-->
#1 Trusted Cybersecurity News Platform
Followed by 5.70+ million
The Hacker News Logo
Get the Latest News
cybersecurity

Malware | Breaking Cybersecurity News | The Hacker News

Category — Malware
FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails

FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails

Oct 08, 2026 Data Breach / Cyber Espionage
Hackers tied to a Chinese cybersecurity company stole email from government organizations, law enforcement agencies, healthcare systems, and religious institutions in Southeast Asia, the FBI and agencies in 6 other countries said on October 8. The company, Integrity Technology Group , has been sanctioned by the U.S. and the UK. The hackers scanned websites for flaws using a tool containing more than 1,300 scripts, guessed passwords for Microsoft 365 and Exchange accounts, and copied mailboxes using tools designed to collect mail. The hackers have been breaking into networks since at least mid-January 2021, according to the agencies'  joint advisory . It describes the hacking in the present tense but provides no date for any theft and does not specify how many organizations were breached. The same hackers targeted U.S. government services, critical manufacturing, healthcare, and IT organizations, along with U.S. law enforcement, education, and religious groups. Organizations ...
ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories

ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories

Oct 08, 2026 Hacking News / Cybersecurity News
The crooks have trust problems of their own. One ransomware affiliate decided to keep the profits for himself. Elsewhere, an attacker left a server exposed, complete with tools and traces of an intrusion. Apparently, keeping things secure is a problem on both sides of the fence. The rest of the week isn't much more reassuring. Malicious code turned up in developer packages and extensions that looked harmless. Familiar online services helped phishing emails appear legitimate. A basic file upload flaw gave attackers a way in, while weak session cookies made impersonation far too easy. Even AI assistants are getting their own instructions hidden inside phishing messages now. What's interesting is the gap between effort and results. Some attacks involve several stages, careful timing, and plenty of tricks. Others get surprisingly far because of a bad design choice or something nobody bothered to check. Both seem to be working well enough. Anyway, here's what else turned u...
UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML

UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML

Oct 08, 2026 Malware / Cyber Espionage
The Russia-aligned threat actor known as UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN . According to TrendAI, the malware has been put to use in attacks targeting Ukrainian government personnel. The cybersecurity company is tracking the cluster under the name Earth Sirrush (previously SHADOW-EARTH-065). ASHVEIN, which its developers internally refer to as "TelemetryBrowser," brings together credential theft, surveillance, and remote-control capabilities. Its functionality includes credential theft from Chrome and Firefox, GDI-based screenshot capture, file enumeration and retrieval, PowerShell remote shell execution, system fingerprinting, and encrypted command-and-control (C2) communications. "ASHVEIN also hides tasking inside invisible HTML elements," TrendAI said . "Some variants use a GitHub-based dead drop resolver as a fallback mechanism, while delivery methods inclu...
cyber security

New Priorities for Critical Infrastructure: A Nation-State Threat Roundtable

websiteSANSCritical Infrastructure / Cybersecurity
Experts from SANS Institute, FirstEnergy, MITRE and Dragos unpack what leaders should prioritize next.
cyber security

AI adoption is outpacing IT visibility

website1PasswordSaaS Security / AI Governance
Individual dashboards only show part of the story. Learn how IT can get a unified view of AI spend and usage.
16 Malicious Firefox Extensions Pose as Rabby and OKX Wallets to Steal Recovery Phrases

16 Malicious Firefox Extensions Pose as Rabby and OKX Wallets to Steal Recovery Phrases

Oct 08, 2026 Browser Security / Malware
Cybersecurity researchers have discovered a cluster of 16 malicious Mozilla Firefox extensions that are capable of stealing cryptocurrency wallet recovery phrases and private keys. "The extensions masquerade as wallet portals, desktop utilities, and browser tools, but their code intercepts recovery phrases and private keys during wallet import flows and attempts to send those secrets to attacker-controlled Cloudflare Workers," Socket researcher Joseph Edwards said in an analysis. The names of the extensions are below - view-focus-bright@webtools.co@6.12.2 quick-track-nest@tabtools.co@8.1.18 vibe-kit-tool@fasttools.co@9.21.9 edge-hub-snap@protools.net@4.12.24 core-hub-peak@neattools.example@8.24.21 sipoo-grozza@browserweb.com@2.1 mozart-seo@webtools.com@1.4 clean-file-bar@neattools.com@4.21.8 clean-net-timer@plugify.example@4.17.1 manager-square@webtools.com@1.4 manager-course@webtools.com@1.4 val-andrew@browserweb.com@1.4 manag...
Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

Oct 08, 2026 Artificial Intelligence / Cloud Security
The npm package known as " tensorlake ," a TypeScript software development kit (SDK) for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack. The malicious version 0.5.144 "contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code," Socket said . Version 0.5.144 is no longer available for download from the npm package registry. An analysis of the compromised release shows that it contains a preinstall hook designed to launch a JavaScript file ("package/lib/setup.mjs"), an obfuscated loader that launches the main credential-stealing and self-propagating worm ("package/lib/Math_Symbol.js") using the Bun runtime. The stealer malware is designed to harvest credentials across local files, CI environments, Kubernetes, and Vault sources. It also drops the HackBrowserData binary, exfiltrate...
⚡ Top Stories This Week
Expert Insights Articles Videos
Cybersecurity Resources