The Hacker News
βœ”
162K subscribers
3.5K photos
22 videos
4 files
9.47K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
🚨 A malicious Notepad++ plugin is turning the legitimate editor into a malware loader.

CERT-UA links the campaign to Russia-aligned UAC-0099. It establishes persistence and deploys MATCHBOIL.V2 for follow-on malware.

Read more: https://thehackernews.com/2026/07/fake-notepad-plugin-delivers.html
😁9🀯4πŸ”₯1πŸ€”1
πŸ›‘ Kimi K3 AI agents found Redis 0-days. Then they built working RCE exploits.

The authenticated chains abuse RESTORE across multiple #Redis releases. Redis has shipped seven security updates, with no exploitation reported in the wild.

Details: https://thehackernews.com/2026/07/kimi-k3-agents-found-redis-zero-days.html
😁10πŸ”₯8
⚠️ Eight NodeBB forum software flaws are now public, along with exploit code.

Three need no account. Another let an ordinary member open the admin panel, while separate bugs exposed private messages and private categories.

Read: https://thehackernews.com/2026/07/nodebb-patches-eight-ai-found-flaws.html
πŸ”₯4😁2
🚨 Golden Chickens has resurfaced with four new malware families.

One can control live Chrome sessions. Another loads 14 attack modules only when the operator needs them.

Inside the rebuilt MaaS toolkit: https://thehackernews.com/2026/07/golden-chickens-resurfaces-with-four.html
πŸ”₯5😁2
πŸ›‘ A hacker switched off Hermes AI’s command approvals and set the agent loose to automate post-exploitation inside Thailand’s Finance Ministry.

It scanned hosts, searched for ways to gain root access, and crawled staff files dating to 2012. The operation surfaced because the attacker left its logs exposed.

Read the full story: https://thehackernews.com/2026/07/hacker-runs-hermes-ai-agent-unattended.html
😁12πŸ‘3πŸ”₯1πŸ‘1
The hard part of AI agent security is not finding the agents. It is controlling what they can do.

Agents can call APIs, access data, change systems, and act without a human in the loop. Static inventories and permissions are not enough to govern that behavior across every platform.

Visibility is the start. Intent-based enforcement is the control.

Read the full analysis: https://thehackernews.com/2026/07/seeing-ai-agents-is-not-enough-security.html
πŸ”₯3πŸ€”1
🚨 One phishing link could have planted a rogue ChatGPT Workspace Agent inside an organization.

New AgentForger flaw could attach existing connectors, turn off approval prompts, run every hour, and take new commands from the victim’s mailbox.

Read how it worked: https://thehackernews.com/2026/07/chatgpt-agentforger-flaw-could-deploy.html
πŸ”₯6😁4
‼️ Bing Images Turned a 1-Pixel SVG Into a SYSTEM Shell on Microsoft’s Servers.

A crafted SVG sent through Bing’s public image search ran commands as NT AUTHORITY\SYSTEM on Microsoft’s Windows servers and root on its Linux servers.

No login, session, or click required.

Read how the image reached a shell: https://thehackernews.com/2026/07/bing-images-flaws-let-crafted-svgs-run.html
😁8🀯7πŸ”₯3πŸ‘2
πŸ›‘ A public PoC exploit now lets a low-privileged Active Directory user impersonate a Domain Controller.

Certighost obtains a Domain Controller certificate, authenticates as that machine, and uses DCSync to retrieve the krbtgt secret.

Read how it works: https://thehackernews.com/2026/07/certighost-exploit-lets-low-privileged.html
πŸ”₯16πŸ€”2
πŸ›‘ Researchers uncovered an actively developed BlueNoroff phishing kit that uses fake Zoom and Teams calls to profile crypto wallets before delivering malware.

It hijacks trusted Telegram accounts, uses AI-generated faces, and pushes a ClickFix β€œSDK update.”

Read how it works: https://thehackernews.com/2026/07/bluenoroff-zoom-phishing-kit-profiles.html
πŸ”₯6😁1
This media is not supported in your browser
VIEW IN TELEGRAM
🚨 A public GitLab RCE PoC lets an authenticated user run commands as the git user on an unpatched 18.11.3 server.

No admin rights, CI runner access, victim interaction, or access to another user’s project.

See how the notebook-diff chain works: https://thehackernews.com/2026/07/researcher-publishes-gitlab-rce-poc.html
πŸ”₯4⚑1πŸ€”1
⚠️ DevMan RaaS now runs a full affiliate portal.

Experts (tracking it as Funky Mantis) say the platform handles payload builds, victim records, chat, teams, support, and payouts in one place. Affiliates get structured workflows, deadlines, and an 80/20 cut.

184 victims claimed so far.

Read: https://thehackernews.com/2026/07/devman-raas-portal-centralizes-payload.html
πŸ”₯4⚑1πŸ€”1
🚨 Cl0p-linked attackers are actively exploiting a critical unauthenticated RCE in internet-exposed PTC Windchill and FlexPLM systems.

They chain two flaws, drop hex-named JSP webshells, and steal engineering data for double extortion.

Manufacturing, automotive, aerospace, and retail firms are the main targets.

Full details β†’ https://thehackernews.com/2026/07/cl0p-affiliates-target-internet-exposed.html
πŸ”₯3😁2🀯2⚑1
🚨 Insurance phishing kits are now hijacking accounts while victims are still logging in.

InsureOTP relays stolen credentials and one-time passwords to legitimate insurance portals in real time, letting attackers complete authentication within the same browsing session.

Read how the operation works: https://thehackernews.com/2026/07/ctm360-research-reveals-how-insurance.html
πŸ”₯3🀯3
This media is not supported in your browser
VIEW IN TELEGRAM
πŸ›‘ ALERT - A malicious JSON request can become unauthenticated RCE on affected Spring Boot fat-JAR apps running Fastjson 1.x.

Fastjson 1.x has no patched release, and ThreatBook and Imperva report attacks targeting the flaw.

Learn how it works and who’s exposed: https://thehackernews.com/2026/07/fastjson-1x-rce-vulnerability-targeted.html
πŸ”₯9⚑1
🚨 The malware arrives in pieces. The victim’s browser puts it together.

SourTrade malvertising delivers a legitimate Bun runtime, malicious bytecode, and PE components separately, then uses the browser to build the final Windows executable with a different hash each session.

See how the browser-assembled malware chain works: https://thehackernews.com/2026/07/malvertising-sends-malware-in-pieces.html
🀯9πŸ‘6πŸ”₯6⚑1😁1😱1
Commit a Jupyter notebook. Open its diff. Run commands as git on the GitLab server.

depthfirstlabs told The Hacker News its public exploit ports to other x86-64 builds with only offset changes.

Patched in June under bug fixes, no CVE.

Read: https://thehackernews.com/2026/07/researcher-publishes-gitlab-rce-poc.html
πŸ”₯3πŸ‘2⚑1
Can a cloud tenant really black out the power grid? We asked the Bit2Watt researchers.

Their answer πŸ ’ the scariest result only works if thousands of GPUs spike their power at the same instant, and in reality they never line up that cleanly, which blunts the attack.

Also notable: they didn't warn any cloud provider first, because there's no product bug to patch.

Read: https://thehackernews.com/2026/07/new-bit2watt-attack-could-let-cloud.html
πŸ”₯3😁3πŸ€”2⚑1🀯1