-->
#1 Trusted Cybersecurity News Platform
Followed by 5.70+ million
The Hacker News Logo
Get the Latest News
cybersecurity

The Hacker News | #1 Trusted Source for Cybersecurity News

Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT

Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT

Sep 30, 2026 Vulnerability / Web Security
Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organizations in North America and Europe. The activity, observed by Mandiant Consulting and Google Threat Intelligence Group (GTIG) in September 2026, has targeted government, financial services, technology, education, and legal and professional services sectors. "Exploitation of CVE-2026-88772 bypasses authentication and triggers an unhandled termination of the NetScaler Packet Processing Engine (NSPPE) to establish initial root-level access," the tech giant said . The attacks have been observed weaponizing the flaw to deploy a post-exploitation toolkit that includes previously unreported PHP web shells, like WHIPSHOT, that are capable of disguising Base64-encoded command-and-control (C2) payloads within native HTTP headers. Also put to use is a novel companion Python tunneler dubbed SLAPSHOT designed to proxy traff...
OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted

OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted

Sep 30, 2026 Vulnerability / Network Security
A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program,  OpenSSL said  on September 29 as it released fixes. DTLS , the TLS variant used for UDP traffic, resends a handshake message if no reply arrives before the timer expires. The leak or crash can happen when such a resend starts while a larger handshake message is stuck part-way through being sent. The flaw, tracked as CVE-2026-84782, is fixed in  OpenSSL 4.0.3, 3.6.5, 3.5.9 and 3.4.8 . Fixed versions for the older 3.0, 1.1.1 and 1.0.2 branches go only to customers who pay for OpenSSL's premium support. OpenSSL 3.0  stopped getting public security fixes  on September 7. OpenSSL has not said whether an attacker can cause a resend while a message is stuck, nor has it reported any attacks exploiting the flaw. DTLS is used, for example, to protect WebRTC data channels and to set up encryption keys for internet calls. Software is exposed to this fla...
Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution

Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution

Sep 30, 2026 Vulnerability / Network Security
Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-88772 (CVSS score: 9.5), has been described as a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling that's rooted in the NetScaler Packet Processing Engine (NSPPE). "Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial-of-service," the U.S. Cybersecurity and Infrastructure Security Agency (CISA) said . The issue, per watchTowr , is that NetScaler implicitly trusts the declared fragment size in the DTLS handshake header's fragment_length field (i.e., 1 byte), while the header simultaneously claims that the complete message, as denoted by the length field, is 120...
cyber security

Reco Finds Four in Five Agents Run With Zero IT Oversight

websiteReco AISaaS Security / AI Security
See which agent permissions security teams aren't reviewing, and why it matters now.
French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks

French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks

Sep 29, 2026 Data Breach / Network Security
An attacker used stolen passwords of staff at France's tax administration to take tax data on hundreds of thousands of taxpayers and businesses in June and July. Neither the tax administration nor France's national cybersecurity agency saw the data leave. The attack was not sophisticated, the agency, ANSSI, says in a  report  (in French) published on Tuesday: it worked because of weak login protection, poorly separated networks and gaps in monitoring. The tax administration, known as the DGFIP, runs France's tax website, impots.gouv.fr. The data came from E-Contact, the tool taxpayers use to message the tax administration. The stolen data covers  a little over 350,000 individuals  and  a little over 250,000 businesses , the DGFIP says. Taxpayers' own online accounts and passwords were not compromised. For individuals, the data that may have been viewed or copied includes their tax ID, contact details, family situation, reference taxable income and tax...
New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses

New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses

Sep 29, 2026 Vulnerability / Hardware Security
A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-Time ( JIT ) engines present in web browsers, language runtimes, and the operating system kernel, across multiple CPU vendors. The new Spectre v2 variant has been codenamed Branch Target Reuse (BTR) . "The key insight is that, while modern CPUs restore architectural code coherence after self-modification, they do not necessarily invalidate stale indirect branch prediction entries (i.e., branch targets)," researchers Sander Wiebing, Yuhui Zhu, Alessandro Biondi, and Cristiano Giuffrida said in an accompanying paper. "In JIT engines, these stale targets can outlive the original code and later be reused when the code cache is repopulated, yielding a transient execute-after-free primitive. This allows attackers to hijack transient control flow to newly generated code at obsolete offsets, bypassing software hardening...
cyber security

