-->
#1 Trusted Cybersecurity News Platform
Followed by 5.70+ million
The Hacker News Logo
Get the Latest News
cybersecurity

The Hacker News | #1 Trusted Source for Cybersecurity News — Index Page

Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

Oct 05, 2026 Vulnerability / Malware
Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling . "Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel," Nozomi Networks said in a report published last week. "The result is a botnet whose traffic can resemble legitimate NAT-traversal activity while still supporting propagation, proxying, tunneling and denial-of-service commands." The operational technology (OT) security company said it observed a spike in attempts to exploit CVE-2021-35394 (CVSS score: 9.8), a critical remote code execution (RCE) flaw in Realtek Jungle SDK starting around September 5, 2026, with a subset of the activity delivering Cling. An analysis of the malware sample has found it to embed exploit logic for various command injectio...
Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access

Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access

Oct 05, 2026 Vulnerability / Artificial Intelligence
Apple has announced that it's taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents. "Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history – without users' full knowledge and understanding," Apple said in a post. "For communication apps, this can also compromise the privacy of the people users are communicating with." Full Disk Access , accessed via Privacy & Security in the Settings app, was introduced by Apple in macOS Mojave (version 10.14), offers users greater control over which applications can access their entire system and data from apps like Mail, Messages, Safari, and Time Machine backups. Once the setting is enabled for an application, it allows that program to bypass certain security restrictions and read and writ...
Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

Oct 05, 2026 Vulnerability / Web Security
A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and seize control of affected systems. "Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login," according to an advisory for the flaw. "A remote attacker can collect a small number of login responses, reconstruct the generator's state, recover the signing key, and forge a valid administrator session cookie, leading to full administrative access and remote code execution via the server_code configuration feature." Hori...
cyber security

Reco Finds Four in Five Agents Run With Zero IT Oversight

websiteReco AISaaS Security / AI Security
See which agent permissions security teams aren't reviewing, and why it matters now.
cyber security

Build Your Email Security Strategy for the Agentic Era

websiteAdaptive SecurityEmail Security / Cybersecurity
Get the 2026 checklist for defending against AI phishing, compromised accounts, and human error.
New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline

New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline

Oct 05, 2026 Zero-Day / Vulnerability
Citrix has released security updates for a high-severity security flaw in NetScaler ADC and Citrix NetScaler Gateway that has been exploited as part of targeted zero-day attacks. The vulnerability, tracked as CVE-2026-88779 , carries a CVSS score of 8.7 out of 10.0. "CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to denial-of-service under specific deployment conditions," Citrix said . "The issue affects customer-managed NetScaler deployments running affected supported versions when the required preconditions are met." For successful exploitation, NetScaler ADC or NetScaler Gateway must be configured either as a SAML service provider (SP) or SAML identity provider(IdP). Customers can check if their NetScaler deployment meets the precondition by reviewing their configuration for entries matching the following - SAML SP - add authentication samlAction SAML IdP - add authentication sam...
ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members

ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members

Oct 04, 2026 Cybercrime / Data Breach
A suspected member of the ShinyHunters digital extortion group, who goes by the online alias "Rey," has been allegedly detained by authorities in Jordan, Reuters reported , citing three people familiar with the matter. Rey, whose real name is Saif ‌al-Din Khader, is said to have been brought into custody on September 29, 2026, and cooperating with the U.S. Federal Bureau of Investigation (FBI) and law enforcement to identify other members of the group. "His cooperation is critical to ongoing efforts to arrest these hackers," a source told the news agency. Rey, who also went by the online alias ReyXBF, is not an unknown face. In a report published in November 2025, independent security journalist Brian Krebs labeled him as one of the three administrators of Scattered LAPSUS$ Hunters (SLH or SLSH), a group that's assessed to be an amalgamation of Scattered Spider, LAPSUS$, and ShinyHunters. "Previously, Rey was an administrator of the data leak w...
China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing

China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing

Oct 04, 2026 Cyber Espionage / Phishing
A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal sector organizations. The campaigns have impersonated prominent economists and AI policymakers, as well as a prominent Anthropic employee, to single out an AI policy expert at a U.S. think tank in February 2026. The phishing email carried the subject line "Request for Feedback on Military Integration of Claude." "This activity likely supports wider Chinese intelligence objectives to better understand ongoing developments within the U.S. AI policy and regulatory landscape and occurs amid intense strategic competition, accusations of model distillation, and export controls involving the U.S. and China," Proofpoint said in an analysis published this week. The enterprise security company has described TA419 as a China-aligned and espionage-motivat...
MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics

MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics

Oct 03, 2026 Cyber Espionage / Artificial Intelligence
The U.K.'s domestic intelligence and security agency has warned that more than 100 academics have helped China boost its intelligence gathering efforts on behalf of Beijing's state security service. In a "Security Service Espionage Alert" issued on September 30, 2026, MI5 said the "primary purpose of the China General Technology Research Institute (CGTRI) 中国通用技术研究院 is to fund research that directly improves Chinese Ministry of State Security (MSS) technical capability for espionage." CGTRI, also known as the China Academy of General Technology (CAGT), is assessed to be a front company for MSS. The body, per MI5, funds academic research in China on topics including artificial intelligence (AI), cybersecurity, covert communications systems, and steganography. More than 100 U.K.-linked academics have contributed to research projects funded by MSS via CGTRI, the alert read. In some cases, the individuals may not be aware that CGTRI is providing monetary ...
Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

Oct 03, 2026 Vulnerability / Critical Infrastructure
The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new , in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations. "In the past two months, Longlegs has attacked at least four organizations, including two critical infrastructure operators (a water utility and a telecommunications provider), a regional government body, and a university," the Broadcom-owned cybersecurity unit said . "Victims were in Portuguese- and Spanish-speaking countries, spanning Europe, Africa, and Latin America."  Warlock, also tracked as Gold Salem, Longlegs, and Storm-2603, gained prominence in mid-2025 in connection with the zero-day exploitation of the "ToolShell" SharePoint flaws to deploy ransomware on ...
The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations

The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations

Oct 03, 2026 Identity Security / Artificial Intelligence
Featuring: Cybersecurity is being reshaped by the expansion of cloud infrastructure, AI, distributed systems, and increasingly complex digital environments. As organizations manage more identities, devices, data, and internet-facing infrastructure, security is shifting toward continuous visibility, control, and the ability to respond to risk at scale. This report examines how core areas of cybersecurity are evolving in response to that shift. Across identity security, telemetry management, human security, endpoint management, human risk intelligence, exposure management, email and domain security, connected device security, AI-native security operations, and cloud security, it explores how organizations are adapting to threats that increasingly move across systems, identities, and infrastructure rather than targeting a single point of failure. Read the full report here:  https://report.papryon.com/thehackernews
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

Oct 02, 2026 Vulnerability / Application Security
A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab  said in an advisory . The gateway is the service that connects a GitLab instance to AI models, and only organizations that host their own gateway need to act. The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1. The flaw is tracked as  CVE-2026-90970 . GitLab disclosed it on October 2 and rated it critical, with a CVSS score of 9.9 out of 10. GitLab runs AI Gateways for its customers and has already fixed them. Customers on GitLab.com, GitLab Dedicated, and self-managed instances that use a GitLab-hosted gateway do not need to act, the company said. Self-managed customers can instead  host their own gateway , an option GitLab offers for keeping AI request and response data inside the customer's own environment. GitLab strongly recommends that those customers update immediately. It sent that gui...
Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

Oct 02, 2026 Cyber Espionage / Malware
Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster under the moniker UAT-11587 . The threat actor was first detected in September 2025 in connection with a spear-phishing campaign directed against Taiwan's academic, think tank, and civil society policy community. Since then, attacks linked to the intrusion set have expanded to target 16 entities across eight Asian countries. "Antino is a Rust-compiled Windows backdoor that supports host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading and persistence," security researcher Ashley Shen said . "Its native command-and-control channel ...
Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes

Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes

Oct 02, 2026 Vulnerability / Cloud Security
Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad actors to take over susceptible systems. The vulnerabilities are listed below - CVE-2026-63688 (CVSS score: 10.0) - A missing authentication for critical function vulnerability in the csm-authorization-storage gRPC server that an unauthenticated remote attacker could exploit to obtain unauthorized access to storage backend administrator credentials for all registered storage arrays. CVE-2026-63692 (CVSS score: 10.0) - A missing authentication for critical function vulnerability in the authorization proxy and tenant service that an unauthenticated network attacker could exploit to bypass authentication controls and gain administrative-level privileges. CVE-2026-67269 (CVSS score: 9.9) - An improper privilege management vulnerability in the ContainerStorageModule Custom Resource reconciler that a low-privilege remote attac...
OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling

OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling

Oct 02, 2026 Artificial Intelligence / Data Security
OpenAI has parted ways with three members of its safety team after they leaked private information in violation of company policies, The Wall Street Journal reported . "We have parted ways with three individuals for violating our policies on accessing and handling sensitive company information," a spokesperson for the company was quoted as saying. "Our investigation confirmed that these individuals mishandled sensitive information outside established company procedures, violating our policies and breaking the trust essential to our work." The impacted employees are Jasmine Wang , Tomek Korbak , and Mikita Balesni , the Journal reported, citing people familiar with the matter. The three researchers have all previously expressed concerns about the pace of artificial intelligence (AI) development. It's said that the individuals shared confidential information with a third-party AI-safety organization. The name of the organization was not disclosed. According...
Why CISOs Struggle to Answer the Board's Three Hardest Questions, and How to Fix the Report

Why CISOs Struggle to Answer the Board's Three Hardest Questions, and How to Fix the Report

Oct 02, 2026 Enterprise Security / Artificial Intelligence
The quarterly board meeting is two weeks out. The security team is pulling exports from the identity provider, the cloud posture tool, the vulnerability scanner, the SIEM and the EDR console. Someone is building a spreadsheet to reconcile them. Someone else is turning that spreadsheet into slides. Then a board member asks three questions: How secure is the organization, overall? What is the actual financial exposure? Is the security posture better than it was last quarter? Most security leaders cannot answer any of them with confidence. Not because the data doesn't exist, but because it lives in a dozen tools that don't share context. A new guide to confident board reporting for CISOs takes on exactly this problem. This article walks through why traditional reporting fails and what a better model looks like. Boards Have Stopped Trusting Activity Metrics For years, security reporting has run on counts. Vulnerabilities found. Patches applied. Alerts closed. P...
Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools

Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools

Oct 02, 2026 Mobile Security / Android
Google has announced a new security measure that limits access to Android's accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled. With malicious Android applications abusing the API serving as the main conduit for malware and financial fraud, the tech giant said the move would block a major attack pathway. Advanced Protection is a security setting that turns on all Android's security features to secure the device against potential threats. "In Android 17, enabling Advanced Protection automatically restricts AccessibilityService access exclusively to verified applications categorized as Accessibility Tools, closing off a major avenue of attack while preserving vital assistive technology," Google said Thursday. The Android AccessibilityService API is a powerful framework that allows an application to run in the background, intercept user interface events, and interact with other applications on...
Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

Oct 02, 2026 Vulnerability / Enterprise Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities ( KEV ) catalog, following reports of active exploitation. The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system. "An improper limitation of a pathname to a restricted directory ('path traversal') [CWE-22] and improper neutralization of NULL byte or NULL character [CWE-158] vulnerability may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests," Fortinet said in an advisory. The vulnerability impacts the following versions - FortiMail 8.0.0 through 8.0.1 (Upgrade to upcoming 8.0.2 or above) FortiMail 7.6.0 through 7.6.6 (Upgrade to upcoming 7.6.7 or above) FortiMail 7.4.0 through 7.4.8 (Upgrade to upcoming 7.4.9 or a...
⚡ Top Stories This Week
Expert Insights Articles Videos
Cybersecurity Resources