π₯ 10β50Γ more code. Security still moves at human speed.
AI can multiply dependencies, vulnerabilities, and fixes faster than teams can review them. More scanning can just mean a bigger backlog.
Learn how to secure AI-speed development without slowing it down.
Watch the webinar: https://thehackernews.com/2026/08/shipping-1050-more-code-watch-this.html
AI can multiply dependencies, vulnerabilities, and fixes faster than teams can review them. More scanning can just mean a bigger backlog.
Learn how to secure AI-speed development without slowing it down.
Watch the webinar: https://thehackernews.com/2026/08/shipping-1050-more-code-watch-this.html
π₯3π1
βΌοΈ New research shows passkey protections can be bypassed without breaking FIDO2 cryptography.
Three demonstrated paths:
β’ Replay Windows-exposed assertions against Entra ID
β’ Recover synced passkey private keys from Google Password Manager
β’ Use Windows Hello keys from a compromised session
See how each works: https://thehackernews.com/2026/08/new-passkey-attacks-can-recover-synced.html
Three demonstrated paths:
β’ Replay Windows-exposed assertions against Entra ID
β’ Recover synced passkey private keys from Google Password Manager
β’ Use Windows Hello keys from a compromised session
See how each works: https://thehackernews.com/2026/08/new-passkey-attacks-can-recover-synced.html
π₯9
β οΈ Phishing can succeed in under a minute.
Median click: 21 seconds. Data entry: 28 seconds later.
Blocking the email isnβt enough if the attackerβs domains and links stay live.
See what email security is still missing: https://thehackernews.com/expert-insights/2026/08/the-blind-spot-in-modern-email-security.html
Median click: 21 seconds. Data entry: 28 seconds later.
Blocking the email isnβt enough if the attackerβs domains and links stay live.
See what email security is still missing: https://thehackernews.com/expert-insights/2026/08/the-blind-spot-in-modern-email-security.html
π₯7π6
π¨ Kimsuky is moving AI onto its own servers.
The North Korean espionage group is running or configuring Ollama, GPT4All, and Msty locally, alongside RAG, coding, and transcription tools. The stack has not been seen used against a victim yet.
See what it found: https://thehackernews.com/2026/08/kimsuky-builds-offline-ai-stack-that.html
The North Korean espionage group is running or configuring Ollama, GPT4All, and Msty locally, alongside RAG, coding, and transcription tools. The stack has not been seen used against a victim yet.
See what it found: https://thehackernews.com/2026/08/kimsuky-builds-offline-ai-stack-that.html
π₯12π3
π Rogue AI β’ Metabase 0-day β’ Spectre bypass β’ Webmail attacks β’ Router backdoors β’ MCP supply-chain malware β’ 440 poisoned packages β’ AI token jacking β’ Device-code phishing β’ $30M crypto attacks β’ 26 ransomware hits a day.
That was just one week.
Catch up with the latest Monday Cybersecurity Recap - https://thehackernews.com/2026/08/weekly-recap-ai-goes-rogue-metabase-0.html
That was just one week.
Catch up with the latest Monday Cybersecurity Recap - https://thehackernews.com/2026/08/weekly-recap-ai-goes-rogue-metabase-0.html
π6π₯1
π¨ China-linked Storm-1175 deploys previously undocumented StormEncryptor ransomware.
Microsoft says the group has shifted from Medusa and likely used N-able N-central CVE-2026-18577 for initial access. Storm-1175 has been observed moving from initial access to data exfiltration and ransomware deployment within days.
Inside the campaign β https://thehackernews.com/2026/08/china-linked-hackers-deploy-new.html
Microsoft says the group has shifted from Medusa and likely used N-able N-central CVE-2026-18577 for initial access. Storm-1175 has been observed moving from initial access to data exfiltration and ransomware deployment within days.
Inside the campaign β https://thehackernews.com/2026/08/china-linked-hackers-deploy-new.html
π₯10
π¨ ALERT - Poisoned #WordPress plugin JSON creates rogue admins and web shells.
Seven BdThemes plugins were disabled after attackers gained write access to vendor-hosted data fetched inside wp-admin.
Here's how the backdoor was planted: https://thehackernews.com/2026/08/bdthemes-supply-chain-attack-poisons.html
Seven BdThemes plugins were disabled after attackers gained write access to vendor-hosted data fetched inside wp-admin.
Here's how the backdoor was planted: https://thehackernews.com/2026/08/bdthemes-supply-chain-attack-poisons.html
π6π€2π₯1
βΌοΈ Hackers shut down a turbine at a Polish CHP plant by crossing a private cellular network.
They pivoted from a compromised wind farm through the grid operatorβs private APN into the plantβs OT network, then put Siemens PLCs into STOP mode.
CERT says itβs the first real-world attack it has seen using this APN route.
See the full incident explained β https://thehackernews.com/2026/08/hackers-breach-polish-power-plant.html
They pivoted from a compromised wind farm through the grid operatorβs private APN into the plantβs OT network, then put Siemens PLCs into STOP mode.
CERT says itβs the first real-world attack it has seen using this APN route.
See the full incident explained β https://thehackernews.com/2026/08/hackers-breach-polish-power-plant.html
π13π₯7π3
β οΈ Gunra ransomware breaches networks, steals data, and destroys backups.
Attacks have exploited Fortinet FortiOS/FortiProxy and Schneider Electric PowerLogic P5 flaws for initial access, before encrypting databases, NAS systems, and other key assets.
How Gunra gets in and spreads: https://thehackernews.com/2026/08/gunra-ransomware-exploits-fortinet-and.html
Attacks have exploited Fortinet FortiOS/FortiProxy and Schneider Electric PowerLogic P5 flaws for initial access, before encrypting databases, NAS systems, and other key assets.
