The Hacker News
โœ”
162K subscribers
3.26K photos
21 videos
4 files
9.22K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: admin@thehackernews.com

๐ŸŒ Website: https://thehackernews.com
Download Telegram
๐Ÿšจ CVE-2026-55200 now has public PoC code.

The libssh2 flaw lets a malicious SSH server trigger memory corruption in a connecting client.

> No credentials
> No user interaction
> Affected through libssh2 1.11.1

The real cleanup problem is finding bundled and static copies in curl, Git, PHP, and appliances.

Learn more โž https://thehackernews.com/2026/06/public-poc-released-for-critical.html
๐Ÿ”ฅ6
๐Ÿ›‘ Microsoft removed 119 Edge extensions hiding malware in images and fonts.

Up to 2.6 MILLION installs. They posed as ad blockers, VPNs, translators, and video downloaders.

Some payloads stole credentials and ran ad fraud.

Read how StegoAd stayed hidden for years โž https://thehackernews.com/2026/06/microsoft-removes-119-edge-extensions.html
๐Ÿ˜20๐Ÿ”ฅ2
The SOC problem is no longer just detection.

It is the queue.

AI is now taking the first pass on alert triage, enrichment, and routine response so analysts can focus on calls that carry risk.

The 2026 Cybersecurity Stars Awards winners show where SOC automation is headed.

Read the story: https://awards.thehackernews.com/blog/ai-reads-the-alert-queue/
๐Ÿค”5
โš ๏ธ Gamaredon ran 35 phishing campaigns against Ukraine in 2025.

ESET says it used new PowerShell tools, HTML smuggling, and CVE-2025-8088 to plant malware in Startup.

Simple malware. Harder infrastructure.

Read more โ†“ https://thehackernews.com/2026/06/gamaredon-expands-ukraine-attacks-with.html
๐Ÿ‘5๐Ÿคฏ3๐Ÿ”ฅ2๐Ÿค”1
๐Ÿ›‘ 236,493 scam domains.

Experts say DCloud Uni-App templates are being used to run fake crypto exchanges, #WhatsApp phishing, gambling scams, and wallet drainers.

Read the full story โž https://thehackernews.com/2026/06/236000-dcloud-uni-app-sites-used-in.html
๐Ÿ˜ฑ4๐Ÿ”ฅ2๐Ÿ˜2
๐Ÿ›‘ EvilTokens hides account takeover risk from your SOC.

Static URL analysis misses it as the phishing page appears only after browser-side decryption. Avoid visibility gaps and accelerate response by uncovering the full attack flow in 1 min.

Read โž https://thn.news/ghost-analysis-2023
๐Ÿ”ฅ9๐Ÿ‘4
Your encrypted credentials may not stay encrypted forever.

Attackers can harvest them now, store them, and decrypt them later when quantum hardware catches up.

That is why post-quantum migration should start with long-lived credentials and machine identities.

Read the full story: https://thehackernews.com/2026/06/why-post-quantum-cryptography-starts.html
๐Ÿ‘10๐Ÿ˜ฑ2๐Ÿ˜1๐Ÿค”1
โš ๏ธ Mustang Panda hid C2 in cloud traffic.

Acronis says the China-aligned group abused Zoho WorkDrive as a command channel in campaigns against Indian government and hydropower targets.

ZOHOMURK read commands from an inbox folder and wrote stolen output to an outbox.

Read ๐Ÿ – https://thehackernews.com/2026/06/mustang-panda-uses-zoho-workdrive-as.html
๐Ÿค”5๐Ÿ‘2
โšก DirtyClone leads the week, but the rest of the queue is ugly:

๐Ÿง Linux root bug
๐Ÿšจ PTC exploited
๐ŸŽ Gaslight malware
๐ŸŽฏ Turla backdoor
๐Ÿงน StealC takedown
๐Ÿค– Agent prompt injection
๐Ÿ•ต๏ธ New infostealers
๐Ÿ“บ DVR proxy abuse
๐Ÿงฉ Urgent CVEs

Full recap: https://thehackernews.com/2026/06/weekly-recap-linux-kernel-flaws-ai.html
๐Ÿ‘6๐Ÿ”ฅ2โšก1
๐Ÿ”ฅ #WhatsApp is finally getting usernames.

The app has started global username reservations before a wider rollout later this year.

So people can message each other without handing over a phone number.

Details here: https://thehackernews.com/2026/06/whatsapp-is-finally-getting-usernames.html
๐Ÿ”ฅ26๐Ÿ‘13๐Ÿ˜9๐Ÿ‘4
๐Ÿ›‘ The extension did not need to steal passwords to be dangerous.

Microsoft found a fake #Perplexity Chrome extension that logged searches and address bar input before redirecting users to real results.

How it worked, and what users should check: https://thehackernews.com/2026/06/malicious-perplexity-chrome-extension.html
๐Ÿคฏ4๐Ÿ”ฅ3๐Ÿ‘2๐Ÿ˜2
๐Ÿšจ Oracle E-Business Suite has a new active exploitation problem.

CVE-2026-46817 is a CVSS 9.8 flaw in Oracle Payments that can allow unauthenticated HTTP takeover.

No public PoC. Attribution unknown.

Read the full report: https://thehackernews.com/2026/06/oracle-e-business-suite-flaw-cve-2026.html
๐Ÿค”4๐Ÿ”ฅ3๐Ÿ˜2โšก1๐Ÿคฏ1
โšก Apple patched WebKit bugs found with AI tools.

The updates fix 30+ flaws across:
> iOS 26.5.2
> macOS Tahoe 26.5.2
> Safari 26.5.2

The fixes include WebKit CVEs, sandbox issues, and kernel-level bugs.

Details: https://thehackernews.com/2026/06/apple-patches-30-ios-macos-safari-flaws.html
โš ๏ธ Public PoC is out for CVE-2026-8037, a critical Progress Kemp LoadMaster API flaw.

It lets unauthenticated attackers run root commands when the API is enabled.

Patch now. Restrict API exposure.

Full story: https://thehackernews.com/2026/06/progress-kemp-loadmaster-flaw-could-let.html
๐Ÿคฏ1
๐ŸŽฎ Tell an AI browser itโ€™s just playing a game.

Researchers say "BioShocking" tricked six AI agents, including #ChatGPT Atlas, Comet, and #Claude, into copying GitHub SSH credentials from a signed-in session.

Read how the attack chain worked: https://thehackernews.com/2026/06/new-bioshocking-attack-tricks-ai.html
๐Ÿ”ฅ3๐Ÿ˜3๐Ÿ‘1
๐Ÿšจ Nearby file sharing has a local blind spot.

Researchers found six flaws in AirDrop and Quick Share that can crash sharing services, bypass Samsung session checks, and trigger a crash in Googleโ€™s Windows app.

Apple and Google have started fixes.

Read: https://thehackernews.com/2026/06/airdrop-and-quick-share-flaws-let.html