The Hacker News
βœ”
165K subscribers
3.94K photos
26 videos
4 files
9.94K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
🚨 Red Heron exploited a Gitea RCE to compromise 13 organizations across six countries.

The actor automated a public exploit, stole repositories and credentials, and in one Taiwanese environment reached root on a three-node Proxmox cluster.

How the campaign escalated: https://thehackernews.com/2026/09/red-heron-exploits-gitea-rce-to.html
😁4
This media is not supported in your browser
VIEW IN TELEGRAM
‼️ Researchers broke Intel TDX’s confidential-computing protections with a $159 DDR5 interposer.

New "DDRop" attack silently drops memory writes so the CPU trusts stale encrypted data. In lab tests, researchers read protected VM memory and forged attestation.

No CVE. No patch. Full details here β†’ https://thehackernews.com/2026/09/new-ddrop-attack-breaks-intel-tdx-and.html
πŸ”₯10
‼️ A Telegram Desktop flaw could send messages from opened HTML exports to an attacker-controlled server.

A bot message could hide JavaScript in pre-fix exports, which ran when the file was opened in a browser with JavaScript enabled.

Updating Telegram does not clean old export files.

Read: https://thehackernews.com/2026/09/telegram-desktop-flaw-lets-hidden.html
πŸ”₯13😁4πŸ€”2
🚨 Thai ISP 3BB attacker had root access and hid MeshCentral for persistence.

Recovered tools sprayed passwords across 55+ internal systems and targeted subscriber login databases.

How the attacker stayed in: https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html
😁9⚑1πŸ”₯1πŸ€”1
⚠️ Two China-linked threat actors exploited the same Chrome-Windows zero-day chain.

UTA0560 used it to deploy the GRIMWEDGE backdoor against NGOs. APT31 used it to install LONGTALE, a credential-stealing Chrome extension.

How the shared exploit chain worked: https://thehackernews.com/2026/09/china-linked-hackers-exploit-chrome.html
πŸ”₯7πŸ‘3
‼️ Attackers are exploiting a Cisco Secure Email Gateway vulnerability that can let a crafted email trigger command execution as root.

Cisco has released fixes, and CISA added CVE-2026-76461 to its KEV catalog.

How the attack works β†’ https://thehackernews.com/2026/09/cisco-secure-email-gateway-flaw.html
😁5
‼️ Warning: LiteSpeed Enterprise before 6.3.7 can let low-privilege website users gain root on shared-hosting servers.

It can bypass CageFS isolation. No CVE is assigned, exploitation is unknown, and 6.3.7 may not auto-update immediately.

Manual update may be required β†’ https://thehackernews.com/2026/09/litespeed-enterprise-flaw-could-let-one.html
⚑4🀯2
Cursor deleted a production database and its backups in nine seconds.

The agent found an unrelated Railway API token with blanket GraphQL permissions while handling a staging task. AI blast radius follows credential reach.

Why access boundaries matter: https://thehackernews.com/expert-insights/2026/09/stop-trying-to-control-ai-behavior.html
😁29πŸ”₯5πŸ‘2⚑1
⚠️ Exposed Vite dev servers are being scanned for cloud credentials.

Attackers are exploiting a Vite flaw to bypass file restrictions and retrieve .env files, AWS and Azure credentials, and infrastructure state.

How the bypass works: https://thehackernews.com/2026/09/mass-scanning-campaign-exploits-vite.html
🀯6😁1
One attack step can now decide what gets tested next.

OpenAEV’s Attack Chaining feeds live findings like credentials, tokens, and open ports into the next stage, while XTM One can plan and adapt the path inside a defined scope.

How the attack path builds: https://thehackernews.com/2026/09/attack-chains-not-just-attack-surfaces.html
πŸ”₯3
🚨 A human attacker exploited Marimo’s pre-auth RCE and reached an SSH bastion in eight seconds.

The operator used harvested AWS credentials to fetch the private key from Secrets Manager and authenticate over SSH. No AI agent was involved.

Read: https://thehackernews.com/2026/09/human-attacker-exploits-marimo-rce.html
πŸ”₯5
Phishing puts financial SOCs under constant pressure. Cut the workload with ANY.RUN: faster analysis, fewer escalations, and 21 min lower MTTR.

β†’ https://thn.news/phishing-soc-detection
πŸ”₯4πŸ‘2
This media is not supported in your browser
VIEW IN TELEGRAM
βœ… Your Business Continuity Management Checklist.

Most resilience programs look complete on paper. Let's make sure yours holds up when it matters most.
Discover 6 ways to align your BCM program with operational reality.

Get the checklist β†’ https://thn.news/bcm-reality-check
😁1
🚨 BambooToken uses MQTT to control Windows and Linux hosts across Asia and South America.

Lumen identified a dozen compromised entities, with activity detected as recently as July 2026.

Learn what's inside the malware’s MQTT command-and-control: https://thehackernews.com/2026/09/bambootoken-malware-uses-mqtt-to.html
πŸ”₯3😁3
‼️ Iran-attributed HEAVYGRAM, also tracked as CHOSEN BRICK, uses Telegram bots to spy on dissidents and journalists.

A joint U.S.-U.K.-Dutch advisory says the Windows malware can steal messages and passwords, record audio, capture screenshots, and exfiltrate files.

Details β†’ https://thehackernews.com/2026/09/iranian-hackers-use-telegram-controlled.html
🀯10πŸ”₯6πŸ€”3
🚨 KREMLIN banking malware bypasses Chromium integrity checks to install a Chrome and Edge extension that steals credentials and session tokens.

It also uses Ethereum smart contracts to rotate C2 and payload locations.

How the attack chain works: https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html
🀯14πŸ”₯11πŸ‘10
⚠️ Forged admin JWTs are being used in WSO2 API Manager exploitation attempts.

CVE-2026-5430 lets unsupported JWT algorithms bypass authentication and can lead to account takeover. Fixes are available.

Read: https://thehackernews.com/2026/09/active-exploitation-attempts-target.html
πŸ”₯3
🚨 Attackers are exploiting a critical WooCommerce Wholesale Lead Capture flaw to plant PHP web shells.

Wordfence has blocked over 100,000 exploit attempts since June against CVE-2026-27540, which affects versions through 2.0.3.1.

Read: https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html
πŸ”₯3πŸ‘1
A unified security dashboard can still hide a broken incident workflow.

Run one incident from detection to clean recovery. Count every console switch, permission change, and ownership handoff.

Six tests reveal whether consolidation actually reduces operational friction: https://thehackernews.com/expert-insights/2026/09/how-to-evaluate-unified-security.html
πŸ”₯2
⚠️ Acronis Backup flaw exploited in limited targeted attacks.

CVE-2026-87886 lets a low-privileged attacker escalate permissions on affected Linux cPanel/WHM and Plesk deployments. Fixes are available.

Which builds need updating β†’ https://thehackernews.com/2026/09/acronis-cpanel-backup-plugin.html
πŸ”₯2
‼️ ALERT - Google says a Pixel modem flaw may be under limited, targeted exploitation.

CVE-2026-58704 can enable adjacent privilege escalation without user interaction. Google patched it in the September Pixel update.

What’s known about the attacks β†’ https://thehackernews.com/2026/09/google-patches-pixel-modem-flaw-amid.html
πŸ€”6😁4