-->
#1 Trusted Cybersecurity News Platform
Followed by 5.70+ million
The Hacker News Logo
Get the Latest News
cybersecurity

Malware | Breaking Cybersecurity News | The Hacker News

Category — Malware
Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

Sep 08, 2026 Vulnerability / Web Security
Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. "This update resolves a critical vulnerability that could result in arbitrary code execution," Adobe said , adding it's "aware that CVE-2026-75650 has been exploited in the wild targeting Adobe Commerce merchants." At its core, the flaw abuses Magento's template system through PHP code injection to generate a "Payment Transaction Failed Reminder" email, triggering code execution in the process.
BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams

BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams

Sep 08, 2026 Web Security / Phishing
Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams. The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO . It has operated out of the Indian state of Rajasthan since at least 2015, driven by two IT service providers named WeConnect Solutions LLC (previously iConnect Soft Solutions LLC) and Garage2Global. Although Garage2Global claims to be a website design, SEO, and digital marketing services provider, the cyber threat intelligence platform said it unearthed evidence indicating the company develops malicious web infrastructure used in SEO poisoning campaigns as part of the BengalSEO scam cluster. "This group utilizes its extensive SEO and web development capabilities to create and promote lure pages with multiple Black Hat SEO techniques," the DFIR Report said in a technical analysis published late last mo...
PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

Sep 07, 2026 Malware / Browser Security
Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. "Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium's own Secure Preferences integrity values," SOCRadar said . "A native-messaging tool then extends it beyond browser telemetry to host-level command execution and file management." Once installed, the PEEP "extension" agent polls its command-and-control (C2) server ("206.237.30[.]232" or " xfjcc[.]fun ") every 30 seconds over plaintext HTTP for new commands, while exfiltrating browsing history, active-tab metadata, and session cookies. It also functions as a remote access and browser monitoring toolkit that runs host commands, steals credentials, hijacks sessions...
cyber security

SANS 2026 Security Awareness & Culture Report Shows What's Next

websiteSANS InstituteSecurity Awareness / Cybersecurity
11 years of practitioner data on what it takes to keep pace with a field that keeps shifting.
cyber security

New Webinar: How AI Broke the Pyramid of Pain for Threat Detection

websitePush SecurityThreat Hunting / Phishing
Attacker tools and infrastructure are now changing at machine speed. Learn what’s changed and how to adapt.
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

Sep 07, 2026 Cybersecurity / Hacking
Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on. Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management gave outsiders useful clues before login. Add active attacks on browsers, routers, and online stores, and there’s plenty to check—even for teams that have kept up with the patches. Read the full recap for the week’s major developments, plus more research, attacks, and security news beyond what we covered last week. ⚡ Threat of the Week N-able Patches Critical N-central Flaws — N-able has released hotfixes to address two severe N-central flaws (CVE-2026-86206 and CVE-2026-86207) that could allow an unauthorized party to bypass authentication controls and gain full access to the platform. ...
Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

Sep 07, 2026 Malware / Vulnerability
Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems. According to Huntress , three unrelated incidents have been found to use diverse initial access methods, namely a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake Geek Squad refund form lure, to activate a four-stage VBScript chain that leads to rogue ScreenConnect installations. However, once the ScreenConnect instances were installed, the cybersecurity company said it observed the clients repeatedly spawning "wscript.exe" to execute VBScripts named 1.vbs, 2.vbs, 3.vbs, and 4.vbs. The incidents were observed in August 2026. The details of the three attacks are below - A social engineering attack that persuaded a user into executing Quick Assist as part of a tech support scam, after which a rogue ScreenConnect remote access client was d...
JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

Sep 07, 2026 Malvertising / Web Security
Cybersecurity researchers have unpacked JSCeal , a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities. "The payloads are protected with javascript-obfuscator , using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers," Check Point Research said in a technical report published last week. JSCeal was first documented by Check Point in July 2025, highlighting the threat actors' use of fake cryptocurrency trading sites to which unsuspecting users are redirected via malicious ads on Facebook and Google. The counterfeit sites instruct them to download bogus installers for TradingView that lead to the deployment of the malware. The activity overlaps with a threat cluster tracked under the monikers WEEVILPROXY and MeadowLocust. Malvertising campaigns distributing the malware make use of two ZIP archives delivered via PowerShell...
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

