The Hacker News
βœ”
165K subscribers
3.95K photos
26 videos
4 files
9.94K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
Attackers operate in minutes. Defenders are stuck operating in days. β³

Frontier AI is accelerating vulnerability discovery and automated attacks, shrinking the time between exposure and exploitation.

Explore practical strategies for securing applications, APIs, and AI at F5's Security for the Post-Mythos World virtual summit, now available on demand.

πŸ‘‰ Watch now: https://thn.news/security-summit-2026
πŸ‘1πŸ”₯1πŸ€”1
The β€œcritical” flaw may not be the one to fix first.

Autonomous pentesting tests whether weaknesses can be reached, exploited, and chained into a viable path to sensitive systems.

Why severity alone can mislead: https://thehackernews.com/2026/09/your-critical-vulnerabilities-might-not.html
🀯3⚑1πŸ‘1
⚠️ Russian state-sponsored hackers used Claude to rebuild malware whenever security tools detected it.

Anthropic says GTG-20006 also used AI for phishing infrastructure and C2 monitoring while targeting more than 20 organizations.

Read: https://thehackernews.com/2026/09/russian-state-sponsored-hackers-use.html
πŸ‘9😁6⚑1πŸ€”1
‼️ Claude was used in multi-agent cyber operations that carried out exploitation and data theft across multiple victims.

Anthropic says some ran in parallel for hours or days with minimal human input.

Inside the operations: https://thehackernews.com/2026/09/claude-used-to-automate-exploitation.html
🀯7πŸ‘4⚑1πŸ‘1
🚨 151 million Claude exchanges in one Alibaba-affiliated distillation campaign.

Anthropic says it was part of a broader operation involving seven China-based AI labs, with some using proxy networks, fraudulent accounts, and rerouted user requests to harvest Claude capabilities.

Inside the operation: https://thehackernews.com/2026/09/anthropic-says-seven-china-based-ai.html
πŸ‘7😁6πŸ”₯4
‼️ GitLab’s CVSS 10 file-read flaw (CVE-2026-85706) drew in-the-wild probes within hours of disclosure.

If an instance has at least one public project, unauthenticated attackers can read logs and config files containing credentials and secrets.

Read: https://thehackernews.com/2026/09/gitlab-cvss-10-file-read-flaw-draws-in.html
😁10πŸ‘7⚑5
🚨 A new report links OpenAI agents to a RubyGems campaign that gained RCE on RubyDoc servers.

The activity pushed 2,000+ packages, exfiltrated public data, and attempted to steal API keys.

How the chain worked: https://thehackernews.com/2026/09/openai-agents-linked-to-rubygems.html
πŸ‘12😱1
AI-related SOC alerts surged 685% in four months. Just 0.02% were real attacks.

But 5.8% exposed genuine security risks, including agents running without permission safeguards, reverse tunnels, keychain dumps, and risky OAuth grants.

Why the noisiest alerts may hide the ones that matter: https://thehackernews.com/2026/09/when-whole-company-adopts-ai-what-it.html
🀯4😁3πŸ”₯1πŸ‘1
🚨 Attackers are exploiting flaws in Artifactory, ScreenConnect, and RouterOS.

Observed attacks gained Artifactory admin control and deployed backdoors, pushed malicious VBScript via ScreenConnect, and seized RouterOS devices without authentication.

CISA added all 5 flaws to KEV.

Inside the attacks: https://thehackernews.com/2026/09/cisa-adds-5-actively-exploited.html
πŸ”₯6😁1
🚨 Fake passkey updates are being used to take over Microsoft cloud accounts.

Once inside, threat actors add their own MFA methods and pull data from SharePoint, OneDrive, and mailboxes.

Inside the passkey phishing chain β†’ https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html
πŸ‘10😁8🀯2πŸ”₯1
⚠️ Nearly 31,000 Twitch users had live OAuth tokens sent to operator-controlled proxies by a malicious browser extension.

JeetBot put the credentials in request URLs, exposing them in proxy logs. Older installs keep sending them until updated.

