The Hacker News
βœ”
162K subscribers
3.56K photos
22 videos
4 files
9.53K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
🚨 Amazon links the 2025 'debug' and 'chalk' npm hijack to North Korea’s Sapphire Sleet.

The wallet-draining attack reached at least 18 packages with more than 2 billion weekly downloads.

Read the full report: https://thehackernews.com/2026/07/amazon-links-debug-and-chalk-npm-hijack.html
🀯11πŸ”₯6😱5😁2⚑1
⚑ The FCC is restricting U.S. approval for new foreign-produced robots and networked power inverters over fears they could be remotely shut down, hijacked, or used for surveillance.

Previously approved models can still be sold and used.

Read the full story: https://thehackernews.com/2026/07/fcc-blocks-new-foreign-produced-robots.html
πŸ”₯6πŸ€”3
🚨 ALERT - Russian hackers are exploiting a Microsoft OWA flaw to deploy OWAReaper.

The browser backdoor can preserve mailbox access after credential rotation and full device re-imaging.

Here's how it stays embedded: https://thehackernews.com/2026/07/russian-hackers-exploit-microsoft-owa.html
πŸ”₯9⚑1
‼️ ALERT >> One visit. No prompt. A compromised South Korean website could infect systems running vulnerable AnySign4PC versions.

State-sponsored hackers used the chain to install SIGNBT or COPPERHEDGE backdoors.

Learn how the page-to-backdoor chain worked: https://thehackernews.com/2026/07/hackers-exploit-anysign4pc-via-hacked.html
🀯10πŸ”₯4
🚨 Silver Fox is using 3 vulnerable drivers to impair security controls and deploy ValleyRAT against a Japanese manufacturer.

Stopping one component may not stop the intrusion. A second recovery path can bring it back.

How the attack stays alive: https://thehackernews.com/2026/07/silverfox-targets-japanese-manufacturer.html
πŸ”₯3⚑1
Traditional firewalls can see an AI connection. They cannot see the prompt, upload, model call, or agent action inside it.

Check Point has launched what it calls the industry’s first AI Network Firewall to inspect that activity, block prompt injection, data exfiltration, and API abuse, and govern MCP servers.

Read more: https://thehackernews.com/2026/07/the-network-has-become-control-plane.html
πŸ”₯6⚑2
🚨 Microsoft 365 Copilot can quietly alter figures during a Word drafting or editing operation, then copy the hidden instructions into the document it creates.

That generated file can carry the manipulation into a later Copilot session.

Here’s how the chain works: https://thehackernews.com/2026/07/microsoft-copilot-for-word-can-copy.html
πŸ€”8😱1
🚨 One crafted Gremlin query. A sandbox escape.

... a platform-wide key that researchers say could retrieve the key for any Azure Cosmos DB account, giving full read and write access across tenants and APIs.

Read how "CosmosEscape" attack crossed the boundary https://thehackernews.com/2026/07/azure-cosmos-db-flaw-exposed-platform.html
😁4πŸ”₯3πŸ‘1
⚑ AI is pushing code into production faster than security teams can review it.

Join this next webinar to learn where traditional AppSec and CVE-based remediation break down, how AI expands the attack surface, and what secure-by-default development looks like in practice.

Register now: https://thehacker.news/secure-ai-development
πŸ”₯4
A threat actor used AI agents to pick targets, find exploit code, and launch attacks.

Also this week: SonicWall credential stuffing, DNS hijacking, fake Claude malware, 900K records accessed, real-time phishing pages, and a hidden-desktop RAT.

25 stories. Read ThreatsDay: https://thehackernews.com/2026/07/threatsday-ai-powered-hacking-370.html
😁3πŸ”₯2⚑1
An enterprise thought Copilot was its entire AI footprint. Reco’s scan found Claude ranked first.

Reco co-founder Gal Nakash maps six places Claude shows up, from connected apps and MCP servers to Claude Code, and the access paths security tools often miss.

