-->
#1 Trusted Cybersecurity News Platform
Followed by 5.70+ million
The Hacker News Logo
Get the Latest News
cybersecurity

network security | Breaking Cybersecurity News | The Hacker News

Category — network security
TP-Link Sued by Four More U.S. States Over Router Security and China Ties

TP-Link Sued by Four More U.S. States Over Router Security and China Ties

Oct 09, 2026 Network Security / Data Privacy
Four more U.S. states sued router maker TP-Link Systems on October 6, bringing the total to five, with   Texas filing a suit in February . Florida, Iowa, Montana and Nebraska allege the California company misled buyers about how secure its routers are and how separate it is from China. TP-Link  denies the claims  and says it will fight them in court. TP-Link Systems is based in Irvine, California. Until a 2024 restructuring, it was affiliated with TP-Link Technologies, a Chinese company that the suits do not name as a defendant. The complaints from  Florida ,  Montana  , and  Nebraska  do not allege that the Chinese government has obtained customers' data through TP-Link. They describe that as a risk under Chinese law. Separately, they say state-backed hackers have exploited flaws in TP-Link routers. Iowa's announcement is worded more strongly in places. Attorney General Brenna Bird's office said TP-Link firmware gives the Chinese governm...
Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access

Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access

Oct 09, 2026 Vulnerability / Endpoint Security
Security researchers have  published a full working exploit  for a pre-authentication remote code execution flaw in AnyDesk Linux that gives attackers root access before anyone approves the connection. AnyDesk patched the flaw in version 8.0.3 in June, but its  changelog  described the fix only as "fixed a bug that could lead to a crash," with no CVE assigned and no security advisory. The exploit, called AnyPwn, targets a heap buffer overflow in AnyDesk's session protocol, a remote desktop tool. The code was released on GitHub on October 8. Administrators should update AnyDesk Linux to at least version 8.0.3. The latest release is 8.1.0. What the Exploit Demonstrates The published exploit works only over direct TCP connections on port 7070. The exploit is probabilistic: the heap layout must place a target object adjacent to the overflowed buffer; otherwise, the service crashes instead of executing the attacker's command. The offsets in the published code...
Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies

Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies

Oct 09, 2026 Vulnerability / Cyber Espionage
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added five security flaws to its Known Exploited Vulnerabilities ( KEV ) catalog, following their abuse by a China-linked threat actor known as Flax Typhoon. The vulnerabilities in question are listed below - CVE-2015-3306 (CVSS score: 10.0) - An improper access control vulnerability in ProFTPD that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands. CVE-2021-3199 (CVSS score: 9.8) - A path traversal vulnerability in ONLYOFFICE Docs that can occur when JSON Web Token (JWT) is used, via a "/.." sequence in an image upload parameter and could allow for remote code execution. CVE-2023-22894 (CVSS score: 7.2) - A cleartext storage of sensitive information vulnerability in Strapi that could allow an attacker with access to the admin panel to discover sensitive user details via the query filter. CVE-2016-3081 (CVSS score: 8.1) - A...
cyber security

New Priorities for Critical Infrastructure: A Nation-State Threat Roundtable

websiteSANSCritical Infrastructure / Cybersecurity
Experts from SANS Institute, FirstEnergy, MITRE and Dragos unpack what leaders should prioritize next.
cyber security

AI adoption is outpacing IT visibility

website1PasswordSaaS Security / AI Governance
Individual dashboards only show part of the story. Learn how IT can get a unified view of AI spend and usage.
GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys

GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys

Oct 09, 2026 Vulnerability / Dark Web
A bug in GoBalance , a tool many dark-web sites use to stay reachable during attacks, lets anyone work out the secret key that controls a site's .onion address using only public information, and then take that address over. Searchlight Cyber, which  disclosed the flaw  on October 8, says an attacker who recovers the key can redirect the site's visitors to a copy of the site they control. Taking over the address does not grant the attacker access to the site's servers, database, or stored user data. How the Flaw Works An .onion address is really  a public key , so whoever holds the matching private key controls the address. To stay reachable, a site publishes a signed record, called a descriptor, that anyone on the Tor network can fetch, and GoBalance signs that record. The flaw is in the signing step. A Tor private key is  64 bytes  long, but GoBalance passed only the first 32 bytes to the signer and dropped the rest. The dropped half is the part that k...
Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments

Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments

Oct 09, 2026 Vulnerability / Network Security
Citrix has released patches for yet another critical security flaw impacting NetScaler ADC and NetScaler Gateway that could result in remote code execution or denial-of-service (DoS) under certain conditions. " CVE-2026-107406 is a memory overflow vulnerability that may lead to remote code execution or denial-of-service under specific configuration conditions," Citrix said. The vulnerability carries a CVSS score of 9.5 out of 10.0. There is no evidence that the issue has been exploited in the wild. Citrix has credited Michael Tucker, Chew Keong Tan, and Alex Bernier of the JPMorgan Chase XOR Team, along with Maxim Suhanov, for discovering and reporting the flaw. Successful exploitation hinges on the NetScaler deployments being configured as a SAML identity provider (IdP) or service provider (SP). Customers can determine if their instances meet the criteria by checking the configuration for entries like below - SAML SP: add authentication samlAction SAML IdP: ...
SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

Oct 07, 2026 Vulnerability / Network Security
SonicWall has released hotfixes for four flaws in its SMA1000 appliances, the gateways that give remote workers access to a company's network and applications. The most serious could allow an attacker without a login to send requests through the appliance and reach internal functions. SonicWall rates it 10.0 on the CVSS scale and says it has no evidence that any of the four flaws is being used in attacks. The most serious flaw, tracked as  CVE-2026-102255 , is a server-side request forgery (SSRF) bug in WorkPlace, the portal that SMA1000 users log in to. It exists due to an unintended access path through SonicWall and can be reached before authentication. An attacker who abuses that path could "reach internal functionality and perform unauthorized operations," SonicWall said in its  security advisory , dated October 6, without saying which functions. All four flaws affect SMA1000 models 6210, 7210 and 8200v on these platform-hotfix versions:
FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials

FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials

Oct 07, 2026 Cybercrime / Network Security
The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways. "The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, enabling threat actors to harvest and crack authentication data at scale," the agencies said . "Initial findings indicate attackers are continuing to scan internet-exposed Fortinet firewalls using previously obtained compromised credentials." FortiBleed was first documented by SOCRadar and Hudson Rock in June 2026, with the activity targeting thousands of Fortinet firewalls as part of a global campaign. In all, the Russian-speaking operation is estimated to have netted more than 86,644 working device credentials spanning 194 countries as of June 19, 2026. "The scale under discus...
Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan

Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan

Oct 06, 2026 Cyber Espionage / Malware
Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection. Threat actors are known to name their malicious software after a legitimate operating system component or a process as a defense evasion measure. By borrowing the name of a real binary, it may make it appear less conspicuous among other Windows processes, lend it a false sense of trust, or be overlooked by an analyst during casual inspection. However, the backdoors examined by Rapid7 have been found to go beyond imitating file names by assuming the identities of email security products like SpamSniper and ShareTech that are widely used in enterprise environments in South Korea and Taiwan. According to vendor Jiran Group, SpamSniper is advertised as "Korea's leading email security solution" that defends organizations against spam, malware, and server attacks. T...
⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests

⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests

Oct 05, 2026 Cybersecurity News / Hacking
A blank field. A public repo. One reply to an email. A box left exposed. None of this sounds dramatic, which is partly the problem. This week’s threats keep finding leverage in small things that were easy to overlook. There are actively exploited bugs in the mix, cleaner intrusion paths, smarter automation, and a long patch list waiting behind them. Some attacks are getting more capable. Others are still getting in because the basics gave way first. Here’s what mattered this week. ⚡ Threat of the Week Citrix Warns of Newly Exploited NetScaler ADC and Gateway Flaw — Citrix released security updates for a high-severity security flaw in NetScaler ADC and NetScaler Gateway that has been exploited as part of targeted zero-day attacks. The vulnerability, tracked as CVE-2026-88779, carries a CVSS score of 8.7 out of 10.0. "CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to denial-of-service under specific depl...
Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

