-->
#1 Trusted Cybersecurity News Platform
Followed by 5.70+ million
The Hacker News Logo
Get the Latest News
cybersecurity

The Hacker News | #1 Trusted Source for Cybersecurity News

CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing

CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing

Aug 26, 2026 Red Teaming / Security Operations
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published the results of two red team assessments it conducted simultaneously against two critical infrastructure organizations, using what it described as similar tradecraft while recording sharply different defensive outcomes. Both organizations were fully compromised at the domain level, and in both, the red team also reached sensitive business systems (SBSs) and cloud resources. The advisory, tracked as AA26-237A and titled "A Tale of Two SOCs," was released on August 25, 2026. CISA identified the first target only as a Government Services and Facilities Sector organization, referred to as Organization A , and the second as a Water and Wastewater Systems Sector entity, referred to as Organization B . "CISA conducted two simultaneous red team assessments using similar tradecraft but observed different defensive responses," the agency said in the advisory. Against Organization A, the re...
Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code

Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code

Aug 26, 2026 Vulnerability / Web Security
The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it. The flaws, tracked as CVE-2026-19913 and CVE-2026-19912 , both stem from the same unsafe deserialization in the mwEmbedLoader.php endpoint of the mwEmbed player library, which Kaltura also distributes as html5lib. Neither requires authentication or a Kaltura session token, and network access to the endpoint is the only precondition CERT/CC states. No patch is available, and CERT/CC said it was "unable to reach Kaltura to coordinate these vulnerabilities." Administrators are advised to restrict or disable external access to the endpoint and to enforce a strict allow-list for the ServiceUrl parameter that permits only legitimate backend API URLs. No exploitation had been reported at the time of writing, and neither CVE appeared in CISA...
Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine

Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine

Aug 26, 2026 Artificial Intelligence / Security Operations
The SOC we've always known was built around a model that guarantees most of the alert queue will never receive analyst review. There's never time. In a traditional SOC, the typical progression follows a well-known pattern: an alert arrives; a detection engine assigns a severity score. The issue then waits for a human to decide if it should escalate to an investigation. Given the volume of network telemetry in the security stack, the queue is an unavoidable result of humans as the investigative layer. Long alert queues also force security teams to decide which signals to analyze before they even know what those signals represent. Threat hunting has always addressed security questions via an alternative approach: start with a hypothesis about attacker behavior, search the available evidence, then prove or disprove it. The sequence is powerful, but it hits the same wall: human capacity. Agentic security operations change the paradigm. The SOCs now being built are predica...
cyber security

Attackers Map Your Network Quietly. Controls Block 1 in 10 of Those Actions

websitePicus SecurityExposure Management
Picus Labs analyzed 338 million attack simulations. See what got through in the Blue Report 2026.
Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests

Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests

Aug 26, 2026 AI Security / Application Security
Aikido Security has published research that recreates the Australian gym-booking incident in a synthetic environment, finding that Claude Opus 4.6, running on the OpenClaw agent harness, exploited a client-side-only booking restriction in 9 of 10 runs. The original incident was first reported by ABC News on August 10, based on chat logs and screenshots the user supplied. He had asked an OpenClaw agent running Opus 4.6 to book him into a gym class. The agent booked sessions months beyond the window the site allowed. It then tested, without being asked, whether the same API would let it cancel another member's waitlist entry. The test removed the person holding the top place and moved the user up one position. The agent told him it could not add the member back. Aikido's test system is a single-page web application backed by a GraphQL API carrying the two flaws described in the original incident. The seven-day booking window is enforced only in the frontend, and the cancel...
OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation

OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation

Aug 26, 2026 Artificial Intelligence / Disinformation
OpenAI on Tuesday said it banned a cluster of Russian ChatGPT accounts that used VPNs to bypass access restrictions and run an influence operation, which relied on its artificial intelligence (AI) tool to generate social media posts and comments that were shared on Substack, Telegram, X, Facebook and LinkedIn. The accounts "were being used to promote the International Burke Institute (IBI), a self-described 'expert community' based in Israel," the company said . "What began as an investigation into AI-generated social media posts led us to a much broader influence operation, built around a website containing copied and misattributed academic work, a 'sovereignty' index that cast Russia in a favourable light, and efforts to disguise the operators' Russian origins." The campaign is assessed to have reached "relatively small audiences," with Telegram channels attracting more users and amassing about 10-20,000 followers each. The m...
cyber security

