-->
#1 Trusted Cybersecurity News Platform
Followed by 5.70+ million
The Hacker News Logo
Get the Latest News
cybersecurity

Web Security | Breaking Cybersecurity News | The Hacker News

Category — Web Security
Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

Aug 29, 2026 Vulnerability / Web Security
Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to Wordfence and Patchstack, are listed below - CVE-2026-76581 (CVSS score: 9.8) - An authentication bypass flaw in the WPMU DEV Dashboard plugin that could allow an unauthenticated attacker, on sites connected to WPMU DEV with Hub Single-Sign On (SSO) enabled and mapped to an administrator, to obtain administrator access and achieve site takeover. (Affects all versions up to, and including, 5.0.1) CVE-2026-18431 (CVSS score: 9.8) - An arbitrary file write flaw in the Avada theme for WordPress that makes it possible for an unauthenticated attacker to write attacker-controlled files to the server, which, in turn, can be exploited to create and execute arbitrary PHP files, resulting in remote code exec...
Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication

Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication

Aug 28, 2026 Vulnerability / Web Security
Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening. "This vulnerability gives an unauthenticated attacker remote control over PaperCut's trusted configuration, which could be used to execute arbitrary Java code inside the application's process," Huntress researchers John Hammond and Andrew Brandt said . Specifically, an attacker can leverage an unauthenticated request to make changes to the server configuration and ultimately achieve code execution. Huntress has explained the flaw as follows - In unpatched versions of PaperCut NG and PaperCut MF,  a specifically crafted request can refer to one page that is rendered for the response, and another page that owns the component or action being executed. PaperCut's authorization check could trust the rendered page and miss the permissions required by the...
Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers

Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers

Aug 28, 2026 Cellular Security / Encryption
Google on Thursday announced new network security protections in Android 17 to bolster connection privacy, address cellular vulnerabilities, and safeguard the privacy of users' home networks. Topping the list is support for Encrypted Client Hello ( ECH ), a privacy standard that prevents networks from eavesdropping on which websites a user is visiting. "This new privacy standard works in tandem with private DNS to obscure the domain names you visit, hiding metadata that can be used to profile you," Google's Bram Bonné and Shuaibo Huang said . "By encrypting the destination website name from the very start, ECH helps ensure that, for supported websites and apps, network providers and network snoopers can no longer easily see which websites or apps you are accessing."
cyber security

Attackers Map Your Network Quietly. Controls Block 1 in 10 of Those Actions

websitePicus SecurityExposure Management
Picus Labs analyzed 338 million attack simulations. See what got through in the Blue Report 2026.
cyber security

How IT Can Reduce Credential Risk Across Every Department

website1PasswordPassword Security / Compliance
Learn how to manage credential access for every user, from your finance team to third-party contractors.
ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body

ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body

Aug 28, 2026 Vulnerability / Cyber Espionage
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting ownCloud to its Known Exploited Vulnerabilities ( KEV ) catalog following reports that a Chinese-speaking threat actor weaponized the vulnerability to target a nuclear research body in the Philippines. The vulnerability, tracked as CVE-2023-49105 (CVSS score: 9.8), is a case of WebDAV API authentication bypass that could allow an attacker to access, modify or delete any file without authentication if the username of the victim is known and the victim has no signing-key configured, which is the default configuration. Disclosed by ownCloud in November 2023, the issue impacts "core" versions from 10.6.0 through 10.13.0. It was fixed in version 10.13.1. CISA's addition of the flaw to the KEV catalog comes a couple of days after Hunt.io said it identified an open directory on the host "31.58.209[.]241," which staged custom Python scripts, o...
19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code

19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code

Aug 28, 2026 Web Security / Supply Chain
Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities. The extensions , per Socket security researcher Karlo Zanki, share similarities in code and tradecraft, with evidence indicating that the campaign may have been active since February 2024. Socket is tracking the activity under the name Superior. The modus operandi is relatively straightforward: the threat actor either acquires legitimate extensions with proper functionality or pushes a clean version that's devoid of any malware. Once the extensions begin to gather user downloads, a new version with the malicious behavior is published.
Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL

Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL

Aug 28, 2026 Vulnerability / Cloud Security
ServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring system and exploitable, in certain circumstances, by an unauthenticated attacker. The company said it deployed a security update to hosted instances and provided the update to its partners and self-hosted customers, which leaves organizations that run their own instances to apply the fixes themselves. The advisory was published on August 27, 2026, and the four vulnerabilities are listed below - CVE-2026-18885 (CVSS score: 10.0) - A code injection vulnerability in the GraphQL Composite Data API that could enable an unauthenticated user to execute arbitrary code and gain access to, or modify, instance data CVE-2026-18886 (CVSS score: 10.0) - An improper access control vulnerability in the system configuration image upload processor that could enable an unauthenticated user to create or modify instance data, resulting in privilege escala...
Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server

Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server

Aug 28, 2026 Vulnerability / Web Security
cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user. The vulnerability, assigned the CVE identifier CVE-2026-65643 , impacts all supported versions of cPanel & WHM. cPanel described the issue as a critical security vulnerability and said that an authenticated account holder who can add parked or addon domains can create arbitrary files on the server. "Successful exploitation leads to code execution as the root user, giving an attacker full control of the server," cPanel said in a notification to customers. cPanel has released the following patched versions - 11.110.0.141 or later 11.134.0.53 or later 11.136.0.37 or later 11.138.0.2 or later 11.138.1.7 or later (WP Squared) The notification names WP Squared in its patched list and does not mention DNSOnly. cPanel patched  three separate flaws in July , and ...
Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE

Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE

Aug 27, 2026 Vulnerability / Web Security
Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting servers that use a Windows filesystem. The Windows path traversal, tracked as  CVE-2026-75604  (CVSS score: 9.0), affects Next.js applications that use both the Pages Router and App Router without Cache Components when the server uses a Windows filesystem. Linux and macOS deployments are not affected. "There is no known workaround for affected windows-hosted applications. You should upgrade immediately if your server is hosted on Windows,"  Vercel said in its advisory . The fixes are available in Next.js 15.5.24 (Maintenance LTS) and 16.3.3 (Active LTS), published on August 25, 2026. Affected users can upgrade by running npm install next@15.5.24 for the 15.5 l...
CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs

CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs

Aug 27, 2026 Vulnerability / Web Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities ( KEV ) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2019-1068 - A remote code execution vulnerability in  Microsoft SQL Server that could allow an attacker to execute code in the context of the SQL Server Database Engine service account. CVE-2026-8452 - An improper restriction of operations within the bounds of a memory buffer vulnerability in Citrix NetScaler ADC and NetScaler Gateway that could lead to denial-of-service. CVE-2022-0995 - An out-of-bounds memory write vulnerability in  Linux Kernel that could allow a local user to gain privileged access or cause a denial of service on the system. CVE-2015-5287 - A privilege escalation vulnerability in  Red Hat Automatic B...
Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code

Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code

Aug 26, 2026 Vulnerability / Web Security
The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it. The flaws, tracked as CVE-2026-19913 and CVE-2026-19912 , both stem from the same unsafe deserialization in the mwEmbedLoader.php endpoint of the mwEmbed player library, which Kaltura also distributes as html5lib. Neither requires authentication or a Kaltura session token, and network access to the endpoint is the only precondition CERT/CC states. No patch is available, and CERT/CC said it was "unable to reach Kaltura to coordinate these vulnerabilities." Administrators are advised to restrict or disable external access to the endpoint and to enforce a strict allow-list for the ServiceUrl parameter that permits only legitimate backend API URLs. No exploitation had been reported at the time of writing, and neither CVE appeared in CISA...
Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests

Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests

Aug 26, 2026 AI Security / Application Security
Aikido Security has published research that recreates the Australian gym-booking incident in a synthetic environment, finding that Claude Opus 4.6, running on the OpenClaw agent harness, exploited a client-side-only booking restriction in 9 of 10 runs. The original incident was first reported by ABC News on August 10, based on chat logs and screenshots the user supplied. He had asked an OpenClaw agent running Opus 4.6 to book him into a gym class. The agent booked sessions months beyond the window the site allowed. It then tested, without being asked, whether the same API would let it cancel another member's waitlist entry. The test removed the person holding the top place and moved the user up one position. The agent told him it could not add the member back. Aikido's test system is a single-page web application backed by a GraphQL API carrying the two flaws described in the original incident. The seven-day booking window is enforced only in the frontend, and the cancel...
A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

Aug 25, 2026 AI Security / Vulnerability
Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden instructions inside the model itself. The findings were shared with The Hacker News ahead of publication, and the report says Oasis Security reported them to NVIDIA's Product Security Incident Response Team (PSIRT) beforehand. The research carries no CVE identifier. No exploitation has been reported as of August 25, 2026. Oasis Security's head of research, Elad Luz, told The Hacker News that NemoClaw v0.0.35 fixed the issue on macOS and Linux. There is no fix on the Windows and WSL path, according to Luz, where v0.0.34 added a Windows installation that carries a warning instead. NemoClaw is NVIDIA's open source reference stack for running agents such as OpenClaw inside its OpenShell sandboxes, and Ollama is one of its supported local inference backends. The report des...
24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

Aug 25, 2026 Phishing / Threat Intelligence
Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. "While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn't do harm, the threat actor’s use of npm isn't to infect developers who install it, but to use the registry and its mirrors as a safe, validated storage for the malware," OX Security researchers Moshe Siman Tov Bustan and Vitalii Chepurko said . The list of npm packages, some of which are still available for download, is below - bgzxcuite2 prezdentkxheiw egair0810 mnteckets airdzticket egypt0811 passport811 vxhjkseuiaqkb ndmushdkeqe ndmxchdjxn2 ndmfguyhoxc3 mjsdqwocvn m2fcsfyjkuxb m3fdfocdoewn @worrisome/reutil testdgdbcsd tesgfvbncsdbcv mndsxcusiwlk1 mn2adskhweox mn3sadkoiewu mn4xcouzvhus mbxcnsuwgs1 s...
Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

