-->
#1 Trusted Cybersecurity News Platform
Followed by 5.70+ million
The Hacker News Logo
Get the Latest News
cybersecurity

The Hacker News | #1 Trusted Source for Cybersecurity News

FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails

FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails

Oct 08, 2026 Data Breach / Cyber Espionage
Hackers tied to a Chinese cybersecurity company stole email from government organizations, law enforcement agencies, healthcare systems, and religious institutions in Southeast Asia, the FBI and agencies in 6 other countries said on October 8. The company, Integrity Technology Group , has been sanctioned by the U.S. and the UK. The hackers scanned websites for flaws using a tool containing more than 1,300 scripts, guessed passwords for Microsoft 365 and Exchange accounts, and copied mailboxes using tools designed to collect mail. The hackers have been breaking into networks since at least mid-January 2021, according to the agencies'  joint advisory . It describes the hacking in the present tense but provides no date for any theft and does not specify how many organizations were breached. The same hackers targeted U.S. government services, critical manufacturing, healthcare, and IT organizations, along with U.S. law enforcement, education, and religious groups. Organizations ...
ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories

ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories

Oct 08, 2026 Hacking News / Cybersecurity News
The crooks have trust problems of their own. One ransomware affiliate decided to keep the profits for himself. Elsewhere, an attacker left a server exposed, complete with tools and traces of an intrusion. Apparently, keeping things secure is a problem on both sides of the fence. The rest of the week isn't much more reassuring. Malicious code turned up in developer packages and extensions that looked harmless. Familiar online services helped phishing emails appear legitimate. A basic file upload flaw gave attackers a way in, while weak session cookies made impersonation far too easy. Even AI assistants are getting their own instructions hidden inside phishing messages now. What's interesting is the gap between effort and results. Some attacks involve several stages, careful timing, and plenty of tricks. Others get surprisingly far because of a bad design choice or something nobody bothered to check. Both seem to be working well enough. Anyway, here's what else turned u...
Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks

Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks

Oct 08, 2026 Data Breach / Web Security
Attackers behind a string of personal data leaks at Japanese organizations have abused APIs for mobile apps and targeted known software flaws, the JPCERT Coordination Center (JPCERT/CC) said. The Tokyo-based center, which takes incident reports, based its  October 8, 2026 alert  on those reports and other information. The alert names no attacker and no affected organization. JPCERT/CC called what it knows "limited and fragmentary" in the alert, translated here from Japanese. It said its account does not mean the same method was used in every incident. Besides consumer apps, the systems hit include business intelligence (BI) tools and employee-facing management systems that their operators did not expect the public to reach. Data stored in them leaked in some cases. For defenders, the alert includes eight source IP addresses, five User-Agent strings, and a list of API controls, including access controls on every endpoint, public or not. The only product it names a...
cyber security

New Priorities for Critical Infrastructure: A Nation-State Threat Roundtable

websiteSANSCritical Infrastructure / Cybersecurity
Experts from SANS Institute, FirstEnergy, MITRE and Dragos unpack what leaders should prioritize next.
UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML

UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML

Oct 08, 2026 Malware / Cyber Espionage
The Russia-aligned threat actor known as UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN . According to TrendAI, the malware has been put to use in attacks targeting Ukrainian government personnel. The cybersecurity company is tracking the cluster under the name Earth Sirrush (previously SHADOW-EARTH-065). ASHVEIN, which its developers internally refer to as "TelemetryBrowser," brings together credential theft, surveillance, and remote-control capabilities. Its functionality includes credential theft from Chrome and Firefox, GDI-based screenshot capture, file enumeration and retrieval, PowerShell remote shell execution, system fingerprinting, and encrypted command-and-control (C2) communications. "ASHVEIN also hides tasking inside invisible HTML elements," TrendAI said . "Some variants use a GitHub-based dead drop resolver as a fallback mechanism, while delivery methods inclu...
ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms

ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms

Oct 08, 2026 Agentic AI / Web Security
Cybersecurity researchers have disclosed details of a targeted campaign aimed at South Korean financial organizations that used an artificial intelligence (AI) pen testing tool named ARTEX to carry out the attacks. The activity, per CrowdStrike Intelligence, was active from late September to early October 2026, and resulted in data exfiltration. "In this activity, the threat actor leveraged ARTEX, a recently released open-source agentic penetration testing (pentesting) tool developed in China, alongside large language models (LLMs)," the cybersecurity company said . CrowdStrike said it discovered the campaign after it identified a set of open directories hosted at a Hong Kong-based IP address, exposing Claude Code session histories, Claude memory files, and ARTEX configuration files. The campaign has not been attributed to any known threat actor or group. But evidence points to a suspected Chinese-speaking operator driven by financial gain. ARTEX is a large lan...
cyber security

AI adoption is outpacing IT visibility

website1PasswordSaaS Security / AI Governance
Individual dashboards only show part of the story. Learn how IT can get a unified view of AI spend and usage.
Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia

Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia

Oct 08, 2026 Web Security / Threat Intelligence
Phishing kits are no longer limited to copying a familiar login page and waiting for a victim to enter credentials. Attackers are increasingly building filtering, session management, and traffic controls into the infrastructure that delivers the phishing page itself. ANY.RUN has identified Wazza, a new phishkit targeting banking, manufacturing, and government organizations across the US, Europe, and Australia. The campaign uses a multi-stage routing chain to screen visitors and automated traffic before delivering an Adobe-themed Device Code phishing page. For security teams, that makes Wazza more than another malicious URL. The campaign shows how attackers can control the path to the final lure, making the initial link less informative and potentially complicating automated detection. MSSPs face an added challenge, as they investigate alerts across multiple customer environments while keeping response times under control. That uncertainty can translate directly into longer in...
16 Malicious Firefox Extensions Pose as Rabby and OKX Wallets to Steal Recovery Phrases

16 Malicious Firefox Extensions Pose as Rabby and OKX Wallets to Steal Recovery Phrases

Oct 08, 2026 Browser Security / Malware
Cybersecurity researchers have discovered a cluster of 16 malicious Mozilla Firefox extensions that are capable of stealing cryptocurrency wallet recovery phrases and private keys. "The extensions masquerade as wallet portals, desktop utilities, and browser tools, but their code intercepts recovery phrases and private keys during wallet import flows and attempts to send those secrets to attacker-controlled Cloudflare Workers," Socket researcher Joseph Edwards said in an analysis. The names of the extensions are below - view-focus-bright@webtools.co@6.12.2 quick-track-nest@tabtools.co@8.1.18 vibe-kit-tool@fasttools.co@9.21.9 edge-hub-snap@protools.net@4.12.24 core-hub-peak@neattools.example@8.24.21 sipoo-grozza@browserweb.com@2.1 mozart-seo@webtools.com@1.4 clean-file-bar@neattools.com@4.21.8 clean-net-timer@plugify.example@4.17.1 manager-square@webtools.com@1.4 manager-course@webtools.com@1.4 val-andrew@browserweb.com@1.4 manag...
U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks

U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks

Oct 08, 2026 Cybercrime / Cyber Espionage
The U.S. State Department is offering up to $10 million for information leading to the identification or location of Zhang Yu, a Chinese national charged in the United States in connection with the 2021 Microsoft Exchange Server attacks known as HAFNIUM. The reward is for information leading to his identification or location, the news outlet  NTD reported  this week, citing a notice from the department's Rewards for Justice program. Zhang remains at large, U.S. authorities say, meaning he has not been arrested. The charges against him have not been tested in court. Rewards for Justice  is the State Department's national security rewards program. It says it has paid more than $250 million to over 125 people since 1984. Zhang is wanted for his alleged role in "malicious cyber activities against U.S. critical infrastructure," NTD quoted the notice as saying. The amount and that wording match an offer the program was already making  in January 2025 . That of...
MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt Data

MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt Data

Oct 08, 2026 Cybercrime / Ransomware
The U.S. Department of Justice (DoJ) on Wednesday announced charges against a 50-year-old U.S. and Israeli national for allegedly defrauding ransomware victims by secretly paying the attackers to obtain decryptors while claiming to use proprietary tools to recover their data. Zohar Pinhasi (aka Zack Silver and Zack Green) has been charged with two counts of wire fraud and one count of wire fraud conspiracy. If convicted, the defendant faces up to 20 years in prison for each count. "By falsely claiming to decrypt ransomware without paying off the ransomers, the defendant re-victimized his clients while extracting a hefty profit for himself," said U.S. Attorney Joseph Nocella, Jr. for the Eastern District of New York. Pinhasi, who owned and operated a Florida company called MonsterCloud, is alleged to have made false representations to ransomware victims, urging them not to pay a ransom and claiming to have "proprietary tools" and "advanced decryption tec...
Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

Oct 08, 2026 Artificial Intelligence / Cloud Security
The npm package known as " tensorlake ," a TypeScript software development kit (SDK) for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack. The malicious version 0.5.144 "contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code," Socket said . Version 0.5.144 is no longer available for download from the npm package registry. An analysis of the compromised release shows that it contains a preinstall hook designed to launch a JavaScript file ("package/lib/setup.mjs"), an obfuscated loader that launches the main credential-stealing and self-propagating worm ("package/lib/Math_Symbol.js") using the Bun runtime. The stealer malware is designed to harvest credentials across local files, CI environments, Kubernetes, and Vault sources. It also drops the HackBrowserData binary, exfiltrate...
Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains

Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains

Oct 07, 2026 Web Security / Domain Hijacking
Attackers compromised three country-code top-level domains (ccTLDs) and obtained unauthorized HTTPS certificates for several Google domains, Google  said on October 6 . Google's own systems were not breached, but any domain ending in .gh (Ghana), .sl (Sierra Leone) or .as (American Samoa) was put at risk. With such a certificate, an attacker could pose as the real site over an encrypted connection and read the private data sent to it. Chrome blocked the unauthorized certificates for Google's domains through  CRLSets , its way of quickly blocking certificates in emergencies, Google said. The company also worked with the certificate authorities (CAs) that issued the certificates to have them revoked, a step meant to protect people using other browsers and apps. Google did not name the domains.  Certificate Transparency  (CT) logs are the public record of certificates issued by CAs. They show at least 12 certificates issued between September 22 and 27 for Google...
Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

Oct 07, 2026 Supply Chain / Malware
Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote access trojans (RAT) to compromised hosts. The campaign has been codenamed MALFEX by CloudSEK and Checkmarx . The activity is assessed to be the work of a lone threat actor who appears to have published 12 packages since August 2023, eight of which have been flagged as malicious. The attack is designed to infect Windows systems through three separate pathways - A loader for Overlord , an open-source RAT written in Go that uses Solana transactions to extract the command-and-control (C2) address A chain that installs movinlike, a Node.js stealer targeting Discord, browsers, Telegram, and cryptocurrency wallets, and A downloader The list of identified malicious packages is below - tlxbnhd tldriver mxdriver img-to-native native-runner function-flag (Still live) function-color (Still live) cdn-img-fet...
SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

Oct 07, 2026 Vulnerability / Network Security
SonicWall has released hotfixes for four flaws in its SMA1000 appliances, the gateways that give remote workers access to a company's network and applications. The most serious could allow an attacker without a login to send requests through the appliance and reach internal functions. SonicWall rates it 10.0 on the CVSS scale and says it has no evidence that any of the four flaws is being used in attacks. The most serious flaw, tracked as  CVE-2026-102255 , is a server-side request forgery (SSRF) bug in WorkPlace, the portal that SMA1000 users log in to. It exists due to an unintended access path through SonicWall and can be reached before authentication. An attacker who abuses that path could "reach internal functionality and perform unauthorized operations," SonicWall said in its  security advisory , dated October 6, without saying which functions. All four flaws affect SMA1000 models 6210, 7210 and 8200v on these platform-hotfix versions:
Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

Oct 07, 2026 Vulnerability / Artificial Intelligence
A critical vulnerability in LMCache , open-source software that speeds up large language model (LLM) servers such as vLLM, lets an attacker run code on the cache server without logging in, and no fixed version is available. The flaw is in LMCache's  multiprocess mode , where the cache runs as a standalone server that LLM workers reach over the ZeroMQ messaging library. A single network message to that server can run commands as the user the LMCache process runs as. The server can be reached from another machine only when an operator sets it to listen on a routable address, rather than the localhost it uses by default. JFrog disclosed the flaw  on October 7 and assigned it a severity score of 9.8 out of 10, in the critical range, the rating it gives a server bound to a routable address. The vulnerability, tracked as  CVE-2026-105192 , affects LMCache from version 0.3.9, released in October 2025, through 0.5.5, the latest stable release, and is also present in the ...
PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet

PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet

Oct 07, 2026 Botnet / Cryptojacking
Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and further expand the scale of the botnet. The financially motivated campaign, dubbed Canto Incognito , has been found to install cryptocurrency miners, including XMRig and Iron, and connects victims to Kryptex, a Russian cryptocurrency mining service. "Compromised hosts are reused to expand the botnet," Lumen Black Lotus Labs said in a report shared with The Hacker News. "Infected servers are turned into scanners and exploit servers, allowing the actor to find and compromise additional vulnerable systems." The malware distributed as part of the campaign has been codenamed PoeLLM owing to what has been described as a "creative" technique that hides the command-and-control (C2) address within a poem the threat actors wr...
The Sixth Voice of the CISO Data Shows Cyber Risk Has Moved Inside the Workflow

The Sixth Voice of the CISO Data Shows Cyber Risk Has Moved Inside the Workflow

Oct 07, 2026 Artificial Intelligence / Data Security
The 2026 findings are not just a year-over-year shift. They mark the latest point in a five-year arc where resilience, AI governance, human risk, and board scrutiny are converging inside the systems where work actually happens. For years, the enterprise cybersecurity story has been told as a straight line of escalation: more attacks, more data loss, more pressure, and more urgency. That narrative is still familiar, but comparing the five most recent years of Voice of the CISO research suggests a more useful reading. The CISO role has not simply become harder because every metric is rising at once. It has become harder because the center of risk has shifted and moved closer to the way work now gets done. The latest 2026 findings show signs of progress. Fewer CISOs expect a material cyberattack in the next 12 months, and fewer report material loss of sensitive information than in 2025. But those improvements sit within a longer trend line that is much less settled. Over five years,...
⚡ Top Stories This Week
Expert Insights Articles Videos
Cybersecurity Resources