-->
#1 Trusted Cybersecurity News Platform
Followed by 5.70+ million
The Hacker News Logo
Get the Latest News
cybersecurity

Malware | Breaking Cybersecurity News | The Hacker News

Category — Malware
Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

Sep 15, 2026 Malware / Cyber Espionage
Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran's intelligence service uses to spy on dissidents, journalists, and activists around the world. The malware is controlled via the Telegram messaging app and can copy a target's emails and chat messages, take screenshots, and activate the microphone to record audio. The FBI calls it HEAVYGRAM , and the U.K.'s National Cyber Security Center (NCSC) calls it CHOSEN BRICK . The  joint advisory  was published on September 15 by the NCSC , the FBI, and the Netherlands' intelligence service, the AIVD. The FBI also released an  updated analysis  of the malware that expands on a  March 2026 alert , the first to describe the campaign, with more technical detail and new indicators of compromise. The FBI attributes the malware to Iran's Ministry of Intelligence and Security (MOIS), the country's main intelligence agency, and dates th...
BambooToken Malware Uses MQTT to Control Windows and Linux Systems

BambooToken Malware Uses MQTT to Control Windows and Linux Systems

Sep 15, 2026
Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport ( MQTT ) protocol as a communication channel to control Windows and Linux systems. The emerging malware family, codenamed BambooToken , is assessed to be active since at least February 2023 and put to use in attacks targeting organizations across Asia and South America. Activity linked to the malware has been detected as recently as July 2026. Lumen Black Lotus Labs said it discovered the previously undocumented malware on VirusTotal in early 2026, with evidence pointing to a skilled threat actor that has managed to stay undetected until now. The initial access vector used to deliver BambooToken remains undetermined. "The actor used Tendyron's 'OnKey' software to sideload agents into targeted machines," Black Lotus Labs said in a report shared with The Hacker News. "Tendyron creates hardware-based tokens employed in high-se...
Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds

Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds

Sep 15, 2026 Vulnerability / Malware
With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new findings from Sysdig show that skilled human operators can move just as swiftly after gaining initial access. In one instance highlighted by the cloud security company, the threat actor pivoted from a vulnerable Marimo notebook to an SSH bastion host in eight seconds using a custom Python toolkit they "wrote and debugged by hand" without any AI agent in the loop. "Eight seconds is the kind of speed we expect to see in AI-assisted attacks," the Sysdig Threat Research Team said . "This operator got there on skill alone, and along the way walked straight past a trap that every agentic threat actor (ATA) we've profiled against this same CVE fell into. Not only can skilled human attackers move at machine speed, but they can also often better evade defenders' detections." The attack chain ha...
cyber security

AI Security's Greatest Hits

websiteWizAI Security / Cheat Sheet
Get 7 of the most widely used AI security resources in one pack. Each asset provides practical tools for securing AI apps, models, and agents.
cyber security

Free Assessment: Identify Hidden Internal Risk

websiteBitdefenderAttack Surface / Threat Detection
Discover unnecessary user access to risky tools, shadow IT, based on real user behavior.
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

Sep 15, 2026 Vulnerability / Cyber Espionage
A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE . Volexity, which is tracking the threat cluster under the moniker UTA0560 , said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026. "The emails contained a message encouraging the users to click a link that led to the website of a U.S.-based university," researchers Ankur Saini, Conor Quigley, Sean Koessel, Steven Adair, and Tom Lancaster said . "These links abused a reflected cross-site scripting (XSS) vulnerability on the website, redirecting recipients to threat-actor-controlled infrastructure hosting a multi-stage exploit chain." The exploit chain, as previously highlighted by Proofpoint, involves three separate flaws – two in Chrome and one in Windows Advanced Local Procedure Call (ALPC). It first ab...
Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries

Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries

Sep 14, 2026 Cyber Espionage / Vulnerability
A suspected Chinese threat actor tracked as Red Heron has been attributed to the rapid exploitation of a recently disclosed security vulnerability in Gitea to compromise internet-facing instances as part of a multi-national campaign. "Red Heron scanned 1,386 Gitea instances across seven countries and maintained a separate dataset of 477 Taiwan-based systems," Acronis Threat Research Unit (TRU) said in an analysis. "The activity progressed from source-code theft to persistent access, credential collection, and lateral movement, including root-level access to a three-node Proxmox cluster." The activity is said to have resulted in confirmed compromises affected organizations in Canada (2), Argentina (1), Taiwan (4), the U.S. (4), Qatar (1), and Sri Lanka (1), with the threat actor using Simplified Chinese labels to classify targets spanning defense, election, energy, aerospace, telecommunications, government, public safety, and research sectors. The Singapore ...
WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution

WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution

Sep 14, 2026 Web Security / Vulnerability
WordPress has announced it's launching an automated security review for every release of a plugin before it's distributed through the WordPress.org update API so as to analyze it for potential security issues and ensure there are no risks involved. "New plugins are reviewed before they enter the directory, but updates ship continuously after that," David Perez, WordPress Official Plugin Repository Team Co-Lead, said . "A plugin can be secure today and introduce a vulnerability, or malicious code, in a future release." WordPress said the lack of a "consistent review step" between the commit of a release and the release of a plugin to downstream users meant that it could open the door for malicious attacks. The content management system (CMS) platform noted that its automated review detected a backdoor committed to a release of a plugin with about 20,000 active installations on July 28, 2026. Because the release was within a cooldown window, ...
⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits

⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits

Sep 14, 2026 Cybersecurity / Hacking
AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job. Some models are also crossing lines on their own. That is not a great combination. The rest of the week is more familiar: old bugs still working, fresh exploit chains, exposed systems, weak defaults, and simple paths that should have been harder to abuse. A few of these stories are clever. Most are just easy. Here’s what mattered this week. ⚡ Threat of the Week OpenAI Agents Behind May 2026 Attack on RubyGems — The "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to researchers. The event was driven by a cluster of OpenAI agents that engaged in en masse publication of thousands of packages to RubyGems in May and June 2026. "The swarm behaves extremely similarly to the German-wiki agents we previously found," researchers Spencer Kitts, Thomas Larsen, and Sydney Von...
Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users

Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users

Sep 14, 2026 Malware / Browser Security
A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service. The extension, named "Twitch Enhanced Viewer | JeetBot," lists HISHIMIRO/jeetbot.cc as its developer and has the following identifiers on the Google Chrome Web Store and Mozilla Firefox Add-Ons store - Chrome - pnhhdhhcadcjfckjhpmjneldiegbojfb - 30,000 users (Published on June 26, 2025) Firefox - twitchenhancedviewer@example.com - 604 users (Published on July 7, 2025) Both extensions are still available for download as of writing. The extension listing description states: "JeetBot is a modern tool for streamers and viewers who appreciate quality, convenience, and control," adding it "expands Twitch capabilities: 1080p stream for regions with constraints." "Current builds (v85.x) forward the token inline as an &auth= query parameter on a network-layer redirect ...
Claude Used to Automate Exploitation and Data Theft Across Multiple Victims

Claude Used to Automate Exploitation and Data Theft Across Multiple Victims

Sep 11, 2026 Artificial Intelligence / Cyber Operations
Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and August 2026. The threat actors, which the artificial intelligence (AI) company has branded Generative Threat Groups (GTGs), span state-sponsored groups, financially motivated criminals, commercial spyware vendors, state propaganda institutions, and politically motivated individuals. "The cybersecurity skills of AI models means that AI has collapsed the labor and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators," Anthropic said . "The use of AI went beyond simple questions and responses from a chatbot but rather involved the use of multi-agent frameworks executing reconnaissance, exploitation, and data exfiltration." Among the notable cases highlighted by Anthropic is the development of an AI-assisted workflow by...
Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection

Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection

Sep 11, 2026 Cyber Espionage / Malware
Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve. The operation has been attributed to a cyber espionage group it calls GTG-20006 (where "GTG" stands for Generative Threat Group), which aligns with broader reporting linking the cluster to Midnight Blizzard (aka APT29 and Cozy Bear). This actor is said to have developed an AI-driven process to automatically rebuild and re-deploy their toolkit if it was detected by security products, thereby undermining defenders' ability to block the artifacts via static detections. Attacks mounted by GTG-20006 have targeted military intelligence targets in Ukrainian and European governments, along with diplomatic and defense organizations and individuals connected to U.S. foreign policy. The toolkit includes a number of programs - Two Windows-based implants A mobile explo...
China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor

China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor

Sep 11, 2026 Vulnerability / Browser Security
A China-linked hacking group exploited a flaw in Sogou Input Method , one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security company Gen Digital said in  research published Thursday . The attack started with a crafted link and ended with the attacker able to do anything the logged-in user could do. Tencent, which owns and develops Sogou, fixed the flaw in April 2026. Gen found the flaw while investigating a live intrusion by UNC3569 , a group that  Google Threat Intelligence ties to China  and places in the country's hacker-for-hire scene. Google has tracked the group since 2021 and says it has targeted government, education, technology, and finance sectors, mostly in East and Southeast Asia. The backdoor it installed is GRAYRABBIT , a small program the group has used for years and that Google describes as its first step onto a machine. It gives an attacker a remote command shell, allows fil...
Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

Sep 11, 2026 Vulnerability / Malware
Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. The second flaw under exploitation is CVE-2026-20316 (CVSS score: 5.3), which could allow an unauthenticated, remote attacker to log in to an affected device using a low-privilege account to access sensitive data within susceptible systems. It can be paired with other Cisco Secure FMC vulnerabilities to elevate privileges. Cisco Talos said it identified three clusters of post-compromise activity of FMC instances associated with state-sponsored and crimeware threat act...
ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