How IT Can Reduce Credential Risk Across Every Department

website1PasswordPassword Security / Compliance
Learn how to manage credential access for every user, from your finance team to third-party contractors.
INTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud Crackdown

INTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud Crackdown

Aug 26, 2026 Cybercrime / Online Scams
An eight-month INTERPOL operation targeting West African organized crime groups has led to arrests of 58 people and the identification of 263 suspects. "The operation, which brought together 22 countries from six continents, is a response to the escalating global threat posed by West African criminal networks – such as the Black Axe and other similar groups," INTERPOL said . "These groups are responsible for a significant share of the world's cyber-enabled financial fraud, typically through romance scams, cryptocurrency and investment scams or business email compromise fraud, as well as other serious and violent crimes." Countries that participated in the effort include Austria, Argentina, Australia, Canada, Côte d'Ivoire, France, Germany, Indonesia, Ireland, Italy, Japan, Malaysia, the Netherlands, Nigeria, Portugal, South Africa, Spain, Sweden, Switzerland, the U.A.E., the U.K., and the U.S. INTERPOL said the investigation identified 196 individu...
New SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode

New SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode

Aug 26, 2026 Malware / Threat Detection
An independent malware researcher has documented a previously unreported Windows backdoor, dubbed SLEEPWALKER , that stays inert in memory until a specifically crafted network packet reaches the machine and then runs commands written in a 23-instruction language of its own design. The sample is an unsigned 64-bit Windows dynamic-link library (DLL) of 59,904 bytes, built to be side-loaded into ERAAgent.exe, the Windows executable for ESET Management Agent. It impersonates Microsoft's dpapi.dll, exporting the same seven data protection functions as the genuine system library, and carries a version resource copied from ESET Management Agent. There are no domains, IP addresses or URLs built into the file, and it makes no outbound connection of its own, so an infected host can look clean to tooling that watches for connections to known-bad infrastructure. Commands arrive as bytecode rather than readable text, so recovering the encryption key yields opcodes in a format that...
Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

Aug 26, 2026 Vulnerability / Cryptojacking
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea. The vulnerability in question is CVE-2026-60004 (CVSS score: 9.8), a case of remote code execution that allows an attacker with ordinary write access to a repository to execute arbitrary shell commands as the Gitea OS user. "Gitea's diffpatch endpoint can be abused to install and execute a Git hook from repository-controlled content," according to an advisory released by Gitea last month. "With default open registration, an unauthenticated visitor can obtain the required write access by registering an account and creating a repository." Security researcher Shai rod (aka NightRang3r) has been credited with discovering and reporting the issue. The issue affects all versions of Gitea from version 1.17 and has been patched in version 1.27.1. As The Hacker News reported pre...
Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes

Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes

Aug 26, 2026 Artificial Intelligence / Cybercrime
Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple's Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask for their device passcode. SOCRadar Threat Research Unit (STRU) said the platform, which it tracks as AnonyMousKIT , is credit-metered and drives lures across five channels from a single victim record, comprising email at 1.50 credits, SMS priced per sender ID, WhatsApp, a recorded voice call at 1 credit, and an AI voice agent at 2 credits. The targets are owners of Apple devices that were recently lost or stolen, and the pages and calls ask each of them for the 4- or 6-digit device passcode, then the Apple ID credentials, and finally a live two-factor authentication (2FA) code. Apple's own guidance states that the company never asks for a password, device passcode, or 2FA code to provide support. "AnonyMousKIT is best understood no...
U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches

U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches

Aug 25, 2026 Critical Infrastructure / Cybercrime
The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an "unprecedented, whole-of-government, economic campaign" against the nation and its enablers. "We are launching an economic onslaught against Iran's financial connections around the globe. Our objective is to sever every economic lifeline that sustains this tyrannical regime until Tehran stands alone," said Secretary of the Treasury Scott Bessent. The action, codenamed Operation Economic Outcast, aims to cut the Iranian regime and the Islamic Revolutionary Guard Corps (IRGC) from the financial "lifelines" that support the "leading state sponsor of terror." To that end, the sanctions designate nearly 60 Iran-linked entities, individuals, and vessels across nuclear, missile, oil, and cyber networks, including the digital assets sector. Specifically, the sanctions take aim at a malicious cyber group affiliated with Iran...
A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

