cybersecurity

Fresh stories for the cybersecurity topic.

China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

cybersecurity

The Hacker News

China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE. Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026. "The

11 hours agoReader view
Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

cybersecurity

The Hacker News

Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass

4 days agoReader view
Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection

cybersecurity

The Hacker News

Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection

Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve. The operation has been attributed to a cyber espionage group it calls GTG-20006 (where "GTG" stands for Generative Threat Group), which aligns with broader reporting linking the cluster to Midnight

4 days agoReader view
BambooToken Malware Uses MQTT to Control Windows and Linux Systems

cybersecurity

The Hacker News

BambooToken Malware Uses MQTT to Control Windows and Linux Systems

Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems. The emerging malware family, codenamed BambooToken, is assessed to be active since at least February 2023 and put to use in attacks targeting organizations across Asia and South America.

2 hours agoReader view
AI Changed the Exposure Problem. Validation Needs to Change With It.

cybersecurity

The Hacker News

AI Changed the Exposure Problem. Validation Needs to Change With It.

There's a lot of noise around AI and cybersecurity right now. What’s actually important is far simpler, if often lost in the hubbub. Vulnerability discovery is getting faster and happening at a much greater scale, while defenders still have to work out which findings actually deserve their action. In the first half of 2026, a whopping 35,853 CVEs were published, roughly 49% more than in the

1 day agoReader view
Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed

cybersecurity

The Hacker News

Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed

The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which the researcher reported last month. "Microsoft has failed to properly patch ShieldBreak CVE-2026-69414," Chaotic

6 days agoReader view
N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

cybersecurity

The Hacker News

N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026. The vulnerability in question is CVE-2026-86218 (CVSS score: 10.0), which has been described as a

7 days agoReader view
ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

cybersecurity

The Hacker News

ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful right up until it isn’t. Different stories, same basic problem: the path in was often already

5 days agoReader view
Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

cybersecurity

The Hacker News

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Google on Tuesday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine. "Out-of-bounds write in V8 in Google Chrome prior to

6 days agoReader view
LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server

cybersecurity

The Hacker News

LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server

A critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user gain root access on a shared-hosting server, cPanel warned in an advisory published on September 14. On such servers, many customers' sites run on a single machine, and an attacker with one of those hosting accounts could exploit the flaw to access or alter other sites and the server itself,

10 hours agoReader view
Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries

cybersecurity

The Hacker News

Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries

A suspected Chinese threat actor tracked as Red Heron has been attributed to the rapid exploitation of a recently disclosed security vulnerability in Gitea to compromise internet-facing instances as part of a multi-national campaign. "Red Heron scanned 1,386 Gitea instances across seven countries and maintained a separate dataset of 477 Taiwan-based systems," Acronis Threat Research Unit (TRU)

1 day agoReader view
CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

cybersecurity

The Hacker News

CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026. The vulnerabilities are listed below - CVE-2026-20079 (CVSS score: 10.0) - An authentication

5 days agoReader view
Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point

cybersecurity

The Hacker News

Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point

Introduction Security teams have gotten pretty good at testing against what can hurt them. Can this EDR agent catch this payload? Will my organization fail the phishing simulation? Does this SIEM rule fire on this particular technique? And, in more mature organizations, this testing happens continuously rather than as a one-off exercise. But no matter how much you validate against these

6 hours agoReader view
Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers

cybersecurity

The Hacker News

Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers

Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data. The first is an automated effort aimed at internet-exposed Vite development servers that's designed to steal cloud credentials, configurations from Amazon Web Services (AWS) and Microsoft Azure instances, and infrastructure state files, per F5 Labs. The

6 hours agoReader view
CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

cybersecurity

The Hacker News

CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. Details of the vulnerabilities are as follows - CVE-2026-42016 (CVSS score: 8.1) - An incorrect authorization

3 days agoReader view
OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers

cybersecurity

The Hacker News

OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers

The "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx. On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, disclosed details of a coordinated cyber attack that targeted the package manager for the

3 days agoReader view
GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

cybersecurity

The Hacker News

GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under

4 days agoReader view
Claude Used to Automate Exploitation and Data Theft Across Multiple Victims

cybersecurity

The Hacker News

Claude Used to Automate Exploitation and Data Theft Across Multiple Victims

Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and August 2026. The threat actors, which the artificial intelligence (AI) company has branded Generative Threat Groups (GTGs), span state-sponsored groups, financially motivated criminals, commercial

4 days agoReader view
Your Critical Vulnerabilities Might Not Be Your Biggest Risk

cybersecurity

The Hacker News

Your Critical Vulnerabilities Might Not Be Your Biggest Risk

Security teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process for determining which of those vulnerabilities actually create a path to compromise. A critical vulnerability may look alarming on a scanner report, but if it sits behind strong segmentation, identity controls, and other defenses that prevent an attacker

4 days agoReader view
PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances

cybersecurity

The Hacker News

PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances

A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances. According to independent reports from Blackpoint Cyber and GreyNoise, the activity originates from "45.142.193[.]132," an IP address that has been linked to

5 days agoReader view
SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

cybersecurity

The Hacker News

SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application The vulnerability, tracked as CVE-2026-44756 (CVSS score: 10.0), has been described as a case of memory corruption. Discovered and reported by SAP

6 days agoReader view
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

cybersecurity

The Hacker News

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. The first campaign, per the tech giant, involved sending over a million scam emails between August 3 and 5, 2026, by masquerading as chief executive officers

2 days agoReader view
F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

cybersecurity

The Hacker News

F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7. When Apache loads any of the three appliances' own PHP scripts, the malware adds the web shell to the copy held in memory, so a check of the file on disk can come back clean. Those three scripts are

6 days agoReader view
Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds

cybersecurity

The Hacker News

Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds

With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new findings from Sysdig show that skilled human operators can move just as swiftly after gaining initial access. In one instance highlighted by the cloud security company, the threat actor pivoted from a vulnerable Marimo notebook to an SSH

5 hours agoReader view
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

cybersecurity

The Hacker News

Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome. The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo,

6 days agoReader view
Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution

cybersecurity

The Hacker News

Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution

Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-76461, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as a case of insufficient validation in the email parsing logic that could allow an unauthenticated, remote attacker

11 hours agoReader view
Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE

cybersecurity

The Hacker News

Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE

A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security teams, answering that means jumping between vulnerability scanners, endpoint tools, cloud inventories, SBOMs, repositories, and application data to build enough context to act. As AI accelerates vulnerability discovery and research, that delay matters more

6 days agoReader view
U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok

cybersecurity

The Hacker News

U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok

U.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting "systematic extraction" of proprietary functionalities and capabilities of American frontier models through distillation attacks. The activity has been described as occurring at an industrial-scale and one that forms the "core" of their AI development strategy, according to

6 days agoReader view
⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits

cybersecurity

The Hacker News

⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits

AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job. Some models are also crossing lines on their own. That is not a great combination. The rest of the week is more familiar: old bugs still working, fresh exploit chains, exposed systems, weak defaults, and simple paths that should have been harder to abuse. A few of

1 day agoReader view
Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE

cybersecurity

The Hacker News

Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE

Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only "under specific conditions" that it has not described. One flaw affects Check Point's Security Gateways, its firewall appliances. The other affects those gateways and the Security

5 days agoReader view
Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks

cybersecurity

The Hacker News

Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks

The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it, security firm Group-IB said in a report published on September 9. A work profile is a separate space that Android typically reserves for employer apps, and what's inside it is kept separate from everything in the personal space. That

5 days agoReader view
Loading...