal-malware-can-bypass-google.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/jsceal-malware-can-bypass-google.html</guid><pubDate>Mon, 07 Sep 2026 13:23:04 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEilF0_vQTn1mpUhivH8aX0vt8SA_Y5wkJqpHriuAdDQKVuWON7ZSzOAbWlwm50oxWlOJ5wMdzBjzy1wRVGNL6IqY8eYFUlIyayK6aiwcXK1fTO9JWZ9hG_QYrNnY_fdm2Lu7Z87p0JOR4WkYD2HNK-6WlcJQgxmUsG1k8k3ye5AT1ggaoiIDAm0kHxYQJ6V/s1600/chrome-cookies.jpg"/></item><item><title>Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication</title><description><![CDATA[Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication, according to&nbsp;CERT Polska's attack warning, published on September 5.

Successful attacks date to at least September 2. The Hacker News’s September 6 review of the warning found no victim count or]]></description><link>https://thehackernews.com/2026/09/attackers-hijack-mikrotik-routers.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/attackers-hijack-mikrotik-routers.html</guid><pubDate>Sun, 06 Sep 2026 15:02:38 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjiSiBDO5j21gorWS-UjrLlDl0RzniibBPjfO4xfPBBLbH1yTQIB88G-hUBRtYNufYwkPpVjWWLu0GXk1TB7pv_x8KbQCbfsL5Ft8JlZLa6iZfvuHU-vKSPNq5Li-e9DtoOvZIOXPYmibx9uc_imnug4ZJUog31KwlA3YKmY8ghOpROVQR8mwPj9qb-1kA/s1600/micro.jpg"/></item><item><title>Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner</title><description><![CDATA[Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself.

One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner.

The company named the four programs ProManager, WinUpdate, SoftManager, and]]></description><link>https://thehackernews.com/2026/09/four-revstealer-linked-modules-disable.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/four-revstealer-linked-modules-disable.html</guid><pubDate>Sun, 06 Sep 2026 14:04:20 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhpRcdfXd6kYnqLLWSFdzGKICUzSr90MsV2f3PXtw8VDVcT-xOP2w4HwnVzrRI4bdJqhboQMFIm9BZ393b89IOqgYx-VVmb_B8-XJCsZ9SAIymdlBpEf5ARizHvn32t8Mr9stzV6nMVcn3utUYI1xSRxhaC29QZjS-C3haNSRPfQI_eBYzXCrwn5rl18Nw/s1600/rev.jpg"/></item><item><title>Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores</title><description><![CDATA[Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an&nbsp;advisory published on September 5.

Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is]]></description><link>https://thehackernews.com/2026/09/unpatched-magento-and-adobe-commerce.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/unpatched-magento-and-adobe-commerce.html</guid><pubDate>Sun, 06 Sep 2026 01:44:47 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjghsT_skiIfdOHK2B0WWDfWnSK0G5Ih7BqsX98tKrY4TH7I77oLEmnldtVHuUMEQaIiZZBSPJGI2t8Me7h9kDtE4YGZ9-5NypnAu2-yFFrXsWYkR6OJPlbqkZDEHBAXCmRjWm6Mk4h0Ni48JT0nrDWMYygztjoi4HuHPbe2y-2jreFVkzrxO8r4IhHIEU/s1600/adobe-exploit.jpg"/></item><item><title>Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials</title><description><![CDATA[JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment.

"Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.]]></description><link>https://thehackernews.com/2026/09/attackers-breached-jetbrains-cadence.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/attackers-breached-jetbrains-cadence.html</guid><pubDate>Sat, 05 Sep 2026 22:22:33 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjH4sbUEhtXF9n1_8s2f6ChnKMmjUv4Ht-DvEtZyLDPuSNhKFoi41aNlu3-u5kJLXUva81rNFwlsprMXE11cnbXc_es968eO-ANvWm0j1Cyi9SaoVUfneQqNINCR7lRs3qkkYdsSoyMu34Mgxs7B4pKclAt4atPw8B-RCFOTChtgeji9NTes_NEdZ2KKu2_/s1600/jet.jpg"/></item><item><title>Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code</title><description><![CDATA[Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions.