Aug 25, 2026 AI Security / Vulnerability
Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden instructions inside the model itself. The findings were shared with The Hacker News ahead of publication, and the report says Oasis Security reported them to NVIDIA's Product Security Incident Response Team (PSIRT) beforehand. The research carries no CVE identifier. No exploitation has been reported as of August 25, 2026. Oasis Security's head of research, Elad Luz, told The Hacker News that NemoClaw v0.0.35 fixed the issue on macOS and Linux. There is no fix on the Windows and WSL path, according to Luz, where v0.0.34 added a Windows installation that carries a warning instead. NemoClaw is NVIDIA's open source reference stack for running agents such as OpenClaw inside its OpenShell sandboxes, and Ollama is one of its supported local inference backends. The report des...
WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android

WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android

Aug 25, 2026 Authentication / Password Security
Meta on Tuesday announced a set of WhatsApp account security features, including support for multiple passkeys to a single account to help users with both iOS and Android devices sign into their accounts using the phishing-resistant method. The tech giant said more than 1 billion people use a passkey to log into WhatsApp. Support for passkeys was first introduced in Android in October 2023, before expanding to iOS in early 2024. Meta also followed it up by integrating passkeys into Facebook logins in June 2025. Users can manage their passkeys by navigating to Settings > Account > Passkeys. Along with the update, WhatsApp said it's adding a full password option as part of two-step verification, and users on Android will see more context on calls from people who aren't in their contacts. "Two-step verification is an extra protection layer that helps prevent someone from taking over your account, even if they get hold of your one-time passcode," WhatsApp...
Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode

Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode

Aug 25, 2026 Vulnerability / AI Security
Marimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in a specially crafted notebook, according to VulnCheck's CVE Numbering Authority (CNA) record. The CNA record says the command can run as a local subprocess when the notebook is opened in edit mode. The vulnerability, tracked as  CVE-2026-75149 , is a code injection issue affecting versions prior to 0.23.15. VulnCheck's CVE Numbering Authority (CNA) record assigns it a CVSS v4 score of 8.7 and a CVSS v3.1 score of 8.8, with user interaction required and no attacker authentication required. Marimo has addressed the issue in version 0.23.15. The CVE was published on August 19. Users running an affected release should move to a version outside the affected range. According to  OSV's CVE import , a crafted notebook can supply an attacker-controlled MCP server command through notebook configurat...
Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

Aug 25, 2026 Phishing / Enterprise Security
Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication. According to ANY.RUN research, 48% of targeted email addresses were potentially compromised. Most of the affected companies are US-based. Mirage2FA Campaign Scope and Impact By stealing passwords and session cookies, attackers can gain access to authenticated Microsoft 365 sessions and SSO-connected services. This creates significant identity-related risks for companies, potentially exposing corporate email, trusted business accounts, and other sensitive data. Once an authenticated Microsoft 365 session is hijacked, a path for impersonation, fraud, and further compromise is created. Key takeaways about Mirage2FA by ANY.RUN The campaign has a broad geographic and corporate reach. Apart from the United States accounting for 63.7% of the tot...
24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

Aug 25, 2026 Phishing / Threat Intelligence
Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. "While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn't do harm, the threat actor’s use of npm isn't to infect developers who install it, but to use the registry and its mirrors as a safe, validated storage for the malware," OX Security researchers Moshe Siman Tov Bustan and Vitalii Chepurko said . The list of npm packages, some of which are still available for download, is below - bgzxcuite2 prezdentkxheiw egair0810 mnteckets airdzticket egypt0811 passport811 vxhjkseuiaqkb ndmushdkeqe ndmxchdjxn2 ndmfguyhoxc3 mjsdqwocvn m2fcsfyjkuxb m3fdfocdoewn @worrisome/reutil testdgdbcsd tesgfvbncsdbcv mndsxcusiwlk1 mn2adskhweox mn3sadkoiewu mn4xcouzvhus mbxcnsuwgs1 s...
E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands

E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands

Aug 25, 2026 Malware / Social Engineering
Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers ( DDRs ) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE . While threat actors are known to abuse legitimate services to point to additional command-and-control (C2) infrastructure and blend in with regular network traffic, the development marks the first time this unusual technique has been spotted in the wild. An FTP banner is a welcome message or text string that an FTP server sends to a client immediately upon connection. The mechanism allows "malware stagers to fetch commands directly from the protocol's initial response," SOCRadar said in a technical report. The modus operandi was first highlighted by the MalwareHunterTeam early last month.  However, it's worth noting that the method is a lot less stealthy than traditional web-based DDRs, as security controls are likely to flag FTP connections ...
⚡ Top Stories This Week
Expert Insights Articles Videos
Cybersecurity Resources