π¨ ALERT - Flying Eagle Android RAT source code is circulating on criminal Telegram channels.
The kit builds signed APKs that capture payment passwords and keystrokes, record screens, and access cameras.
Experts also traced matching infrastructure fingerprints to 170 internet servers.
Read how the kit works: https://thehackernews.com/2026/07/flying-eagle-android-rat-traces-found.html
The kit builds signed APKs that capture payment passwords and keystrokes, record screens, and access cameras.
Experts also traced matching infrastructure fingerprints to 170 internet servers.
Read how the kit works: https://thehackernews.com/2026/07/flying-eagle-android-rat-traces-found.html
π₯6β‘2π2π€―2π€1
π¨ New Gitea RCE (CVE-2026-60004) lets repository writers plant a malicious Git hook and run shell commands as the Gitea service account.
On default-configured instances, outsiders can register, create a repository, and obtain the required write access.
A public PoC is available.
Find details here: https://thehackernews.com/2026/07/new-gitea-rce-lets-repository-writers.html
On default-configured instances, outsiders can register, create a repository, and obtain the required write access.
A public PoC is available.
Find details here: https://thehackernews.com/2026/07/new-gitea-rce-lets-repository-writers.html
π6π₯2β‘1
π¨ Public PoC released for CVE-2026-16232, an actively exploited Check Point SmartConsole authentication bypass.
The flaw lets unauthenticated attackers obtain full admin access to Security Management Server and MDS systems.
See how it works: https://thehackernews.com/2026/07/rapid7-releases-poc-for-exploited-check.html
The flaw lets unauthenticated attackers obtain full admin access to Security Management Server and MDS systems.
See how it works: https://thehackernews.com/2026/07/rapid7-releases-poc-for-exploited-check.html
π₯5
β‘ Russiaβs FSB says it has charged #Telegram founder Pavel Durov with aiding terrorist activity and placed him on an international wanted list.
The agency alleges Ukrainian operatives used Telegram and a dating bot to coerce young Russians into sabotage and attacks.
Telegramβs response β https://thehackernews.com/2026/07/russia-charges-telegram-founder-pavel.html
The agency alleges Ukrainian operatives used Telegram and a dating bot to coerce young Russians into sabotage and attacks.
Telegramβs response β https://thehackernews.com/2026/07/russia-charges-telegram-founder-pavel.html
π36π₯7π3π€―2
Most organizations have incident response plans. Yet 73% say they would not be fully ready for a major cyberattack tomorrow.
The problem is execution: 90% expect coordination trouble, while 78% say blind spots can leave attackers with persistent access.
Read what breaks down under pressure: https://thehackernews.com/2026/07/73-of-organizations-say-they-are-not.html
The problem is execution: 90% expect coordination trouble, while 78% say blind spots can leave attackers with persistent access.
Read what breaks down under pressure: https://thehackernews.com/2026/07/73-of-organizations-say-they-are-not.html
π2π₯2π2β‘1
This media is not supported in your browser
VIEW IN TELEGRAM
π One malicious webpage visit was enough to compromise Tor Browser. No settings changes. No extra clicks.
Firefox JIT flaw, CVE-2026-10702, runs code inside the browserβs renderer process and forms the first stage of an Android 17 root chain.
Read how the exploit works: https://thehackernews.com/2026/07/researchers-show-single-malicious.html
Firefox JIT flaw, CVE-2026-10702, runs code inside the browserβs renderer process and forms the first stage of an Android 17 root chain.
Read how the exploit works: https://thehackernews.com/2026/07/researchers-show-single-malicious.html
π€―15π±2π₯1
AI is compressing the time between vulnerability disclosure and exploitation.
That makes CVSS-only prioritization more dangerous. A 5.5 flaw with a path to a critical asset can matter more than an isolated 9.8.
Read why attack paths should drive remediation: https://thehackernews.com/2026/07/mythos-asks-right-question-it-doesnt.html
That makes CVSS-only prioritization more dangerous. A 5.5 flaw with a path to a critical asset can matter more than an isolated 9.8.
