-->
#1 Trusted Cybersecurity News Platform
Followed by 5.70+ million
The Hacker News Logo
Get the Latest News
cybersecurity

network security | Breaking Cybersecurity News | The Hacker News

Category — network security
BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access

BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access

Sep 02, 2026 Network Security / Supply Chain Attack
Virtualizor said hackers used a Border Gateway Protocol (BGP) hijack to divert Softaculous traffic. The hackers then used the diverted update traffic to deliver a malicious Virtualizor package to some installations. A hosting-provider account separately said 5 of its 34 checked Virtualizor hypervisors sustained root-level compromise. The incident window ran from approximately August 28 at 20:57 Coordinated Universal Time (UTC) to August 30 at 06:10 UTC. Virtualizor said every operator should check its servers because the company has no affected-version range or definitive list of installations that received the package. Virtualizor released Patch 9 with a Security Analyzer on September 1, but the vendor said cryptographic package signing remained future work. Operators should run the official scanner, rotate and restrict application programming interface (API) credentials, and audit each server for persistence and unauthorized access. "This affected a handful of servers rat...
Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

Sep 02, 2026 Vulnerability / Network Security
SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks. The vulnerabilities , discovered internally by SonicWall's William Perry and Adam Babis, are listed below - CVE-2026-83548 (CVSS score: 10.0) -  A pre-authentication SSRF vulnerability in the Appliance Work Place interface that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations. CVE-2026-83549 (CVSS score: 7.8) - A post-authentication operating system command injection vulnerability in the Appliance Management Console (AMC) that could allow a remote authenticated attacker as administrator to execute arbitrary commands under specific conditions, leading to remote code execution. SonicWall said it has "investigated a case indicating the active exploitation of the vulnerabilities," suggesting th...
Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

Sep 02, 2026 Vulnerability / Network Security
Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnerability in question is CVE-2026-9586 (CVSS score: 9.3), a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3 (104997) that can allow attackers to remotely execute arbitrary code as the PostgreSQL superuser without credentials. Sangoma released patches for the flaw in Switchvox 8.4.0.2 on July 14, 2026. "An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization," according to a description of the flaw on CVE.org. "An unauthenticated remote attacker can execute arbitrary SQL statements against the backend Postg...
cyber security

Shadow AI Agents Are Multiplying. Here's How to Find and Secure Them

websiteNudge SecuritySaaS Security / AI Security
Learn how eight common discovery approaches work, what they find, and what they don’t.
cyber security

Gartner: 70% of SOCs Will Pilot AI Agents. Only 15% Will See Results

websiteProphet SecurityAI SOC / Cybersecurity
Here are Gartner’s key questions to ask when pressure-testing AI SOC vendors in production.
⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More

⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More

Aug 31, 2026 Cybersecurity / Hacking
The boring parts caused most of the trouble. A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. Old bugs formed new attack chains. Even an AI agent decided its assigned task was optional. Elsewhere, fake apps, helpful support calls, cheap banking kits, exposed systems, and weak defaults kept things moving. Different attacks, same useful mistake: something familiar was trusted without a second look. Here is the week... ⚡ Threat of the Week U.S. Disrupts Chinese Proxy Network Enabling Cyber Espionage — The U.S. Federal Bureau of Investigation (FBI) disrupted infrastructure associated with a technical quartermaster who sold reconnaissance, proxy management, and operational routing capabilities for Chinese cyber espionage activities. The QTYF group is said to have created and operated the QScan and QTRouter frameworks, which have been used to target U.S. critical infrastructu...
China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs

China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs

Aug 31, 2026 Cyber Espionage / Network Security
A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linux management hosts used to route, authenticate, and manage high-value networks. Sygnia, the incident response firm that investigated the intrusion, said the actor turned the compromised routers into collection platforms, capturing network traffic, harvesting credentials, and suppressing the logging and telemetry that defenders rely on to reconstruct an attack. The firm assessed that the hacker group used its foothold to explore paths to connected high-value environments, including critical infrastructure. However, activity against those networks was limited to scanning and connection attempts rather than confirmed compromise. Controlling the routers gave the actor a vantage point over traffic moving through trusted network paths, Sygnia said. "...
TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor

TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor

Aug 30, 2026 Social Engineering / Malware
Microsoft has disclosed details of a new ClickFix variant, dubbed TerminalFix , that aims to trick users into running a malicious command in Windows Terminal or PowerShell. "While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the same technique but direct users to Windows Terminal or PowerShell instead, increasing the likelihood that complex, multi-line scripts execute successfully," Microsoft security researchers Sagar Patil, Suriyaraj Natarajan, and Parasharan Raghavan said in an analysis published this week. The campaign, targeting organizations across multiple sectors, leverages compromised websites as a starting point to serve fake Cloudflare CAPTCHA verifications that prompt unsuspecting site visitors to copy and execute a malicious PowerShell command. The attack chain, per the Windows maker, is a sophisticated multi-stage process that leverages DLL sideloading, steganographic payload extraction, extensive ...
Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network

Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network

Aug 28, 2026 Data Breach / Ransomware
Berlin's state government has confirmed that it is the target of an extortion attempt following the August compromise of the city's state administrative network, and said it will not meet the extortionists' demands. The same statement disclosed that forensic work had found further data outflows in the portfolio of the Senate Department for Mobility, Transport, Climate Protection and Environment, with the exfiltration dated between August 7 and August 12, 2026. Scope and content are still being examined, and the Senate Chancellery said personal or other non-public data cannot be excluded from what was taken. The department first reported an outflow on August 7, the Senate Chancellery said in response to questions, seven days before it was cut off from the network on August 14. Berlin has published no figure for how much left the network. The only itemized account in circulation is the attackers' own, a leak-site post indexed on August 28 that claims 5.79 terabyt...
Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers

Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers

Aug 28, 2026 Cellular Security / Encryption
Google on Thursday announced new network security protections in Android 17 to bolster connection privacy, address cellular vulnerabilities, and safeguard the privacy of users' home networks. Topping the list is support for Encrypted Client Hello ( ECH ), a privacy standard that prevents networks from eavesdropping on which websites a user is visiting. "This new privacy standard works in tandem with private DNS to obscure the domain names you visit, hiding metadata that can be used to profile you," Google's Bram Bonné and Shuaibo Huang said . "By encrypting the destination website name from the very start, ECH helps ensure that, for supported websites and apps, network providers and network snoopers can no longer easily see which websites or apps you are accessing."
Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth

Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth

Aug 28, 2026 Vulnerability / IoT Security
Security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU , including a Bluetooth Low Energy (BLE) path that can reach root on the robot's Locomotion PC. The flaws are tracked as  CVE-2026-76639  and  CVE-2026-76640 , with the first involving a network-adjacent path through chat_go and bashrunner and the second beginning from BLE proximity. An exact fixed firmware release has not been verified in any accessible Unitree guidance, leaving G1 EDU owners without a confirmed release target for either vulnerability. Laflamme said Unitree patched the cloud account-to-robot ownership check in July 2026, closing the cross-owner arbitrary-G1 path. As of the August 27 disclosure, a G1 owner could still use an account bound to their own robot to recover its Advanced Encryption Standard (AES) key. The underlying BLE issues, a write to 0xFFE2 that does not require pairing and the BSS buffer overflow,...
China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access

China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access

Aug 28, 2026 Vulnerability / Network Security
VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics ( ZBT ), each of which gives an unauthenticated remote attacker the ability to run commands as root on affected devices. The implants, named SPEAKINGSTONE and DARKLANTERN by the company's zero-day research team, are tracked as CVE-2026-74232 and CVE-2026-74233 . VulnCheck, which assigned both identifiers as a CVE Numbering Authority (CNA), rated each 9.3 on the CVSS 4.0 scoring system and 9.8 on CVSS 3.1. Both vectors record a network attack requiring no privileges and no user interaction. SPEAKINGSTONE, which runs as the service yunmgrd , sends beacons over UDP port 10000 to a hardcoded command-and-control (C2) server. Because the implant dials outward, it functions from behind NAT and ordinary egress filtering. Its protocol supports message types that execute arbitrary commands as root, exfiltrate the WAN PPPoE username and password, wri...
FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations

FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations

Aug 26, 2026 Cyber Espionage / Critical Infrastructure
The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country. The activity has been attributed to a Chinese state-sponsored group known as QTFY, employed by Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司).  "Among the targets of QTFY are the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the U.S. Senate," DoJ said. Damon Rouse, a security researcher at Lumen Black Lotus Labs who has been tracking the activity for over the past 18 months, told The Hacker News that the digital quartermaster has been active since May 2018. Nanjing counts both China's Ministry of State Security (MSS) and the People's Liberation Army (PLA) among its customers. ...
Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler

Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler

Aug 26, 2026 Malware / Cyber Espionage
Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore , an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC). Group-IB, in a new analysis published today, described the cyber espionage actor as among the most active Iranian APT groups in 2026. Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Screening Serpens, Smoke Sandstorm, Subtle Snail, and UNC1549) is assessed to be linked to Tortoiseshell (aka Imperial Kitten and Unyielding Wasp), which is part of the Charming Kitten (aka Eclipsed Wasp) cluster. Tortoiseshell is known to be active since at least July 2018, mainly targeting defense, aerospace, IT service providers, and military organizations in the Middle East and the U.S. Nimbus Manticore also has a history of orchestrating its own version of the Dream Job campaign to deliver malware under the pretext of job opportunity-themed social engine...
Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine

Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine

Aug 26, 2026 Artificial Intelligence / Security Operations
The SOC we've always known was built around a model that guarantees most of the alert queue will never receive analyst review. There's never time. In a traditional SOC, the typical progression follows a well-known pattern: an alert arrives; a detection engine assigns a severity score. The issue then waits for a human to decide if it should escalate to an investigation. Given the volume of network telemetry in the security stack, the queue is an unavoidable result of humans as the investigative layer. Long alert queues also force security teams to decide which signals to analyze before they even know what those signals represent. Threat hunting has always addressed security questions via an alternative approach: start with a hypothesis about attacker behavior, search the available evidence, then prove or disprove it. The sequence is powerful, but it hits the same wall: human capacity. Agentic security operations change the paradigm. The SOCs now being built are predica...
New SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode

New SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode

Aug 26, 2026 Malware / Threat Detection
An independent malware researcher has documented a previously unreported Windows backdoor, dubbed SLEEPWALKER , that stays inert in memory until a specifically crafted network packet reaches the machine and then runs commands written in a 23-instruction language of its own design. The sample is an unsigned 64-bit Windows dynamic-link library (DLL) of 59,904 bytes, built to be side-loaded into ERAAgent.exe, the Windows executable for ESET Management Agent. It impersonates Microsoft's dpapi.dll, exporting the same seven data protection functions as the genuine system library, and carries a version resource copied from ESET Management Agent. There are no domains, IP addresses or URLs built into the file, and it makes no outbound connection of its own, so an infected host can look clean to tooling that watches for connections to known-bad infrastructure. Commands arrive as bytecode rather than readable text, so recovering the encryption key yields opcodes in a format that...
A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

Aug 25, 2026 AI Security / Vulnerability
Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden instructions inside the model itself. The findings were shared with The Hacker News ahead of publication, and the report says Oasis Security reported them to NVIDIA's Product Security Incident Response Team (PSIRT) beforehand. The research carries no CVE identifier. No exploitation has been reported as of August 25, 2026. Oasis Security's head of research, Elad Luz, told The Hacker News that NemoClaw v0.0.35 fixed the issue on macOS and Linux. There is no fix on the Windows and WSL path, according to Luz, where v0.0.34 added a Windows installation that carries a warning instead. NemoClaw is NVIDIA's open source reference stack for running agents such as OpenClaw inside its OpenShell sandboxes, and Ollama is one of its supported local inference backends. The report des...
E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands

E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands

Aug 25, 2026 Malware / Social Engineering
Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers ( DDRs ) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE . While threat actors are known to abuse legitimate services to point to additional command-and-control (C2) infrastructure and blend in with regular network traffic, the development marks the first time this unusual technique has been spotted in the wild. An FTP banner is a welcome message or text string that an FTP server sends to a client immediately upon connection. The mechanism allows "malware stagers to fetch commands directly from the protocol's initial response," SOCRadar said in a technical report. The modus operandi was first highlighted by the MalwareHunterTeam early last month.  However, it's worth noting that the method is a lot less stealthy than traditional web-based DDRs, as security controls are likely to flag FTP connections ...
Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

Aug 25, 2026 Vulnerability / Enterprise Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-21962 (CVSS score: 10.0), allows an unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in. Successful exploitation of the flaw can lead to unauthorized access to the instances or modification of critical data. "Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion, or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in accessible data," CISA said . While patches for the flaw w...
⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

Aug 24, 2026 Cybersecurity / Hacking
A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet. That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes exploit work cheaper, and researchers keep finding attacks that sound harder than they actually are. Plenty to clean up. Here’s the short version. ⚡ Threat of the Week U.S. Warns of AI-Powered Attacks on Siemens PLCs — Threat actors are using AI to write exploit scripts targeting internet-exposed Siemens S7 Series programmable logic controllers (PLCs) used across water, energy, manufacturing, and other critical infrastructure sectors, according to the U.S. government. The agencies warned: "This is not a theoretical risk—it is an active threat." The exploitation of poorly secured PLCs could result in disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, and compliance violations, not...
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

Aug 21, 2026 Malware / Threat Intelligence
Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2 4.0. "When the module loads, it locates the bundled binary, marks it executable, and launches it as a detached background process," TrendAI, Trend Micro's enterprise cybersecurity business, said in a report published Thursday. "No install hook function call is needed; a single import anywhere in the dependency graph, even a transitive one, is enough to execute the payload." The list of identified packages is below - streak-metrics-math@1.0.0,1.0.1 kit-map-vim@1.0.0 streak-map-cache@1.0.0 streak-map-kit@1.0.0 map-streak-kit@1.0.0 streak-cache-map@1.0.0 streak-calc-metrics@1.0.0 streak-calc-math@1.0.0 streak-math-abz@1.0.0 streak-metricsaz@1.0.0 streak-math-metrics@1.0.0 streak-metrica...
Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0

Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0

Aug 21, 2026 Vulnerability / Enterprise Security
Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal security review. Four of the security vulnerabilities affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, regardless of the device configuration. A brief description of each of the flaws is below - CVE-2026-20030 (CVSS score: 10.0) - An SQL injection vulnerability CVE-2026-20357 (CVSS score: 10.0) - A missing authentication for critical function vulnerability CVE-2026-20358 (CVSS score: 10.0) - An external control of file system vulnerability CVE-2026-20359 (CVSS score: 9.9) - An insufficiently protected credentials vulnerability The issues affect Cisco Crosswork Release version 7.2.1 and earlier, and have been addressed in version 7.2.1-SP. Cisco has also released fixes to remediate five vulnerabilities affecting Cisco Secure Workload, including Software-as-a-Service (SaaS) a...
Expert Insights Articles Videos
Cybersecurity Resources