-->
#1 Trusted Cybersecurity News Platform
Followed by 5.70+ million
The Hacker News Logo
Get the Latest News
cybersecurity

The Hacker News | #1 Trusted Source for Cybersecurity News — Index Page

FOMO in the SOC: Where AI Platforms like Claude Actually Fit

FOMO in the SOC: Where AI Platforms like Claude Actually Fit

Aug 03, 2026 Artificial Intelligence / Enterprise Security
AI is moving incredibly fast, and every security leader is feeling the pressure to keep up. AI platforms like Claude, Codex and Cursor are already helping security teams write detections, investigate alerts, summarize incidents, and automate repetitive work. The conversation has evolved from whether AI belongs in the SOC, to where each type of AI delivers the most value. With so many new AI products entering the market, it's easy to assume one tool can solve every problem. In reality, different types of AI are designed for different jobs. Understanding that difference is what transforms AI FOMO into better security outcomes. Join AI SOC: Where Claude belongs in the SOC AI is changing security operations The way security teams work is changing quickly. Attackers are already using AI to generate phishing campaigns, automate malware development, and move faster than ever before. At the same time, defenders are using AI to triage alerts, create detection rules, automate ...
Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS

Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS

Aug 03, 2026 Mobile Security / Vulnerability
An unknown Chinese-threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit. Attack surface management platform Censys said it identified the threat actor running more than 100 web properties, most of which are fake Amazon Web Services (AWS) sign-in pages on a domain that also hosts the exploit toolkit. "The hosting concentrates in Hong Kong but reaches into Japan, the United States, and Europe," Censys researcher Aidan Holland said in an analysis published on July 31, 2026. DarkSword, discovered and detailed earlier this year by Google Threat Intelligence Group (GTIG), iVerify, and Lookout, refers to a full-chain exploit kit that is believed to have been used by commercial surveillance vendors and suspected state-sponsored actors in disparate campaigns targeting Saudi Arabia, Turkey, Malaysia, and Ukraine since at least November 2025. The kit, which specifically targets iOS ...
PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web

PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web

Aug 03, 2026 Data Breach / Dark Web
The Police National Legal Database (PNLD) has confirmed that police, government and customer contact information was compromised and published on the dark web. The data included names, organisations and work email addresses belonging to police officers, police staff, criminal justice professionals, government partners and customers. The incident, identified on July 26, also exposed some names and email addresses belonging to people who had submitted questions through Ask the Police. That exposure could make phishing messages targeting named officers appear more convincing, according to UK government guidance . PNLD said, "There is no evidence to suggest that passwords or other security credentials have been compromised." The service provides legal information, products and services to UK police forces and criminal justice organisations. It is not the Police National Computer or the Police National Database, is not a crime-recording system, and does not hold confidentia...
cyber security

AI Threat Readiness 101

websiteWizCloud Security / AI Security
Learn the four pillars of AI threat readiness and how security teams can reduce risk faster with detection, validation, and remediation built for today's threat landscape.
cyber security

The State of Shadow AI in 2026 (And How Attackers Are Taking Advantage)

websitePush SecurityShadow AI / Browser Security
AI adoption has exploded, but every new app, integration and extension introduces new threats and risks.
Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable

Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable

Aug 03, 2026 Data Security / Vulnerability
Thermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered before analysis software loads them. The vendor's July 31 security bulletin says nearly undetectable changes to .fsa and .hid outputs could occur if laboratory controls are circumvented. Thermo Fisher tracks the issue as CVE-2026-17583 and rates it High with a CVSS v4.0 score of 8.2. Five supported product lines have received updates that add digital signatures, while three end-of-life data collection products will receive no vendor update. Thermo Fisher credits Nathan Adams, Kevin Dyer and Laura Gaydosh Combs, together with the U.S. Cybersecurity and Infrastructure Security Agency, with identifying the issue and coordinating disclosure. Thermo Fisher urged customers to install the applicable updates. For customers unable to implement the updates or use another third-party analysis platform, the company recommends controls coverin...
N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete

N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete

Aug 03, 2026 Vulnerability / Endpoint Security
N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers. Its first fix was incomplete. CVE-2026-18577 affects N-central builds prior to 2026.3.1.7. N-able shipped build 2026.3.1.7 on August 2 as the first unaffected version. N-central is the remote monitoring and management platform managed service providers and IT teams use to administer customer endpoints. After compromising an N-central server, the attackers used Take Control to reach managed endpoints and registered Cloudflare tunnels as services on the devices. The tunnels connect outbound to Cloudflare's edge, so they need no inbound firewall rule or open listening port. Running them as services lets them survive a reboot. N-able said the tunnels preserved access after the route through the N-central server was revoked. Nothing in the disclosure suggests Cloudflare was compromised; the attackers abused it...
Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code

Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code

Aug 03, 2026 Vulnerability / AI Security
Three high-severity security flaws have been disclosed in Hugging Face's Diffusers library that could allow crafted model repositories to stealthily execute arbitrary code on machines that load it, opening the artificial intelligence (AI) supply chain to security risk. "These vulnerabilities are bypassing trust_remote_code, the safeguard designed to stop unreviewed code from running in the custom pipelines loading process," Zafran Labs researchers Gal Zaban and Ido Shani said in an analysis published last week. The shortcomings have been collectively named FaceHugger . With Hugging Face becoming the "GitHub of the AI era" and its libraries and repositories prevalent in enterprise environments, vulnerabilities in libraries like Diffusers can grant attackers extensive access owing to how the library is embedded into production pipelines, CI/CD systems, and container images. Diffusers is a Python package that serves as a library of state-of-the-art (SOT...
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

Aug 01, 2026 Vulnerability / Threat Intelligence
An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard , the Bitcoin-only hardware wallet made by Canadian firm Coinkite . A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG) instead of the STM32 hardware random number generator (RNG). Block says an attacker who can determine or sufficiently constrain the device UID, timer state, and prior RNG-call history can reproduce candidate output streams offline without accessing the device. Candidate seeds can then be checked by deriving their addresses and comparing them with public blockchain data. Coinkite shipped emergency firmware for every affected model and release track on July 31, but installing it does not repair an existing seed. Coinkite tells owners with exposed seeds to generate a new one on patched f...
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites

Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites

Aug 01, 2026 Web Security / Supply Chain Attack
Attackers modified a JavaScript file served by advertising technology company Adform , turning it into a browser-side tool that rewrites cryptocurrency wallet addresses. Adform detected the incident on July 27, 2026, removed the malicious code, notified affected clients, and reported it to authorities. Anyone who visited a site carrying the affected script on July 27 and copied a Bitcoin, Ethereum, or Tron address may have pasted a different address inserted by the malicious code instead. Adform is telling people to clear their browser cache because the altered file may remain cached after the fix, and to check any wallet address before sending funds. Adform says the code was not designed to install software or establish persistence and operated only while an affected page remained open. The captured sample also rewrites addresses entered directly into form fields, so clipboard copying was not the only path to replacement. The public timeline is unresolved. Adform's noti...
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Aug 01, 2026 Vulnerability / Enterprise Security
Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449 , carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could result in arbitrary code execution in the context of the current user without requiring any user interaction. The update also resolves another high-severity flaw ( CVE-2026-48448 , CVSS score: 8.6) stemming from SQL injection that could pave the way for arbitrary file reads. "This update addresses critical vulnerabilities that could result in arbitrary code execution and arbitrary file system read," Adobe said in an advisory. The company noted that it's not aware of any of the flaws being exploited in the wild. Both shortcomings have been addressed in ACC v7: 7.4.3 build 9398 for W...
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

