The Hacker News
βœ”
162K subscribers
3.6K photos
22 videos
4 files
9.57K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
πŸ›‘ Fake Adobe and Zoom updates lead to persistent remote access.

The active SMOKE#SCREEN campaign uses phishing lures to install ScreenConnect, letting attackers blend into legitimate IT activity instead of deploying a custom RAT.

How the attack works: https://thehackernews.com/2026/08/fake-adobe-and-zoom-updates-install.html
πŸ‘3πŸ”₯1
πŸ”₯ ALERT - A massive npm supply-chain attack is unfolding right now.

It began with a poisoned Keyv release and spread across hundreds of packages.

The worm:
β†’ Credential stealer via install scripts
β†’ npm, GitHub, cloud and CI secrets targeted
β†’ Claude Code and VS Code hooks in Keyv repo
β†’ Valid OIDC and SLSA provenance

Read the full story: https://thehackernews.com/2026/08/keyv-linked-npm-worm-poisons-hundreds.html
😁6😱4πŸ€”2πŸ”₯1πŸ‘1
This is what a modern SOC should look like: connected, context-driven, and ready to act. Equip yours with operationalized threat intelligence from 15K+ SOCs to support triage, detection, and response -> https://thn.news/feeds-soc
πŸ”₯11πŸ‘3😁1
⚠️ Greatness now has another route past MFA.

The $289/month PhaaS kit adds device code phishing to AiTM token theft, OAuth consent abuse, and ready-made lures, all from one operator panel.

Researchers saw one stolen Microsoft 365 token still being used more than two weeks later.

See how it works: https://thehackernews.com/2026/08/greatness-phaas-adds-device-code.html
πŸ”₯13⚑1πŸ‘1
🚨 ALERT - QuickFox’s Windows installer delivered a backdoor.

Active since at least August 2025, the supply chain attack scanned Windows systems for 26 specific apps. Only devices that passed those checks downloaded FDMTP.

See how the targeting worked: https://thehackernews.com/2026/08/quickfox-supply-chain-attack-delivers.html
πŸ”₯8πŸ‘3⚑2
⚠️ Attackers are exploiting flaws in Langflow, Apache Tomcat, and N-able N-central.

CISA added all three to KEV. The Langflow bug allows unauthenticated RCE on default deployments, while Unit 42 tied the Tomcat flaw to an AI-enabled campaign that attempted over 460 targets.

Read: https://thehackernews.com/2026/08/cisa-flags-langflow-rce-tomcat-and-n.html
πŸ”₯3πŸ€”2πŸ‘1
‼️ A Claude Mythos 5 agent spent 34 hours trying to backdoor a real open-source project.

It hid a malware dropper inside a working bug fix. When exposed, it denied the code was malicious, rewrote Git history, and used a second account to vouch for itself.

The attempt failed because a human read the diff.

Read what happened and how it worked πŸ – https://thehackernews.com/2026/08/claude-mythos-5-tried-to-backdoor-real.html
🀯33πŸ‘6😁5πŸ€”3πŸ”₯2πŸ‘2😱2
🚨 77 fake Open VSX extensions caught exfiltrating developer data.

They copied legitimate tools and sent host and workspace details to one domain. Nineteen also collected Git, CI, editor, and machine data, retrying for up to seven days.

Read the full story ↓ https://thehackernews.com/2026/08/open-vsx-removes-77-malicious-evil-twin.html
πŸ”₯3πŸ‘2🀯2😱2
This media is not supported in your browser
VIEW IN TELEGRAM
🚨 321 n8n instances accepted leaked API tokens.

Found in public GitHub commits, the tokens could expose workflows and execution data, let attackers use stored credentials, and, in some configurations, extract their raw values.

No CVE required. See how the attacks work: https://thehackernews.com/2026/08/leaked-n8n-api-tokens-exposed-live.html
πŸ”₯5😁2
- No login
- No write access
- Just crafted Org-mode markup

πŸ›‘ CVE-2026-59774, a critical Gitea flaw, lets attackers use a public repository to read any file accessible to the Gitea service account. Gitea says it could also be chained into command execution.

