The Hacker News
βœ”
162K subscribers
3.55K photos
22 videos
4 files
9.52K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
🚨 UPDATE - Public PoC exploit released for CVE-2026-42533, chaining an #nginx memory leak and heap overflow to bypass ASLR and achieve unauthenticated command execution.

Read: https://thehackernews.com/2026/07/critical-nginx-vulnerability-can-crash.html
πŸ”₯11⚑1
‼️ BREAKING β€” Claude AI found a working HAWK-256 key-recovery attack.

HAWK is a NIST post-quantum cryptography candidate. It also made an impractical 7-round AES-128 attack up to 800x faster.

Read this here: https://thehackernews.com/2026/07/claude-ai-just-cracked-post-quantum.html
🀯35πŸ”₯13😁6πŸ‘4😱2⚑1
⚠️ Two compromised joyfill npm beta packages run malware as soon as Node.js imports them. No install hook needed.

The implant fetches a DEV#POPPER-linked RAT through three blockchains, while a detached branch can keep running after builds or tests exit.

Read the full story: https://thehackernews.com/2026/07/two-compromised-joyfill-npm-packages.html
😁6πŸ”₯1πŸ‘1🀯1
🚨 OpenAI says the Hugging Face breach was broader than first disclosed.

The system used exposed credentials to access four third-party accounts, using one as a relay and staging point and another for data storage.

Read the new details: https://thehackernews.com/2026/07/openai-agent-used-exposed-credentials.html
πŸ€”5πŸ”₯3😁3πŸ‘2⚑1
🚨 ALERT - Flying Eagle Android RAT source code is circulating on criminal Telegram channels.

The kit builds signed APKs that capture payment passwords and keystrokes, record screens, and access cameras.

Experts also traced matching infrastructure fingerprints to 170 internet servers.

Read how the kit works: https://thehackernews.com/2026/07/flying-eagle-android-rat-traces-found.html
πŸ”₯6⚑2😁2🀯2πŸ€”1
🚨 New Gitea RCE (CVE-2026-60004) lets repository writers plant a malicious Git hook and run shell commands as the Gitea service account.

On default-configured instances, outsiders can register, create a repository, and obtain the required write access.

A public PoC is available.

Find details here: https://thehackernews.com/2026/07/new-gitea-rce-lets-repository-writers.html
πŸ‘6πŸ”₯2⚑1
🚨 Public PoC released for CVE-2026-16232, an actively exploited Check Point SmartConsole authentication bypass.

The flaw lets unauthenticated attackers obtain full admin access to Security Management Server and MDS systems.

See how it works: https://thehackernews.com/2026/07/rapid7-releases-poc-for-exploited-check.html
πŸ”₯5
⚑ Russia’s FSB says it has charged #Telegram founder Pavel Durov with aiding terrorist activity and placed him on an international wanted list.

The agency alleges Ukrainian operatives used Telegram and a dating bot to coerce young Russians into sabotage and attacks.

Telegram’s response ↓ https://thehackernews.com/2026/07/russia-charges-telegram-founder-pavel.html
😁36πŸ”₯7πŸ‘3🀯2
Most organizations have incident response plans. Yet 73% say they would not be fully ready for a major cyberattack tomorrow.

The problem is execution: 90% expect coordination trouble, while 78% say blind spots can leave attackers with persistent access.

Read what breaks down under pressure: https://thehackernews.com/2026/07/73-of-organizations-say-they-are-not.html
πŸ‘2πŸ”₯2😁2⚑1
This media is not supported in your browser
VIEW IN TELEGRAM
πŸ›‘ One malicious webpage visit was enough to compromise Tor Browser. No settings changes. No extra clicks.

Firefox JIT flaw, CVE-2026-10702, runs code inside the browser’s renderer process and forms the first stage of an Android 17 root chain.

Read how the exploit works: https://thehackernews.com/2026/07/researchers-show-single-malicious.html
🀯15😱2πŸ”₯1
AI is compressing the time between vulnerability disclosure and exploitation.