The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code.

"A]]></description><link>https://thehackernews.com/2026/09/critical-vmware-workstation-and-fusion.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/critical-vmware-workstation-and-fusion.html</guid><pubDate>Sat, 05 Sep 2026 21:35:08 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhzExwAd4Vsd2Xz-9kex6ucfK6MDmftPVCfiOGQICWDKrgxMJ6fOj0EttLP2kpYBDv4xSYdrEXt8Wntz916Oa2tyrMnaSHDLH9vb5RF4ncjvwdkeFU8GwaqWvT6zLHRTKIF-BOGK8p24Im4NwqlqZxTokMsYOfXSBdA0-jXxMbMozfjdK-iyyavdAywjAAh/s1600/vmware-host.jpg"/></item><item><title>Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted</title><description><![CDATA[Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk.

The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets]]></description><link>https://thehackernews.com/2026/09/trezor-says-shipmonk-breach-exposed.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/trezor-says-shipmonk-breach-exposed.html</guid><pubDate>Sat, 05 Sep 2026 19:47:02 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhIuPjOUFz-c7o9qipnKr4soYR6NxJJxAYgcDqwTPl3LB5XXiag7UpIq8-qFzCbiC1cnlpWfyaRvAt9MVxIlSXeuEN_97devL_mSI25Ee73cO47vDq4dqsM8Nq08d7FogI7sVIPWlnMTD-Una_rRwyTyXqKG6am2DrU_EoIESLicWgDvpxsw6e8yAHmJnGI/s1600/trezor.jpg"/></item><item><title>Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel</title><description><![CDATA[A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox.

The activity was concentrated on DSEwiki, a German software developer wiki that runs]]></description><link>https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html</guid><pubDate>Sat, 05 Sep 2026 13:25:10 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjBL2gQMKgajDATkCjnHyMtUkVhK5mcTQ2ebqcXngB6oZ71uiJ3skI9P4zikK1s5PCH4nhPG7ZyFHHWC13OVF2KRr_pIQ2U7zFITnNc3Qc_Am3bv0E1AzL9UVmrJ9vUJzZalktYIxWGlc-d5zYdicOJexMDWQ-4NIKinC_AksG1Mepn7QmFGWC1x52gVpw/s1600/agents-openai.jpg"/></item><item><title>Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities</title><description><![CDATA[Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe.

The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as]]></description><link>https://thehackernews.com/2026/09/attackers-exploit-papercut-flaws-to.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/attackers-exploit-papercut-flaws-to.html</guid><pubDate>Sat, 05 Sep 2026 13:01:53 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEguiDwimIl7rewJeRtSYeCkmhBUPSN0lsURwcKXrBtQ4vANRZqEkbjcPBIjODR0kFgIbLqwLiaBcB6lX8M6rilVclrxZcsKogB3NNhnwqJz3dZwgWGZ-6NHnAEGM-ENsEebYhn81lWBN0-nqfYrMLlHoQ3ebfHB7V74NpbKpOZZ84WZYyli7w1lDKJrCtds/s1600/papercut-hacks.jpg"/></item><item><title>Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters</title><description><![CDATA[Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters.

"Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as 'funding' to prevent email filters from parsing them," the Microsoft Security Research team said.

The]]></description><link>https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html</guid><pubDate>Fri, 04 Sep 2026 21:27:15 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjoD4eMYuhLT8HvcHbYe8A4hkhmDH1f4pIWTIm5AXKueqdpY1NS8yNiTtlzS4mdIS8PLY8_zM1uQDNpO1U49HCUoJT8nn2Bpb6krpcYpOSQ3H3Z6fUsm-UkoFvj8fk8oShK0eUhO6px8hox_ZzlnX8tu0pJKpJ3UAF2Vcb3XyBXjCt_8uD8OOkMMgUjv8Pc/s1600/emails.jpg"/></item><item><title>PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution</title><description><![CDATA[PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server.

