The Hacker News
βœ”
165K subscribers
3.95K photos
26 videos
4 files
9.95K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
Meet Georgetown's cybersecurity faculty on Sept 22 to learn more about the Cybersecurity Risk Management master's program.

Attend our virtual webinar on Sept 22.

Learn more β†’ https://thn.news/risk-management-event
😁2
‼️ Critical Unbound DNSSEC validator flaw (CVE-2026-82717) could allow remote code execution.

An attacker who controls a malicious zone can trigger the heap overflow by querying a vulnerable resolver. 1.26.0 and earlier are affected.

Read details β†’ https://thehackernews.com/2026/09/critical-unbound-dnssec-validator-flaw.html
πŸ”₯4πŸ‘1
⚑ Can you prove a CVE is exploitable without running the exploit?

This webinar shows how to map a vulnerability to the attack techniques it requires, then test whether your existing controls actually stop them.

Can’t join live? Sign up and get the recording: https://thehacker.news/ready-for-mythos-class-attacks
πŸ‘2
🚨 Iran-linked Handala Hack is tied to a Telegram-controlled backdoor that can steal passwords and messaging data.

HEAVYGRAM also executes commands, captures screenshots, and downloads additional malware.

See how Telegram becomes the control channel: https://thehackernews.com/2026/09/iran-linked-handala-hack-tied-to.html
πŸ”₯6πŸ€”4⚑2
‼️ ALERT - Critical Docker Sandboxes flaw lets malicious guest code escape the shared workspace and read or modify files across a macOS host.

CVE-2026-77179 crosses the virtio-fs boundary with the host account’s rights.

Read how the escape works β†’ https://thehackernews.com/2026/09/critical-docker-sandboxes-flaw-lets.html
πŸ”₯4πŸ‘3πŸ‘2
πŸ”₯ 25 New CYBER stories in this week’s ThreatsDay Bulletin:

β†’ Exposed AI systems breached
β†’ Stealers hunt agent tokens + prompts
β†’ Agents rewrite their own models
β†’ Ransomware jumps on a fresh flaw
β†’ Telnet brute-force still works
β†’ RF attacks leak audio remotely
β†’ and more...

Check out the full list of threats here: https://thehackernews.com/2026/09/threatsday-self-rewriting-agents-800.html
πŸ”₯3
‼️ NEW - Critical Check Point management flaw lets unauthenticated attackers run code as root.

The 9.8-rated bug (CVE-2026-91843) sits in the login path before authentication.

Affected versions and fix details: https://thehackernews.com/2026/09/critical-check-point-management-server.html
😁7πŸ”₯4
RatHat can keep shell access to an Android device even after the malicious app is uninstalled.

It abuses Accessibility and local ADB pairing to establish persistent operator access, with AI used to help navigate the device.

How it survives removal: https://thehackernews.com/2026/09/rathat-android-malware-abuses-adb-to.html
🀯7πŸ‘3πŸ”₯2πŸ‘1
🚨 A claimed bug bounty hunter likely used an LLM to build PhantomRaven, an npm stealer that collects developer credentials and CI/CD secrets.

CrowdStrike linked the operator to malicious npm packages and similar activity targeting PyPI.

Read: https://thehackernews.com/2026/09/claimed-bug-bounty-hunter-likely-used.html
πŸ‘3πŸ”₯2
⚠️ Importing one of 13 npm packages can load the WeaselBiscuit stealer directly into memory.

It harvests Chrome extension storage on Windows, macOS, and Linux. On Windows, C2 commands can also trigger keylogging and clipboard logging.

How the npm delivery chain works: https://thehackernews.com/2026/09/weaselbiscuit-stealer-spreads-via-13.html
πŸ”₯2
🚨 Plugin4Shell vulnerability can make four widely used AI coding agents install plugin code that differs from the version they report as pinned.

The attack requires control of the plugin repository.

How it works: https://thehackernews.com/2026/09/plugin4shell-lets-repository-owners.html
πŸ”₯3
⚑ ReportURI browser alerts caught a ClickFix campaign before some reputation services did.

CSP reports from compromised e-commerce sites exposed attacker-controlled domains used in a chain that copied PowerShell commands to victims’ clipboards.

How the attack surfaced: https://thehackernews.com/2026/09/an-abandoned-cdn-domain-was-re.html
πŸ”₯2
🚨 Azure AI Foundry flaw lets unauthorized attackers elevate privileges over the network.

The CVSS 10.0 issue stems from missing authentication for a critical function. Microsoft says it is fully mitigated, with no evidence of exploitation.

Here's what the flaw could allow: https://thehackernews.com/2026/09/microsoft-patches-cvss-100-azure-ai.html
πŸ‘1
⚠️ Transparent Tribe is targeting government and defense entities in India and Afghanistan with a new Rust backdoor.

RUSTYSHADE uses private GitHub repos for encrypted C2, while post-compromise activity includes Windows and Linux file stealers.

Read more about Operation RapidRust: https://thehackernews.com/2026/09/transparent-tribe-deploys-new-rust.html
πŸ‘1