β οΈ Cheap Android TV boxes are posing as Samsung, Huawei, Xiaomi, and Vivo phones to click ads on operator-run sites.
When HDMI is active, they often switch to routing strangersβ traffic through the ownerβs broadband as SOCKS5 proxies.
Inside the Fuyao botnet: https://thehackernews.com/2026/07/cheap-android-tv-boxes-pose-as-phones.html
When HDMI is active, they often switch to routing strangersβ traffic through the ownerβs broadband as SOCKS5 proxies.
Inside the Fuyao botnet: https://thehackernews.com/2026/07/cheap-android-tv-boxes-pose-as-phones.html
π₯10π2
π¨ A fake βCase Documentsβ shortcut launched HollowFrame and the Matryoshka backdoor on two law firm endpoints.
The attack disabled parts of Microsoft Defender, established persistence, and used HTTP or a private GitHub repository for commands, file transfers, and more payloads.
Inside the attack chain: https://thehackernews.com/2026/07/hollowframe-loader-deploys-matryoshka.html
The attack disabled parts of Microsoft Defender, established persistence, and used HTTP or a private GitHub repository for commands, file transfers, and more payloads.
Inside the attack chain: https://thehackernews.com/2026/07/hollowframe-loader-deploys-matryoshka.html
π±9β‘3π₯3
π¨ A suspected Chinese-speaking threat actor is targeting government networks across Central Asia with two backdoors that run mostly in memory.
OctLurk and SilkLurk can steal credentials, collect email, scan networks, and load additional plugins, while LurkProxy routes traffic through compromised hosts.
Inside the campaign: https://thehackernews.com/2026/08/suspected-chinese-speaking-hackers.html
OctLurk and SilkLurk can steal credentials, collect email, scan networks, and load additional plugins, while LurkProxy routes traffic through compromised hosts.
Inside the campaign: https://thehackernews.com/2026/08/suspected-chinese-speaking-hackers.html
π₯18π2π2β‘1π1π€―1
β οΈ You join hotel Wi-Fi. The network redirects you to a fake browser update.
Microsoft says compromised guest networks are delivering CornFlake lures to travelers. The implant can steal browser credentials, log keystrokes, capture webcam images, and record microphone audio.
How the hotel Wi-Fi trap works: https://thehackernews.com/2026/08/hijacked-hotel-wi-fi-pushes-fake.html
Microsoft says compromised guest networks are delivering CornFlake lures to travelers. The implant can steal browser credentials, log keystrokes, capture webcam images, and record microphone audio.
How the hotel Wi-Fi trap works: https://thehackernews.com/2026/08/hijacked-hotel-wi-fi-pushes-fake.html
π15β‘5π₯1
π¨ Adobe patched a CVSS 10.0 vulnerability in Campaign Classic that could execute arbitrary code without any user interaction.
A second bug could expose files on the system. Eight Adobe Bridge flaws were also fixed.
Here's what users need to patch - https://thehackernews.com/2026/08/adobe-campaign-classic-cvss-100-flaw.html
A second bug could expose files on the system. Eight Adobe Bridge flaws were also fixed.
Here's what users need to patch - https://thehackernews.com/2026/08/adobe-campaign-classic-cvss-100-flaw.html
π₯12π€―6β‘2π2
π Attackers hijacked Adformβs shared tracking script to swap crypto wallet addresses in usersβ browsers.
The code could rewrite addresses copied, pasted, or entered into forms while the page remained open.
How the adtech supply-chain attack worked: https://thehackernews.com/2026/08/hackers-poison-adform-script-to-swap.html
The code could rewrite addresses copied, pasted, or entered into forms while the page remained open.
How the adtech supply-chain attack worked: https://thehackernews.com/2026/08/hackers-poison-adform-script-to-swap.html
π€9π₯5β‘3π1
βΌοΈ WARNING: A 41-minute sweep drained 1,196 Bitcoin addresses of 1,082.65 BTC, worth about $70 million.
Researchers linked the incident to a Coldcard firmware vulnerability that weakened wallet seed generation.
Installing the patch is not enough.
