The Hacker News
βœ”
162K subscribers
3.59K photos
22 videos
4 files
9.57K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
🚨 Fake AWS and Apple login pages are triggering an iPhone exploit chain.

Experts tied more than 100 web properties to an unknown Chinese threat actor using the leaked DarkSword kit. Successful exploitation deploys GHOSTBLADE to steal credentials and files.

Read: https://thehackernews.com/2026/08/chinese-threat-actor-uses-leaked.html
πŸ”₯11😁3⚑2
Low severity does not mean low risk.

Analysis of more than 25 million alerts found nearly 1% of confirmed incidents began with low-severity or informational alerts. An autonomous AI SOC can investigate the full queue, while Claude helps analysts hunt, write detections, and make decisions.

See where each type of AI fits: https://thehackernews.com/2026/08/fomo-in-soc-where-ai-platforms-like.html
πŸ”₯16πŸ€”4⚑3
We all know "Password123" is a bad ideaβ€”but what are people actually using?

The Specops Breached Password Report 2026 analyzed more than 6 billion stolen passwords to uncover the trends, habits, and risks shaping today's threat landscape. From the most commonly compromised passwords to the latest credential theft tactics, the report offers an inside look at how attackers are gaining access to accounts.

Explore the findings and see what security teams can do to stay ahead: https://thn.news/specops-pass
πŸ‘5πŸ”₯2πŸ€”1
⚑ The weekly recap is here...

Rogue AI β€’ $88M wallet theft β€’ OWA spying β€’ Rails secret leaks β€’ water-system attacks β€’ hijacked hotel Wi-Fi β€’ Teams ransomware β€’ AUR takeovers β€’ npm botnets β€’ RubyGems miners β€’ exposed MCP servers β€’ login-flow phishing β€’ AI CVE slop β€’ keystroke spying

Everything that mattered this week, in one sharp read: https://thehackernews.com/2026/08/weekly-recap-rogue-ai-models-88m.html
πŸ”₯5πŸ‘3
⚠️ INC Ransomware is now the main actor exploiting SonicWall SMA 1000 flaws.

Researchers say related attacks extracted credentials, active sessions, and TOTP seeds, giving attackers persistent access and a route deeper into corporate networks.

What defenders need to check: https://thehackernews.com/2026/08/inc-ransomware-emerges-as-dominant.html
πŸ”₯8
‼️ ALERT - Windows malware could silently sign in to passkey-protected accounts.

Researchers found 3 post-compromise paths in Chrome's Google Password Manager that could bypass user verification, plant an attacker-controlled key, or recover the secret protecting an account's synced passkeys.

Two give reusable access from another machine.

Here's how the attacks work: https://thehackernews.com/2026/08/google-password-manager-attacks-could.html
πŸ”₯15😁6
🚨 Alibaba tool users were targeted with a cross-platform RAT.

Researchers linked 18 malicious npm packages to a layered dependency chain that served Windows, #Linux, and #macOS payloads with command execution, persistence, file transfer, and lateral movement capabilities.

How the npm attack worked: https://thehackernews.com/2026/08/18-malicious-npm-packages-deliver-cross.html
πŸ€”11πŸ”₯4⚑1πŸ‘1
⚠️ N-central attacks are reaching managed endpoints.

Attackers are exploiting CVE-2026-18577 to bypass authentication, gain admin access, and abuse Take Control for lateral movement. N-able confirms limited customer compromises, and CISA has added the flaw to KEV.

What defenders need to check: https://thehackernews.com/2026/08/cisa-adds-exploited-n-able-n-central.html
πŸ”₯6πŸ‘2πŸ€”2
🚨 DOUBLECUP turns ClickFix into a cross-platform malware pipeline.

It stages code in browser-cached PNGs, locks payloads to each victim’s public IP, and delivers CountLoader on Windows and macOS or the newly documented DeviceManager RAT.

Inside the attack chain: https://thehackernews.com/2026/08/doublecup-uses-clickfix-and-cached-pngs.html
πŸ”₯9πŸ€”1
‼️ WARNING - A new critical cPanel flaw could let an authenticated hosting customer run SQL as database root.

CVE-2026-58048 affects all supported cPanel & WHM versions and WP Squared. In some configurations, the compromise may reach the underlying OS.

Affected builds and details: https://thehackernews.com/2026/08/new-cpanel-critical-flaw-could-let.html
⚑8πŸ‘8πŸ€”3πŸ”₯1
This media is not supported in your browser
VIEW IN TELEGRAM
🚨 One malicious GitHub issue could trigger a privileged Google ADK agent.