Oct 05, 2026 Vulnerability / Malware
Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling . "Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel," Nozomi Networks said in a report published last week. "The result is a botnet whose traffic can resemble legitimate NAT-traversal activity while still supporting propagation, proxying, tunneling and denial-of-service commands." The operational technology (OT) security company said it observed a spike in attempts to exploit CVE-2021-35394 (CVSS score: 9.8), a critical remote code execution (RCE) flaw in Realtek Jungle SDK starting around September 5, 2026, with a subset of the activity delivering Cling. An analysis of the malware sample has found it to embed exploit logic for various command injectio...
New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline

New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline

Oct 05, 2026 Zero-Day / Vulnerability
Citrix has released security updates for a high-severity security flaw in NetScaler ADC and NetScaler Gateway that has been exploited as part of targeted zero-day attacks. The vulnerability, tracked as CVE-2026-88779 , carries a CVSS score of 8.7 out of 10.0. "CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to denial-of-service under specific deployment conditions," Citrix said . "The issue affects customer-managed NetScaler deployments running affected supported versions when the required preconditions are met." For successful exploitation, NetScaler ADC or NetScaler Gateway must be configured either as a SAML service provider (SP) or SAML identity provider(IdP). Customers can check if their NetScaler deployment meets the precondition by reviewing their configuration for entries matching the following - SAML SP - add authentication samlAction SAML IdP - add authentication samlIdPPro...
Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

Oct 02, 2026 Vulnerability / Enterprise Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities ( KEV ) catalog, following reports of active exploitation. The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system. "An improper limitation of a pathname to a restricted directory ('path traversal') [CWE-22] and improper neutralization of NULL byte or NULL character [CWE-158] vulnerability may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests," Fortinet said in an advisory. The vulnerability impacts the following versions - FortiMail 8.0.0 through 8.0.1 (Upgrade to upcoming 8.0.2 or above) FortiMail 7.6.0 through 7.6.6 (Upgrade to upcoming 7.6.7 or above) FortiMail 7.4.0 through 7.4.8 (Upgrade to upcoming 7.4.9 or a...
CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV

CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV

Oct 01, 2026 Vulnerability / Network Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities ( KEV ), following reports of active exploitation. The vulnerability, tracked as CVE-2026-76504 (CVSS score: 9.8), could allow an unauthenticated, remote attacker to access an affected system with the privileges of the admin user. "Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request," CISA said. Successful exploitation could allow an attacker to sidestep authentication by sending a crafted HTTP request to the API of the affected system, and gain access to the API as the admin user.
Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs

Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs

Oct 01, 2026 Vulnerability / Web Security
Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and attempt theft of configuration data. LevelBlue's Threat Hunt Operations & Research (THOR) team, which analyzed the exploitation activity across multiple customer environments, said it identified malicious NetScaler authentication events containing attacker-controlled usernames designed to weaponize CVE-2026-88771. CVE-2026-88771 (CVSS score: 9.5) is an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.  The security flaw, along with CVE-2026-88772, was disclosed last week after reports that the Dutch National Cyber Security Centre (NCSC-NL) reportedly sent a pre-notification to organizations in the Netherlands that urged organizations to shut their appliances down, citing active exploitation. As of writing, there are currently no d...
Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager

Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager

Sep 30, 2026 Vulnerability / Network Security
Attackers are exploiting a new critical zero-day flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in an  advisory  on September 30. The flaw, CVE-2026-76504 , could allow a remote attacker with no login access to use the Manager's API as the admin user. Fixed releases are available, and there is no workaround. It carries a CVSS score of 9.8 out of 10. It sits in the part of the Manager's API that handles login sessions. The Manager mishandles URI encoding in an HTTP request. A crafted request can therefore bypass an authentication rule intended to restrict access to a single API endpoint. The attacker needs no credentials, only the ability to send that request to the Manager's API. Managers exposed to the internet are at risk of compromise, according to Cisco. By default, the admin user holds the netadmin role, which is allowed to perform all operations on the device. Cisco said its Product Security I...
Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT

Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT

Sep 30, 2026 Vulnerability / Web Security
Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organizations in North America and Europe. The activity, observed by Mandiant Consulting and Google Threat Intelligence Group (GTIG) in September 2026, has targeted government, financial services, technology, education, and legal and professional services sectors. In a post shared on LinkedIn, Charles Carmakal, chief technology officer at Mandiant Consulting, said the targeted intrusions have impacted dozens of organizations, warning of "broad and opportunistic exploitation of CVE-2026-88772 and CVE-2026-88771 by a variety of threat actors in the near term." "Exploitation of CVE-2026-88772 bypasses authentication and triggers an unhandled termination of the NetScaler Packet Processing Engine (NSPPE) to establish initial root-level access," the tech giant said . The attacks have been observed weaponizing the f...
OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted

OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted

Sep 30, 2026 Vulnerability / Network Security
A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program,  OpenSSL said  on September 29 as it released fixes. DTLS , the TLS variant used for UDP traffic, resends a handshake message if no reply arrives before the timer expires. The leak or crash can happen when such a resend starts while a larger handshake message is stuck part-way through being sent. The flaw, tracked as CVE-2026-84782, is fixed in  OpenSSL 4.0.3, 3.6.5, 3.5.9 and 3.4.8 . Fixed versions for the older 3.0, 1.1.1 and 1.0.2 branches go only to customers who pay for OpenSSL's premium support. OpenSSL 3.0  stopped getting public security fixes  on September 7. OpenSSL has not said whether an attacker can cause a resend while a message is stuck, nor has it reported any attacks exploiting the flaw. DTLS is used, for example, to protect WebRTC data channels and to set up encryption keys for internet calls. Software is exposed to this fla...
Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution

Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution

Sep 30, 2026 Vulnerability / Network Security
Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-88772 (CVSS score: 9.5), has been described as a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling that's rooted in the NetScaler Packet Processing Engine (NSPPE). "Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial-of-service," the U.S. Cybersecurity and Infrastructure Security Agency (CISA) said . The issue, per watchTowr , is that NetScaler implicitly trusts the declared fragment size in the DTLS handshake header's fragment_length field (i.e., 1 byte), while the header simultaneously claims that the complete message, as denoted by the length field, is 120...
French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks

French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks

Sep 29, 2026 Data Breach / Network Security
An attacker used stolen passwords of staff at France's tax administration to take tax data on hundreds of thousands of taxpayers and businesses in June and July. Neither the tax administration nor France's national cybersecurity agency saw the data leave. The attack was not sophisticated, the agency, ANSSI, says in a  report  (in French) published on Tuesday: it worked because of weak login protection, poorly separated networks and gaps in monitoring. The tax administration, known as the DGFIP, runs France's tax website, impots.gouv.fr. The data came from E-Contact, the tool taxpayers use to message the tax administration. The stolen data covers  a little over 350,000 individuals  and  a little over 250,000 businesses , the DGFIP says. Taxpayers' own online accounts and passwords were not compromised. For individuals, the data that may have been viewed or copied includes their tax ID, contact details, family situation, reference taxable income and tax...
⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats

⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats

Sep 28, 2026 Cybersecurity News / Hacking
A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week this was: forgotten assumptions turning into live attack surface. Elsewhere, weak service accounts, old bugs, exposed systems, phishing kits, and strangely easy exploit paths kept doing useful work for attackers. Nothing exotic. Mostly things nobody expected to matter anymore. Here’s the full recap of what mattered this week. ⚡ Threat of the Week Citrix Warns of Actively Exploited NetScaler ADC and Gateway Flaws — Citrix released patches to address multiple vulnerabilities, including CVE-2026-88771 and CVE-2026-88772, that have come under active exploitation. CVE-2026-88771 is an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands, while successful exploitation of CVE-2026-88772 could allow for remote code execution or denial-of-service. CISA...
Expert Insights Articles Videos
Cybersecurity Resources