The flaw, tracked as CVE-2026-6471 (CVSS score: 7.2), has been present since logical decoding was introduced in PostgreSQL 9.4 in 2014. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are]]></description><link>https://thehackernews.com/2026/09/postgresql-fixes-12-year-old-logical.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/postgresql-fixes-12-year-old-logical.html</guid><pubDate>Fri, 04 Sep 2026 20:50:19 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh2Gb4Wd-HSxdrPbdtUFxmldzzEkPEZcW1NkT7tV9-EfTAjDENSExJBWmOey_IJ5UKjszQfCNGkVoBtuxya00rFMrh_lJUAuS66Gr3kvU8GgFjMr7DF-7Ux1rUqwz-aDhum8HkVjxNKQTc6DXHG203CPXwg9sOMcA7nfsq6A81C9cJhb3HUu9GZDIj7FZY/s1600/PostgreSQL.jpg"/></item><item><title>New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic</title><description><![CDATA[A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors.

The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host and]]></description><link>https://thehackernews.com/2026/09/new-ted-backdoor-hides-inside-victims.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/new-ted-backdoor-hides-inside-victims.html</guid><pubDate>Fri, 04 Sep 2026 20:21:13 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgzLyhHupZwRy1pOQzT93Qhs5waZ8gqtlgDJUKgt1f37dz3KqIDDZY8uNo8QguZNccBHivdA_ecnY8cQUyhZQAvLH4APu3imxP-rwo2dYLZtKnJ92IkRPFmwepmJgRk9GrLrJiN_IbInwvNXaW7N5761YfEB1IIK4uDdNBTy6Koz8uXgOSXaQWixXM1Wts/s1600/HAProxy.jpg"/></item><item><title>Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws</title><description><![CDATA[Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence.

The vulnerabilities in question are -


  CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag &amp; Drop Form Builder that allows unauthenticated attackers to upload files of any type, including]]></description><link>https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html</guid><pubDate>Fri, 04 Sep 2026 14:18:45 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj9jQ8JSakEpnqxzsAZhwXnVvTMB0Lrbj7shOcXtSJzA30wcMTbkAIUGvSZPiBXOLeAW66Jpuysxn56W8YWD00hsCNB742oLqeyvgD8MXdIHHqwyeehyoyXx9G9c6XjxwN10Co_XVZuBkRjMquzgf9V17gh2Gw-xff0qJ9rh3sPO4tBq4OjjS0dxsl73WKT/s1600/wp-main.jpg"/></item><item><title>Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws</title><description><![CDATA[Plex is urging users to update their instances to the latest version following the release of an update that patches multiple security flaws.

The fixes are available in Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The streaming media service did not elaborate on what those issues are, but said CVE identifiers have been requested for them.

"We recommend all server owners and Desktop users]]></description><link>https://thehackernews.com/2026/09/plex-urges-immediate-updates-after.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/plex-urges-immediate-updates-after.html</guid><pubDate>Fri, 04 Sep 2026 13:05:14 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg7RQQCR9QxY1NZ80GCfpUjvGGcw9QDirshH7KrSyc097EIaNqLLVGgnnlOE095qTOt2q9CTu91gJ_Pf7Y9-AcZahb35e7XG2YrA8D4O0FPwVRSzBzMT5ecKzu0bnAxP603K5q8R_7IZrE-iSAAJQsmMWXBt8IPwHIIz3u6Kf-okZyo0G1fLoe9VOzZEEQF/s1600/plex.jpg"/></item><item><title>Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day</title><description><![CDATA[Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild.

The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine.

"Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote]]></description><link>https://thehackernews.com/2026/09/google-releases-chrome-update-to-patch.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/google-releases-chrome-update-to-patch.html</guid><pubDate>Fri, 04 Sep 2026 12:48:47 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjelmC2UuYemuI1nBeaecfPBZ1Bfb5nz6T51_OhCUPHJivX8ioIjrYMVtVsjsrcA0xbEe_O4iMthJ2xwXWJVhAb5CCJlhnJS4McM9IpmPww86RSznT3h7pg5DYOXlnwon616y-1s2qwbWbmR40B5JCvYbtwM8lD5Fk5yLHWS7IKmH5pXQ8qO4SfEasBhhsq/s1600/chrome-v8-exploit.jpg"/></item><item><title>GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests</title><description><![CDATA[OpenAI on Thursday officially unveiled GPT‑6 Astra, which it described as the "world's most intelligent and aligned model."

The development comes days after the artificial intelligence (AI) company said the model had reached the "Critical" cybersecurity capability threshold under its Preparedness Framework.

"Astra is state-of-the-art on computer use, browsing, software engineering,]]></description><link>https://thehackernews.com/2026/09/gpt-6-astra-scores-100-on-exploitbench.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/gpt-6-astra-scores-100-on-exploitbench.html</guid><pubDate>Fri, 04 Sep 2026 12:17:52 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhbaZmLqqSMfwaOmjs47_PEd97T29HeDX_1dAOZn0Qzo0HuloopzzhZ7pnQzlsHvXvIAwzMWq1tbza325niZMSgjTMn0z5MyT-CWb7NfoprOWz2L_cj6tosVDyyp2ZbV4s59p-khE64lXWULLOW8zVMCv720iwDwCYUEuAHYkV8m2diDsyzFKwvNifzq-oT/s1600/gpt6.jpg"/></item><item><title>ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories</title><description><![CDATA[The worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click “Allow.” Why break in when someone might open the door?

That idea runs through this edition. Attackers use real tools, fake login pages, old account links, and software guides that point to unsafe downloads. One wrong letter in a web address can be enough.

There is also]]></description><link>https://thehackernews.com/2026/09/threatsday-ceo-phishing-kits-5k-dropbox.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/threatsday-ceo-phishing-kits-5k-dropbox.html</guid><pubDate>Thu, 03 Sep 2026 23:32:47 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhUcEnh-e0_L2Oz7JQcSCFBd90F29Z7_wHbJYiWOxWeZTeLLHbRZYK6vt1PrcUOgSFei7fxLMnP2lp0QyEOW2rzfcsnBFhayNHtKLPtHJFsu55w_GxuA3XLkZf-kleynMxXjc8zELZt7FBZFdqCAtesj3Fj148fwlGitAxZxu6t1wZDb7wgZQ1MR-Vmc4FL/s1600/threats-main.jpg"/></item><item><title>Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root</title><description><![CDATA[Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version.

The Nexus vulnerability, tracked as CVE-2026-20212 (CVSS score: 9.8), is]]></description><link>https://thehackernews.com/2026/09/critical-cisco-nexus-9000-flaw-lets.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/critical-cisco-nexus-9000-flaw-lets.html</guid><pubDate>Thu, 03 Sep 2026 21:22:07 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgj9su2Wd6Yb88IvMpg5v1P8IyPg4KWKTeBXjerFgxz0U5WLKO2U50jymR-fKujsKeMFZ3q1VEupMRFZUz5gD47JRzVceagYJJ3bCTT8t532rY63po54kanBCPX4_hmKsxe-1b52IGrYc__TH5Y2F13G6L32HNKPQxL34iqzEPuBGynDCu6xFdKHplXvdY/s1600/cisco-flaws.jpg"/></item><item><title>BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory</title><description><![CDATA[Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts.

"Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial]]></description><link>https://thehackernews.com/2026/09/brazetsu-malware-turns-compromised.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/brazetsu-malware-turns-compromised.html</guid><pubDate>Thu, 03 Sep 2026 20:56:47 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh9vYkFCrVzaEl0WQj4XBILj6pIxDJ92eWgVrkOa_pdvJJoKF95JCX7VmQzY0HPZkhg5IMvjfCu15YCs5AMJ22NM6SBX7j7sCgpfiaUZZAL4Uc5vP0-q9VKN4LNSY4a701mmRCgLJQxCjnmnsSAxD7gFnyf9-dRaSxPZuGqLuOIQ415vCOjH-DZRtYSBHA/s1600/access-for-sale.jpg"/></item><item><title>Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data</title><description><![CDATA[Thomson Reuters disclosed on Wednesday that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit, in March 2026, affecting courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada.

West Publishing said it discovered the activity on June 30, 2026. A subset of court records could contain individuals' names]]></description><link>https://thehackernews.com/2026/09/thomson-reuters-court-software-breach.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/thomson-reuters-court-software-breach.html</guid><pubDate>Thu, 03 Sep 2026 20:09:05 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiX1nx19KbhbT0_rYFjMzqgJuG35q7QvJiMrikolTZV9sWztkSoSFUr95E-h-9vHv-GBGmRHAyh5Du0DDMYMr1m0VbD5YgYO6dVoY7p8d6Z5BbORiBOGgJfZjg4euf9uwUkGO4ZX8QZXUpuU0CFUwNV46UozcdMJ9SyZ4T4cy4pAI9ho7xYQ8cDJaFdfKM/s1600/reuters.jpg"/></item><item><title>US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries</title><description><![CDATA[An RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be part of a broader campaign spanning 46 countries.

Around 45% of observed activity was associated with the United States, making it the campaign's top geographic target. ANY.RUN research connected 601 cases to the wider operation, which uses]]></description><link>https://thehackernews.com/2026/09/us-becomes-top-target-in-rmm-phishing.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/us-becomes-top-target-in-rmm-phishing.html</guid><pubDate>Thu, 03 Sep 2026 17:28:00 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg_OZ4yHwsQM1Z9se2g-uJPuSkiSNpmyWCCi_a9dKpH9jnTuFYyts16e2gdkB45YknrA-nuzp6-mbEi-1adV92N-7aBjfYL69ECPlWOV7a5xb5rG6kqsMzc3WJ0-lXLBMO86aB3WTJ6MFLR0N0YbC8TElIg0-Jh6SIDe8mc3nCyzoE6zugVDFHFfjPEGkI/s1600/targets.jpg"/></item><item><title>Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks</title><description><![CDATA[Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads.

According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government departments, technology companies, and hotels since February 2026.

"The technique's appeal is that node.exe (the]]></description><link>https://thehackernews.com/2026/09/attackers-turn-trusted-nodejs-runtime.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/attackers-turn-trusted-nodejs-runtime.html</guid><pubDate>Thu, 03 Sep 2026 16:13:01 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEixQdi-o7wSstsDvvGluX8EDCUhGUHwpKjSkMSaigZZkFOEI_mWS0kLYvjSaG9olG2Y8GYxqH2kKRUtT82RVMLfW-FuBdrWMbGSfJMVVK3YAL3FClWT6t0Dz33NzHEYK1dL93JLl7YzyETY1i9ZYpRty-BG5Vfk_vGUggKigBtpQZxKuUW8-Jg3m9xZV8BL/s1600/jsnode.jpg"/></item><item><title>Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means</title><description><![CDATA[In early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for credentials across 469 locations across developer environments, Continuous Integration/Continuous Deployment (CI/CD) tooling, cloud configurations, and even AI tool configs.