Read why attack paths should drive remediation: https://thehackernews.com/2026/07/mythos-asks-right-question-it-doesnt.html
β‘3π2π1π₯1
You can't fix what you can't see π
Before Black Hat, Bolster AI is helping security teams uncover phishing sites, fake domains, fraudulent ads, impersonation, and other external threats targeting their customers.
Request your personalized report before Black Hat or stop by Booth #4900 to see what's already out there: https://thn.news/blkht-sec
Before Black Hat, Bolster AI is helping security teams uncover phishing sites, fake domains, fraudulent ads, impersonation, and other external threats targeting their customers.
Request your personalized report before Black Hat or stop by Booth #4900 to see what's already out there: https://thn.news/blkht-sec
π4π₯2
β οΈ Fraudsters built nearly 100 fake websites impersonating major Russian companies to steal advance payments from international buyers.
The 9-year campaign uses lookalike domains, forged contracts, and altered bank details to redirect corporate payments.
Read how the scheme works: https://thehackernews.com/2026/07/nine-year-fraud-campaign.html
The 9-year campaign uses lookalike domains, forged contracts, and altered bank details to redirect corporate payments.
Read how the scheme works: https://thehackernews.com/2026/07/nine-year-fraud-campaign.html
π₯7π€4π2β‘1π1
π¨ A coordinated cyberattack targeted 30+ Minnesota water systems. One plant went offline.
Other cities reported communications failures and affected automated controls. Officials have not identified the attacker or how access was gained.
Read the full story: https://thehackernews.com/2026/07/coordinated-cyberattack-targets-30.html
Other cities reported communications failures and affected automated controls. Officials have not identified the attacker or how access was gained.
Read the full story: https://thehackernews.com/2026/07/coordinated-cyberattack-targets-30.html
π5β‘4π₯2
π¨ Broadcom patches three critical VMware flaws affecting vCenter and ESX.
Two could let remote attackers bypass authentication or run code through vCenter. A third could let a VM administrator escape to the ESX host.
Details: https://thehackernews.com/2026/07/three-critical-vmware-flaws-allow-auth.html
Two could let remote attackers bypass authentication or run code through vCenter. A third could let a VM administrator escape to the ESX host.
Details: https://thehackernews.com/2026/07/three-critical-vmware-flaws-allow-auth.html
π₯8π€2
AI agents have quickly become another privileged identity to manage.
At #BlackHat, we're previewing:
β’ AI Agent Security
β’ NHI Governance
β’ Shadow AI discovery
β’ Unified visibility across human, machine & AI identities
Gain Early Access:
β’ AI Agent Security: https://thn.news/ai-agent-sec
β’ NHI Governance: https://thn.news/nhi-policy
Booth #4720
At #BlackHat, we're previewing:
β’ AI Agent Security
β’ NHI Governance
β’ Shadow AI discovery
β’ Unified visibility across human, machine & AI identities
Gain Early Access:
β’ AI Agent Security: https://thn.news/ai-agent-sec
β’ NHI Governance: https://thn.news/nhi-policy
Booth #4720
π3π₯2
π¨ Ruflo left 233 MCP tools exposed without authentication by default, including shell command execution.
On any network-reachable deployment, one request could expose LLM keys, conversations, and persistent AI memory.
How one POST turns into full compromise: https://thehackernews.com/2026/07/ruflo-mcp-flaw-lets-unauthenticated.html
On any network-reachable deployment, one request could expose LLM keys, conversations, and persistent AI memory.
How one POST turns into full compromise: https://thehackernews.com/2026/07/ruflo-mcp-flaw-lets-unauthenticated.html
π8π₯2
β‘ UPDATE β The HAWK team has withdrawn its post-quantum digital-signature scheme from NISTβs standardization process after confirming #Anthropic's key-recovery attack sharply reduced its security margin.
NIST now lists HAWK as withdrawn.
Read the updated story: https://thehackernews.com/2026/07/claude-ai-just-cracked-post-quantum.html
NIST now lists HAWK as withdrawn.
