The Hacker News
βœ”
162K subscribers
3.11K photos
20 videos
4 files
9.07K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
🚨 New Cisco SD-WAN vulnerability under active exploitation.

CVE-2026-20245 lets authenticated netadmin attackers run commands as root via crafted file uploads.

No patches or mitigations are available.

Check /var/log/scripts.log for IoCs.

Read: https://thehackernews.com/2026/06/cisco-catalyst-sd-wan-manager-cve-2026.html
πŸ”₯8⚑5
🚨 73 Microsoft GitHub repos just went dark.

They were hit by Miasma, a self-replicating supply chain attack spreading through trusted open-source channels.

Azure and MicrosoftDocs repos were among those impacted.

Read this: https://thehackernews.com/2026/06/miasma-worm-hits-73-microsoft-github.html
πŸ”₯12😁5πŸ‘3⚑1πŸ‘1
πŸ”₯ AI just found 21 zero-days in FFmpeg.

That’s the video library bundled inside many apps, tools, containers, and devices. Some bugs sat untouched for 15–20 years.

Google Chrome also dropped PATCHES for a record 429 vulnerabilities this week.

Read: https://thehackernews.com/2026/06/ai-agent-uncovers-21-zero-days-in.html
😁14🀯10πŸ”₯3⚑2πŸ‘1
🚨 A SolarWinds Serv-U bug is now on CISA’s exploited list.

CVE-2026-28318 can let unauthenticated requests crash the file server.

Patch: Serv-U 15.5.4 HF1.

Federal agencies have until June 19, 2026.

Read: https://thehackernews.com/2026/06/cisa-adds-actively-exploited-solarwinds.html
⚑3πŸ‘1πŸ”₯1😁1
⚑ Your Smart TV might be scraping the web for πŸ€– AI.

Not hacked. You tapped "accept" for fewer ads.

It said "occasionally." The fine print allows 200 GB a month.

Read ➝ https://thehackernews.com/2026/06/free-apps-are-quietly-turning-smart-tvs.html

Your IP. Your bandwidth. Someone else's bot.
🀯21πŸ‘4⚑3πŸ”₯1😁1
OpenAI is adding β€œLOCKDOWN MODE” to #ChatGPT.

It won’t stop prompt injections.

It’s built to reduce what attackers want next: a way to leak your data out.

The mode limits tools that connect to the web or external services, including browsing, images, deep research, agent mode, and file downloads.

Read ➝ https://thehackernews.com/2026/06/new-chatgpt-lockdown-mode-limits-tools.html
πŸ‘16😁7😱4πŸ”₯2
⚑ #Microsoft is adding a 2-hour delay before VS Code extensions auto-update.

The wait gives maintainers more time to catch bad or compromised releases before they spread further.

⁃ Microsoft, #GitHub, and #OpenAI extensions update instantly
⁃ Manual updates still work anytime
⁃ npm, pnpm, Bun, Yarn, and Bundler added similar delays

Read details: https://thehackernews.com/2026/06/vs-code-adds-2-hour-extension-auto.html
😁15πŸ”₯8πŸ‘5πŸ€”3
🚨 Dozens of U.S. firms were targeted with a simple playbook:

> Fake invoice email
> Fake IT support call
> Screen share
> Remote access tool
> Data theft
> Extortion demand within 30 mins

UNC3753 hit legal, finance, and professional services firms in Jan–May 2026.

Read: https://thehackernews.com/2026/06/unc3753-used-vishing-and-physical.html
πŸ‘6😱4😁3πŸ”₯2πŸ€”2🀯1
⚠️ China-linked spies hid where security tools often don’t look.

They used BRICKSTORM, PLENET, and AGENTPSD on #Linux appliances, including Egnyte Storage Sync, pfSense, and Synology NAS.

The access lasted at least 18 months.

Full story: https://thehackernews.com/2026/06/verdantbamboo-deploys-bsd-variant-of.html
πŸ‘8πŸ”₯8
AI isn’t just finding open-source bugs.

It may turn thousands of ignored scanner alerts into real attack chains β€” faster than maintainers can patch them.

That could force a new model for open-source security.

Why this matters now: https://thehackernews.com/2026/06/the-hardest-fork.html
πŸ‘11πŸ”₯3
πŸ›‘ Hackers can get into some Check Point VPNs without knowing the password.

And it’s already being exploited.

The bug is CVE-2026-50751 and affects IKEv1 Remote Access/Mobile Access setups.

Check if your gateways are exposed.