Aug 01, 2026 Malware / Cyber Espionage
A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake , a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report. Researchers track the operation as CaptiveCrunch and attribute it to Storm-2945 . It assesses Storm-2945 to be an operational sub-cluster of Midnight Blizzard , also known as APT29 and Cozy Bear. The U.S. and U.K. governments attribute the broader actor to Russia's Foreign Intelligence Service (SVR). On the compromised networks ReliaQuest investigated, the captive portal gateway also served as the DNS resolver assigned to connected devices. Administrative control of that gateway let the attackers forge Domain Name System (DNS) answers and redirect the resulting traffic. They could then redirect a laptop's automatic connectivity check to a fake browser or operating system update. Some pages use ClickFix instructions that tell victims to open a termina...
Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk

Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk

Jul 31, 2026 Malware / Threat Intelligence
A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, since January 2025. These targeted organizations operate across several sectors, such as healthcare, research, government offices, ministries of foreign affairs, logistics, law-enforcement agencies, urban planning and facilities management, and public educational establishments, per Kaspersky. The activity has not been linked to any known adversary or group. The attacks are characterized by the use of two new obfuscated backdoors the Russian cybersecurity company is tracking as OctLurk and SilkLurk , as well as a specialized utility codenamed LurkProxy to proxy network traffic. "OctLurk and SilkLurk can download and inject additional plugins to perform further malicious actions, including launching command shells, perf...
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

Jul 31, 2026 Endpoint Security / Malware
Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka . According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a link to an encrypted archive, which holds a Windows Shortcut (LNK). Executing the file triggers a multi-stage chain that involves privilege escalation, weakening Microsoft Defender protections, and downloading additional payloads. While HollowFrame is launched via a DLL side-loading pair comprising the legitimate Python binary ("python.exe") and a rogue DLL ("python311.dll"), Matryoshka comes in two variants, one which supports HTTP-based communication and command execution, and another that uses GitHub for command-and-control (C2), including beaconing, tasking, reconnaissance, file transfer, and secondary payload delivery. "Together, HollowFrame and Matryoshka gave the actor a pers...
Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies

Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies

Jul 31, 2026 IoT Security / Botnet
Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators. Researchers named the operation Fuyao and attributed it to Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China company founded in 2019. The same apps have a second job. When a box detects an HDMI signal, it usually switches to relaying other people's traffic through the owner's broadband line as a SOCKS5 exit node. With HDMI off, it goes back to waiting for ad-fraud tasks. Bitsight found the operation by registering an expired domain used as a factory backdoor and telemetry collector. Most identifiable devices reported the model name H96_MAX_V11, though Bitsight said its sinkhole view was skewed toward older models from one brand and did not establish a complete affected-model list. In one day, after filtering for devices carrying the Fuyao apps, the sinkhol...
Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined

Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined

Jul 31, 2026 Vulnerability / Browser Security
Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined. Both versions were released last month. In its latest patch for Chrome 151, released Wednesday, the tech giant resolved 370 flaws , out of which 349 were reported by Google itself. Seven of the vulnerabilities have been marked critical in severity. The development comes amid an exponential surge in vulnerability discovery, mainly fueled by the advent of large language models (LLMs) that have accelerated the process, leading to an unprecedented spike in new bug reports, so much so that issues are being flagged at a faster rate than companies can fix them. According to statistics shared by the U.S. National Vulnerabilities Database (NVD), 46,872 flaws have been recorded so far in 2026, nearing the 49,920 vulnerabilities reported for the entirety of 2025.
Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw

Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw

Jul 31, 2026 Mobile Security / Vulnerability
An academic study has disclosed a "widespread class" of security vulnerabilities impacting 4G and 5G core networks that, if successfully exploited, could trigger denial-of-service (DoS) attacks and even session hijacking, allowing an attacker to seize control of a user's network session. The findings have been released by a group of researchers from Singapore's Nanyang Technological University in a paper titled "Understanding Implicit Trust Errors in Core Carrier Networks through Multi-Agent Flaw Discovery and Analysis." The study has uncovered dozens of vulnerabilities in the signaling interfaces of LTE/5G core networks, and specifically covers two LTE implementations (Open5GS and OpenAirInterface) and five 5G implementations (Open5GS, free5GC, OpenAirInterface, SD-Core, and eUPF) across two core signaling protocols, GPRS Tunnelling Protocol Control Plane ( GTP-C ) and Packet Forwarding Control Protocol ( PFCP ). "Our research finds these vulne...
6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026

