βΌοΈ ALERT - Windows malware could silently sign in to passkey-protected accounts.
Researchers found 3 post-compromise paths in Chrome's Google Password Manager that could bypass user verification, plant an attacker-controlled key, or recover the secret protecting an account's synced passkeys.
Two give reusable access from another machine.
Here's how the attacks work: https://thehackernews.com/2026/08/google-password-manager-attacks-could.html
Researchers found 3 post-compromise paths in Chrome's Google Password Manager that could bypass user verification, plant an attacker-controlled key, or recover the secret protecting an account's synced passkeys.
Two give reusable access from another machine.
Here's how the attacks work: https://thehackernews.com/2026/08/google-password-manager-attacks-could.html
π₯15π6
π¨ Alibaba tool users were targeted with a cross-platform RAT.
Researchers linked 18 malicious npm packages to a layered dependency chain that served Windows, #Linux, and #macOS payloads with command execution, persistence, file transfer, and lateral movement capabilities.
How the npm attack worked: https://thehackernews.com/2026/08/18-malicious-npm-packages-deliver-cross.html
Researchers linked 18 malicious npm packages to a layered dependency chain that served Windows, #Linux, and #macOS payloads with command execution, persistence, file transfer, and lateral movement capabilities.
How the npm attack worked: https://thehackernews.com/2026/08/18-malicious-npm-packages-deliver-cross.html
π€11π₯3β‘1π1
β οΈ N-central attacks are reaching managed endpoints.
Attackers are exploiting CVE-2026-18577 to bypass authentication, gain admin access, and abuse Take Control for lateral movement. N-able confirms limited customer compromises, and CISA has added the flaw to KEV.
What defenders need to check: https://thehackernews.com/2026/08/cisa-adds-exploited-n-able-n-central.html
Attackers are exploiting CVE-2026-18577 to bypass authentication, gain admin access, and abuse Take Control for lateral movement. N-able confirms limited customer compromises, and CISA has added the flaw to KEV.
What defenders need to check: https://thehackernews.com/2026/08/cisa-adds-exploited-n-able-n-central.html
π₯6π2π€2
π¨ DOUBLECUP turns ClickFix into a cross-platform malware pipeline.
It stages code in browser-cached PNGs, locks payloads to each victimβs public IP, and delivers CountLoader on Windows and macOS or the newly documented DeviceManager RAT.
Inside the attack chain: https://thehackernews.com/2026/08/doublecup-uses-clickfix-and-cached-pngs.html
It stages code in browser-cached PNGs, locks payloads to each victimβs public IP, and delivers CountLoader on Windows and macOS or the newly documented DeviceManager RAT.
Inside the attack chain: https://thehackernews.com/2026/08/doublecup-uses-clickfix-and-cached-pngs.html
π₯9
βΌοΈ WARNING - A new critical cPanel flaw could let an authenticated hosting customer run SQL as database root.
CVE-2026-58048 affects all supported cPanel & WHM versions and WP Squared. In some configurations, the compromise may reach the underlying OS.
Affected builds and details: https://thehackernews.com/2026/08/new-cpanel-critical-flaw-could-let.html
CVE-2026-58048 affects all supported cPanel & WHM versions and WP Squared. In some configurations, the compromise may reach the underlying OS.
Affected builds and details: https://thehackernews.com/2026/08/new-cpanel-critical-flaw-could-let.html
β‘8π8π€2π₯1
This media is not supported in your browser
VIEW IN TELEGRAM
π¨ One malicious GitHub issue could trigger a privileged Google ADK agent.
Google pulled 3 ADK AI workflows after researchers demonstrated that adk-botβs trusted identity could become a bridge to CI runner code execution and bot PAT exfiltration.
How the chain worked: https://thehackernews.com/2026/08/google-deletes-3-adk-ai-workflows-after.html
Google pulled 3 ADK AI workflows after researchers demonstrated that adk-botβs trusted identity could become a bridge to CI runner code execution and bot PAT exfiltration.
How the chain worked: https://thehackernews.com/2026/08/google-deletes-3-adk-ai-workflows-after.html
π₯8
AI is lowering the bar for cyberattacks.
LLMs help less experienced attackers understand vulnerabilities, prototype code, debug payloads, and adapt known techniques faster. The result is a wider pool of capable attackers and less time for defenders to react.
What security teams need to change: https://thehackernews.com/2026/08/when-vibe-hacking-turns-ai-into-junior.html
LLMs help less experienced attackers understand vulnerabilities, prototype code, debug payloads, and adapt known techniques faster. The result is a wider pool of capable attackers and less time for defenders to react.
What security teams need to change: https://thehackernews.com/2026/08/when-vibe-hacking-turns-ai-into-junior.html
π₯6
π Fake Adobe and Zoom updates lead to persistent remote access.
The active SMOKE#SCREEN campaign uses phishing lures to install ScreenConnect, letting attackers blend into legitimate IT activity instead of deploying a custom RAT.
How the attack works: https://thehackernews.com/2026/08/fake-adobe-and-zoom-updates-install.html
The active SMOKE#SCREEN campaign uses phishing lures to install ScreenConnect, letting attackers blend into legitimate IT activity instead of deploying a custom RAT.
How the attack works: https://thehackernews.com/2026/08/fake-adobe-and-zoom-updates-install.html
π2π₯1
π₯ ALERT - A massive npm supply-chain attack is unfolding right now.
It began with a poisoned Keyv release and spread across hundreds of packages.
The worm:
β Credential stealer via install scripts
β npm, GitHub, cloud and CI secrets targeted
β Claude Code and VS Code hooks in Keyv repo
β Valid OIDC and SLSA provenance
Read the full story: https://thehackernews.com/2026/08/keyv-linked-npm-worm-poisons-hundreds.html
It began with a poisoned Keyv release and spread across hundreds of packages.
The worm:
β Credential stealer via install scripts
β npm, GitHub, cloud and CI secrets targeted
β Claude Code and VS Code hooks in Keyv repo
β Valid OIDC and SLSA provenance
Read the full story: https://thehackernews.com/2026/08/keyv-linked-npm-worm-poisons-hundreds.html
π5π±4π€2π₯1π1
This is what a modern SOC should look like: connected, context-driven, and ready to act. Equip yours with operationalized threat intelligence from 15K+ SOCs to support triage, detection, and response -> https://thn.news/feeds-soc
π₯9π3π1
β οΈ Greatness now has another route past MFA.
The $289/month PhaaS kit adds device code phishing to AiTM token theft, OAuth consent abuse, and ready-made lures, all from one operator panel.
Researchers saw one stolen Microsoft 365 token still being used more than two weeks later.
See how it works: https://thehackernews.com/2026/08/greatness-phaas-adds-device-code.html
The $289/month PhaaS kit adds device code phishing to AiTM token theft, OAuth consent abuse, and ready-made lures, all from one operator panel.
Researchers saw one stolen Microsoft 365 token still being used more than two weeks later.
See how it works: https://thehackernews.com/2026/08/greatness-phaas-adds-device-code.html
π₯5