That makes CVSS-only prioritization more dangerous. A 5.5 flaw with a path to a critical asset can matter more than an isolated 9.8.

Read why attack paths should drive remediation: https://thehackernews.com/2026/07/mythos-asks-right-question-it-doesnt.html
⚑3😁2πŸ‘1πŸ”₯1
You can't fix what you can't see πŸ‘€

Before Black Hat, Bolster AI is helping security teams uncover phishing sites, fake domains, fraudulent ads, impersonation, and other external threats targeting their customers.

Request your personalized report before Black Hat or stop by Booth #4900 to see what's already out there: https://thn.news/blkht-sec
πŸ‘4πŸ”₯2
⚠️ Fraudsters built nearly 100 fake websites impersonating major Russian companies to steal advance payments from international buyers.

The 9-year campaign uses lookalike domains, forged contracts, and altered bank details to redirect corporate payments.

Read how the scheme works: https://thehackernews.com/2026/07/nine-year-fraud-campaign.html
πŸ”₯7πŸ€”4πŸ‘2⚑1😁1
🚨 A coordinated cyberattack targeted 30+ Minnesota water systems. One plant went offline.

Other cities reported communications failures and affected automated controls. Officials have not identified the attacker or how access was gained.

Read the full story: https://thehackernews.com/2026/07/coordinated-cyberattack-targets-30.html
πŸ‘6⚑4πŸ”₯3
🚨 Broadcom patches three critical VMware flaws affecting vCenter and ESX.

Two could let remote attackers bypass authentication or run code through vCenter. A third could let a VM administrator escape to the ESX host.

Details: https://thehackernews.com/2026/07/three-critical-vmware-flaws-allow-auth.html
πŸ”₯8πŸ€”3
AI agents have quickly become another privileged identity to manage.

At #BlackHat, we're previewing:

β€’ AI Agent Security
β€’ NHI Governance
β€’ Shadow AI discovery
β€’ Unified visibility across human, machine & AI identities

Gain Early Access:

β€’ AI Agent Security: https://thn.news/ai-agent-sec
β€’ NHI Governance: https://thn.news/nhi-policy

Booth #4720
πŸ‘3πŸ”₯3
🚨 Ruflo left 233 MCP tools exposed without authentication by default, including shell command execution.

On any network-reachable deployment, one request could expose LLM keys, conversations, and persistent AI memory.

How one POST turns into full compromise: https://thehackernews.com/2026/07/ruflo-mcp-flaw-lets-unauthenticated.html
😁8πŸ”₯3
⚑ UPDATE β€” The HAWK team has withdrawn its post-quantum digital-signature scheme from NIST’s standardization process after confirming #Anthropic's key-recovery attack sharply reduced its security margin.

NIST now lists HAWK as withdrawn.

Read the updated story: https://thehackernews.com/2026/07/claude-ai-just-cracked-post-quantum.html
😁9πŸ€”4πŸ”₯2
‼️ WARNING -- Critical Rails flaw CVE-2026-66066 could let unauthenticated attackers read server files through crafted image uploads.

The bug affects apps using Active Storage with Vips. Stolen Rails keys, database credentials, cloud keys, and API tokens could enable RCE.

Patch now. Read the full story - https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html
πŸ‘7πŸ”₯4πŸ€”2
🚨 UPDATE: A third-party PoC now claims to reproduce the full Rails Active Storage file-read-to-RCE chain.

The Rails Security Team told The Hacker News it is not aware of any exploitation, confirmed the affected-version range, and said Rails 7.1 and earlier will receive no backport.

Read the updated story: https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html
πŸ”₯6
⚠️ Attackers are exploiting Cisco FMC zero-day CVE-2026-20316.

The flaw lets unauthenticated remote attackers use static credentials to access sensitive data through a low-privilege account.

Cisco warns it can be chained with other FMC flaws to elevate privileges.

Here's what admins should check: https://thehackernews.com/2026/07/cisco-fmc-zero-day-actively-exploited.html
πŸ”₯3😱3🀯1