The Hacker News
βœ”
162K subscribers
3.49K photos
22 videos
4 files
9.46K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
UPDATE: OpenSSL told THN that it views HollowByte as a server configuration issue, not a protocol flaw.

But key questions remain: whether the shipped fix improves glibc’s memory behavior and whether extended-support branches received the fix.

Okta still advises users running affected versions to upgrade.

Read: https://thehackernews.com/2026/07/openssl-hollowbyte-flaw-could-freeze.html
πŸ”₯8
🚨 A Russian intelligence service is hijacking exposed IP cameras across Europe and Ukraine to track military routes and weapons shipments.

In Ukraine, the feeds have aided attempts to neutralize troops and destroy equipment.

Read here: https://thehackernews.com/2026/07/russian-intelligence-hacks-ip-cameras.html
πŸ€”17πŸ”₯5🀯3
Attackers can move in 29 minutes. High and critical application flaws take 55 days on average to fix.

The real problem is not how many vulnerabilities AI finds. It is how long those vulnerabilities stay exposed.

Read why mobilization now matters most: https://thehackernews.com/2026/07/mythos-didnt-break-your-security.html
🀯4😁1
Starting the week with a fresh batch of security problems to track.

πŸ”΄ WordPress RCE
⚠️ SonicWall Zero-Days
πŸ€– AI Key-Hunting Botnet
πŸ—‚οΈ SharePoint Exploitation
πŸ’Ύ OpenSSL Memory DoS
πŸ” Crypto Wallet Stealer
πŸ›‘ EDR-Killing Ransomware
πŸ“© Fake GST Malware
🏭 Nuclear Data Leak
🧩 Public Code Abuse

Read the full Cybersecurity Recap: https://thehackernews.com/2026/07/weekly-recap-wordpress-rce-sonicwall-0.html
πŸ”₯8
AI agents are inheriting long-lived secrets, broad access, and accounts that nobody properly manages.

Compromise one, and an attacker gains an identity that can call tools, chain actions, and move through systems at machine speed.

Why securing AI agents starts with privilege, not the model: https://thehackernews.com/expert-insights/2026/07/the-new-insider-has-no-pulse-securing.html
πŸ”₯5πŸ‘1
🚨 This malware hides in Microsoft 365 calendar events dated to 2050.

You would never scroll that far.
HollowGraph counts on it.

The calendar carries attacker commands and stolen files through normal Graph traffic.

Here's how it works: https://thehackernews.com/2026/07/hollowgraph-malware-hides-c2-and-stolen.html
πŸ”₯7😁4⚑2πŸ‘2
🚨 A malware operator left its server wide open, exposing a 1,048-file phishing toolkit.

A live campaign used a fake Mexican government site and WebDAV to drop an in-memory infostealer. The recovered files point to an AI-assisted build-and-test workflow.

Read more: https://thehackernews.com/2026/07/exposed-server-reveals-ai-assisted.html
😁16πŸ”₯4⚑2
7,600 malicious GitHub repositories are spreading SmartLoader malware.

Researchers found 800+ fake AI Skills and MCP server repos using copied projects, fake profiles, and READMEs to deliver malware.

Read the full analysis: https://thehackernews.com/2026/07/fakegit-campaign-uses-7600-github.html
⚑8
⚠️ Attackers are exploiting a critical ServiceNow AI Platform flaw in the wild.

CVE-2026-6875 is a pre-authentication sandbox escape that could let an unauthenticated attacker run arbitrary code.

Self-hosted customers should check their patch status now.

Details: https://thehackernews.com/2026/07/critical-servicenow-ai-platform-flaw.html
πŸ”₯6
πŸ›‘ New ENCFORGE ransomware is built to encrypt AI model weights, vector indexes, and training data.

Deployed via Langflow CVE-2025-3248 (CVSS 9.8, CISA KEV). Experts link it to the same operator from the earlier agentic attack.

Learn how the attack reached host root: https://thehackernews.com/2026/07/new-encforge-ransomware-targets-ai.html
😁4πŸ‘2πŸ”₯1
UPDATE: SharkNinja has responded to The Hacker News story on the Shark robot vacuum flaw.

