-->
#1 Trusted Cybersecurity News Platform
Followed by 5.70+ million
The Hacker News Logo
Get the Latest News
cybersecurity

Cybercrime | Breaking Cybersecurity News | The Hacker News

Category — Cybercrime
ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories

ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories

Aug 06, 2026 Hacking News / Cybersecurity News
Apparently, opening the thing is now enough. A repo can run before the first prompt, a package can hide among hundreds, and a harmless-looking PDF can finish the job. This week runs on cheap leverage: exposed servers, recycled bugs, poisoned agent instructions, remote-access tools dressed as support software, and trusted defaults doing attackers a favor. Nothing here is especially mystical. Just ordinary systems trusting slightly too much, slightly too early. The full list follows. The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out.
CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps

CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps

Aug 06, 2026 Vulnerability / Blockchain
Coinspect has identified CryptoJS.lib.WordArray.random() as the weak random number generator behind the Ill Bloom wallet drains . Introduced in the JavaScript cryptography library 12 years ago, the function supplied weak entropy that affected wallet apps used to generate recovery phrases. Coinspect's on-chain analysis puts the measured theft across two sweeps since late May at a lower bound of roughly $5.7 million. The blockchain security firm, which coined the Ill Bloom name in July, has now confirmed five applications that used the generator as an entropy source for recovery-phrase generation: RRWallet , which Coinspect says is discontinued. No fix. Bexo Wallet , which Coinspect says has been fixed in version 20.1.0, although the updated builds had not yet been uploaded. NanChat , which independently confirmed versions before 1.3.0 were affected. Fixed in 1.3.0. Bitcoin Libre , which Coinspect says fixed the issue in version 4, released July 2024. Milo , w...
Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service

Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service

Aug 06, 2026 Ransomware / Cybercrime
A federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison on August 5 for creating and running Ransom Cartel , the ransomware-as-a-service operation he stood up in 2021. Between 2021 and 2023, Ransom Cartel conspirators attacked at least 18 companies, including firms in California, New York and Nebraska, and others abroad, according to the Justice Department. Silnikau, a 40-year-old Belarusian national who worked under the handles "J.P. Morgan," "lansky" and "xxx," did not carry out most of those intrusions himself. He built the business around them: the locking software, the stolen credentials he bought from initial access brokers, and a hidden panel where affiliates monitored attacks, negotiated with victims and split proceeds. He ran a ratings system that rewarded the productive ones, and pushed ransom payments through cryptocurrency mixers. Sixteen years run past the 13 years and seven months handed to Yaroslav ...
cyber security

AI Threat Readiness 101

websiteWizCloud Security / AI Security
Learn the four pillars of AI threat readiness and how security teams can reduce risk faster with detection, validation, and remediation built for today's threat landscape.
cyber security

The State of Shadow AI in 2026 (And How Attackers Are Taking Advantage)

websitePush SecurityShadow AI / Browser Security
AI adoption has exploded, but every new app, integration and extension introduces new threats and risks.
Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People

Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People

Aug 06, 2026 Cybercrime / Law Enforcement
Connor Riley Moucka pleaded guilty in Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft and a related conspiracy over the 2024 breaches of Snowflake customer accounts . The intrusions reached at least 165 organizations and exposed records belonging to at least 100 million people. Moucka, 26, of Kitchener, Ontario, personally took at least $495,000 from ransoms and data sales. He is due to be sentenced on October 27 and faces a two-year mandatory minimum on the identity theft count and up to 30 years on the rest. What got the attackers in was old passwords. The credentials had been harvested years earlier by infostealer malware and never rotated, and the accounts had multi-factor authentication (MFA) switched off. No exploit, no flaw in the platform. The Justice Department has never named the company, in Wednesday's announcement or in the October 2024 indictment, identifying the victim only as a U.S. software-as-a-service (SaaS) pr...
Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures

Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures

Aug 05, 2026 Malware / Threat Intelligence
A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks. The server-side gate hides the malicious page from crawlers and sandboxes while presenting selected Mac users with a fake software download. Microsoft said the wider cluster distributed MacSync and Atomic Stealer (AMOS) ; the chain it analyzed through the gate ended in AMOS. The attack still requires the user to copy and run an obfuscated command in Terminal. That command retrieves scripts and launches an infostealer targeting credentials, browser data, authentication stores, cryptocurrency wallets, and sensitive files. Microsoft has not disclosed victim numbers, targeted sectors, or the identity of the operators. Users should not follow any website, CAPTCHA, chat, or download instruction that asks them to paste text into Terminal. Micro...
OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes

OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes

Aug 05, 2026 Cybercrime / Artificial Intelligence
OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes. To that end, it banned a coordinated network of ChatGPT accounts likely originating from Southeast Asia and operating from the city of Poipet, a region with extensive ties to scam compounds and human trafficking in the past. The cluster of accounts is said to have used OpenAI's models to create and support the operation of fake online personas, generate and translate messages sent to scam targets, create promotional content for their fraudulent schemes, and assist with day-to-day activities. The promotional content included creating social media advertisements for "chatter" jobs in Poipet specifically targeting users in Bangladesh and India that promised a base salary of $800 (and a bonus of $100 for "full attendance"), alon...
Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt

Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt

Aug 05, 2026 AI Security / Threat Intelligence
Cybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) models on underground cybercrime forums and messaging platforms. One such service, Poison Claude, claims to offer access to Anthropic's large language models (LLMs), including Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6. "Advertisements for Poison Claude explain how the service can offer the cheap tokens: by taking advantage of free bonus credits, such as the US$100 bonus credit on AWS for Bedrock accounts," Okta researchers Jeremy Kirk and Mathew Woodyard said in an analysis published Tuesday. "The service plainly states on its website that: 'We add those accounts to our pool, your request is routed to a specific account under the hood (you don't see this), and you get charged 5-15% of the official per-token price depending on the model.'" Poison Claude accepts payments in cryptocurrencies. Once a cus...
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

Aug 04, 2026 Phishing / Cybercrime
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and seize control of user accounts. "Greatness supports AiTM [adversary-in-the-middle] credential and token theft, device code phishing, and OAuth consent abuse, all from the same operator panel and shared backend infrastructure," ZeroBEC said in a report shared with The Hacker News detailing the PhaaS kit's latest capabilities. "The platform now supports AiTM token theft, device code phishing, OAuth consent abuse, and multiple target platforms, including iCloud, Yahoo, and Google Workspace. This evolution reflects the broader trend of PhaaS platforms expanding from simple credential harvesting to integrated attack ecosystems." The phishing platform was first pu...
Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access

Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access

Aug 04, 2026 Threat Intelligence / Endpoint Security
Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Monitoring and Management (RMM) programs like ConnectWise ScreenConnect. The campaign has been codenamed SMOKE#SCREEN by Securonix Threat Research. "The campaign relies on a toolkit of VBScript droppers, batch file loaders, compiled .NET executables and an HTML phishing page, all ultimately pointing to a live WsgiDAV-based staging server at 207.174.0[.]143:8080," researchers Shikha Sangwan, Akshay Gaikwad, and Aaron Beardslee said in a report shared with The Hacker News. Successful attacks culminate with a ScreenConnect agent installed and beaconing to one of three attacker-controlled relay servers, providing the attackers with persistent remote access to compromised systems. The activity has not been attributed to ...
DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT

DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT

Aug 04, 2026 Social Engineering / Cybercrime
A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims' browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager . "The first stage drops a steganographic PNG image into the browser's cache, retrieves its hidden content, and executes the second stage," SOCRadar said in a technical report. "This second stage decrypts the final payload in memory via a custom SHA-256 stream cipher in Counter (CTR) mode along with bitwise XOR using the victim's public IP address as the cryptographic key." Payloads delivered via the loader service include CountLoader , with variants for both Windows and macOS, and DeviceManager, which utilizes EtherHiding to resolve its command-and-control (C2) infrastructure and communicate with the server over HTTP or DNS tunneling. The service is assessed to be active since ea...
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