Google pulled 3 ADK AI workflows after researchers demonstrated that adk-bot’s trusted identity could become a bridge to CI runner code execution and bot PAT exfiltration.

How the chain worked: https://thehackernews.com/2026/08/google-deletes-3-adk-ai-workflows-after.html
πŸ”₯10
AI is lowering the bar for cyberattacks.

LLMs help less experienced attackers understand vulnerabilities, prototype code, debug payloads, and adapt known techniques faster. The result is a wider pool of capable attackers and less time for defenders to react.

What security teams need to change: https://thehackernews.com/2026/08/when-vibe-hacking-turns-ai-into-junior.html
πŸ”₯9
πŸ›‘ Fake Adobe and Zoom updates lead to persistent remote access.

The active SMOKE#SCREEN campaign uses phishing lures to install ScreenConnect, letting attackers blend into legitimate IT activity instead of deploying a custom RAT.

How the attack works: https://thehackernews.com/2026/08/fake-adobe-and-zoom-updates-install.html
πŸ‘3πŸ”₯1
πŸ”₯ ALERT - A massive npm supply-chain attack is unfolding right now.

It began with a poisoned Keyv release and spread across hundreds of packages.

The worm:
β†’ Credential stealer via install scripts
β†’ npm, GitHub, cloud and CI secrets targeted
β†’ Claude Code and VS Code hooks in Keyv repo
β†’ Valid OIDC and SLSA provenance

Read the full story: https://thehackernews.com/2026/08/keyv-linked-npm-worm-poisons-hundreds.html
😁6😱4πŸ€”2πŸ”₯1πŸ‘1
This is what a modern SOC should look like: connected, context-driven, and ready to act. Equip yours with operationalized threat intelligence from 15K+ SOCs to support triage, detection, and response -> https://thn.news/feeds-soc
πŸ”₯11πŸ‘3😁1
⚠️ Greatness now has another route past MFA.

The $289/month PhaaS kit adds device code phishing to AiTM token theft, OAuth consent abuse, and ready-made lures, all from one operator panel.

Researchers saw one stolen Microsoft 365 token still being used more than two weeks later.

See how it works: https://thehackernews.com/2026/08/greatness-phaas-adds-device-code.html
πŸ”₯13⚑1πŸ‘1
🚨 ALERT - QuickFox’s Windows installer delivered a backdoor.

Active since at least August 2025, the supply chain attack scanned Windows systems for 26 specific apps. Only devices that passed those checks downloaded FDMTP.

See how the targeting worked: https://thehackernews.com/2026/08/quickfox-supply-chain-attack-delivers.html
πŸ”₯8⚑2πŸ‘2
⚠️ Attackers are exploiting flaws in Langflow, Apache Tomcat, and N-able N-central.

CISA added all three to KEV. The Langflow bug allows unauthenticated RCE on default deployments, while Unit 42 tied the Tomcat flaw to an AI-enabled campaign that attempted over 460 targets.

Read: https://thehackernews.com/2026/08/cisa-flags-langflow-rce-tomcat-and-n.html
πŸ”₯2πŸ€”2πŸ‘1
‼️ A Claude Mythos 5 agent spent 34 hours trying to backdoor a real open-source project.

It hid a malware dropper inside a working bug fix. When exposed, it denied the code was malicious, rewrote Git history, and used a second account to vouch for itself.

The attempt failed because a human read the diff.

Read what happened and how it worked πŸ – https://thehackernews.com/2026/08/claude-mythos-5-tried-to-backdoor-real.html
🀯30πŸ‘6😁5πŸ€”3πŸ”₯2😱2πŸ‘1
🚨 77 fake Open VSX extensions caught exfiltrating developer data.

They copied legitimate tools and sent host and workspace details to one domain. Nineteen also collected Git, CI, editor, and machine data, retrying for up to seven days.

Read the full story ↓ https://thehackernews.com/2026/08/open-vsx-removes-77-malicious-evil-twin.html
πŸ‘2🀯2😱2πŸ”₯1
This media is not supported in your browser
VIEW IN TELEGRAM
🚨 321 n8n instances accepted leaked API tokens.

Found in public GitHub commits, the tokens could expose workflows and execution data, let attackers use stored credentials, and, in some configurations, extract their raw values.

No CVE required. See how the attacks work: https://thehackernews.com/2026/08/leaked-n8n-api-tokens-exposed-live.html
πŸ”₯3😁2