Here's what Coldcard users need to know: https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html
Researchers linked the incident to a Coldcard firmware vulnerability that weakened wallet seed generation.
Installing the patch is not enough.
Here's what Coldcard users need to know: https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html
π€―25π₯7π5π2
β‘ UPDATE - Coldcard-linked theft estimates have jumped from $70 million to $88.6 million.
Galaxy Research says two more suspected sweep waves bring the total to 1,367.05 BTC across 4,585 addresses.
The activity appears ongoing, and the third wave may involve a different operator.
Read: https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html
Galaxy Research says two more suspected sweep waves bring the total to 1,367.05 BTC across 4,585 addresses.
The activity appears ongoing, and the third wave may involve a different operator.
Read: https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html
π10π8π4π₯3π€2
π¨ Hugging Face Diffusers can run code it was told not to trust.
Three high-severity flaws let crafted model repositories bypass trust_remote_code during custom pipeline loading.
How FaceHugger gets past the check: https://thehackernews.com/2026/08/hugging-face-diffusers-flaws-could-let.html
Three high-severity flaws let crafted model repositories bypass trust_remote_code during custom pipeline loading.
How FaceHugger gets past the check: https://thehackernews.com/2026/08/hugging-face-diffusers-flaws-could-let.html
π₯6π6
π Attackers took over N-central servers.
N-able says they reached customer endpoints through Take Control and left Cloudflare tunnels for persistent access. The first fix missed an alternate exploit path.
What MSPs need to check: https://thehackernews.com/2026/08/n-able-says-attackers-take-over-n.html
N-able says they reached customer endpoints through Take Control and left Cloudflare tunnels for persistent access. The first fix missed an alternate exploit path.
What MSPs need to check: https://thehackernews.com/2026/08/n-able-says-attackers-take-over-n.html
π₯10
β οΈ DNA test files could be altered before analysts ever see them.
In a CVE-2026-17583 demonstration, a researcher combined two peopleβs profiles into one Applied Biosystems file.
It raised no warning and appeared untouched since 2015.
How the tampering works - https://thehackernews.com/2026/08/thermo-fisher-patches-flaw-that-could.html
In a CVE-2026-17583 demonstration, a researcher combined two peopleβs profiles into one Applied Biosystems file.
It raised no warning and appeared untouched since 2015.
How the tampering works - https://thehackernews.com/2026/08/thermo-fisher-patches-flaw-that-could.html
π€―5π₯4β‘2
π¨ PNLD breach puts U.K. police and government contact details on the dark web.
Names, organisations and work emails were exposed, potentially making phishing aimed at named officers more convincing.
ExfilSquad, a newly surfaced extortion group, claimed the breach.
Read - https://thehackernews.com/2026/08/pnld-breach-exposes-uk-police-and.html
Names, organisations and work emails were exposed, potentially making phishing aimed at named officers more convincing.
ExfilSquad, a newly surfaced extortion group, claimed the breach.
Read - https://thehackernews.com/2026/08/pnld-breach-exposes-uk-police-and.html
π₯8β‘2π2
π¨ Fake AWS and Apple login pages are triggering an iPhone exploit chain.
Experts tied more than 100 web properties to an unknown Chinese threat actor using the leaked DarkSword kit. Successful exploitation deploys GHOSTBLADE to steal credentials and files.
Read: https://thehackernews.com/2026/08/chinese-threat-actor-uses-leaked.html
Experts tied more than 100 web properties to an unknown Chinese threat actor using the leaked DarkSword kit. Successful exploitation deploys GHOSTBLADE to steal credentials and files.
Read: https://thehackernews.com/2026/08/chinese-threat-actor-uses-leaked.html
π₯10β‘2π2
Low severity does not mean low risk.
Analysis of more than 25 million alerts found nearly 1% of confirmed incidents began with low-severity or informational alerts. An autonomous AI SOC can investigate the full queue, while Claude helps analysts hunt, write detections, and make decisions.
See where each type of AI fits: https://thehackernews.com/2026/08/fomo-in-soc-where-ai-platforms-like.html
Analysis of more than 25 million alerts found nearly 1% of confirmed incidents began with low-severity or informational alerts. An autonomous AI SOC can investigate the full queue, while Claude helps analysts hunt, write detections, and make decisions.