Sep 10, 2026 Hacking News / Cybersecurity News
A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful right up until it isn’t. Different stories, same basic problem: the path in was often already there. Nothing here needed magic. Mostly access, trust, weak edges, and someone willing to keep poking. That’s the week. The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out.
Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks

Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks

Sep 10, 2026 Malware / Mobile Security
The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it, security firm Group-IB said in a report published on September 9. A work profile is a separate space that Android typically reserves for employer apps, and what's inside it is kept separate from everything in the personal space. That split hides the trojan from the banking app's own malware checks, Group-IB said, so a fraudulent payment can look unrelated to the alert already raised on the phone. It has confirmed the full chain on infected devices in Indonesia. Android's  platform documentation  says any app in the phone's main profile can start the setup for a work profile, and that the user is told what a work profile does before one is created. Group-IB said banking apps carry security code that looks for known malware on the phone. From inside a work profile, that scan does not reach the personal space wher...
CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

Sep 10, 2026 Vulnerability / Network Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities ( KEV ) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026. The vulnerabilities are listed below - CVE-2026-20079 (CVSS score: 10.0) - An authentication bypass vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. CVE-2026-19490 (CVSS score: 9.3) - An authentication bypass vulnerability in  Citrix NetScaler ADC and NetScaler Gateway when the appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy). CVE-2025-25249 (CVSS score: 7.3) - A heap-based buffer overflow ...
Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key

Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key

Sep 10, 2026 Cloud Security / Artificial Intelligence
Nearly one in ten of the internet-facing LiteLLM servers that  Wiz Research  scanned in February accepted  sk-1234 , the example admin key in LiteLLM's own setup guide. LiteLLM is an open-source AI gateway, the software a company puts between its applications and the model providers it pays for. That key is the gateway's administrator credential. Anyone who holds it can read every model provider's API key stored on the server. In Wiz's tests, it also reached the cloud IAM credentials of the machine the gateway runs on. Changing the key needs no upgrade, and it closes every path in Wiz's report that depends on holding it. Where the Number Comes From Wiz ran one scan. It found 3,074 LiteLLM gateways on Shodan in February, and 294 of them accepted the key. In 191 of those 294, no key was set at all, so they would have accepted anything. The rest had the setup guide's value left in place. A second scan in August found more than 85,000 instances, but W...
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

Sep 09, 2026 Vulnerability / Cyber Espionage
Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome. The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo, PerplexedGoblin, RedBravo, TA412, Tide Castle, and Violet Typhoon) on August 28, 2026. "Within days, several other espionage-motivated clusters began using BlueMoon, the majority of which have a suspected China nexus," Proofpoint said in a report published today. "However, BlueMoon may not be exclusive to China-aligned actors, as some usage remains unattributed and there are also potentially more actors using the exploit kit." The exploit chain employs three vulnerabilities - CVE-2026-85046 , a type confusion in V8 in Google Chrome CVE-2026-87491 , an out-of-bounds...
Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

Sep 09, 2026 Malware / Artificial Intelligence
Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others.  Information stealers like Lumma Stealer or Vidar are equipped to harvest a wide range of data from compromised systems. This can include credential, session tokens, and API keys. Once the data is stolen, threat actors who have purchased access to these off-the-shelf offerings put them up for sale on underground forums in the form of stealer logs to enable follow-on attacks. "Session tokens and API keys are sought specifically by threat actors because it is often possible to replay those secrets and bypass credential-based authentication," Jeremy Kirk, director of threat intelligence at Okta, said in a report shared with The Hacker News. "Once successfully replayed, a threat actor is effectively logged in to an LLM service without actua...
F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

Sep 09, 2026 Malware / Web Security
Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7. When Apache loads any of the three appliances' own PHP scripts, the malware adds the web shell to the copy held in memory, so a check of the file on disk can come back clean. Those three scripts are the same ones F5 pointed customers to in March, when it said changes to them alone do not show a break-in. A web shell is usually a small script an attacker drops into a web server's folders to run commands through ordinary web requests. Because it sits on disk, defenders look for it by scanning files and comparing them against known-good copies. That approach does not work here. As the researchers put it, the web shell "does not need to exist in its final form on disk." The three scripts are apm_css.php3, full_wt.php3 and webtop_popup_css.php3, part of the BIG-IP APM webtop. ...
Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours

Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours

Sep 08, 2026 Artificial Intelligence / Cybercrime
Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations , with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours. Google Threat Intelligence Group (GTIG) said it has observed attackers with diverse motivations targeting proprietary AI models across healthcare, government, and media sectors, exfiltrating API credentials, and co-opting victim cloud environments to sustain unauthorized AI workloads. This highlights growing attacker focus on enterprise AI assets for espionage, extortion, and resource theft. "At this point, we can assume that all threat actors are using AI in some capacity and their operations have benefited," John Hultquist, chief analyst at GTIG, said in a statement shared with The Hacker News. "Like everyone else, we're concerned about the vulnerability problem, but AI is being applie...
⚡ Top Stories This Week
Expert Insights Articles Videos
Cybersecurity Resources