Sep 06, 2026 Malware / Endpoint Security
Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner. The company named the four programs ProManager , WinUpdate , SoftManager , and LockAppHost and  published the findings on September 2 , along with a  technical white paper . REVSTEALER has been sold as a commercial infostealer since at least February 2026, when the earliest sample was first detected on VirusTotal. The core stealer exfiltrates browser passwords and cookies, cryptocurrency wallets, gaming accounts, messaging data, and files, then reports "complete" to its server, deletes itself, and leaves no persistence. The four newly documented programs work differently. Each installs itself into the user's profile and stays there. Elastic recovered the ...
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Sep 05, 2026 Zero Day / Vulnerability
Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an  advisory published on September 5 . Sansec, which discovered the flaw and named it StyleSmuggler , said attacks started on September 4. "Sansec is publishing early because stores are being compromised right now," the company said. As of September 6, Adobe has not published an advisory, a CVE identifier, a patch, or a workaround, and its  Adobe Commerce security bulletin index  lists nothing after the August 11 update. A successful attack gives the attacker code execution on the store's server and installs a persistent backdoor. Sansec said all current versions are affected, including 2.4.9, and that it reproduced the full unauthenticated chain on clean Magento Open Source installations of 2.4.7, 2.4.8, and 2.4.9. Its ...
Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

Sep 05, 2026 Vulnerability / Web Security
Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as create privileged accounts. "Observed post-exploitation activity included delivery of Windows registry hive collection tools, Metasploit/Meterpreter-related Java payloads, and commands used to identify hosts, users, processes, and sensitive configuration data," Arctic Wolf said. The cybersecurity company told The Hacker News that the activity has targeted vulnerable PaperCut servers across the education sector, impacting organizations ranging from K-12 schools to major universities in the U.S. and Europe. Some of the identified malicious activity includes - Running discover...
New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic

New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic

Sep 04, 2026 Malware / Network Security
A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host and the ability to replace the running binary. Rapid7 Labs attributed the toolkit with medium confidence to North Korean state-sponsored actors and put the two victims in South Korea's automotive and media sectors. Command-and-control (C2) requests never reach a backend server and are erased from HAProxy's own connection counters, so neither the backend logs nor the load balancer's statistics record them. "Further evidence is necessary to make a more definitive assessment," Rapid7 said. A request for one specific image path puts the filter into C2 mode, Rapid7 said i...
Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

Sep 04, 2026 Vulnerability / Web Security
Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including executable PHP files, leading to remote code execution. (Fixed in version 6.3.314) CVE-2026-32475 (CVSS score: 9.0/9.8) - A vulnerability in Elementor Pro that allows unauthenticated attackers to upload files of any type, including executable PHP files, leading to remote code execution. (Fixed in version 4.2.2) As with arbitrary file upload vulnerabilities of this kind, an attacker can leverage them to write a PHP web shell to the site and execute arbitrary code, which can then be abused to create administrator accounts, exfiltrate data, or seize control of the entire WordPress site. It...
ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories

ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories

Sep 03, 2026 Hacking News / Cybersecurity News
The worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click “Allow.” Why break in when someone might open the door? That idea runs through this edition. Attackers use real tools, fake login pages, old account links, and software guides that point to unsafe downloads. One wrong letter in a web address can be enough. There is also ransomware, stolen ID data, hidden attack servers, and weak settings that should have been fixed long ago. Here’s the full list. The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out.
BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory

BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory

Sep 03, 2026 Cybercrime / Artificial Intelligence
Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts. "Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial assets," Group-IB malware analysts Julio Guapo Menezes and Miguel Salazar said in a technical report. "The framework exhibits high operational maturity, utilizing a modular architecture and stealth techniques that allowed some samples to remain fully undetectable on VirusTotal at the time of analysis." BraZetsu is a portmanteau of "Brazil" and "Zetsu," a fictional character from the Japanese Manga series Naruto who is known to operate as a threat from the shadows. The naming is inspired by the fact that the initial access tool stealthily infiltrat...
Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks

Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks

Sep 03, 2026 Malware / Web Security
Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads. According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government departments, technology companies, and hotels since February 2026. "The technique's appeal is that node.exe (the binary that runs Node.js) is a legitimate, signed developer tool," the Broadcom-owned cybersecurity division said in a report shared with The Hacker News. "The attacker's malicious code lives in interpreted scripts rather than in a binary, making it less likely to trigger signature-based detection, while a registry Run key entry can relaunch the payload at every login." In one intrusion observed between March 23 and July 25, 2026, targeting an unspecified Asian technology company, attackers downloaded the official Node.js installer from nodejs[.]org and used the t...
Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means

Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means

Sep 03, 2026 Malware / DevOps
In early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for credentials across 469 locations across developer environments , Continuous Integration/Continuous Deployment (CI/CD) tooling, cloud configurations, and even AI tool configs. Earlier variants of the infostealer worm only checked 189 paths. The jump says a lot. Attackers have stopped trying to break trust relationships and started using the credentials that already make those relationships work. Software supply chains have always depended on trust.  Developers trust package registries. Organizations trust maintainers. CI/CD systems trust the credentials and identities they're given. Applications trust the dependencies they pull down during a build.  Attackers realized they don't need to break any of that. They just needed to find where the credentials and standing privileges already sit. This is what is driving the current focus on software supply ...
Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone

Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone

Sep 03, 2026 Spyware / Mobile Security
The iPhone belonging to a member of Serbia's student protest movement was infected with NSO Group's Pegasus spyware , according to new findings from the Citizen Lab in collaboration with the SHARE Foundation. "Our analysis confirmed that an iMessage zero-click exploit was used to infect the device with NSO Group's Pegasus spyware," the Citizen Lab said . "We found high-confidence indicators of infection from a period across December 2025 – January 2026; however, this does not preclude the possibility of additional infections." It's assessed that the zero-click exploit used in the attack targeted Apple iMessage, and has been addressed by Apple with iOS 18.4.1 , which was released in April 2025. The discovery comes in the aftermath of Apple sending a new set of threat notifications to customers whom it suspected may have been targeted by mercenary spyware attacks. The alerts were sent to an unspecified number of users in 110 countries. In a...
Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

Sep 02, 2026 Malware / Social Engineering
An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers. "The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users," Microsoft said . The installers, once launched, deploy malware that's capable of setting up persistence, weakening security protections, and communicating with attacker-controlled infrastructure. The activity has resulted in victims spanning healthcare, manufacturing, gaming, technology, logistics, government, and education sectors. The Windows maker has assessed with moderate confidence that the campaign is consistent with a Chinese threat cluster dubbed Silver Fox (aka Yinhu), which has a track record of using spoofed vendor download pages to distribute Gh0st RAT and ValleyRAT (a...
Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages

Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages

Sep 02, 2026 Web Security / Malware
A Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run by Brazilian government and educational institutions, and using them to divert visitors to attacker-controlled pages promoting online gambling and sports betting. Check Point Research said it has tracked the campaign since mid-2025. The modules reverse-proxy visitors to a set of phishing pages while the traffic still appears to originate from the legitimate domain. The site's own security headers are stripped, allowing the injected content to run freely. Those pages pose as trusted app stores including Google Play, Microsoft Store, and Amazon, and push online gambling and sports betting behind that facade. Check Point said the likely goal is search engine optimization (SEO) manipulation at scale, with compromised high-reputation domains, many of them Brazilian government sites, chained together to inflate search rankings. AN...
BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access

BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access

Sep 02, 2026 Network Security / Supply Chain Attack
Virtualizor said hackers used a Border Gateway Protocol (BGP) hijack to divert Softaculous traffic. The hackers then used the diverted update traffic to deliver a malicious Virtualizor package to some installations. A hosting-provider account separately said 5 of its 34 checked Virtualizor hypervisors sustained root-level compromise. The incident window ran from approximately August 28 at 20:57 Coordinated Universal Time (UTC) to August 30 at 06:10 UTC. Virtualizor said every operator should check its servers because the company has no affected-version range or definitive list of installations that received the package. Virtualizor released Patch 9 with a Security Analyzer on September 1, but the vendor said cryptographic package signing remained future work. Operators should run the official scanner, rotate and restrict application programming interface (API) credentials, and audit each server for persistence and unauthorized access. "This affected a handful of servers rat...
Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control

Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control

Sep 02, 2026 Malvertising / Mobile Security
Cybersecurity researchers have disclosed details of a new Android banking trojan called StreamRat that was promoted to Spanish-speaking users through a fake television-streaming campaign on Meta and can give operators near-complete control of infected devices. ThreatFabric said the campaign's advertisement focused on Spain and reached an estimated 570,950 Meta accounts in the European Union that saw it at least once, with totals for infected devices and confirmed victims remaining unreported. Device takeover requires the victim to grant a succession of controls after sideloading the Android Package (APK). Users should stop the installation when a streaming app requests system controls unrelated to streaming. "There is little doubt that StreamRat is a new and technically sophisticated threat, developed by individuals with prior experience in the Android malware ecosystem," ThreatFabric said in its  StreamRat analysis . ThreatFabric did not attribute the campaign t...
⚡ Top Stories This Week
Expert Insights Articles Videos
Cybersecurity Resources