Earlier variants of the infostealer worm only checked 189 paths. The jump says a lot. Attackers have]]></description><link>https://thehackernews.com/2026/09/shai-huluds-reach-just-grew-to-469.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/shai-huluds-reach-just-grew-to-469.html</guid><pubDate>Thu, 03 Sep 2026 16:06:39 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjfx0JCqLgANXGkgF5NMg__RxJg5IJ8HgQcvr_2zxEM6HSYzesKdLjKbrqmtAegyIpBmLxnryF5CeJlRh4J09q3e1kOo8dEzGXjhQpunnmGoL6wzEW_6R7lsN4zE5IybADP50VCjGGrBercYm6OIMCYsSgbHJ6sN9AYY3v6kCqPof8TWzR2O_ybViE1aYo/s1600/Shai-Hulud.gif"/></item><item><title>Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone</title><description><![CDATA[The iPhone belonging to a member of Serbia's student protest movement was infected with NSO Group's Pegasus spyware, according to new findings from the Citizen Lab in collaboration with the SHARE Foundation.

"Our analysis confirmed that an iMessage zero-click exploit was used to infect the device with NSO Group's Pegasus spyware," the Citizen Lab said. "We found high-confidence indicators of]]></description><link>https://thehackernews.com/2026/09/pegasus-zero-click-spyware-exploit.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/pegasus-zero-click-spyware-exploit.html</guid><pubDate>Thu, 03 Sep 2026 14:13:17 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjaEvtAyNP-TiY3M6wMUFNKymiK_BeQH_MEIzeFf79X0fNFV0gyV3MiegzULqTG6bC-20nprEpTHySkf3Hf0N72sLy-oVN6_ndqU4OwSm37Cx0OYrr2MbzpiII3ly4tEv891mjYhbSV18Eg94BBSitXG8XnON3QjpRqGkErk15L1FoeYT94R8WGlK8xUuJt/s1600/iphone-exploit.jpg"/></item><item><title>Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon</title><description><![CDATA[The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a proof-of-concept (PoC) for a privilege escalation flaw impacting Crowdstrike Falcon.

"FalconFlank is a 0-day privilege escalation that abuses the office malicious macros remediation in CrowdStrike Falcon Sensor," the researcher said in]]></description><link>https://thehackernews.com/2026/09/researcher-releases-falconflank-poc.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/researcher-releases-falconflank-poc.html</guid><pubDate>Thu, 03 Sep 2026 11:56:59 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjmg6caSDWQVOPIIl9NAXS4ofXmOdWz1eIGPMKMLCbHXc_uWiv11QNh2k-f43JAoVVQNMQj54d2yqJ_iO9vzwIO8nvQIyxr7N6GDCKsYDmSJEpyjiUBsY-zhMcmfEsWcEqDrKvrEkXxQC1LPldFXkqbJHO81V7oHnsRtuyjMZKzubBjwrK_yQ2xT2om89Ja/s1600/windows-exploit.jpg"/></item><item><title>CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners</title><description><![CDATA[The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers' crosshairs.

The vulnerabilities are as follows -


  CVE-2026-83548 (CVSS score: 10.0) - A server-side request forgery vulnerability in SonicWall SMA 1000 Appliances that could allow a remote unauthenticated]]></description><link>https://thehackernews.com/2026/09/cisa-adds-seven-exploited-flaws-as.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/cisa-adds-seven-exploited-flaws-as.html</guid><pubDate>Thu, 03 Sep 2026 10:49:04 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhaGEC2JQn3dU5muXzZhp9ouduHJ5hE4vWW4zHDomXp7hJ3hHafGPmMU33aKs7A8dwhvqsMiwh8PNi4GUNzH635enPZT3oPdcZejqkA9vpPYbQTLZaAhzAVAuUFksC4mCNX6SRUzUx1vhSxokKBz9RBGXXOBJshSXfYLIox2OCi2htQdcmyDJDMvWTamC8/s1600/cisa.jpg"/></item><item><title>Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs</title><description><![CDATA[Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program.

