-->
#1 Trusted Cybersecurity News Platform
Followed by 5.70+ million
The Hacker News Logo
Get the Latest News
cybersecurity

The Hacker News | #1 Trusted Source for Cybersecurity News — Index Page

P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands

P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands

Oct 09, 2026 Mobile Security / Malware
Cybersecurity researchers have disclosed details of a previously unseen variant of the DarkSword iOS exploit kit called P7 DarkSword . "Compared with the variants we usually observe, P7 reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and adds two way C2 communication with the attacker's infrastructure," iVerify said in a new report published Thursday. The name "P7" is a nod to the threat actor's use of the "p7_" variable prefix in changes made to the original DarkSword code. DarkSword was first publicly documented earlier this March by Google Threat Intelligence Group (GTIG), iVerify, and Lookout, detailing its ability to target iPhones running iOS versions between iOS 18.4 and 18.7. The kit was detected in the wild in November 2025. The toolkit is engineered to chain multiple iOS vulnerabilities to escape the browser sandbox, escalate to kernel privileges, and inject the main payload into SpringBoard, t...
TP-Link Sued by Four More U.S. States Over Router Security and China Ties

TP-Link Sued by Four More U.S. States Over Router Security and China Ties

Oct 09, 2026 Network Security / Data Privacy
Four more U.S. states sued router maker TP-Link Systems on October 6, bringing the total to five, with   Texas filing a suit in February . Florida, Iowa, Montana and Nebraska allege the California company misled buyers about how secure its routers are and how separate it is from China. TP-Link  denies the claims  and says it will fight them in court. TP-Link Systems is based in Irvine, California. Until a 2024 restructuring, it was affiliated with TP-Link Technologies, a Chinese company that the suits do not name as a defendant. The complaints from  Florida ,  Montana  , and  Nebraska  do not allege that the Chinese government has obtained customers' data through TP-Link. They describe that as a risk under Chinese law. Separately, they say state-backed hackers have exploited flaws in TP-Link routers. Iowa's announcement is worded more strongly in places. Attorney General Brenna Bird's office said TP-Link firmware gives the Chinese governm...
Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access

Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access

Oct 09, 2026 Vulnerability / Endpoint Security
Security researchers have  published a full working exploit  for a pre-authentication remote code execution flaw in AnyDesk Linux that gives attackers root access before anyone approves the connection. AnyDesk patched the flaw in version 8.0.3 in June, but its  changelog  described the fix only as "fixed a bug that could lead to a crash," with no CVE assigned and no security advisory. The exploit, called AnyPwn, targets a heap buffer overflow in AnyDesk's session protocol, a remote desktop tool. The code was released on GitHub on October 8. Administrators should update AnyDesk Linux to at least version 8.0.3. The latest release is 8.1.0. What the Exploit Demonstrates The published exploit works only over direct TCP connections on port 7070. The exploit is probabilistic: the heap layout must place a target object adjacent to the overflowed buffer; otherwise, the service crashes instead of executing the attacker's command. The offsets in the published code...
cyber security

New Priorities for Critical Infrastructure: A Nation-State Threat Roundtable

websiteSANSCritical Infrastructure / Cybersecurity
Experts from SANS Institute, FirstEnergy, MITRE and Dragos unpack what leaders should prioritize next.
cyber security

AI adoption is outpacing IT visibility

website1PasswordSaaS Security / AI Governance
Individual dashboards only show part of the story. Learn how IT can get a unified view of AI spend and usage.
Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects

Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects

Oct 09, 2026 Vulnerability / Artificial Intelligence
Anthropic on Thursday unveiled OSS Scanner as an opt-in vulnerability scanner to help secure the open-source ecosystem using artificial intelligence (AI). "It's an opt-in service informed by our experience using Claude to find vulnerabilities during Project Glasswing," Anthropic said . "Projects that join will receive thorough, periodic security scans by our strongest models at no cost." Anthropic also noted that the outputs of the scanner will be fully model-generated and do not require human review or triage, thereby facilitating faster and more frequent scanning. These reports are expected to be generated by its strongest models, including Claude Mythos. The company pointed out that it expects to use a set of criteria similar to Google's OSS-Fuzz to pick projects, while emphasizing that the process may evolve over time. Project maintainers are advised to provide a short description  explaining the importance of their project in cases where "...
Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge

Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge

Oct 09, 2026 Vulnerability / Cryptojacking
Threat actors have been observed exploiting two recently disclosed flaws in the AhsayCBS backup utility to seize control of affected devices and deploy web shells and XMRig cryptocurrency miners. Details of the flaws are below - CVE-2026-105133 (CVSS v4 score: 5.5) - An improper authentication vulnerability in the checkSysPwd() function in the "com/ahsay/obs/api/ApiStructsAction.java" component. CVE-2026-105134 (CVSS v4 score: 9.3) - An operating system command injection vulnerability in the Replication Receiver component. A remote attacker could chain the two vulnerabilities to bypass authentication and execute arbitrary commands on affected systems. It's worth noting that CVE identifiers for these flaws were not published until October 4, 2026. According to Huntress, exploitation efforts aimed at the two flaws began on October 7, 2026, at 11:20 p.m. UTC, with unidentified threat actors weaponizing them to achieve remote code execution on impacted hosts...
Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies

Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies

Oct 09, 2026 Vulnerability / Cyber Espionage
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added five security flaws to its Known Exploited Vulnerabilities ( KEV ) catalog, following their abuse by a China-linked threat actor known as Flax Typhoon. The vulnerabilities in question are listed below - CVE-2015-3306 (CVSS score: 10.0) - An improper access control vulnerability in ProFTPD that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands. CVE-2021-3199 (CVSS score: 9.8) - A path traversal vulnerability in ONLYOFFICE Docs that can occur when JSON Web Token (JWT) is used, via a "/.." sequence in an image upload parameter and could allow for remote code execution. CVE-2023-22894 (CVSS score: 7.2) - A cleartext storage of sensitive information vulnerability in Strapi that could allow an attacker with access to the admin panel to discover sensitive user details via the query filter. CVE-2016-3081 (CVSS score: 8.1) - A...
The AI Velocity Paradox: Why Security Is Decades Behind AI Ambition

The AI Velocity Paradox: Why Security Is Decades Behind AI Ambition

Oct 09, 2026 Identity Security / Artificial Intelligence
As enterprises race to deploy autonomous AI agents to accelerate business, a new report reveals they are tethered to security architectures built for a different era. The " Horizons of Identity Security " report from SailPoint highlights a critical “velocity paradox,” in which organizations invest in AI-speed business operations while continuing to rely on human-speed security controls, creating a structural failure that legacy approaches cannot solve. The data shows that while businesses have spent years maturing their identity programs for human employees, those same playbooks are fundamentally broken when applied to the ephemeral, autonomous, and rapidly multiplying world of non-human AI agents. A Market Stalled at the Starting Line Despite years of investment in identity and access management, the market's overall security maturity has hit a wall. According to the report, the center of gravity remains firmly planted in the foundational stages, with a combined 6...
GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys

GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys

Oct 09, 2026 Vulnerability / Dark Web
A bug in GoBalance , a tool many dark-web sites use to stay reachable during attacks, lets anyone work out the secret key that controls a site's .onion address using only public information, and then take that address over. Searchlight Cyber, which  disclosed the flaw  on October 8, says an attacker who recovers the key can redirect the site's visitors to a copy of the site they control. Taking over the address does not grant the attacker access to the site's servers, database, or stored user data. How the Flaw Works An .onion address is really  a public key , so whoever holds the matching private key controls the address. To stay reachable, a site publishes a signed record, called a descriptor, that anyone on the Tor network can fetch, and GoBalance signs that record. The flaw is in the signing step. A Tor private key is  64 bytes  long, but GoBalance passed only the first 32 bytes to the signer and dropped the rest. The dropped half is the part that k...
Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own

Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own

Oct 09, 2026 Vulnerability / Mobile Security
Three research teams broke into Google's Pixel 10 on October 8 at Pwn2Own Ireland, a hacking contest in Cork whose rules require every target to be fully patched. The contest pays researchers to show working exploits and passes the flaws to the vendors. One of the three Pixel exploits earned Ikotas Labs $300,000, the contest's top prize, and made the team the overall winner. Trend Micro's Zero Day Initiative (ZDI), which runs Pwn2Own,  posted the results  but had not published how the three exploits work as of October 9. The wins were demonstrations on contest phones, and at least two of the three used a bug that was already known before the attempt. The  contest rules  require each entry to use bugs that are not already known to the vendor or to the organizer. An entry that uses an already-known bug, which ZDI calls a collision, can still be accepted at a lower prize. The three Pixel 10 wins, in the order they happened: Team ...
Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments

Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments

Oct 09, 2026 Vulnerability / Network Security
Citrix has released patches for yet another critical security flaw impacting NetScaler ADC and NetScaler Gateway that could result in remote code execution or denial-of-service (DoS) under certain conditions. " CVE-2026-107406 is a memory overflow vulnerability that may lead to remote code execution or denial-of-service under specific configuration conditions," Citrix said. The vulnerability carries a CVSS score of 9.5 out of 10.0. There is no evidence that the issue has been exploited in the wild. Citrix has credited Michael Tucker, Chew Keong Tan, and Alex Bernier of the JPMorgan Chase XOR Team, along with Maxim Suhanov, for discovering and reporting the flaw. Successful exploitation hinges on the NetScaler deployments being configured as a SAML identity provider (IdP) or service provider (SP). Customers can determine if their instances meet the criteria by checking the configuration for entries like below - SAML SP: add authentication samlAction SAML IdP: ...
FBI Seizes 7 Domains, Disrupts Flax Typhoon Tools Used in Critical Infrastructure Intrusions

FBI Seizes 7 Domains, Disrupts Flax Typhoon Tools Used in Critical Infrastructure Intrusions

Oct 09, 2026 Cyber Espionage / Botnet
The U.S. Federal Bureau of Investigation (FBI) and Department of Justice (DoJ) have announced the disruption of malicious tools used by a China-linked advanced persistent threat group known as Flax Typhoon. To that end, the agencies seized several domains and blocked access to platforms that were used to scan, and in some cases infiltrate, U.S. critical infrastructure. The list of seized domains is as follows - c0cc[.]cc 98aiblog[.]com 98aicai[.]com 98aicode[.]com outlook3650[.]com youtubecard[.]com linkedinns[.]net Flax Typhoon , also tracked as Ethereal Panda and RedJuliett, is associated with Integrity Technology Group, a Beijing-based company that contracts with the Chinese government. It was previously attributed to a botnet called Raptor Train that comprised thousands of compromised small office/home office (SOHO) and IoT devices. It was taken down following a U.S. court-authorized operation in September 2024. "These state-sponsored hackers co...
FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails

FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails

Oct 08, 2026 Data Breach / Cyber Espionage
Hackers tied to a Chinese cybersecurity company stole email from government organizations, law enforcement agencies, healthcare systems, and religious institutions in Southeast Asia, the FBI and agencies in 6 other countries said on October 8. The company, Integrity Technology Group , has been sanctioned by the U.S. and the UK. The hackers scanned websites for flaws using a tool containing more than 1,300 scripts, guessed passwords for Microsoft 365 and Exchange accounts, and copied mailboxes using tools designed to collect mail. The hackers have been breaking into networks since at least mid-January 2021, according to the agencies'  joint advisory . It describes the hacking in the present tense but provides no date for any theft and does not specify how many organizations were breached. The same hackers targeted U.S. government services, critical manufacturing, healthcare, and IT organizations, along with U.S. law enforcement, education, and religious groups. Organizations ...
ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories

ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories

Oct 08, 2026 Hacking News / Cybersecurity News
The crooks have trust problems of their own. One ransomware affiliate decided to keep the profits for himself. Elsewhere, an attacker left a server exposed, complete with tools and traces of an intrusion. Apparently, keeping things secure is a problem on both sides of the fence. The rest of the week isn't much more reassuring. Malicious code turned up in developer packages and extensions that looked harmless. Familiar online services helped phishing emails appear legitimate. A basic file upload flaw gave attackers a way in, while weak session cookies made impersonation far too easy. Even AI assistants are getting their own instructions hidden inside phishing messages now. What's interesting is the gap between effort and results. Some attacks involve several stages, careful timing, and plenty of tricks. Others get surprisingly far because of a bad design choice or something nobody bothered to check. Both seem to be working well enough. Anyway, here's what else turned u...
Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks

Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks

Oct 08, 2026 Data Breach / Web Security
Attackers behind a string of personal data leaks at Japanese organizations have abused APIs for mobile apps and targeted known software flaws, the JPCERT Coordination Center (JPCERT/CC) said. The Tokyo-based center, which takes incident reports, based its  October 8, 2026 alert  on those reports and other information. The alert names no attacker and no affected organization. JPCERT/CC called what it knows "limited and fragmentary" in the alert, translated here from Japanese. It said its account does not mean the same method was used in every incident. Besides consumer apps, the systems hit include business intelligence (BI) tools and employee-facing management systems that their operators did not expect the public to reach. Data stored in them leaked in some cases. For defenders, the alert includes eight source IP addresses, five User-Agent strings, and a list of API controls, including access controls on every endpoint, public or not. The only product it names a...
⚡ Top Stories This Week
Expert Insights Articles Videos
Cybersecurity Resources