See where each type of AI fits: https://thehackernews.com/2026/08/fomo-in-soc-where-ai-platforms-like.html
π₯13π€3β‘2
We all know "Password123" is a bad ideaβbut what are people actually using?
The Specops Breached Password Report 2026 analyzed more than 6 billion stolen passwords to uncover the trends, habits, and risks shaping today's threat landscape. From the most commonly compromised passwords to the latest credential theft tactics, the report offers an inside look at how attackers are gaining access to accounts.
Explore the findings and see what security teams can do to stay ahead: https://thn.news/specops-pass
The Specops Breached Password Report 2026 analyzed more than 6 billion stolen passwords to uncover the trends, habits, and risks shaping today's threat landscape. From the most commonly compromised passwords to the latest credential theft tactics, the report offers an inside look at how attackers are gaining access to accounts.
Explore the findings and see what security teams can do to stay ahead: https://thn.news/specops-pass
π4π₯1
β‘ The weekly recap is here...
Rogue AI β’ $88M wallet theft β’ OWA spying β’ Rails secret leaks β’ water-system attacks β’ hijacked hotel Wi-Fi β’ Teams ransomware β’ AUR takeovers β’ npm botnets β’ RubyGems miners β’ exposed MCP servers β’ login-flow phishing β’ AI CVE slop β’ keystroke spying
Everything that mattered this week, in one sharp read: https://thehackernews.com/2026/08/weekly-recap-rogue-ai-models-88m.html
Rogue AI β’ $88M wallet theft β’ OWA spying β’ Rails secret leaks β’ water-system attacks β’ hijacked hotel Wi-Fi β’ Teams ransomware β’ AUR takeovers β’ npm botnets β’ RubyGems miners β’ exposed MCP servers β’ login-flow phishing β’ AI CVE slop β’ keystroke spying
Everything that mattered this week, in one sharp read: https://thehackernews.com/2026/08/weekly-recap-rogue-ai-models-88m.html
π₯3π2
β οΈ INC Ransomware is now the main actor exploiting SonicWall SMA 1000 flaws.
Researchers say related attacks extracted credentials, active sessions, and TOTP seeds, giving attackers persistent access and a route deeper into corporate networks.
What defenders need to check: https://thehackernews.com/2026/08/inc-ransomware-emerges-as-dominant.html
Researchers say related attacks extracted credentials, active sessions, and TOTP seeds, giving attackers persistent access and a route deeper into corporate networks.
What defenders need to check: https://thehackernews.com/2026/08/inc-ransomware-emerges-as-dominant.html
π₯5
βΌοΈ ALERT - Windows malware could silently sign in to passkey-protected accounts.
Researchers found 3 post-compromise paths in Chrome's Google Password Manager that could bypass user verification, plant an attacker-controlled key, or recover the secret protecting an account's synced passkeys.
Two give reusable access from another machine.
Here's how the attacks work: https://thehackernews.com/2026/08/google-password-manager-attacks-could.html
Researchers found 3 post-compromise paths in Chrome's Google Password Manager that could bypass user verification, plant an attacker-controlled key, or recover the secret protecting an account's synced passkeys.
Two give reusable access from another machine.
Here's how the attacks work: https://thehackernews.com/2026/08/google-password-manager-attacks-could.html
π₯13π5
π¨ Alibaba tool users were targeted with a cross-platform RAT.
Researchers linked 18 malicious npm packages to a layered dependency chain that served Windows, #Linux, and #macOS payloads with command execution, persistence, file transfer, and lateral movement capabilities.
How the npm attack worked: https://thehackernews.com/2026/08/18-malicious-npm-packages-deliver-cross.html
Researchers linked 18 malicious npm packages to a layered dependency chain that served Windows, #Linux, and #macOS payloads with command execution, persistence, file transfer, and lateral movement capabilities.
How the npm attack worked: https://thehackernews.com/2026/08/18-malicious-npm-packages-deliver-cross.html
π€8π₯1