"The Fairwind Program gives high-priority defenders (like governments, healthcare providers, and telecommunications services) early access to advanced models that help them]]></description><link>https://thehackernews.com/2026/09/google-anthropic-and-openai-unveil.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/google-anthropic-and-openai-unveil.html</guid><pubDate>Wed, 02 Sep 2026 23:57:49 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiu5sAuC-e7tUigtaAj0gicqzy_kWZTZRujpV3IxqGW1wr_VCuXbKXG7M-nNIac5QO2GY_KtEQ8HfnUENc6JZpS8haeGQIvOH4EddDvrQTJwXY2kkZcz41JbeT1_YhVuyrArJV4sUB3hrT9dFIazMbT-_8hLxg0jrQzHLPLv_h3bNb98puP5yVwgA1zoIsQ/s1600/aiai.jpg"/></item><item><title>Fake Software Installers Disable Windows Update and Weaken Microsoft Defender</title><description><![CDATA[An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers.

"The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users," Microsoft]]></description><link>https://thehackernews.com/2026/09/fake-software-installers-disable.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/fake-software-installers-disable.html</guid><pubDate>Wed, 02 Sep 2026 22:11:06 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjhKCtgI2bIF4kLY71qjkluS80XAm5YPA9y9GzTxC8XBTaxq1d42jyZ-bxAr7OlZ-wCc4-RDp_NmUPKxd9TS1dvtjt3gysB86SkMuQ5q6vGb7HTh-DVMNC8VJcJFC2sJmiSQ740SX-miCoyiGfkAXLqO1ySH3zenWcAP7g6ilReO9jRsnl3Tnw279K7NYF3/s1600/windows-updates.jpg"/></item><item><title>Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code</title><description><![CDATA[Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine, four of them still unpatched at publication.

The command executes as the user, outside the agent's sandbox and without an approval prompt, and exploitation requires the repository to arrive]]></description><link>https://thehackernews.com/2026/09/malicious-git-configs-can-make-claude.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/malicious-git-configs-can-make-claude.html</guid><pubDate>Wed, 02 Sep 2026 19:36:59 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhlrspu4otI5zjtu2q78NDrwnqfbTv4jzqXhH-txAo8pCjXDPRJjLvfWpRyHvbimqVvAOZWI0pMVmu2jWVdETbh2csa2UkMHx0M2uu9cJkB0_E4x1mjjs_1F9RYZjozZQvIYN5Xux43DX1u0jCQE_Pk19yE8BnR_RxXN-QXmP5jf74ZQgE9uQVUONJoQKQ/s1600/aix.gif"/></item><item><title>Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages</title><description><![CDATA[A Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run by Brazilian government and educational institutions, and using them to divert visitors to attacker-controlled pages promoting online gambling and sports betting.

Check Point Research said it has tracked the campaign since mid-2025.

The modules]]></description><link>https://thehackernews.com/2026/09/malicious-apache-modules-hijack.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/malicious-apache-modules-hijack.html</guid><pubDate>Wed, 02 Sep 2026 19:14:16 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEixn-0jJvMDlL85UUyW0E5PUDeUnMbGMxZJEnJMOAXXAuiqD-e1D9IoZdYsNwwDY16NA7x7GFHzVrx6LqJU7u7ywR50UWP4DGybNAhTlLPeAiBcVwVUJPgV1KbD1u0aUNy_468Y6gMQJ8FlnfGFlz_iCJcAeOeTiPViV1195lHwovULdtSBlsvPWOGpNU8/s1600/check.jpg"/></item><item><title>BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access</title><description><![CDATA[Virtualizor said hackers used a Border Gateway Protocol (BGP) hijack to divert Softaculous traffic. The hackers then used the diverted update traffic to deliver a malicious Virtualizor package to some installations. A hosting-provider account separately said 5 of its 34 checked Virtualizor hypervisors sustained root-level compromise.