Read the article: https://thehackernews.com/expert-insights/2026/07/claude-runs-across-six-surfaces-in-your.html
πŸ‘5πŸ”₯3
⚠️ A sponsored search result leads to a fake macOS update that fills the screen, copies a command to the clipboard, and tells the victim to run it in Terminal.

The DPRK-linked campaign then installs a backdoor that fetches a stealer targeting 157 crypto wallets and cloud credentials.

Read the full attack chain: https://thehackernews.com/2026/07/dprk-linked-macos-malvertising-uses.html
😁4πŸ€”4⚑1πŸ‘1
⚑ Anthropic says Claude models breached three organizations after a misconfigured CTF gave them live internet access.

The test was simulated. The internet was not.

One model accessed production data. Another published a PyPI package downloaded by 15 real systems.

Full report: https://thehackernews.com/2026/07/anthropic-says-claude-mistook-open.html
😁16πŸ”₯14πŸ€”4🀯4⚑2
🚨 A Chinese-speaking threat actor used DeepSeek to autonomously find exposed systems, choose public exploits, and launch attacks after an initial Telegram command.

Experts say the wider operation attempted to exploit 460+ targets.

Read the full story β†’ https://thehackernews.com/2026/07/chinese-hacker-commands-deepseek-via.html
🀯4πŸ”₯2😁2
🚨 New from Ethiack: A crafted MATLAB/HDF5 upload can make Rails Active Storage read server secrets.

Attackers could then use a stolen secret_key_base to forge a variation key and reach RCE via CVE-2025-24293.

Rails also released a forensic toolkit to check exposure and hunt for exploitation.

Read the updated story: https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html
πŸ”₯1
πŸ›‘ Researchers found 84 flaws across seven open-source 4G and 5G cores.

If internal interfaces are exposed, some could crash core components or redirect a subscriber’s uplink traffic. A session-hijacking flaw also turned up in two commercial 5G cores.

Details: https://thehackernews.com/2026/07/researchers-report-84-flaws-in-4g-and.html
πŸ‘2πŸ”₯2
Passkeys cannot stop an attack that starts after login.

Device code phishing sends victims to Microsoft’s real login page, where one copied code can grant an attacker access. Push now tracks 25+ kits. Barracuda counted 7 million attacks in four weeks.

See how it works: https://thehackernews.com/2026/07/6-reasons-why-device-code-phishing-is.html
🀯6πŸ‘3😁1
😲 Google fixed 1,442 security flaws across three recent Chrome releases.

Versions 149 and 150 alone patched more bugs than the previous 23 milestones combined. Chrome 151 added 370 more, including 7 critical flaws.

Google is now testing twice-weekly security releases as AI speeds up vulnerability discovery and cyberattacks.

Full story: https://thehackernews.com/2026/07/three-recent-chrome-releases-fix-1442.html
πŸ‘4😱3πŸ”₯2πŸ‘1
Malware investigations often stop at the first file.

Stairwell's new Backstory is the first agentic investigation platform that traces related malware variants, identifies affected systems, and maps the full blast radius of an incident in seconds.

Instead of stopping at a single alert, security teams can quickly understand what happened, where malware spread, and what needs to be contained before an incident escalates.

Learn more about Backstory: https://thn.news/demo-stairwell
πŸ‘3πŸ”₯1
⚠️ Cheap Android TV boxes are posing as Samsung, Huawei, Xiaomi, and Vivo phones to click ads on operator-run sites.

When HDMI is active, they often switch to routing strangers’ traffic through the owner’s broadband as SOCKS5 proxies.

Inside the Fuyao botnet: https://thehackernews.com/2026/07/cheap-android-tv-boxes-pose-as-phones.html
πŸ”₯3
🚨 A fake β€œCase Documents” shortcut launched HollowFrame and the Matryoshka backdoor on two law firm endpoints.

The attack disabled parts of Microsoft Defender, established persistence, and used HTTP or a private GitHub repository for commands, file transfers, and more payloads.

Inside the attack chain: https://thehackernews.com/2026/07/hollowframe-loader-deploys-matryoshka.html
😱2⚑1πŸ”₯1