Read: https://thehackernews.com/2026/06/critical-check-point-vpn-flaw-exploited.html
πŸ”₯9
AI is finding zero-days faster than security teams can respond.
NIST can't keep pace with CVEs.
Exploitation windows are now measured in hours.

Most vulnerability management programs weren't built for this environment.

In the latest Resilient Cyber episode, Chris Hughes sits down with Ivan Dwyer of Axonius to discuss what comes next β€” asset visibility, board conversations, AI vs. AI, and the metrics that actually matter when the volume explodes.

The Vulnpocalypse Playbook >> https://thn.news/vulnpocalypse-guide
😱8πŸ€”3😁2
🚨 Meta caught NSO Group trying again.

This time, the spyware vendor was linked to phishing links aimed at #WhatsApp users β€” even after a court order barred it from targeting them.

Now Meta wants NSO held in contempt.

Details: https://thehackernews.com/2026/06/meta-blocks-nso-groups-new-whatsapp.html
πŸ”₯11πŸ‘3😁2🀯1
⚠️ AI didn't just make phishing better. It made it endless.

Attackers now spin up fake login pages and tailored lures in minutes. Every polished email piles onto your Tier 1 queue, and a real credential theft can sit buried while your team clears the noise.

Here's how SOCs are cutting through it πŸ‘‡ https://thehackernews.com/2026/06/ai-phishing-is-crushing-socs-with-alert.html
😁10πŸ”₯1
> A worm loose in #Microsoft's own repos.
> A phone flaw is already being used to break in.
> Accounts stolen just by chatting with a support bot.
> A browser update that quietly mined crypto.
> Fake job ads hunting people with security clearances.
> A spy sitting in one inbox for five months.

That was just last week.

Here's everything you missed πŸ‘‡ https://thehackernews.com/2026/06/weekly-recap-instagram-account-hacks.html
πŸ”₯8😁2πŸ‘1πŸ‘1
🚨 A single stray "!" in the #Linux kernel's firewall code (nftables).

That one character let any normal logged-in user become root, and step out of the container.

The fix? One line.

And the exploit (CVE-2026-23111) to abuse it just went public.

Read: https://thehackernews.com/2026/06/one-character-linux-kernel-flaw-enables.html
🀯13⚑5😱3πŸ”₯2
🚨 Hackers are already exploiting a flaw in LiteLLM, a widely used open-source AI gateway.

One bug (CVE-2026-42271) lets any logged-in user run commands on the server. Chain it with a second bug, and attackers get in with no login at all.

At risk: API keys, stored secrets, and everything connected to it.

πŸ”— Details: https://thehackernews.com/2026/06/litellm-flaw-cve-2026-42271-exploited.html
😁17πŸ”₯2😱2
The "IT helpdesk" messaging you on Microsoft Teams could be a complete stranger.

Then your manager calls to confirm it's urgent. Same voice, except it's an AI clone built from a clip online.

Brian Long, founder of Adaptive Security, takes apart the rest: no malware, no exploit, all built-in Microsoft tools. The only thing they have to break is you.

The 10-minute window where nobody notices πŸ‘‡ https://thehackernews.com/expert-insights/2026/06/how-attackers-are-adding-ai-voice.html
πŸ‘7πŸ”₯2😱2⚑1
πŸ›‘ 37 poisoned wheels. 19 PyPI packages.

The malware can run when Python starts, before you import the poisoned PyPI package.

"Hades" installs Bun, starts a hidden stealer, and grabs GitHub, cloud, CI/CD, SSH, Docker, and developer secrets.

Read more on the Hades PyPI attack: https://thehackernews.com/2026/06/hades-pypi-attack-19-packages-poisoned.html
πŸ€”5πŸ”₯2⚑1
🚨 A website can figure out what you're doing on your computer.

No download. No permission. No popup.

> It's called FROST.
> Up to 95% accurate.
> And there's no fix yet.

You just leave the tab open, and JavaScript times your SSD to tell which sites you visit and which apps you open.

πŸ”— Learn how this works: https://thehackernews.com/2026/06/new-frost-attack-lets-websites-track.html
🀯22πŸ”₯4⚑1
🚨 WARNING: Google just fixed a Chrome zero-day already used in real attacks.

The bug (CVE-2026-11645) hits V8, Chrome’s JavaScript engine, and can let attackers run code through a crafted HTML page.

Update your browser now.

Read the full story: https://thehackernews.com/2026/06/chrome-v8-zero-day-cve-2026-11645.html
πŸ”₯9πŸ‘6πŸ‘1