-->
#1 Trusted Cybersecurity News Platform
Followed by 5.70+ million
The Hacker News Logo
Get the Latest News
cybersecurity

Malware | Breaking Cybersecurity News | The Hacker News

Category — Malware
Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets

Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets

Sep 30, 2026 Vulnerability / Email Security
Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team. The attack exploits CVE-2026-73570 (CVSS score: 8.9), an unauthenticated operating system command injection flaw that can lead to remote code execution when Simple Network Management Protocol (SNMP) notifications are enabled and the optional zimbra-snmp package is installed. Exploitation of CVE-2026-73570 can be triggered by a specially crafted SMTP request (i.e., email against exposed Zimbra servers without requiring authentication or user interaction. The vulnerability was patched by Zimbra in July 2026 with the release of version 10.1.20. "Following successful exploitation, observed activity included deployment of JSP web shells and reverse shells, privilege escalation, persistent remote-access tooling, and memory-backed execution," the tech giant said . "Thr...
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures

Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures

Sep 30, 2026 Malware / Artificial Intelligence
Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware. Huntress, which observed the activity in late September 2026, said it marks the abuse of yet another feature in trusted artificial intelligence (AI) platforms. Prior campaigns have weaponized shared conversations with AI chatbots and malicious Claude Artifacts to distribute stealer malware and remote access trojans (RATs). Custom GPTs refer to a personalized version of ChatGPT that, as the name implies, allows users to define custom instructions, upload reference files, and enable specific skills to handle unique tasks without any coding. They are hosted on the legitimate ChatGPT website with the Custom GPT name at the top. "In the incidents we saw, victims interacted with an attacker-created Custom GPT, which was programmed to respond to their prompts with a message that includ...
Know Your Enemy: Browser-Based Attack Techniques in 2026

Know Your Enemy: Browser-Based Attack Techniques in 2026

Sep 30, 2026 Web Security / Phishing
Given that the browser is where business apps are accessed and used, it makes sense that attacks are happening there too. Most breaches today begin in a browser session. Often, they never leave it, with the entire attack chain from initial access to exfiltration playing out in the browser. Here are the six most dangerous techniques that should be on every security team's radar in 2026. 1. Phishing for credentials and sessions Modern phishing kits don't just steal passwords — they intercept live sessions. Reverse-proxy adversary-in-the-middle (AiTM) kits like Tycoon2FA, Sneaky2FA, and Evilginx relay credentials and session tokens in real time, bypassing most forms of MFA. These kits are sold as turnkey Phishing-as-a-Service platforms with anti-bot protection, dynamic lure generation, and automated session replay — reducing the barrier to sophisticated phishing to effectively zero. At the same time, phishing delivery has moved well beyond email — attackers deliver link...
cyber security

Reco Finds Four in Five Agents Run With Zero IT Oversight

websiteReco AISaaS Security / AI Security
See which agent permissions security teams aren't reviewing, and why it matters now.
cyber security

Build Your Email Security Strategy for the Agentic Era

websiteAdaptive SecurityEmail Security / Cybersecurity
Get the 2026 checklist for defending against AI phishing, compromised accounts, and human error.
Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT

Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT

Sep 30, 2026 Vulnerability / Web Security
Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organizations in North America and Europe. The activity, observed by Mandiant Consulting and Google Threat Intelligence Group (GTIG) in September 2026, has targeted government, financial services, technology, education, and legal and professional services sectors. In a post shared on LinkedIn, Charles Carmakal, chief technology officer at Mandiant Consulting, said the targeted intrusions have impacted dozens of organizations, warning of "broad and opportunistic exploitation of CVE-2026-88772 and CVE-2026-88771 by a variety of threat actors in the near term." "Exploitation of CVE-2026-88772 bypasses authentication and triggers an unhandled termination of the NetScaler Packet Processing Engine (NSPPE) to establish initial root-level access," the tech giant said . The attacks have been observed weaponizing the f...
Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor

Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor

Sep 29, 2026 Malware / Cyber Espionage
Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft. The campaigns, aimed at people and organizations tied to Ukraine, have affected more than 100 organizations since January, mostly in the U.S. and U.K. At least one computer was infected, but the number of breached organizations has not been disclosed. Security agencies in the U.S., U.K., Australia, Canada and New Zealand  said in December 2023  that Star Blizzard almost certainly works under Center 18 of Russia's Federal Security Service (FSB). The group has long stolen email passwords by posing as people its targets know. By 2023, it had already used  fake conference and event invitations  as bait, often exchanging messages with a target before sending a malicious link. Microsoft counted at least 13 larger campaigns this year, each with tens to hundreds of emails, on top of ...
⚡ Top Stories This Week
Expert Insights Articles Videos
Cybersecurity Resources