Read: https://thehackernews.com/2026/09/malicious-twitch-browser-extension.html
πŸ”₯5⚑4πŸ‘3
🚨 Only 495 of 35,853 CVEs published in H1 2026 were exploited in the wild.

The harder problem for defenders is no longer finding vulnerabilities. It’s identifying which exposures actually demand immediate action.

See why vulnerability volume alone can’t tell defenders what to fix first: https://thehackernews.com/2026/09/ai-changed-exposure-problem-validation.html
πŸ‘7πŸ‘1
⚑ THIS WEEK IN CYBER

AI agents went off-script.
A zero-click worm surfaced.
Exploit chains got shorter.
Old bugs kept paying off.
Rootkits stayed quiet.
Scam infrastructure took a hit.

Also inside:
β†’ AI-powered espionage
β†’ PaperCut exploitation
β†’ phishing through trusted infrastructure
β†’ fresh 0-days and patch bypasses
β†’ exposed systems attackers are already probing

The pattern this week is simple: attacks are getting faster, but many of the doors are still painfully ordinary.

Full recap ↓ https://thehackernews.com/2026/09/weekly-recap-rogue-ai-agents-wechat.html
πŸ‘8πŸ‘4
πŸ”₯ WordPress is adding a new security gate to every plugin release.

Before distribution, each release will be reviewed with AI models and Jetpack Scan, and high-risk updates will be blocked automatically. The system recently caught a backdoored release before it reached the WordPress-org update API.

How the new review works: https://thehackernews.com/2026/09/wordpress-adds-automated-plugin-reviews.html
πŸ‘9πŸ”₯2
The EU CRA requires formal documentation built during the product lifecycle.

The EU CRA's December 2027 deadline requires a governed open source inventory, current SBOM coverage, and an audit trail for every remediation decision. You can't build that once a vulnerability is found. Non-compliance risks your EU market access. See what's required, and start now.

Start here β†’ https://thn.news/cra-readiness-eu
πŸ€”5
🚨 Red Heron exploited a Gitea RCE to compromise 13 organizations across six countries.

The actor automated a public exploit, stole repositories and credentials, and in one Taiwanese environment reached root on a three-node Proxmox cluster.

How the campaign escalated: https://thehackernews.com/2026/09/red-heron-exploits-gitea-rce-to.html
😁4
This media is not supported in your browser
VIEW IN TELEGRAM
‼️ Researchers broke Intel TDX’s confidential-computing protections with a $159 DDR5 interposer.

New "DDRop" attack silently drops memory writes so the CPU trusts stale encrypted data. In lab tests, researchers read protected VM memory and forged attestation.

No CVE. No patch. Full details here β†’ https://thehackernews.com/2026/09/new-ddrop-attack-breaks-intel-tdx-and.html
πŸ”₯10
‼️ A Telegram Desktop flaw could send messages from opened HTML exports to an attacker-controlled server.

A bot message could hide JavaScript in pre-fix exports, which ran when the file was opened in a browser with JavaScript enabled.

Updating Telegram does not clean old export files.

Read: https://thehackernews.com/2026/09/telegram-desktop-flaw-lets-hidden.html
πŸ”₯13😁4πŸ€”2
🚨 Thai ISP 3BB attacker had root access and hid MeshCentral for persistence.

Recovered tools sprayed passwords across 55+ internal systems and targeted subscriber login databases.

How the attacker stayed in: https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html
😁9⚑1πŸ”₯1πŸ€”1
⚠️ Two China-linked threat actors exploited the same Chrome-Windows zero-day chain.

UTA0560 used it to deploy the GRIMWEDGE backdoor against NGOs. APT31 used it to install LONGTALE, a credential-stealing Chrome extension.

How the shared exploit chain worked: https://thehackernews.com/2026/09/china-linked-hackers-exploit-chrome.html
πŸ”₯7πŸ‘3
‼️ Attackers are exploiting a Cisco Secure Email Gateway vulnerability that can let a crafted email trigger command execution as root.

Cisco has released fixes, and CISA added CVE-2026-76461 to its KEV catalog.

How the attack works β†’ https://thehackernews.com/2026/09/cisco-secure-email-gateway-flaw.html
😁5