Build Your Email Security Strategy for the Agentic Era

websiteAdaptive SecurityEmail Security / Cybersecurity
Get the 2026 checklist for defending against AI phishing, compromised accounts, and human error.
Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor

Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor

Sep 29, 2026 Malware / Cyber Espionage
Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft. The campaigns, aimed at people and organizations tied to Ukraine, have affected more than 100 organizations since January, mostly in the U.S. and U.K. At least one computer was infected, but the number of breached organizations has not been disclosed. Security agencies in the U.S., U.K., Australia, Canada and New Zealand  said in December 2023  that Star Blizzard almost certainly works under Center 18 of Russia's Federal Security Service (FSB). The group has long stolen email passwords by posing as people its targets know. By 2023, it had already used  fake conference and event invitations  as bait, often exchanging messages with a target before sending a malicious link. Microsoft counted at least 13 larger campaigns this year, each with tens to hundreds of emails, on top of ...
Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown

Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown

Sep 29, 2026 Vulnerability / Enterprise Security
Kiteworks on Monday said it worked with federal intelligence authorities over the weekend as it identified and addressed a critical security vulnerability during the scheduled precautionary shutdown . "During the shutdown, this activity led to the discovery of a previously unknown critical vulnerability confined to a capability that is enabled for less than 1% of the customer base," the company said in a statement. "Kiteworks developed and deployed a fix during the window, [and] applied an additional protective layer across all environments." There is no evidence that the vulnerability has ever been exploited in a malicious context. Other Kiteworks products are not affected by the flaw. The development comes days after Kiteworks, previously Accellion, urged customers to take their systems offline for a period of nine hours, in addition to shutting down environments it hosts on behalf of customers, after receiving intelligence about a potential imminent cybe...
101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent

101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent

Sep 29, 2026 Supply Chain / Malware
Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed PhantomSub . "The malicious packages abuse the 'Baileys' WhatsApp open source project to add the victims to groups without their consent," OX Security researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko said in a technical write-up published Monday. These packages have been collectively downloaded 490,000 times, out of which 116,000 occurred in the last 30 days. The names of some of the packages are below - ourin-baileys @nexustechpro/baileys @badzz88/baileys @ostyado/baileys levvleys @vanzxy/baileys @yudzxml/baileys @chatunity/baileys @kelvdra/baileys neuralwhatsapp lilys-baileys @fyxzpediaa/baileys noxleyss @xrelly-stack/bails alipclutch-baileys kurobails eliteprotech-baileys @xayz/baileys chromestaff-baileys @sanzoffc/baileys @s...
Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation

Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation

Sep 29, 2026 United States
Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group. "It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters," the Politie Landelijke Opsporing en Interventies said in an X post Monday. Police said the individual is expected to appear before the Rotterdam District Court on September 29, 2026. Although law enforcement officials did not disclose any additional details, independent security journalist Brian Krebs and DataBreaches.Net identified the arrested man as Pepijn van der Stap (aka Umbreon), who was previously apprehended in 2023 for his role in a series of data thefts and extortions. Per DataBreaches.Net, van der Stap was arrested on September 15, 2026. In 2023, it emerged that the individual worked at cybersecurity company Hadrian and volunteered at the Dutch Institute for Vulnerability Disclosure (DIVD). ...
Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

Sep 29, 2026 Identity Security / Artificial Intelligence
A malicious MCP server could trick an application built on the official  MCP Python SDK  into handing over the OAuth credentials it uses to log in to a real service, the SDK's maintainers said in a security advisory. Affected versions sent the client secret, the authorization code, and the PKCE proof key to a token endpoint the attacker controlled. The fix is in versions 1.30.0 and 2.2.0. The Model Context Protocol (MCP) is an open standard for connecting AI applications to outside tools and data, and this package is its official Python SDK for building MCP servers and clients. With the stolen credentials, the attacker can request a valid access token from the real login service. Cycode, the security firm that reported the flaw , demonstrated that full exchange in a test and says the resulting token carries whatever permissions the app was granted. The client secret is long-lived, so it keeps working until it is changed. The flaw is rated high (7.5) for the two prov...
OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions

OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions

Sep 29, 2026 Artificial Intelligence / Supply Chain
OpenAI on Monday shelved plans to release GPT-6.1 Astra, a next-generation artificial intelligence (AI) model that was planned for an October launch, after it failed internal safety and alignment audits. The development was first reported by The Wall Street Journal. The move "marks a rare case of a major AI developer ditching a new release because of safety concerns," the news publication said. The ChatGPT maker said it made the decision to scrap its GPT-6.1 Astra model release after testing raised questions about whether it can follow user instructions without deviating from expected behavior. The Journal reported that the model exhibited higher levels of deception than its predecessor during evaluation, and failed to disclose what actions it had carried out. In some cases, it went ahead without seeking permission or attempted to use outside tools in scenarios where doing so could be deemed unsafe. "While (GPT-6.1 Astra) improved on axes such as model laziness...
OpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External Chatbot

OpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External Chatbot

Sep 29, 2026 Artificial Intelligence / Web Security
OpenAI said it has made the decision to pause training of its most powerful models after one of its agents during reinforcement learning (RL) training contacted an external chatbot by exploiting a loophole in its internet-access restrictions. "An agent attempting to complete a search-based training task queried a public chatbot service through a gap in our internet-access restrictions: insufficient DNS filtering in its training sandbox," OpenAI said . "Before this, the agent issued queries via our search tool and unsuccessfully tried to access search engines directly. Note that all internet access apart from the DNS resolver in this report hit our offline webcache and therefore did not access the live internet." OpenAI said it has since added blocking controls at two independent layers to prevent this access in the first place. It also said its misalignment monitoring system detected the behavior within 15 minutes and it was acknowledged by a human reviewer...
Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks

Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks

Sep 28, 2026 Vulnerability / Endpoint Security
Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks. The vulnerability, tracked as CVE-2026-86950 , refers to an out-of-bounds write impacting the CoreGraphics component that could lead to arbitrary code execution when processing a maliciously crafted file. The iPhone maker said the issue was addressed with improved bounds checking. It credited Meta Product Security with discovering and reporting the issue. "Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27," it added. However, the company offered no details on how many individuals were targeted, if any of those attempts were successful, or when the first instance of CVE-2026-86950 exploitation occurred. The shortcoming has been addressed in the following devices and operating syste...
Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks

Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks

Sep 28, 2026 Cyber Attack / Threat Intelligence
Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis. The malware has been seen in a small number of targeted intrusions at telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Its use goes back to at least October 2025. Microsoft found NeedyMantis while following up on indicators from Kaspersky's investigation into the  supply chain attack on DAEMON Tools . In that attack, official, signed installers for the DAEMON Tools Lite disk image program carried malicious code from April 8, 2026. The developer replaced them with a clean version on May 5. Microsoft tracks the activity tied to that attack as Storm-3069. It says Storm-3069 is one group that uses NeedyMantis, though it has not seen the malware itself spread through a supply chain attack. Defenders can check their networks using the fi...
IAM for AI agents: A Practical Enterprise Framework

IAM for AI agents: A Practical Enterprise Framework

Sep 28, 2026 AI Agent Security / Enterprise Security
What is IAM for AI agents? AI agents authenticate, invoke tools, and act across enterprise systems with delegated authority. IAM for AI Agents is the identity-control architecture that governs those actors. This guide covers the limits of conventional provisioning, the components that matter, how to evaluate framework choices, and what runtime evidence proves an agent behaved as intended. Identity and access management (IAM) for AI agents treats each agent as a non-human identity with a human owner, a defined purpose, scoped authorization, an expiration, and continuous monitoring. The complication is architectural. IAM platforms express intended access, while applications and infrastructure reveal what the agent actually executed. Between the two sits identity dark matter: the agents, credentials, application-local accounts, and authentication paths that central identity data never reports. A framework that cannot observe that surface produces policy intent, not assurance. Wh...
Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M

Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M

Sep 28, 2026 Vulnerability / Cybercrime
The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain high-level internal credentials and then, on September 24, used them to send fraudulent withdrawal commands to Bitget's wallet system. Exchanges keep most customer funds in offline cold wallets and use hot and warm wallets to process withdrawals. Transfers from those wallets must still be approved before they are signed. The stolen funds came from part of Bitget's hot and warm wallets, and its cold wallets were not affected. Bitget  said last week  that a critical backend system in its wallet infrastructure had been compromised and used to spoof transaction data and trigger its approval process. It had not said how the attacker got in. Bitget CEO Gracy Chen described the attack on Monday in a livestream, in an interview with  The...
⚡ Top Stories This Week
Expert Insights Articles Videos
Cybersecurity Resources