The Hacker News
βœ”
162K subscribers
3.5K photos
22 videos
4 files
9.47K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
‼️ Bing Images Turned a 1-Pixel SVG Into a SYSTEM Shell on Microsoft’s Servers.

A crafted SVG sent through Bing’s public image search ran commands as NT AUTHORITY\SYSTEM on Microsoft’s Windows servers and root on its Linux servers.

No login, session, or click required.

Read how the image reached a shell: https://thehackernews.com/2026/07/bing-images-flaws-let-crafted-svgs-run.html
😁8🀯7πŸ”₯3πŸ‘2
πŸ›‘ A public PoC exploit now lets a low-privileged Active Directory user impersonate a Domain Controller.

Certighost obtains a Domain Controller certificate, authenticates as that machine, and uses DCSync to retrieve the krbtgt secret.

Read how it works: https://thehackernews.com/2026/07/certighost-exploit-lets-low-privileged.html
πŸ”₯16πŸ€”2
πŸ›‘ Researchers uncovered an actively developed BlueNoroff phishing kit that uses fake Zoom and Teams calls to profile crypto wallets before delivering malware.

It hijacks trusted Telegram accounts, uses AI-generated faces, and pushes a ClickFix β€œSDK update.”

Read how it works: https://thehackernews.com/2026/07/bluenoroff-zoom-phishing-kit-profiles.html
πŸ”₯6😁1
This media is not supported in your browser
VIEW IN TELEGRAM
🚨 A public GitLab RCE PoC lets an authenticated user run commands as the git user on an unpatched 18.11.3 server.

No admin rights, CI runner access, victim interaction, or access to another user’s project.

See how the notebook-diff chain works: https://thehackernews.com/2026/07/researcher-publishes-gitlab-rce-poc.html
πŸ”₯4⚑1πŸ€”1
⚠️ DevMan RaaS now runs a full affiliate portal.

Experts (tracking it as Funky Mantis) say the platform handles payload builds, victim records, chat, teams, support, and payouts in one place. Affiliates get structured workflows, deadlines, and an 80/20 cut.

184 victims claimed so far.

Read: https://thehackernews.com/2026/07/devman-raas-portal-centralizes-payload.html
πŸ”₯4⚑1πŸ€”1
🚨 Cl0p-linked attackers are actively exploiting a critical unauthenticated RCE in internet-exposed PTC Windchill and FlexPLM systems.

They chain two flaws, drop hex-named JSP webshells, and steal engineering data for double extortion.

Manufacturing, automotive, aerospace, and retail firms are the main targets.

Full details β†’ https://thehackernews.com/2026/07/cl0p-affiliates-target-internet-exposed.html
πŸ”₯3😁2🀯2⚑1
🚨 Insurance phishing kits are now hijacking accounts while victims are still logging in.

InsureOTP relays stolen credentials and one-time passwords to legitimate insurance portals in real time, letting attackers complete authentication within the same browsing session.

Read how the operation works: https://thehackernews.com/2026/07/ctm360-research-reveals-how-insurance.html
πŸ”₯3🀯3
This media is not supported in your browser
VIEW IN TELEGRAM
πŸ›‘ ALERT - A malicious JSON request can become unauthenticated RCE on affected Spring Boot fat-JAR apps running Fastjson 1.x.

Fastjson 1.x has no patched release, and ThreatBook and Imperva report attacks targeting the flaw.

Learn how it works and who’s exposed: https://thehackernews.com/2026/07/fastjson-1x-rce-vulnerability-targeted.html
πŸ”₯9⚑1
🚨 The malware arrives in pieces. The victim’s browser puts it together.

SourTrade malvertising delivers a legitimate Bun runtime, malicious bytecode, and PE components separately, then uses the browser to build the final Windows executable with a different hash each session.

See how the browser-assembled malware chain works: https://thehackernews.com/2026/07/malvertising-sends-malware-in-pieces.html
🀯9πŸ‘6πŸ”₯6⚑1😁1😱1
Commit a Jupyter notebook. Open its diff. Run commands as git on the GitLab server.

depthfirstlabs told The Hacker News its public exploit ports to other x86-64 builds with only offset changes.

Patched in June under bug fixes, no CVE.

Read: https://thehackernews.com/2026/07/researcher-publishes-gitlab-rce-poc.html
πŸ”₯3πŸ‘2⚑1
Can a cloud tenant really black out the power grid? We asked the Bit2Watt researchers.

Their answer πŸ ’ the scariest result only works if thousands of GPUs spike their power at the same instant, and in reality they never line up that cleanly, which blunts the attack.

Also notable: they didn't warn any cloud provider first, because there's no product bug to patch.

Read: https://thehackernews.com/2026/07/new-bit2watt-attack-could-let-cloud.html
😁3πŸ€”2⚑1πŸ”₯1🀯1