6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026

Jul 31, 2026 Phishing / Browser Security
Device code phishing - the abuse of the OAuth 2.0 device authorization grant to steal access tokens - has evolved from a niche red-team technique to an industrial-scale threat in under six months. Designed for input-constrained devices like smart TVs, printers, and so on, the device authorization login flow has been adopted by a wide range of apps and use-cases that it wasn't originally intended for - most commonly CLI logins. Researchers first described the attack vector in 2020, but it took until 2024 before nation-state actors like Storm-2372 started using it in the wild. By 2025, ShinyHunters was using device code phishing against Salesforce tenants at scale, then in February 2026, the EvilTokens kit arrived and criminal adoption skyrocketed. By April, Microsoft was reporting 10 to 15 entirely new campaigns every 24 hours . Barracuda counted 7 million attacks in four weeks . The FBI issued a standalone advisory on Kali365 , the first US federal agency PSA about a specif...
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

Jul 31, 2026 Artificial Intelligence / Cyber Attack
Palo Alto Networks' Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously. After an initial Telegram instruction, the agent found internet-facing systems and selected public exploits. The researchers recovered no further operator input in the session. The operator, tracked through the aliases knaithe and KnYuan , launched exploitation attempts against more than 460 targets using autonomous and conventional workflows. Unit 42 described seven exploit tracks. They span eight Common Vulnerabilities and Exposures (CVE) identifiers because the n8n chain combines two vulnerabilities. The DeepSeek-led attacks against Langflow and n8n failed because the exposed systems did not meet the exploits' configuration requirements. In separate manual operations, Unit 42 reported data exfiltration from three organizations through the NetScaler memory-overread flaw CVE-2026-3055 and command execution on 11...
Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations

Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations

Jul 31, 2026 Artificial Intelligence / Offensive Security
Anthropic on Thursday became the latest artificial intelligence (AI) company to reveal that three of its models, including Claude Opus 4.7, Mythos 5, and an unnamed research model, had breached three unnamed organizations during cybersecurity testing without its knowledge. The AI firm said the earliest incidents date back to April 2026, adding it made the discoveries after launching a "large-scale retrospective review" in response to a recent disclosure from OpenAI that a combination of its models escaped the sandboxed environment by exploiting a previously unreported zero-day in Artifactory to obtain internet access and break into Hugging Face's production systems with an end goal to cheat on an evaluation. "After reviewing 141,006 evaluation runs where Claude could have obtained internet access, we identified three incidents in which a model accessed the internet from within or while interacting with the evaluation environment of Irregular, one of our third-...
DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

Jul 30, 2026 Malvertising / Cryptocurrency
Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Contagious Interview campaign. The defining aspect of the attack is that bogus macOS software update screen stealthily copies an attack command to the clipboard and then prompts the victim to execute it via the Terminal app, a known technique referred to as ClickFix . "The experience is designed to induce panic," AllSecure said in a report shared with The Hacker News. "The computer appears frozen or rebooting, so a user who believes the OS has failed follows instructions they would otherwise find suspicious." The campaign is also noteworthy for its use of blockchain-hosted command-and-control (C2), with the malware extracting the live server address from an Ethereum smart contract. Thi...
ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories

ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories

Jul 30, 2026 Hacking News / Cybersecurity News
A lot of security still comes down to trusting the wrong screen. This week, that screen might be a login page, an install guide, a recruiter call, or a familiar service behaving slightly wrong. Behind it: reused credentials, exposed systems, quiet loaders, abused trust, and exploit paths that should have been harder. Some defenses improved. The loose parts still got found first. Anyway, here's the mess. The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out.
⚡ Top Stories This Week
Expert Insights Articles Videos
Cybersecurity Resources