The Hacker News
βœ”
162K subscribers
3.49K photos
22 videos
4 files
9.46K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
GitHub is cutting public bug bounty payouts by at least half.

The reset comes as AI floods programs with low-effort reports while helping skilled researchers find real bugs faster.

Top rewards now move to an invite-only VIP tier.

Read the full story: https://thehackernews.com/2026/07/github-cuts-public-bug-bounty-payouts.html
🀯18πŸ”₯4πŸ‘2😱2πŸ€”1
⚠️ Attackers are exploiting a Check Point SmartConsole flaw that can grant full administrative access.

CVE-2026-16232 affects management servers exposed directly to the internet under a specific configuration. Check Point says a small number of customers were targeted.

Read: https://thehackernews.com/2026/07/check-point-patches-exploited.html
πŸ”₯5
πŸ›‘ A newly disclosed, 9-year-old #Linux flaw lets unprivileged users overwrite root-owned files and gain persistent root access.

On affected XFS systems, the overwrite survives reboot without changing ownership, permissions, timestamps, or the setuid bit.

Read: https://thehackernews.com/2026/07/nine-year-old-refluxfs-linux-flaw-gives.html
πŸ”₯9⚑3πŸ‘2
πŸ”₯ Google now lets users RECOVER LOCKED ACCOUNTS with a selfie video.

Users save a face clip, then record another when they need to prove the account is theirs. An optional setting can expand how Google uses that data beyond sign-in.

What is stored and how it may be used: https://thehackernews.com/2026/07/google-adds-selfie-video-recovery-for.html
😱16πŸ€”8⚑4πŸ”₯1
🚨 Attackers turned GitHub-hosted runners into cPanel attack infrastructure.

They planted 583 malicious workflows to target cPanel and WHM servers exposed to CVE-2026-41940, hunting for cloud keys, API tokens, SSH data, and other secrets.

How the campaign worked: https://thehackernews.com/2026/07/attackers-weaponize-github-actions.html
πŸ”₯6πŸ‘3
Social engineering is now a margin game.

Convincing lures cost 95% less to produce. Median time to click: 21 seconds.

Doppel’s Josh Bartolomie says defenders should stop chasing lures and make attacks too costly to scale.

Learn how to break the economics: https://thehackernews.com/expert-insights/2026/07/how-to-make-social-engineering.html
πŸ”₯5
πŸ›‘ China-nexus JadeProx breached a Vietnamese hospital’s medical imaging server and targeted Malaysia’s foreign ministry with a new Windows loader.

The same operation also hid malware inside a fake Claude installer.

How the campaign worked: https://thehackernews.com/2026/07/china-nexus-jadeprox-uses-new-triback.html
πŸ”₯5😁1
‼️ Chaos Hid Its C2 Inside Chrome.

Instead of connecting directly to its command server, Chaos #ransomware’s msaRAT launches Chrome or Edge in hidden mode and uses the browser to send encrypted commands over WebRTC, making the malicious traffic look like normal browser activity.

Read: https://thehackernews.com/2026/07/chaos-ransomware-uses-msarat-to-route.html
😱7πŸ‘5🀯1
This media is not supported in your browser
VIEW IN TELEGRAM
🚨 Researchers say one short message let Claude Cowork escape its Linux VM and access files across the host Mac.

The SharedRoot chain used CVE-2026-46331 to gain guest root, then crossed through Cowork’s read-write host mount.

Read how it worked: https://thehackernews.com/2026/07/claude-cowork-flaw-could-let-ai-agent.html
πŸ‘10
This media is not supported in your browser
VIEW IN TELEGRAM
🚨 Attackers are targeting the datacenters that train, host, and serve AI, not just the AI models themselves.

Lava has released FORGE: The Top 10 Data Center & AI Infrastructure Security Risks: https://thn.news/forge-risk-guide

Built with security leaders and practitioners across neoclouds, HPC, and enterprise security β€” open, free, and made to evolve.
πŸ”₯8😁2
⚑ Spyware on Phones, Malware in Code, Attacks on Factories

This week’s #ThreatsDay roundup covers 15 security stories spanning mobile surveillance, software supply-chain attacks, AI abuse, and industrial systems.

