-->
#1 Trusted Cybersecurity News Platform
Followed by 5.70+ million
The Hacker News Logo
Get the Latest News
cybersecurity

cyber espionage | Breaking Cybersecurity News | The Hacker News

Category — cyber espionage
Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development

Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development

Aug 10, 2026 Cyber Espionage / Artificial Intelligence
North Korea's state hackers are no longer content to type prompts into public chatbots. One of the country's main espionage groups has begun running artificial intelligence (AI) offline on its own servers, connecting document-search tools to files in its possession, and collecting the software parts needed to build AI into its malware. South Korean security firm Genians says it uncovered the setup after months of tracking and log analysis on infrastructure tied to Kimsuky, a hacking unit under North Korea's Reconnaissance General Bureau. Genians found no evidence that the group had trained an AI model of its own, and the firm does not offer that as reassurance. It describes an actor in a "research and knowledge acquisition" stage, assembling and testing existing tools rather than making new models, with the apparent aim of folding AI through the operation, from writing malware to analyzing data. For an intelligence unit that has spent years phishing governm...
Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain

Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain

Aug 05, 2026 Cyber Espionage / Threat Intelligence
Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer. The new dead drop resolver approach, observed in two trojanized npm packages "bianira-ui" and "fluid-type-ui," has been codenamed NullReceiver by OpenSourceMalware, which has described it as a "deliberate improvement on EtherHiding." The activity has been linked to North Korea. The packages are currently no longer available for download from npm. However, statistics show that they have been downloaded a few hundred times since they were first published on July 28, 2026 - bianira-ui (109 downloads), uploaded by an npm user named "npmuser1101" fluid-type-ui (587 downloads), uploaded by an npm user named "npmuser3002" EtherHiding was first publicly documented by Guardio Labs in October...
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

Aug 01, 2026 Malware / Cyber Espionage
A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake , a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report. Researchers track the operation as CaptiveCrunch and attribute it to Storm-2945 . It assesses Storm-2945 to be an operational sub-cluster of Midnight Blizzard , also known as APT29 and Cozy Bear. The U.S. and U.K. governments attribute the broader actor to Russia's Foreign Intelligence Service (SVR). On the compromised networks ReliaQuest investigated, the captive portal gateway also served as the DNS resolver assigned to connected devices. Administrative control of that gateway let the attackers forge Domain Name System (DNS) answers and redirect the resulting traffic. They could then redirect a laptop's automatic connectivity check to a fake browser or operating system update. Some pages use ClickFix instructions that tell victims to open a termina...
cyber security

AI Is Flooding Security with Bugs Nobody Proved

websiteSANSVulnerability / Artificial intelligence
Stephen Sims on why unproven AI findings pile up as a triage burden. Read the full SANS blog.
cyber security

Exploit Time Just Dropped From 30 Days to 30 Minutes

websiteRecoAI Security / SaaS Security
Download the 11-step checklist CISOs use to close exposure windows first.
Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts

Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts

Jul 30, 2026 Vulnerability / Web Security
South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally installed financial-security software and infect targeted visitors with SIGNBT or COPPERHEDGE backdoors. A compromised page could infect a system running a vulnerable AnySign4PC version without a prompt or user-initiated download. The Korea Internet & Security Agency (KISA) says AnySign4PC versions 1.1.4.4 through 1.1.4.6 are affected and lists version 1.1.5.0 as the fixed release. It recommends deleting vulnerable installations. AhnLab refers to two exploited products only as financial-security software A and I. Its report does not disclose their identities, affected or fixed versions, or vulnerability identifiers. AhnLab said it identified evidence of related attacks at 72 organizations in 2026. The company also found 15 legitimate websites used as watering holes. Its investigation also foun...
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation

Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation

Jul 30, 2026 Email Security / Vulnerability
The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access (OWA), to target U.S. and European government entities, as well as the telecommunications, financial, hospitality, and aerospace sectors. The activity, which began on July 22, 2026, involves the weaponization of CVE-2026-42897 (CVSS score: 8.1), a cross-site scripting (XSS) vulnerability in OWA. It was flagged by Microsoft as having been exploited in attacks as far back as May 2026. Enterprise security company Proofpoint has attributed the activity to Laundry Bear (aka CL-STA-1114, TA488, UNK_PitStop, and Void Blizzard), which was recently attributed to the zero-day exploitation of CVE-2025-66376, an XSS flaw in Zimbra's Classic UI, since at least July 2025 before it was patched four months later. In these attacks, the threat actors sent out messages from adversary-controlled P...
⚡ Top Stories This Week
Expert Insights Articles Videos
Cybersecurity Resources