Read the updated story: https://thehackernews.com/2026/07/claude-ai-just-cracked-post-quantum.html
π8π€3π₯2
βΌοΈ WARNING -- Critical Rails flaw CVE-2026-66066 could let unauthenticated attackers read server files through crafted image uploads.
The bug affects apps using Active Storage with Vips. Stolen Rails keys, database credentials, cloud keys, and API tokens could enable RCE.
Patch now. Read the full story - https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html
The bug affects apps using Active Storage with Vips. Stolen Rails keys, database credentials, cloud keys, and API tokens could enable RCE.
Patch now. Read the full story - https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html
π7π₯3π€2
π¨ UPDATE: A third-party PoC now claims to reproduce the full Rails Active Storage file-read-to-RCE chain.
The Rails Security Team told The Hacker News it is not aware of any exploitation, confirmed the affected-version range, and said Rails 7.1 and earlier will receive no backport.
Read the updated story: https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html
The Rails Security Team told The Hacker News it is not aware of any exploitation, confirmed the affected-version range, and said Rails 7.1 and earlier will receive no backport.
Read the updated story: https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html
π₯5
β οΈ Attackers are exploiting Cisco FMC zero-day CVE-2026-20316.
The flaw lets unauthenticated remote attackers use static credentials to access sensitive data through a low-privilege account.
Cisco warns it can be chained with other FMC flaws to elevate privileges.
Here's what admins should check: https://thehackernews.com/2026/07/cisco-fmc-zero-day-actively-exploited.html
The flaw lets unauthenticated remote attackers use static credentials to access sensitive data through a low-privilege account.
Cisco warns it can be chained with other FMC flaws to elevate privileges.
Here's what admins should check: https://thehackernews.com/2026/07/cisco-fmc-zero-day-actively-exploited.html
π±3π₯2
π¨ Amazon links the 2025 'debug' and 'chalk' npm hijack to North Koreaβs Sapphire Sleet.
The wallet-draining attack reached at least 18 packages with more than 2 billion weekly downloads.
Read the full report: https://thehackernews.com/2026/07/amazon-links-debug-and-chalk-npm-hijack.html
The wallet-draining attack reached at least 18 packages with more than 2 billion weekly downloads.
Read the full report: https://thehackernews.com/2026/07/amazon-links-debug-and-chalk-npm-hijack.html
π€―10π₯5π±5π1
β‘ The FCC is restricting U.S. approval for new foreign-produced robots and networked power inverters over fears they could be remotely shut down, hijacked, or used for surveillance.
Previously approved models can still be sold and used.
Read the full story: https://thehackernews.com/2026/07/fcc-blocks-new-foreign-produced-robots.html
Previously approved models can still be sold and used.
Read the full story: https://thehackernews.com/2026/07/fcc-blocks-new-foreign-produced-robots.html
π₯4π€2
π¨ ALERT - Russian hackers are exploiting a Microsoft OWA flaw to deploy OWAReaper.
The browser backdoor can preserve mailbox access after credential rotation and full device re-imaging.
Here's how it stays embedded: https://thehackernews.com/2026/07/russian-hackers-exploit-microsoft-owa.html
The browser backdoor can preserve mailbox access after credential rotation and full device re-imaging.
Here's how it stays embedded: https://thehackernews.com/2026/07/russian-hackers-exploit-microsoft-owa.html
π₯7
βΌοΈ ALERT >> One visit. No prompt. A compromised South Korean website could infect systems running vulnerable AnySign4PC versions.
State-sponsored hackers used the chain to install SIGNBT or COPPERHEDGE backdoors.
Learn how the page-to-backdoor chain worked: https://thehackernews.com/2026/07/hackers-exploit-anysign4pc-via-hacked.html
State-sponsored hackers used the chain to install SIGNBT or COPPERHEDGE backdoors.
Learn how the page-to-backdoor chain worked: https://thehackernews.com/2026/07/hackers-exploit-anysign4pc-via-hacked.html
π€―9π₯2