The incident window ran from approximately August 28 at 20:57]]></description><link>https://thehackernews.com/2026/09/bgp-hijack-delivers-malicious.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/bgp-hijack-delivers-malicious.html</guid><pubDate>Wed, 02 Sep 2026 18:42:45 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjc5HwRa7RftYjoKUzpULa7DXn6tt4sZ7RrL1PNBN0Um5di5vxvgRQvmF3rF9-Xb7URM6YD9t-kEu0e3VBeERcdHio4Bz92EOYUwR2s3dosskPZbfztVyjAQ8p-h9PZ7ns3O8uOJ-DSxWPSIanM7l0lC2AZr71eXzWkSXTb_TjLmyBKvMR1KE97xp8PKJU/s1600/virtualizer.jpg"/></item><item><title>Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control</title><description><![CDATA[Cybersecurity researchers have disclosed details of a new Android banking trojan called StreamRat that was promoted to Spanish-speaking users through a fake television-streaming campaign on Meta and can give operators near-complete control of infected devices.

ThreatFabric said the campaign's advertisement focused on Spain and reached an estimated 570,950 Meta accounts in the European Union]]></description><link>https://thehackernews.com/2026/09/meta-ads-push-streamrat-android-trojan.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/meta-ads-push-streamrat-android-trojan.html</guid><pubDate>Wed, 02 Sep 2026 17:52:02 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhNhCfat7BT6m53utL9Z1iMKYQv6B3QwsQdxZBzkmr1WsJpDDdFGZgHjaLuHSXMBBJSyfxtyR750K33X3GzZwYkHac_3mpIITheSY4lh8LMK-ufnQ9htwhkmfv2MRKfZKtYdROU7VuO0HMmK7BQ7FlttrQiToqHq9zffChgBIOJT8yLL5vT7JY43_FDK-A/s1600/android-trojan.jpg"/></item><item><title>How to Secure Enterprise AI: From Adoption to Incident Readiness</title><description><![CDATA[The debate about whether AI delivers business value is over. The challenge now is implementing it at scale and securely across every function while meeting board-level pressure to move fast. Organizations must focus on adopting AI at business speed without losing control of cyber risk. Download the full eBook here.&nbsp;

The Business Reality&nbsp;

In Sygnia’s 2026 CISO Survey Report, which]]></description><link>https://thehackernews.com/2026/09/how-to-secure-enterprise-ai-from.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/how-to-secure-enterprise-ai-from.html</guid><pubDate>Wed, 02 Sep 2026 17:00:00 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi3ZMbYZ20M3vMq_61k1PH7V-0evy5iTQQAGHDcA5khnJ304G746XRgkusnpa7Z31yIJLA7SX5ShzsKdvk1JfTwpVTSm4VPlkYoYVdwW9TaBULJ5363G0e-Z7ff86vvSGBiZTzaZeC6O4RRvJYuP7CrsAz4MeaX53UO0PICXuoa0H-u0qxXJHJcCM_Ovrg/s1600/ss.jpg"/></item><item><title>Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain</title><description><![CDATA[SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks.

The vulnerabilities, discovered internally by SonicWall's William Perry and Adam Babis, are listed below -


  CVE-2026-83548 (CVSS score: 10.0) -&nbsp; A pre-authentication SSRF vulnerability in the Appliance]]></description><link>https://thehackernews.com/2026/09/attackers-exploit-two-sonicwall-sma.html</link><guid isPermaLink="false">https://thehackernews.com/2026/09/attackers-exploit-two-sonicwall-sma.html</guid><pubDate>Wed, 02 Sep 2026 16:23:49 +0530</pubDate><author>info@thehackernews.com (The Hacker News)</author><enclosure length="12216320" type="image/jpeg" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhHkRZMEpG9dgsbvSzYfaPZC5u0gmzUw-5NHDTcsQ-MQtxr6pqNrngG2LsyMJ0KKxA364L3Lq4xhGAxCTRQ3C8szlo9aLJeWXw37C6hsAD5YbYCJF8KuQyuWMIPNCNDXX8-1HN76xxYhxffeenDDyWobOpA4AXC76hFcdh1vnqpjI_pLF2YuxiAwu87cHwC/s1600/sonicwall.jpg"/></item></channel></rss>