The Hacker News
βœ”
162K subscribers
3.54K photos
22 videos
4 files
9.51K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
⚑ Microsoft says MAI-Cyber-1-Flash helps MDASH reach 95.95% on CyberGym at half the cost of its current best model mix.

The cybersecurity-specific model handles up to 90% of tasks, while GPT-5.4 takes the hardest 10%.

Read how the system works: https://thehackernews.com/2026/07/microsoft-says-new-cybersecurity-ai.html
πŸ”₯7
πŸ›‘ A researcher says AI helped turn a #Linux traffic-control race into a root exploit.

CVE-2026-53264 lets a local user gain root on the tested CentOS Stream 9 build, but needs user namespaces, specific kernel options, and build-specific ROP offsets.

Read how the exploit works: https://thehackernews.com/2026/07/researcher-says-ai-helped-develop-linux.html
πŸ”₯10
🚨 A critical TeamCity flaw could let attackers run OS commands without logging in.

CVE-2026-63077 affects all on-premises versions and bypasses authentication through the agent polling protocol. JetBrains has released fixes and reports no known exploitation.

Full details - https://thehackernews.com/2026/07/critical-teamcity-flaw-could-let.html
πŸ”₯8🀯5
AI agents do not need to break permissions to act outside their intended role.

Lasso says its platform builds a behavioral baseline for each agent and can block intent drift in under 50ms, linking red team findings directly to runtime controls.

How the closed loop works: https://thehackernews.com/expert-insights/2026/07/a-look-inside-lassos-ai-security.html
πŸ”₯6πŸ€”2
🚨 Iranian state-backed Nimbus Manticore is turning compromised systems into covert network relays.

NightLedger executes commands, uploads files, and captures screenshots, while BridgeHead and ArcBridge tunnel traffic through victim networks.

Read more: https://thehackernews.com/2026/07/nimbus-manticore-deploys-nightledger.html
😁11⚑2πŸ€”2πŸ”₯1
⚠️ ALERT - OpenWrt users, this one needs attention.

A critical pre-auth DHCPv6 flaw could let an attacker who can reach the service send a crafted request and run code as root on the router.

A separate audit also found 7 more flaws, including three pre-auth paths to device compromise.

What users need to update now: https://thehackernews.com/2026/07/critical-openwrt-dhcpv6-flaw-could-let.html
πŸ”₯10⚑1
πŸ”₯ JFrog confirms OpenAI models exploited a zero-day in self-hosted "Artifactory," escalated privileges, and moved laterally until they reached the open internet.

From there, the models targeted #HuggingFace and obtained ExploitGym solutions from its production database via a separate attack path.

Here's how it happened: https://thehackernews.com/2026/07/jfrog-confirms-openai-models-exploited.html
πŸ”₯7πŸ€”3🀯3⚑1
‼️ 24,650 internet-exposed BMCs are leaking IPMI authentication hashes before login, giving attackers what they need to crack passwords offline.

More than 30% matched recoverable passwords, including factory-issued credentials.

Read what exposed servers need to lock down: https://thehackernews.com/2026/07/24650-internet-exposed-bmcs-disclose.html
😁4🀯3πŸ”₯1
🚨 A new Mirai-derived botnet called Tengu can reboot compromised #Linux devices when defenders kill its main process, giving the malware another chance to return.

It also supports 25 DDoS methods, SOCKS5 proxying, shell commands, and additional ELF or APK payloads.

See how Tengu resists removal: https://thehackernews.com/2026/07/tengu-botnet-reboots-compromised-linux.html
πŸ”₯9⚑1
πŸ•΅οΈ Your network tool sees traffic to an LLM provider's API. Your browser extension sees an employee building an agent in Copilot Studio. Neither one sees the Agentforce bot quietly holding API access to your CRM.

That's the real problem with shadow AI agent discovery: every method has a blind spot, and most vendors don't say so upfront.

Nudge Security's new guide breaks down the most common discovery approaches: network traffic analysis, browser extensions, endpoint agents, identity signals, SaaS API discovery, and more; what each one actually catches, and where the coverage gaps are.

