The Hacker News
162K subscribers
3.52K photos
22 videos
4 files
9.49K links
Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

📨 Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
⚠️ A crypter called Cruciferra is helping common RATs and stealers shut down security tools and run with fewer forensic traces.

It has appeared in phishing campaigns delivering 11 malware families, including Indian tax lures linked to TA4922.

Read: https://thehackernews.com/2026/07/cruciferra-crypter-uses-byovd-and.html
🤔4😱32🔥2
🛑 A fake Microsoft Teams update deploys two legitimate RMM tools on the same Windows host.

Operation BlueDash installs Level RMM and ScreenConnect in parallel, apparently to retain remote access if one is removed.

How the phishing chain works: https://thehackernews.com/2026/07/operation-bluedash-deploys-level-rmm.html
👍7🔥31
🛑 A user with n8n workflow-edit rights could turn a crafted expression into OS command execution as the n8n process.

This 8.7-rated flaw needs no victim interaction and could expose stored credentials and reachable internal services.

Details: https://thehackernews.com/2026/07/n8n-sandbox-escape-lets-workflow.html
🤔6🔥21😱1
This week’s security mess came from every direction.

Rogue AI models, an exploited Check Point auth bypass, TriBack espionage, Hermes AI abuse, Zimbra zero-day attacks, a Certighost PoC, ClickFix lures, slopsquatting, malicious SVGs, Phantom Stealer, fake interviews, DDoS tooling, and an energy-sector breach.

Catch up on what mattered this week: https://thehackernews.com/2026/07/weekly-recap-rogue-ai-agents-check.html
👏51
🛑 WARNING - Public PoC released for a vBulletin flaw that turns one unauthenticated request into code execution.

No login, no click. The request reaches PHP’s eval().

Self-hosted admins should update now.

Details: https://thehackernews.com/2026/07/public-exploit-released-for-patched.html
🔥7😁3👍21
🚨 After law enforcement disrupted JackSkid, Dysphoria shifted its IoT botnet C2 to blockchain name services and infected-device relays.

Weak Telnet and SSH passwords remain the main way in.

Read how the botnet adapted: https://thehackernews.com/2026/07/dysphoria-iot-botnet-adds-blockchain-c2.html
😁9👍3🔥2
NVIDIA and 36 other organisations have launched the Open Secure AI Alliance and released NOOA, a framework for testing and auditing AI agents.


NOOA can run model-generated Python, so NVIDIA says it must be isolated in a container, VM, or sandbox.


Read the full story: https://thehackernews.com/2026/07/nvidia-forms-37-member-open-secure-ai.html
🔥12🤔4😁3
🚨 Attackers are exploiting a CVSS 10.0 command injection flaw in on-prem Arista VeloCloud Orchestrator.

A successful exploit could compromise the orchestrator and give attackers access to managed Edge devices. CISA has ordered federal agencies to patch by July 30.

Details: https://thehackernews.com/2026/07/attackers-exploit-arista-velocloud.html
🔥9😁4👍2
Microsoft says MAI-Cyber-1-Flash helps MDASH reach 95.95% on CyberGym at half the cost of its current best model mix.

The cybersecurity-specific model handles up to 90% of tasks, while GPT-5.4 takes the hardest 10%.

Read how the system works: https://thehackernews.com/2026/07/microsoft-says-new-cybersecurity-ai.html
🔥7
🛑 A researcher says AI helped turn a #Linux traffic-control race into a root exploit.

CVE-2026-53264 lets a local user gain root on the tested CentOS Stream 9 build, but needs user namespaces, specific kernel options, and build-specific ROP offsets.

Read how the exploit works: https://thehackernews.com/2026/07/researcher-says-ai-helped-develop-linux.html
🔥10
🚨 A critical TeamCity flaw could let attackers run OS commands without logging in.

CVE-2026-63077 affects all on-premises versions and bypasses authentication through the agent polling protocol. JetBrains has released fixes and reports no known exploitation.

Full details - https://thehackernews.com/2026/07/critical-teamcity-flaw-could-let.html
🔥7🤯5
AI agents do not need to break permissions to act outside their intended role.

Lasso says its platform builds a behavioral baseline for each agent and can block intent drift in under 50ms, linking red team findings directly to runtime controls.

How the closed loop works: https://thehackernews.com/expert-insights/2026/07/a-look-inside-lassos-ai-security.html
🔥6🤔2
🚨 Iranian state-backed Nimbus Manticore is turning compromised systems into covert network relays.

NightLedger executes commands, uploads files, and captures screenshots, while BridgeHead and ArcBridge tunnel traffic through victim networks.

Read more: https://thehackernews.com/2026/07/nimbus-manticore-deploys-nightledger.html
😁10🤔2🔥1
⚠️ ALERT - OpenWrt users, this one needs attention.

A critical pre-auth DHCPv6 flaw could let an attacker who can reach the service send a crafted request and run code as root on the router.

A separate audit also found 7 more flaws, including three pre-auth paths to device compromise.

What users need to update now: https://thehackernews.com/2026/07/critical-openwrt-dhcpv6-flaw-could-let.html
🔥9
🔥 JFrog confirms OpenAI models exploited a zero-day in self-hosted "Artifactory," escalated privileges, and moved laterally until they reached the open internet.

From there, the models targeted #HuggingFace and obtained ExploitGym solutions from its production database via a separate attack path.

Here's how it happened: https://thehackernews.com/2026/07/jfrog-confirms-openai-models-exploited.html
🔥7🤔3🤯3
‼️ 24,650 internet-exposed BMCs are leaking IPMI authentication hashes before login, giving attackers what they need to crack passwords offline.

More than 30% matched recoverable passwords, including factory-issued credentials.

Read what exposed servers need to lock down: https://thehackernews.com/2026/07/24650-internet-exposed-bmcs-disclose.html
😁3🤯2🔥1
🚨 A new Mirai-derived botnet called Tengu can reboot compromised #Linux devices when defenders kill its main process, giving the malware another chance to return.

It also supports 25 DDoS methods, SOCKS5 proxying, shell commands, and additional ELF or APK payloads.

See how Tengu resists removal: https://thehackernews.com/2026/07/tengu-botnet-reboots-compromised-linux.html
🔥6
🕵️ Your network tool sees traffic to an LLM provider's API. Your browser extension sees an employee building an agent in Copilot Studio. Neither one sees the Agentforce bot quietly holding API access to your CRM.

That's the real problem with shadow AI agent discovery: every method has a blind spot, and most vendors don't say so upfront.

Nudge Security's new guide breaks down the most common discovery approaches: network traffic analysis, browser extensions, endpoint agents, identity signals, SaaS API discovery, and more; what each one actually catches, and where the coverage gaps are.

👉 See how the methods stack up side by side
👉 Understand what each one misses (and why)
👉 Get the questions to ask any vendor claiming "full" agent coverage

Read the Guide: https://thn.news/ai-discovery-methods
🤔5👍2🔥2
🚨 UPDATE - Public PoC exploit released for CVE-2026-42533, chaining an #nginx memory leak and heap overflow to bypass ASLR and achieve unauthenticated command execution.

Read: https://thehackernews.com/2026/07/critical-nginx-vulnerability-can-crash.html
🔥9
‼️ BREAKING — Claude AI found a working HAWK-256 key-recovery attack.

HAWK is a NIST post-quantum cryptography candidate. It also made an impractical 7-round AES-128 attack up to 800x faster.

Read this here: https://thehackernews.com/2026/07/claude-ai-just-cracked-post-quantum.html
🤯24🔥12😁5👍4😱2