-->
#1 Trusted Cybersecurity News Platform
Followed by 5.70+ million
The Hacker News Logo
Get the Latest News
cybersecurity

Vulnerability | Breaking Cybersecurity News | The Hacker News

Category — Vulnerability
Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access

Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access

Oct 09, 2026 Vulnerability / Endpoint Security
Security researchers have  published a full working exploit  for a pre-authentication remote code execution flaw in AnyDesk Linux that gives attackers root access before anyone approves the connection. AnyDesk patched the flaw in version 8.0.3 in June, but its  changelog  described the fix only as "fixed a bug that could lead to a crash," with no CVE assigned and no security advisory. The exploit, called AnyPwn, targets a heap buffer overflow in AnyDesk's session protocol, a remote desktop tool. The code was released on GitHub on October 8. Administrators should update AnyDesk Linux to at least version 8.0.3. The latest release is 8.1.0. What the Exploit Demonstrates The published exploit works only over direct TCP connections on port 7070. The exploit is probabilistic: the heap layout must place a target object adjacent to the overflowed buffer; otherwise, the service crashes instead of executing the attacker's command. The offsets in the published code...
Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects

Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects

Oct 09, 2026 Vulnerability / Artificial Intelligence
Anthropic on Thursday unveiled OSS Scanner as an opt-in vulnerability scanner to help secure the open-source ecosystem using artificial intelligence (AI). "It's an opt-in service informed by our experience using Claude to find vulnerabilities during Project Glasswing," Anthropic said . "Projects that join will receive thorough, periodic security scans by our strongest models at no cost." Anthropic also noted that the outputs of the scanner will be fully model-generated and do not require human review or triage, thereby facilitating faster and more frequent scanning. These reports are expected to be generated by its strongest models, including Claude Mythos. The company pointed out that it expects to use a set of criteria similar to Google's OSS-Fuzz to pick projects, while emphasizing that the process may evolve over time. Project maintainers are advised to provide a short description  explaining the importance of their project in cases where "...
Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge

Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge

Oct 09, 2026 Vulnerability / Cryptojacking
Threat actors have been observed exploiting two recently disclosed flaws in the AhsayCBS backup utility to seize control of affected devices and deploy web shells and XMRig cryptocurrency miners. Details of the flaws are below - CVE-2026-105133 (CVSS v4 score: 5.5) - An improper authentication vulnerability in the checkSysPwd() function in the "com/ahsay/obs/api/ApiStructsAction.java" component. CVE-2026-105134 (CVSS v4 score: 9.3) - An operating system command injection vulnerability in the Replication Receiver component. A remote attacker could chain the two vulnerabilities to bypass authentication and execute arbitrary commands on affected systems. It's worth noting that CVE identifiers for these flaws were not published until October 4, 2026. According to Huntress, exploitation efforts aimed at the two flaws began on October 7, 2026, at 11:20 p.m. UTC, with unidentified threat actors weaponizing them to achieve remote code execution on impacted hosts...
cyber security

New Priorities for Critical Infrastructure: A Nation-State Threat Roundtable

websiteSANSCritical Infrastructure / Cybersecurity
Experts from SANS Institute, FirstEnergy, MITRE and Dragos unpack what leaders should prioritize next.
cyber security

AI adoption is outpacing IT visibility

website1PasswordSaaS Security / AI Governance
Individual dashboards only show part of the story. Learn how IT can get a unified view of AI spend and usage.
Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies

Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies

Oct 09, 2026 Vulnerability / Cyber Espionage
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added five security flaws to its Known Exploited Vulnerabilities ( KEV ) catalog, following their abuse by a China-linked threat actor known as Flax Typhoon. The vulnerabilities in question are listed below - CVE-2015-3306 (CVSS score: 10.0) - An improper access control vulnerability in ProFTPD that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands. CVE-2021-3199 (CVSS score: 9.8) - A path traversal vulnerability in ONLYOFFICE Docs that can occur when JSON Web Token (JWT) is used, via a "/.." sequence in an image upload parameter and could allow for remote code execution. CVE-2023-22894 (CVSS score: 7.2) - A cleartext storage of sensitive information vulnerability in Strapi that could allow an attacker with access to the admin panel to discover sensitive user details via the query filter. CVE-2016-3081 (CVSS score: 8.1) - A...
GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys

GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys

Oct 09, 2026 Vulnerability / Dark Web
A bug in GoBalance , a tool many dark-web sites use to stay reachable during attacks, lets anyone work out the secret key that controls a site's .onion address using only public information, and then take that address over. Searchlight Cyber, which  disclosed the flaw  on October 8, says an attacker who recovers the key can redirect the site's visitors to a copy of the site they control. Taking over the address does not grant the attacker access to the site's servers, database, or stored user data. How the Flaw Works An .onion address is really  a public key , so whoever holds the matching private key controls the address. To stay reachable, a site publishes a signed record, called a descriptor, that anyone on the Tor network can fetch, and GoBalance signs that record. The flaw is in the signing step. A Tor private key is  64 bytes  long, but GoBalance passed only the first 32 bytes to the signer and dropped the rest. The dropped half is the part that k...
⚡ Top Stories This Week
Expert Insights Articles Videos
Cybersecurity Resources