The company says it has "completely addressed" the vulnerability, but has not said when the fix shipped, whether it reissued the exposed device certificates or only rescoped the policy, or how many devices were affected.

Full statement in the article: https://thehackernews.com/2026/07/unpatched-shark-vacuum-flaw-could-let.html
⚑4
πŸ›‘ ALERT - WordPress sites are under active attack.

Attackers are exploiting the #wp2shell chain to gain unauthenticated RCE on vulnerable stock installations, with no plugins required. Public exploit code is now fueling mass scanning and web shell deployments.

Read what defenders should check: https://thehackernews.com/2026/07/wordpress-wp2shell-exploitation-grows.html
πŸ”₯8πŸ‘3⚑2
Developer laptops are heavily monitored, yet valid credentials still hide in files, caches, logs, and AI tool directories.

Carole Winqwist of GitGuardian explains what endpoint security misses, why those secrets matter, and how teams can find them before an incident.

See what the most monitored device still hides: https://thehackernews.com/expert-insights/2026/07/the-most-monitored-device-in-company-is.html
πŸ‘4πŸ”₯3
⚑ A cloud tenant could threaten the power grid without exploiting a single vulnerability.

New research called Bit2Watt shows how legitimate GPU workloads can be tuned to create rapid power swings, then models how synchronized fleets could destabilize the grid beneath a data center.

Full story: https://thehackernews.com/2026/07/new-bit2watt-attack-could-let-cloud.html
πŸ”₯4😁2⚑1
Claude Mythos turned a Firefox security patch into a working code-execution exploit in under an hour.

It built 8 exploits from 18 Firefox patches and chained 8 Windows kernel bugs to SYSTEM.

The patch-to-exploit window is collapsing.

Read why patching faster is no longer enough: https://thehackernews.com/2026/07/n-day-is-becoming-n-hour-patching.html
😁11πŸ‘5πŸ”₯4
🚨 Invisible text on an #Android screen can hijack an AI agent and make it run commands on the PC controlling the phone.

Researchers tested 5 open-source frameworks. Every one failed at least six of seven attacks.

Read how the chain works: https://thehackernews.com/2026/07/open-source-android-ai-agents-could-let.html
🀯7πŸ”₯6😁3
🚨 A critical Zimbra flaw could allow command injection on servers with SNMP notifications enabled.

Zimbra 10.1.20 also fixes four XSS bugs and a mail-forwarding bypass that could let authenticated users exfiltrate email.

Read the full details: https://thehackernews.com/2026/07/zimbra-patches-critical-snmp-command.html
πŸ”₯5
🚨 Attackers are exploiting Palo Alto Networks PAN-OS flaw CVE-2026-0257 to deploy Qilin ransomware.

Some intrusions ended in rapid encryption. Others escalated to credential theft, data exfiltration, and double extortion.

How the attacks unfolded: https://thehackernews.com/2026/07/qilin-ransomware-attackers-exploit-pan.html
πŸ”₯4
🚨 Patching your #SharePoint Server may not be enough if it was already exposed.

Attackers are exploiting CVE-2026-50522, a critical RCE flaw, to pull machine keys with a single request and maintain access, watchTowr says.

A public PoC is available, and this is the third SharePoint Server flaw linked to active exploitation in July 2026.

Details: https://thehackernews.com/2026/07/critical-sharepoint-rce-cve-2026-50522.html
πŸ‘5
⚑ Google built an AI that finds and patches software vulnerabilities on its own, and it's capable enough that Google won't release it publicly.

In testing, "Gemini 3.5 Flash Cyber" found more new bugs than rival models and even wrote a working exploit that slipped past standard defenses.

Read more: https://thehackernews.com/2026/07/google-launches-gemini-35-flash-cyber.html
😁17πŸ”₯3⚑1
πŸ›‘ Invisible text on a web page was enough to hijack AWS's Kiro AI coding tool.

Ask it to summarize a page, and hidden instructions make Kiro rewrite its own config and run attacker code. The approval prompt did nothing.

Learn how the attack crossed Kiro's security boundary: https://thehackernews.com/2026/07/aws-kiro-flaw-let-poisoned-web-page.html
πŸ”₯11😁2⚑1