Aug 03, 2026 Vulnerability / Cybercrime
The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. In a report published over the weekend, Resecurity said it observed the INC Ransomware accelerating its activity since the beginning of August 2026, listing multiple victims on its data leak site. Per statistics listed on Ransomware.Live, the group has claimed 885 victims to date, with the most recent victim listed on August 2, 2026. The attacks are suspected to involve the exploitation of CVE-2026-15409 and CVE-2026-15410 , which could be chained to facilitate arbitrary command execution and take over susceptible devices. Fixes for the vulnerability pair were released by SonicWall in mid-July 2026. The two shortcomings are assessed to have been weaponized as zero-days, with Rapid7 noting that the attacks leveraged the foothold to extract high-value credentials, active session dat...
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

Aug 01, 2026 Vulnerability / Threat Intelligence
An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard , the Bitcoin-only hardware wallet made by Canadian firm Coinkite . A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG) instead of the STM32 hardware random number generator (RNG). Block says an attacker who can determine or sufficiently constrain the device UID, timer state, and prior RNG-call history can reproduce candidate output streams offline without accessing the device. Candidate seeds can then be checked by deriving their addresses and comparing them with public blockchain data. Coinkite shipped emergency firmware for every affected model and release track on July 31, but installing it does not repair an existing seed. Coinkite tells owners with exposed seeds to generate a new one on patched f...
Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies

Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies

Jul 31, 2026 IoT Security / Botnet
Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators. Researchers named the operation Fuyao and attributed it to Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China company founded in 2019. The same apps have a second job. When a box detects an HDMI signal, it usually switches to relaying other people's traffic through the owner's broadband line as a SOCKS5 exit node. With HDMI off, it goes back to waiting for ad-fraud tasks. Bitsight found the operation by registering an expired domain used as a factory backdoor and telemetry collector. Most identifiable devices reported the model name H96_MAX_V11, though Bitsight said its sinkhole view was skewed toward older models from one brand and did not establish a complete affected-model list. In one day, after filtering for devices carrying the Fuyao apps, the sinkhol...
6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026

6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026

Jul 31, 2026 Phishing / Browser Security
Device code phishing - the abuse of the OAuth 2.0 device authorization grant to steal access tokens - has evolved from a niche red-team technique to an industrial-scale threat in under six months. Designed for input-constrained devices like smart TVs, printers, and so on, the device authorization login flow has been adopted by a wide range of apps and use-cases that it wasn't originally intended for - most commonly CLI logins. Researchers first described the attack vector in 2020, but it took until 2024 before nation-state actors like Storm-2372 started using it in the wild. By 2025, ShinyHunters was using device code phishing against Salesforce tenants at scale, then in February 2026, the EvilTokens kit arrived and criminal adoption skyrocketed. By April, Microsoft was reporting 10 to 15 entirely new campaigns every 24 hours . Barracuda counted 7 million attacks in four weeks . The FBI issued a standalone advisory on Kali365 , the first US federal agency PSA about a specif...
ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories

ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories

Jul 30, 2026 Hacking News / Cybersecurity News
A lot of security still comes down to trusting the wrong screen. This week, that screen might be a login page, an install guide, a recruiter call, or a familiar service behaving slightly wrong. Behind it: reused credentials, exposed systems, quiet loaders, abused trust, and exploit paths that should have been harder. Some defenses improved. The loose parts still got found first. Anyway, here's the mess. The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out.
SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT

SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT

Jul 30, 2026 Cybercrime / Threat Intelligence
The Chinese cybercrime group known as Silver Fox has been observed using new drivers as part of bring your own vulnerable driver (BYOVD) attacks targeting a Japanese organization in the industrial manufacturing sector to ultimately deliver ValleyRAT (aka Winos 4.0) for persistent remote access. "In this campaign, the group combines new vulnerable-driver abuse, newly observed abuse of legitimate applications for DLL sideloading, defense evasion, and layered recovery mechanisms to keep ValleyRAT running," Cato Networks researchers Shani Kurtzberg, Tomer Pugach, Dr. Guy Waizel, Zohar Buber, Idan Tarab, and Shani Kurtzberg said in an analysis. The attack chain begins with an invoice-themed phishing lure that uses attacker-controlled content hosted on legitimate QQ and Tencent Cloud services to trigger a DLL side-loading chain via a ZIP archive that paves the way for the deployment of ValleyRAT, but not before leveraging the BYOVD technique to obtain kernel access and impai...
Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet

Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet

Jul 30, 2026 Software Security / Threat Intelligence
Amazon has tied the September 2025 hijack of the npm packages debug and chalk to North Korea. For ten months, the incident sat in the public record as crypto theft: a maintainer phished through a lookalike npm domain and a wallet-draining script pushed into at least 18 packages carrying more than 2 billion weekly downloads between them. The original Aikido and Wiz reports did not attribute the incident to North Korea. In research published July 29, Amazon Threat Intelligence assesses with medium confidence that the group behind the March 2026 axios compromise was behind it. The same group planted a trojanized file in a small package called typo-crypto in March 2025, according to Amazon, a full year before it reached axios. Analysts found it while chasing a domain registered in 2025 that surfaced during the axios investigation. Downloads were low, but the tradecraft "aligns with what we later observed in attacks on more popular packages," Amazon wrote, and the compa...
Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments

Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments

Jul 29, 2026 Cybercrime / Threat Intelligence
Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with an aim to siphon funds from international firms for more than nine years. According to Russian cybersecurity vendor F6 , the threat actors have set up clone websites of Russian companies across fertilizer manufacturers, petrochemical companies, metallurgical plants, logistics operators, and banks. The operation has been ongoing since 2017. "Most of the content on these fraudulent websites was copied from the legitimate company websites. Some also used lookalike domain names," the cybersecurity company said in an exclusive report shared with The Hacker News. "These fake websites, available in English, French, Arabic, and Russian, were used to target international customers and steal advance payments for goods that did not exist." Analysis indicates that the phony prepayment scheme has primarily singled out o...
Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity

Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity

Jul 29, 2026 Cybercrime / Law Enforcement
The Federal Security Service of the Russian Federation (FSB) on Wednesday said it charged Telegram founder Pavel Durov for allegedly facilitating terrorist activities and for failing to remove prohibited information in violation of Russian law. The principal security agency said the instant messaging platform "failed to remove numerous channels, chats, and bots on the platform that are actively used by Ukrainian special services and by terrorist and extremist organizations to plan and coordinate acts of sabotage and terrorism, mass killings, and cyber-fraud operations within the Russian Federation." These actions have resulted in numerous casualties, including among women and children, as well as significant damage amounting to billions, it added. Durov has been charged in connection with an ongoing criminal investigation under Part 1.1 of Article 205.1 of the Criminal Code of the Russian Federation for aiding terrorist activity. He has also been placed on the inte...
Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates

Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates

Jul 29, 2026 Mobile Security / Threat Intelligence
Source code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels. Hunt.io and independent researcher NetAskari traced matching control panels and certificates to 170 internet servers. They linked the framework to a fake "公安一网通办" Public Security service application targeting Android users in China. The kit supports payment-password and keystroke capture, screen recording, camera access, and phishing prompts for financial, adult-content, and government-service applications. Hunt.io's search of the preceding 30 days of telemetry found infrastructure fingerprints on 170 servers, a count that does not establish 170 infected phones, victims, operators, or confirmed command-and-control (C2) systems. The researchers found 158 servers through the AdminPro page title, HTTPS redirect behaviour, and matching response headers, then identified 12 more through a default certificate packaged with Flying Eagle. They sa...
⚡ Top Stories This Week
Expert Insights Articles Videos
Cybersecurity Resources