πŸ‘‰ See how the methods stack up side by side
πŸ‘‰ Understand what each one misses (and why)
πŸ‘‰ Get the questions to ask any vendor claiming "full" agent coverage

Read the Guide: https://thn.news/ai-discovery-methods
πŸ€”5πŸ‘2πŸ”₯2⚑1
🚨 UPDATE - Public PoC exploit released for CVE-2026-42533, chaining an #nginx memory leak and heap overflow to bypass ASLR and achieve unauthenticated command execution.

Read: https://thehackernews.com/2026/07/critical-nginx-vulnerability-can-crash.html
πŸ”₯10⚑1
‼️ BREAKING β€” Claude AI found a working HAWK-256 key-recovery attack.

HAWK is a NIST post-quantum cryptography candidate. It also made an impractical 7-round AES-128 attack up to 800x faster.

Read this here: https://thehackernews.com/2026/07/claude-ai-just-cracked-post-quantum.html
🀯34πŸ”₯13😁6πŸ‘4😱2⚑1
⚠️ Two compromised joyfill npm beta packages run malware as soon as Node.js imports them. No install hook needed.

The implant fetches a DEV#POPPER-linked RAT through three blockchains, while a detached branch can keep running after builds or tests exit.

Read the full story: https://thehackernews.com/2026/07/two-compromised-joyfill-npm-packages.html
😁5πŸ‘1🀯1
🚨 OpenAI says the Hugging Face breach was broader than first disclosed.

The system used exposed credentials to access four third-party accounts, using one as a relay and staging point and another for data storage.

Read the new details: https://thehackernews.com/2026/07/openai-agent-used-exposed-credentials.html
πŸ€”5😁3πŸ‘2⚑1πŸ”₯1
🚨 ALERT - Flying Eagle Android RAT source code is circulating on criminal Telegram channels.

The kit builds signed APKs that capture payment passwords and keystrokes, record screens, and access cameras.

Experts also traced matching infrastructure fingerprints to 170 internet servers.

Read how the kit works: https://thehackernews.com/2026/07/flying-eagle-android-rat-traces-found.html
πŸ”₯5😁2🀯2⚑1πŸ€”1
🚨 New Gitea RCE (CVE-2026-60004) lets repository writers plant a malicious Git hook and run shell commands as the Gitea service account.

On default-configured instances, outsiders can register, create a repository, and obtain the required write access.

A public PoC is available.

Find details here: https://thehackernews.com/2026/07/new-gitea-rce-lets-repository-writers.html
πŸ‘6⚑1
🚨 Public PoC released for CVE-2026-16232, an actively exploited Check Point SmartConsole authentication bypass.

The flaw lets unauthenticated attackers obtain full admin access to Security Management Server and MDS systems.

See how it works: https://thehackernews.com/2026/07/rapid7-releases-poc-for-exploited-check.html
πŸ”₯3
⚑ Russia’s FSB says it has charged #Telegram founder Pavel Durov with aiding terrorist activity and placed him on an international wanted list.

The agency alleges Ukrainian operatives used Telegram and a dating bot to coerce young Russians into sabotage and attacks.

Telegram’s response ↓ https://thehackernews.com/2026/07/russia-charges-telegram-founder-pavel.html
😁30πŸ”₯6πŸ‘3🀯2
Most organizations have incident response plans. Yet 73% say they would not be fully ready for a major cyberattack tomorrow.

The problem is execution: 90% expect coordination trouble, while 78% say blind spots can leave attackers with persistent access.

Read what breaks down under pressure: https://thehackernews.com/2026/07/73-of-organizations-say-they-are-not.html
πŸ‘2😁2⚑1
This media is not supported in your browser
VIEW IN TELEGRAM
πŸ›‘ One malicious webpage visit was enough to compromise Tor Browser. No settings changes. No extra clicks.

Firefox JIT flaw, CVE-2026-10702, runs code inside the browser’s renderer process and forms the first stage of an Android 17 root chain.

Read how the exploit works: https://thehackernews.com/2026/07/researchers-show-single-malicious.html
🀯15😱1
AI is compressing the time between vulnerability disclosure and exploitation.

That makes CVSS-only prioritization more dangerous. A 5.5 flaw with a path to a critical asset can matter more than an isolated 9.8.

Read why attack paths should drive remediation: https://thehackernews.com/2026/07/mythos-asks-right-question-it-doesnt.html
⚑3πŸ‘1😁1