The Hacker News
βœ”
162K subscribers
3.47K photos
22 videos
4 files
9.44K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
⚑ Google built an AI that finds and patches software vulnerabilities on its own, and it's capable enough that Google won't release it publicly.

In testing, "Gemini 3.5 Flash Cyber" found more new bugs than rival models and even wrote a working exploit that slipped past standard defenses.

Read more: https://thehackernews.com/2026/07/google-launches-gemini-35-flash-cyber.html
😁16πŸ”₯3
πŸ›‘ Invisible text on a web page was enough to hijack AWS's Kiro AI coding tool.

Ask it to summarize a page, and hidden instructions make Kiro rewrite its own config and run attacker code. The approval prompt did nothing.

Learn how the attack crossed Kiro's security boundary: https://thehackernews.com/2026/07/aws-kiro-flaw-let-poisoned-web-page.html
πŸ”₯11😁2
Apple’s Hide My Email exposed the real address it was designed to hide.

A flaw caused users’ personal email addresses to appear in mail logs when messages sent to an alias were rejected as spam.

Apple fixed it on July 3, more than a year after disclosure.

Read how the leak worked: https://thehackernews.com/2026/07/apple-fixes-hide-my-email-bug-that.html
🀯13😁7πŸ‘3πŸ”₯2
πŸ”₯ OpenAI says its own AI models broke out of a sandbox, exploited a zero-day, and targeted Hugging Face’s production infrastructure to cheat a security benchmark.

The incident showed how long-running models can learn and work around approval-system blind spots.

Read the full story: https://thehackernews.com/2026/07/openai-says-its-own-ai-models-escaped.html
😱17😁2πŸ€”2⚑1🀯1
⚠️ An attacker does not need the reviewer’s broader Azure DevOps permissions.

In tests, one hidden PR comment steered the reviewer’s AI coding agent into other projects and leaked data the attacker could not access directly.

How the missing MCP guardrail enables the chain: https://thehackernews.com/2026/07/microsoft-azure-devops-mcp-flaw-lets.html
😱7
One extra β€œt” hid a package built to rig live betting results.

Newtonsoftt.Json[.]Net worked as a normal JSON library for most users, but targeted Digitain’s FG-Crash backend when the right conditions were present.

Inside the selective attack: https://thehackernews.com/2026/07/trojanized-newtonsoftjson-fork-hides.html
😁5πŸ”₯3
πŸ›‘ MFA didn’t stop Kratos.

The phishing kit stole Microsoft 365 session cookies, letting attackers enter accounts without another MFA check. Police took 200+ servers offline and arrested the alleged operator in Indonesia.

But about 1,800 customers may still have the code.

Read: https://thehackernews.com/2026/07/police-dismantle-kratos-phishing-kit.html
πŸ”₯10😁3
Around 79% of attacks are malware-free, CrowdStrike estimates.

Endpoint alerts alone can miss credential theft and lateral movement across identity and cloud systems. AI cannot connect what the SOC never captured.

Why network evidence matters: https://thehackernews.com/2026/07/why-modern-socs-need-multi-layered.html
πŸ”₯3
Windmill servers are under active attack.

Experts say attackers are exploiting CVE-2026-29059 to read arbitrary server files without logging in. On some systems, the same flaw can lead to superadmin access and code execution.

Full details: https://thehackernews.com/2026/07/hackers-exploit-windmill-flaw-to-read.html
πŸ”₯4
76% of employees now use AI at work. Most of those tools were never reviewed by security.

When approval takes six weeks and a workaround takes six minutes, AI use moves out of sight.

How to make the secure path the faster one: https://thehackernews.com/2026/07/the-fastest-path-to-ai-adoption-runs.html
πŸ”₯3😁3πŸ‘2
πŸ›‘ One visit to a malicious webpage could have been enough to expose your #WhatsApp Web chats.

CVE-2026-48294 in Adobe Acrobat’s Chrome extension could read messages, contact names, chat previews, and profile data without malware, stolen credentials, or session cookies.

The extension has over 314 million users.

See how HermeticReader worked: https://thehackernews.com/2026/07/adobe-acrobat-extension-flaw-let.html
πŸ€”5😁2πŸ‘1πŸ”₯1
⚑ AI is pushing code output up 10–50x. Security programs still assume humans can review what humans build.

That model breaks at machine speed.

Learn how to govern AI-built software with secure-by-default architecture.

Save your seat: https://thehacker.news/secure-ai-development
πŸ”₯6😁2
🚨 A flaw in Ubuntu’s snap-confine could turn local user access into root.

CVE-2026-8933 chains FUSE and symlink race conditions to plant malicious udev rules and execute commands as root.

Default Ubuntu #Linux Desktop 24.04, 25.10, and 26.04 installations are affected.

Read how the exploit works: https://thehackernews.com/2026/07/ubuntu-snap-confine-flaw-could-give.html
πŸ”₯5
GitHub is cutting public bug bounty payouts by at least half.

The reset comes as AI floods programs with low-effort reports while helping skilled researchers find real bugs faster.

Top rewards now move to an invite-only VIP tier.

Read the full story: https://thehackernews.com/2026/07/github-cuts-public-bug-bounty-payouts.html
🀯13πŸ”₯3πŸ‘2😱2