β€’ PyPI Lockdown
β€’ PLC Attacks
β€’ Fake VPN Malware
β€’ Vibe-Code Bugs
β€’ AI Jailbreaks
β€’ TrickBot DNS
β€’ AI Bug Hunter

...and more. Read: https://thehackernews.com/2026/07/threatsday-android-spyware-plc-attacks.html
πŸ”₯6
Not every dangerous machine identity is stolen. Some are fake from the start.

Fabricated machine identities can blend into NHI sprawl, gain privileges, and evade controls built to catch stolen credentials because no legitimate owner exists to raise the alarm.

See how it works: https://thehackernews.com/2026/07/how-synthetic-identity-fraud-is-coming.html
πŸ‘3
πŸ›‘ No link. No attachment. Just viewing the email.

A Russian state-supported espionage group exploited a Zimbra zero-day for at least 5 months to steal passwords, 2FA recovery codes, organization directories, and 90 days of mail.

Read how ZimReaper worked - https://thehackernews.com/2026/07/russian-espionage-group-exploited.html
πŸ”₯12🀯7😁4😱2⚑1
🚨 A malicious Notepad++ plugin is turning the legitimate editor into a malware loader.

CERT-UA links the campaign to Russia-aligned UAC-0099. It establishes persistence and deploys MATCHBOIL.V2 for follow-on malware.

Read more: https://thehackernews.com/2026/07/fake-notepad-plugin-delivers.html
😁7🀯2πŸ”₯1πŸ€”1
πŸ›‘ Kimi K3 AI agents found Redis 0-days. Then they built working RCE exploits.

The authenticated chains abuse RESTORE across multiple #Redis releases. Redis has shipped seven security updates, with no exploitation reported in the wild.

Details: https://thehackernews.com/2026/07/kimi-k3-agents-found-redis-zero-days.html
😁8πŸ”₯7
⚠️ Eight NodeBB forum software flaws are now public, along with exploit code.

Three need no account. Another let an ordinary member open the admin panel, while separate bugs exposed private messages and private categories.

Read: https://thehackernews.com/2026/07/nodebb-patches-eight-ai-found-flaws.html
πŸ”₯2😁2
🚨 Golden Chickens has resurfaced with four new malware families.

One can control live Chrome sessions. Another loads 14 attack modules only when the operator needs them.

Inside the rebuilt MaaS toolkit: https://thehackernews.com/2026/07/golden-chickens-resurfaces-with-four.html
πŸ”₯3😁2
πŸ›‘ A hacker switched off Hermes AI’s command approvals and set the agent loose to automate post-exploitation inside Thailand’s Finance Ministry.

It scanned hosts, searched for ways to gain root access, and crawled staff files dating to 2012. The operation surfaced because the attacker left its logs exposed.

Read the full story: https://thehackernews.com/2026/07/hacker-runs-hermes-ai-agent-unattended.html
😁10πŸ‘2πŸ”₯1πŸ‘1
The hard part of AI agent security is not finding the agents. It is controlling what they can do.

Agents can call APIs, access data, change systems, and act without a human in the loop. Static inventories and permissions are not enough to govern that behavior across every platform.

Visibility is the start. Intent-based enforcement is the control.

Read the full analysis: https://thehackernews.com/2026/07/seeing-ai-agents-is-not-enough-security.html
πŸ”₯2
🚨 One phishing link could have planted a rogue ChatGPT Workspace Agent inside an organization.

New AgentForger flaw could attach existing connectors, turn off approval prompts, run every hour, and take new commands from the victim’s mailbox.

Read how it worked: https://thehackernews.com/2026/07/chatgpt-agentforger-flaw-could-deploy.html
πŸ”₯3😁3
‼️ Bing Images Turned a 1-Pixel SVG Into a SYSTEM Shell on Microsoft’s Servers.

A crafted SVG sent through Bing’s public image search ran commands as NT AUTHORITY\SYSTEM on Microsoft’s Windows servers and root on its Linux servers.

No login, session, or click required.

Read how the image reached a shell: https://thehackernews.com/2026/07/bing-images-flaws-let-crafted-svgs-run.html
😁8🀯3πŸ”₯2