The Hacker News
βœ”
156K subscribers
2.38K photos
14 videos
4 files
8.31K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
⚠️ Researchers uncovered ZeroDayRAT, a commercial mobile spyware sold on Telegram targeting Android and iOS.

It enables live camera/mic feeds, GPS tracking, SMS and OTP theft, and wallet hijacking via a self-hosted panel β€” turning phones into full surveillance nodes.

πŸ”— Read β†’ https://thehackernews.com/2026/02/new-zerodayrat-mobile-spyware-enables.html
πŸ‘7😁4⚑1
⚑ Lithuania is investing €24.1M to harden its digital society against AI-era cybercrime.

The national mission links universities, industry, and government to build fraud detection, disinformation tracking, and critical infrastructure defenses as GenAI reshapes attack tactics.

πŸ”— Inside the program and threat shift β†’ https://thehackernews.com/2026/02/safe-and-inclusive-esociety-how.html
πŸ€”5πŸ‘1😁1
The week in cyber:

πŸ“Ž Add-in supply chain abuse
🧠 AI in attack workflows
πŸ› Active zero-days patched
πŸ” Privileged access exploits
☁️ Cloud infra hijacks
πŸ€– Crypto mining botnets
πŸ“‘ IRC-based C2 returns
πŸ› οΈ PoC exploits weaponized
🏭 Defense sector targeting

πŸ”— Full Weekly Cybersecurity Recap β†’ https://thehackernews.com/2026/02/weekly-recap-outlook-add-ins-hijack-0.html
⚑7
πŸ›‘ A new academic study mapped password recovery attack paths across Bitwarden, LastPass, and Dashlaneβ€”testing zero-knowledge designs against a malicious server model.

Researchers identified 25 attack scenarios impacting vault integrity and recovery flows. No active exploitation reported.

πŸ”— Research scope, attack methods and vendor fixes β†’ https://thehackernews.com/2026/02/study-uncovers-25-password-recovery.html
πŸ‘29
πŸ”’ Apple’s latest beta brings end-to-end encryption to RCS β€” but only for Apple-to-Apple chats so far.

It’s part of iOS 26.4 testing alongside new memory protections designed to block spyware at the kernel level.

πŸ”— Inside Apple’s new security stack β†’ https://thehackernews.com/2026/02/apple-tests-end-to-end-encrypted-rcs.html
πŸ‘17πŸ€”2😁1
⚑ Microsoft warns some firms are embedding manipulative prompts in β€œSummarize with AI” buttons.

Researchers identified 50+ hidden instructions that push assistants to remember and recommend specific brands β€” with effects persisting across future chats, often without user awareness.

πŸ”— Read β†’ https://thehackernews.com/2026/02/microsoft-finds-summarize-with-ai.html
πŸ”₯11
Most β€œAI for GRC” still stops at task automation β€” drafting policies or extracting clauses.

As Yair Kuznitsov, CEO of Anecdotes, explains, agentic GRC replaces the workflow itself. Agents collect evidence, evaluate controls, trigger remediation, and maintain audit trails autonomously.

Decision-making is embedded.

πŸ”— CCM agent execution model β†’ https://thehackernews.com/expert-insights/2026/02/ai-shouldnt-improve-workflows-it-should.html
πŸ‘7πŸ”₯1
⚠️ ☠️ πŸ€– A trojanized Oura AI connector is being used to spread SmartLoader malware.

Attackers cloned the MCP server, staged fake GitHub contributors, and planted it in trusted registries. The payload drops StealC to steal credentials, wallets, and cloud access.

πŸ”— Read β†’ https://thehackernews.com/2026/02/smartloader-attack-uses-trojanized-oura.html
πŸ‘7
Network Detection & Response is now central to SOC workflowsβ€”not an add-on.

Testing Corelight’s Investigator showed analysts tracing exploits, reverse shells, and lateral movement in one dashboard, mapped to MITRE and guided by embedded AI.

NDR serves as a force multiplier for mid-tier teams.

πŸ”— Inside: hunt workflows β†’ https://thehackernews.com/2026/02/my-day-getting-my-hands-dirty-with-ndr.html
πŸ‘8
Infosec Compliance Now 2026 | Earn 4 CPEs

Registration for the 6th annual Infosec Compliance Now virtual event is live! Attend and earn up to 4 free CPE credits while learning about AI-powered GRC, cyber resilience, continuous control monitoring using automation, and more!

Register β†’ https://thn.news/cyber-risk-event
πŸ”₯4πŸ‘1
⚠️ Cloud attacks move faster than investigations.

Wiz experts show how workloads vanish, identities rotate, and logs expire before response even starts.

Minutes β€” not days β€” decide outcomes. See how context-aware forensics rebuilds full attack timelines fast.

πŸ”— See cloud breaches reconstructed step-by-step β†’ https://thehackernews.com/2026/02/cloud-forensics-webinar-learn-how-ai.html
πŸ”₯8πŸ‘1😁1
πŸ›‘ A firmware-level Android backdoor called Keenadu is being shipped inside signed tablet builds.

Telemetry shows 13,715 users globally encountered its modules. It injects into every app via core system libraries, enabling remote control, data theft, and ad fraud.

πŸ”— Read β†’ https://thehackernews.com/2026/02/keenadu-firmware-backdoor-infects.html
🀯10😱5πŸ€”3😁1
πŸ€– AI assistants with web browsing can be weaponized as stealth command relays.

Check Point showed Copilot and Grok fetching attacker URLs and returning commands through normal responses β€” blending C2 traffic into enterprise use.

πŸ”— Read details β†’ https://thehackernews.com/2026/02/researchers-show-copilot-and-grok-can.html
πŸ‘6😁6🀯5πŸ‘2
⚠️ CISA added 4 actively exploited flaws to its KEV list, including a Chrome zero-day and critical Zimbra SSRF bug.

Attacks range from browser heap corruption to server command execution and worm delivery.

πŸ”— Exploited CVEs, affected tech, patch timelines β†’ https://thehackernews.com/2026/02/cisa-flags-four-security-flaws-under.html
⚑3πŸ”₯1
⚑ Notepad++ pushed a security update after attackers hijacked its updater to deliver malware to select users.

Version 8.9.2 adds a β€œdouble lock” verification system & hardens the auto-updater after a hosting breach enabled poisoned updates.

πŸ”— Read β†’ https://thehackernews.com/2026/02/notepad-fixes-hijacked-update-mechanism.html
πŸ‘8πŸ”₯3😁3🀯2
🚨 China-linked UNC6201 exploited a CVSS 10.0 (CVE-2026-22769) Dell RecoverPoint zero-day since 2024 using hard-coded credentials.

Access led to Tomcat web shells, BRICKSTORM installs, and newer GRIMBOLT backdoors built to evade detection.

πŸ”— Read β†’ https://thehackernews.com/2026/02/dell-recoverpoint-for-vms-zero-day-cve.html
πŸ”₯5