-->
#1 Trusted Cybersecurity News Platform
Followed by 5.70+ million
The Hacker News Logo
Get the Latest News
cybersecurity

The Hacker News | #1 Trusted Source for Cybersecurity News — Index Page

ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms

ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms

Oct 08, 2026 Agentic AI / Web Security
Cybersecurity researchers have disclosed details of a targeted campaign aimed at South Korean financial organizations that used an artificial intelligence (AI) pen testing tool named ARTEX to carry out the attacks. The activity, per CrowdStrike Intelligence, was active from late September to early October 2026, and resulted in data exfiltration. "In this activity, the threat actor leveraged ARTEX, a recently released open-source agentic penetration testing (pentesting) tool developed in China, alongside large language models (LLMs)," the cybersecurity company said . CrowdStrike said it discovered the campaign after it identified a set of open directories hosted at a Hong Kong-based IP address, exposing Claude Code session histories, Claude memory files, and ARTEX configuration files. The campaign has not been attributed to any known threat actor or group. But evidence points to a suspected Chinese-speaking operator driven by financial gain. ARTEX is a large lan...
Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia

Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia

Oct 08, 2026 Web Security / Threat Intelligence
Phishing kits are no longer limited to copying a familiar login page and waiting for a victim to enter credentials. Attackers are increasingly building filtering, session management, and traffic controls into the infrastructure that delivers the phishing page itself. ANY.RUN has identified Wazza, a new phishkit targeting banking, manufacturing, and government organizations across the US, Europe, and Australia. The campaign uses a multi-stage routing chain to screen visitors and automated traffic before delivering an Adobe-themed Device Code phishing page. For security teams, that makes Wazza more than another malicious URL. The campaign shows how attackers can control the path to the final lure, making the initial link less informative and potentially complicating automated detection. MSSPs face an added challenge, as they investigate alerts across multiple customer environments while keeping response times under control. That uncertainty can translate directly into longer in...
16 Malicious Firefox Extensions Pose as Rabby and OKX Wallets to Steal Recovery Phrases

16 Malicious Firefox Extensions Pose as Rabby and OKX Wallets to Steal Recovery Phrases

Oct 08, 2026 Browser Security / Malware
Cybersecurity researchers have discovered a cluster of 16 malicious Mozilla Firefox extensions that are capable of stealing cryptocurrency wallet recovery phrases and private keys. "The extensions masquerade as wallet portals, desktop utilities, and browser tools, but their code intercepts recovery phrases and private keys during wallet import flows and attempts to send those secrets to attacker-controlled Cloudflare Workers," Socket researcher Joseph Edwards said in an analysis. The names of the extensions are below - view-focus-bright@webtools.co@6.12.2 quick-track-nest@tabtools.co@8.1.18 vibe-kit-tool@fasttools.co@9.21.9 edge-hub-snap@protools.net@4.12.24 core-hub-peak@neattools.example@8.24.21 sipoo-grozza@browserweb.com@2.1 mozart-seo@webtools.com@1.4 clean-file-bar@neattools.com@4.21.8 clean-net-timer@plugify.example@4.17.1 manager-square@webtools.com@1.4 manager-course@webtools.com@1.4 val-andrew@browserweb.com@1.4 manag...
cyber security

New Priorities for Critical Infrastructure: A Nation-State Threat Roundtable

websiteSANSCritical Infrastructure / Cybersecurity
Experts from SANS Institute, FirstEnergy, MITRE and Dragos unpack what leaders should prioritize next.
cyber security

AI adoption is outpacing IT visibility

website1PasswordSaaS Security / AI Governance
Individual dashboards only show part of the story. Learn how IT can get a unified view of AI spend and usage.
U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks

U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks

Oct 08, 2026 Cybercrime / Cyber Espionage
The U.S. State Department is offering up to $10 million for information leading to the identification or location of Zhang Yu, a Chinese national charged in the United States in connection with the 2021 Microsoft Exchange Server attacks known as HAFNIUM. The reward is for information leading to his identification or location, the news outlet  NTD reported  this week, citing a notice from the department's Rewards for Justice program. Zhang remains at large, U.S. authorities say, meaning he has not been arrested. The charges against him have not been tested in court. Rewards for Justice  is the State Department's national security rewards program. It says it has paid more than $250 million to over 125 people since 1984. Zhang is wanted for his alleged role in "malicious cyber activities against U.S. critical infrastructure," NTD quoted the notice as saying. The amount and that wording match an offer the program was already making  in January 2025 . That of...
MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt Data

MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt Data

Oct 08, 2026 Cybercrime / Ransomware
The U.S. Department of Justice (DoJ) on Wednesday announced charges against a 50-year-old U.S. and Israeli national for allegedly defrauding ransomware victims by secretly paying the attackers to obtain decryptors while claiming to use proprietary tools to recover their data. Zohar Pinhasi (aka Zack Silver and Zack Green) has been charged with two counts of wire fraud and one count of wire fraud conspiracy. If convicted, the defendant faces up to 20 years in prison for each count. "By falsely claiming to decrypt ransomware without paying off the ransomers, the defendant re-victimized his clients while extracting a hefty profit for himself," said U.S. Attorney Joseph Nocella, Jr. for the Eastern District of New York. Pinhasi, who owned and operated a Florida company called MonsterCloud, is alleged to have made false representations to ransomware victims, urging them not to pay a ransom and claiming to have "proprietary tools" and "advanced decryption tec...
Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

Oct 08, 2026 Artificial Intelligence / Cloud Security
The npm package known as " tensorlake ," a TypeScript software development kit (SDK) for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack. The malicious version 0.5.144 "contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code," Socket said . Version 0.5.144 is no longer available for download from the npm package registry. An analysis of the compromised release shows that it contains a preinstall hook designed to launch a JavaScript file ("package/lib/setup.mjs"), an obfuscated loader that launches the main credential-stealing and self-propagating worm ("package/lib/Math_Symbol.js") using the Bun runtime. The stealer malware is designed to harvest credentials across local files, CI environments, Kubernetes, and Vault sources. It also drops the HackBrowserData binary, exfiltrate...
Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains

Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains

Oct 07, 2026 Web Security / Domain Hijacking
Attackers compromised three country-code top-level domains (ccTLDs) and obtained unauthorized HTTPS certificates for several Google domains, Google  said on October 6 . Google's own systems were not breached, but any domain ending in .gh (Ghana), .sl (Sierra Leone) or .as (American Samoa) was put at risk. With such a certificate, an attacker could pose as the real site over an encrypted connection and read the private data sent to it. Chrome blocked the unauthorized certificates for Google's domains through  CRLSets , its way of quickly blocking certificates in emergencies, Google said. The company also worked with the certificate authorities (CAs) that issued the certificates to have them revoked, a step meant to protect people using other browsers and apps. Google did not name the domains.  Certificate Transparency  (CT) logs are the public record of certificates issued by CAs. They show at least 12 certificates issued between September 22 and 27 for Google...
Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

Oct 07, 2026 Supply Chain / Malware
Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote access trojans (RAT) to compromised hosts. The campaign has been codenamed MALFEX by CloudSEK and Checkmarx . The activity is assessed to be the work of a lone threat actor who appears to have published 12 packages since August 2023, eight of which have been flagged as malicious. The attack is designed to infect Windows systems through three separate pathways - A loader for Overlord , an open-source RAT written in Go that uses Solana transactions to extract the command-and-control (C2) address A chain that installs movinlike, a Node.js stealer targeting Discord, browsers, Telegram, and cryptocurrency wallets, and A downloader The list of identified malicious packages is below - tlxbnhd tldriver mxdriver img-to-native native-runner function-flag (Still live) function-color (Still live) cdn-img-fet...
SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

Oct 07, 2026 Vulnerability / Network Security
SonicWall has released hotfixes for four flaws in its SMA1000 appliances, the gateways that give remote workers access to a company's network and applications. The most serious could allow an attacker without a login to send requests through the appliance and reach internal functions. SonicWall rates it 10.0 on the CVSS scale and says it has no evidence that any of the four flaws is being used in attacks. The most serious flaw, tracked as  CVE-2026-102255 , is a server-side request forgery (SSRF) bug in WorkPlace, the portal that SMA1000 users log in to. It exists due to an unintended access path through SonicWall and can be reached before authentication. An attacker who abuses that path could "reach internal functionality and perform unauthorized operations," SonicWall said in its  security advisory , dated October 6, without saying which functions. All four flaws affect SMA1000 models 6210, 7210 and 8200v on these platform-hotfix versions:
Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

Oct 07, 2026 Vulnerability / Artificial Intelligence
A critical vulnerability in LMCache , open-source software that speeds up large language model (LLM) servers such as vLLM, lets an attacker run code on the cache server without logging in, and no fixed version is available. The flaw is in LMCache's  multiprocess mode , where the cache runs as a standalone server that LLM workers reach over the ZeroMQ messaging library. A single network message to that server can run commands as the user the LMCache process runs as. The server can be reached from another machine only when an operator sets it to listen on a routable address, rather than the localhost it uses by default. JFrog disclosed the flaw  on October 7 and assigned it a severity score of 9.8 out of 10, in the critical range, the rating it gives a server bound to a routable address. The vulnerability, tracked as  CVE-2026-105192 , affects LMCache from version 0.3.9, released in October 2025, through 0.5.5, the latest stable release, and is also present in the ...
PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet

PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet

Oct 07, 2026 Botnet / Cryptojacking
Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and further expand the scale of the botnet. The financially motivated campaign, dubbed Canto Incognito , has been found to install cryptocurrency miners, including XMRig and Iron, and connects victims to Kryptex, a Russian cryptocurrency mining service. "Compromised hosts are reused to expand the botnet," Lumen Black Lotus Labs said in a report shared with The Hacker News. "Infected servers are turned into scanners and exploit servers, allowing the actor to find and compromise additional vulnerable systems." The malware distributed as part of the campaign has been codenamed PoeLLM owing to what has been described as a "creative" technique that hides the command-and-control (C2) address within a poem the threat actors wr...
The Sixth Voice of the CISO Data Shows Cyber Risk Has Moved Inside the Workflow

The Sixth Voice of the CISO Data Shows Cyber Risk Has Moved Inside the Workflow

Oct 07, 2026 Artificial Intelligence / Data Security
The 2026 findings are not just a year-over-year shift. They mark the latest point in a five-year arc where resilience, AI governance, human risk, and board scrutiny are converging inside the systems where work actually happens. For years, the enterprise cybersecurity story has been told as a straight line of escalation: more attacks, more data loss, more pressure, and more urgency. That narrative is still familiar, but comparing the five most recent years of Voice of the CISO research suggests a more useful reading. The CISO role has not simply become harder because every metric is rising at once. It has become harder because the center of risk has shifted and moved closer to the way work now gets done. The latest 2026 findings show signs of progress. Fewer CISOs expect a material cyberattack in the next 12 months, and fewer report material loss of sensitive information than in 2025. But those improvements sit within a longer trend line that is much less settled. Over five years,...
FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials

FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials

Oct 07, 2026 Cybercrime / Network Security
The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways. "The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, enabling threat actors to harvest and crack authentication data at scale," the agencies said . "Initial findings indicate attackers are continuing to scan internet-exposed Fortinet firewalls using previously obtained compromised credentials." FortiBleed was first documented by SOCRadar and Hudson Rock in June 2026, with the activity targeting thousands of Fortinet firewalls as part of a global campaign. In all, the Russian-speaking operation is estimated to have netted more than 86,644 working device credentials spanning 194 countries as of June 19, 2026. The campaign subsequently pr...
Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details

Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details

Oct 07, 2026 Vulnerability / Web Security
Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions. The arbitrary file access flaw, tracked as CVE-2026-21589 (CVSS score: 9.3) affects multiple products, including Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. "This arbitrary file access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions," the Australian company said. "Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be sensitive files present that increase your risk." Atlassian said impacted Atlassian Cloud pro...
What Is Agentic Pentesting? What It Proves, and Where It Stops.

What Is Agentic Pentesting? What It Proves, and Where It Stops.

Oct 07, 2026 Vulnerability / Security Testing
If you’re evaluating an agentic pentesting solution right now, you’ve probably heard the same pitch more than once: point it at a target, and it discovers, validates, and exploits attack paths autonomously, the way a real attacker would. That promise is worth taking seriously. It’s also worth pressure testing, and three questions do the heavy lifting.  What can the assessment actually prove?   When is that proof produced? And,  How much of your environment does the proof cover?  Most evaluations stop at the first step. However, it’s at the second and third ones where validation programs are won or lost. One note on where we stand: Picus builds and sells autonomous pentesting . That is exactly why we can be precise about where it ends, because the limits belong to the method, not to any vendor's implementation, and no roadmap can remove them. The problem in four numbers Four numbers from this year explain why the second and third questions now c...
Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws

Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws

Oct 07, 2026 Artificial Intelligence / Vulnerability
Anthropic on Tuesday said it's expanding a program that allows vetted cybersecurity professionals to test its advanced artificial intelligence (AI) models with reduced safeguards and blocking classifiers, as the company claimed its Project Glasswing initiative uncovered at least 129,000 verified software vulnerabilities between April and July 2026. The company said it also found an additional 5,500 verified software vulnerabilities between April and October 2026 through open-source scanning efforts. "Of these verified vulnerabilities, more than 33,000 have so far been rated as critical- or high-severity," Anthropic said . "This is likely an undercount, as it is based on survey data from only a subset of Glasswing partners. As such, we expect the true impact to be at least five times higher." The updated program, called the Cyber Verification Program (CVP), features three access tiers, allowing organizations and security teams to apply for one that best a...
⚡ Top Stories This Week
Expert Insights Articles Videos
Cybersecurity Resources