Aug 25, 2026 Vulnerability / Web Security
Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators. The vulnerabilities, as disclosed by Patchstack , are listed below - CVE-2026-61979 (CVSS score: 8.1) - An unauthenticated privilege escalation vulnerability stemming from signature algorithm confusion (Fixed in version 17.0.5 for the Standard edition) CVE-2026-15981 (CVSS score: 9.8) - An authentication bypass vulnerability stemming from accepting malformed signatures as valid (Fixed in version 17.0.6 for the Standard edition) "This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's openssl_verify(), causing an error return value of -1 to be evaluated as truthy and therefore treated as a successful signature verification," according to a...
Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

Aug 25, 2026 Vulnerability / Enterprise Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-21962 (CVSS score: 10.0), allows an unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in. Successful exploitation of the flaw can lead to unauthorized access to the instances or modification of critical data. "Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion, or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in accessible data," CISA said . While patches for the flaw w...
Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning

Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning

Aug 24, 2026 Malware / SEO Poisoning
Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft clients. McAfee Labs said it detected and blocked more than 6,300 attempts to access malicious sites, adding that it found lookalike gaming websites designed to mimic legitimate projects, including branding, feature lists, FAQs, installation guides, developer credits, and links to genuine GitHub repositories. Notably, one of the sites has been built using Lovable , an artificial intelligence (AI)-powered website builder, highlighting how readily available tools can further lower the barrier and make it easier to launch convincing new malicious sites. Weedhack was first documented by the cybersecurity company back in June 2026, detailing its use of SEO poisoning and YouTube to redirect traffic to the bogus domains. The attack triggers a multi-stage sequence that culminates in the deployment of JAR payloads that can ...
WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

Aug 24, 2026 Malware / Endpoint Security
Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that's used to deliver next-stage payloads and likely sell access to ransomware groups. According to findings from Gen Digital, WordlistLoader is being used to deliver Amatera Stealer (aka ACR Stealer or AcridRain Stealer) via ClearFake campaigns, which employ the ClickFix (aka FakeCaptcha) technique to dupe victims into running malicious commands under the pretext of completing CAPTCHA verification checks. "Once the visitor clicks on the 'I'm not a robot' checkbox, they're walked through the well-known ClickFix flow, where a malicious command is copied into their clipboard and the victim is instructed to paste it into the Windows Run dialog and execute it, leading to the download of WordlistLoader that ultimately results in the execution of Amatera," security researcher Vojtěch Krejsa said . The ClickFix prompts are displayed on real websites th...
UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

Aug 24, 2026 Cybercrime / Malware
Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors. The vast majority of the targets are located in Brazil, Bolivia, China, Canada, and Vietnam. Details of the threat activity came to light following the discovery of an open directory hosted at "139.180.197[.]150," which was observed communicating with one of the compromised machines. "The actor leveraged publicly disclosed vulnerabilities to gain initial access at scale," Cisco Talos said in a two-part report published last week. The actor employed a mixture of open-source offensive frameworks, including Metasploit , ysoserial , PentestGPT , DeepAudit, and multiple privilege escalation exploits to automate intrusion operations and establish persistence." UAT-10147 has been described as a threat actor that conducts search engine op...
GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

Aug 21, 2026 Vulnerability / Enterprise Security
A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-19478 (CVSS score: 9.4), a case of code injection that allows an unauthenticated attacker to modify or delete publicly accessible GitLab projects and rewrite their data under certain conditions without requiring credentials, user interaction, or obscure configuration. The following versions of GitLab Community Edition (CE) and Enterprise Edition (EE) are affected by the flaw - 18.2 before 18.11.11 19.0 before 19.0.8 19.1 before 19.1.6 19.2 before 19.2.4 In an alert released earlier this week, GitLab said the issue could be exploited via a GraphQL directive. Fixes for the flaw were rolled out in GitLab CE and EE versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11. Preemptive exposure management firm watchTowr told The Hacker News that it was able to reproduce the vulnerability within minutes of ...
New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

Aug 20, 2026 Artificial Intelligence / Data Security
Adversa AI has disclosed an attack technique that it says can cause xAI's Grok chatbot to send a user's name, approximate location, subscription tier, and the prompts from the ongoing conversation to an attacker-controlled server after the user asks it to summarize an ordinary web page. The AI security company, which has codenamed the technique "Cryptographic Context Injection ," said the transfer completed without a confirmation step and with no visible warning in its proof-of-concept demonstration. There is no patch, no CVE identifier, and no user-facing workaround, and the writeup does not report any exploitation in the wild. Asked which build was tested, Adversa told The Hacker News the target was the Grok web chat at grok.com running Grok 4.5 Fast, and that the attack was reproduced once on August 19, 2026. The writeup gives no success rate. The company said it has attempted the attack 20 times since June with a 40% success rate, and that the failures cam...
Expert Insights Articles Videos
Cybersecurity Resources