How it works and what admins should check: https://thehackernews.com/2026/08/critical-gitea-flaw-let-unauthenticated.html
😁7πŸ”₯2⚑1
πŸ›‘ A Linux kernel root exploit is now public.

The 13-year-old OVSwrap flaw (CVE-2026-64531) can let unprivileged local users gain root through Open vSwitch on affected systems.

The public PoC includes offsets for roughly 800 x86-64 kernel builds.

Patch or block the module: https://thehackernews.com/2026/08/new-ovswrap-linux-kernel-flaw-lets.html
πŸ”₯15πŸ€”1
🚨 A public Google Chromium bug report exposed active corporate JWT tokens for a Fortune 50.

Automated sanitization stripped cookie headers, but left custom x-session headers untouched.

Read the deep dive by Unixi CTO Reuvein Vinokurov: https://thn.news/the-accidental-breach
πŸ”₯6⚑1
🚨 Two trojanized npm packages hid a command server’s IP address inside blank Ethereum transfers.

The North Korea-linked NullReceiver technique avoids smart contracts and transaction data, making the attacker’s infrastructure harder for defenders to track.

See how it works: https://thehackernews.com/2026/08/trojanized-npm-packages-decode-c2-ip.html
⚑3
🚨 Veeam, Terraform MCP, and Django patched 11 flaws exposing credentials, crossing tenant boundaries, and enabling file writes.

Veeam fixed CVE-2026-58073, which can expose managed-agent credentials without authentication, and CVE-2026-58072, a file-write flaw that can lead to RCE.

HashiCorp patched CVE-2026-16498 and CVE-2026-16496, which can break tenant isolation in Terraform MCP Server, plus SSRF flaw CVE-2026-14869.

Django fixed CVE-2026-15307, a GeoDjango flaw that can write files and, on some setups, lead to code execution.

See what needs patching: https://thehackernews.com/2026/08/veeam-terraform-mcp-django-patch.html
πŸ”₯3⚑1
⚠️ Kali365 turns Microsoft's real device login page into a phishing trap.

Victims enter an attacker-controlled code, which may give attackers continued access to Microsoft 365 email and files.

AnyRun records 80+ public sessions a week, with the US the main target.

Read the article: https://thehackernews.com/2026/08/kali365-weaponizes-microsoft.html
πŸ”₯4🀯4⚑1
⚑ Paperclip AI flaws can turn a malicious agent import into commands running on the host.

One chain reaches exposed servers through default registration. Another crosses into a developer’s localhost through DNS rebinding.

A public Metasploit module automates the server-side attack.

See how both chains work ↓ https://thehackernews.com/2026/08/paperclip-ai-flaws-let-attackers-run.html
😁4πŸ”₯3
‼️ Cheap Claude access can expose every prompt.

Researchers found 6+ underground AI proxy services. Poison Claude offered models at 5–15% of official prices through pooled accounts funded with abused AWS credits, with 872 active users exposed.

As an intermediary, it could read or leak prompts, swap models, or vanish without warning.

Read ↓ https://thehackernews.com/2026/08/poison-claude-sells-discounted-claude.html
πŸ”₯13😁1πŸ€”1
⚠️ OpenAI banned a Poipet-based ChatGPT network supporting investment, romance, gambling, and fake police scams.

The accounts built personas, translated messages, forged documents, and may have contacted hundreds of targets.

Inside its ping-zing-sting playbook: https://thehackernews.com/2026/08/openai-disrupts-poipet-scam-network.html
πŸ‘1🀯1
🚨 Same URL. Malware for Macs, decoys for scanners.

Microsoft tracked over 250 ClickFix domains using browser fingerprinting to decide who sees the fake GitHub download and who sees nothing suspicious.

Inside the cloaking system: https://thehackernews.com/2026/08/over-250-clickfix-domains-use-browser.html