How Gunra gets in and spreads: https://thehackernews.com/2026/08/gunra-ransomware-exploits-fortinet-and.html
π₯9
π Malicious MCP servers can make AI coding agents exfiltrate SSH keys, .env secrets, source code, and customer data.
The attack, dubbed βGhostSplice,β splits a request across MCP channels so no single fragment looks overtly malicious. In the researchersβ tests, splitting the request in two raised average compliance across 11 API-tested models from 42% to 82%.
See how it works: https://thehackernews.com/2026/08/malicious-mcp-servers-can-split.html
The attack, dubbed βGhostSplice,β splits a request across MCP channels so no single fragment looks overtly malicious. In the researchersβ tests, splitting the request in two raised average compliance across 11 API-tested models from 42% to 82%.
See how it works: https://thehackernews.com/2026/08/malicious-mcp-servers-can-split.html
π₯12
This media is not supported in your browser
VIEW IN TELEGRAM
β‘ Windows Plug and Play can be abused to gain SYSTEM.
Researchers used emulated USB devices to make Windows fetch signed vendor software, then chained package flaws to SYSTEM on Windows 11.
It can also work over RDP when USB redirection is enabled.
See how Plug And Pwn works: https://thehackernews.com/2026/08/researchers-turn-usb-auto-install-into.html
Researchers used emulated USB devices to make Windows fetch signed vendor software, then chained package flaws to SYSTEM on Windows 11.
It can also work over RDP when USB redirection is enabled.
See how Plug And Pwn works: https://thehackernews.com/2026/08/researchers-turn-usb-auto-install-into.html
π₯7π5
[Video] AI agents are keeping access long after they're needed.
There are 109 non-human identities for every human. 82% of organizations have found unapproved shadow AI, and only 21% have a proper way to shut agents down.
See how identity controls the full AI agent lifecycle: https://thehackernews.com/videos/2026/08/ai-agent-lifecycle-risks.html
There are 109 non-human identities for every human. 82% of organizations have found unapproved shadow AI, and only 21% have a proper way to shut agents down.
See how identity controls the full AI agent lifecycle: https://thehackernews.com/videos/2026/08/ai-agent-lifecycle-risks.html
π₯3π1
π¨ Fake crypto startup hires three suspected North Korean IT workers.
Researchers created Ballena Azul, interviewed the candidates, signed them as employees, and gave them work VMs. No exploit was needed. The access came through the hiring process.
See how they got hired: https://thehackernews.com/2026/08/researchers-built-fake-crypto-startup.html
Researchers created Ballena Azul, interviewed the candidates, signed them as employees, and gave them work VMs. No exploit was needed. The access came through the hiring process.
See how they got hired: https://thehackernews.com/2026/08/researchers-built-fake-crypto-startup.html
π8π₯2
βΌοΈ A malicious SIM can take over the modem from inside the device.
Researchers found 9 of 26 tested phones and cellular modules accept RUN AT commands from the SIM, including 6 of the 8 modules. On one commercial EV charger, they chained the interface to code execution.
Here's how the attack works - https://thehackernews.com/2026/08/a-malicious-sim-card-can-run-attacker.html
Researchers found 9 of 26 tested phones and cellular modules accept RUN AT commands from the SIM, including 6 of the 8 modules. On one commercial EV charger, they chained the interface to code execution.
Here's how the attack works - https://thehackernews.com/2026/08/a-malicious-sim-card-can-run-attacker.html
π7π₯4β‘2
π¨ Mozilla revoked the Firefox and Thunderbird Linux signing key after an unencrypted copy was accidentally committed to a private repo.
No unauthorized access was found, but older downloads can stop verifying and some Firefox RPM updates may fail.
Read: https://thehackernews.com/2026/08/mozilla-revokes-firefox-and-thunderbird.html
No unauthorized access was found, but older downloads can stop verifying and some Firefox RPM updates may fail.
Read: https://thehackernews.com/2026/08/mozilla-revokes-firefox-and-thunderbird.html
π8π₯3
π₯ OpenAI just released a more cyber-permissive GPT-5.6.
GPT-5.6-Cyber is built for vulnerability research, penetration testing, incident response, and exploit development, with reduced refusals for some higher-risk dual-use tasks.
Read the full story: https://thehackernews.com/2026/08/openai-launches-gpt-56-cyber-with.html
GPT-5.6-Cyber is built for vulnerability research, penetration testing, incident response, and exploit development, with reduced refusals for some higher-risk dual-use tasks.
Read the full story: https://thehackernews.com/2026/08/openai-launches-gpt-56-cyber-with.html
π₯14π5π€5π2
β‘ ICYMI: One click from a logged-in #WordPress admin can trigger a chain from pre-auth XSS to PHP code execution.
CVE-2026-64638 affects all WordPress versions, and the login-page XSS itself requires no authentication.
Patch now:
https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html
CVE-2026-64638 affects all WordPress versions, and the login-page XSS itself requires no authentication.
Patch now:
https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html
π6π₯4π2
Only 45% of security teams consolidate asset and exposure data into one view.
New Ponemon research with Axonius shows how fragmented visibility weakens prioritization and remediation, and the five fundamentals that can fix it.
Download the playbook: https://thn.news/asset-playbook-guide
New Ponemon research with Axonius shows how fragmented visibility weakens prioritization and remediation, and the five fundamentals that can fix it.
Download the playbook: https://thn.news/asset-playbook-guide
π7
π¨ DeadLock ransomware is making its extortion infrastructure harder to disrupt.
It uses Polygon smart contracts to rotate victim-chat proxies, Session for encrypted communications, and blockchain-hosted leak content.
See how it works: https://thehackernews.com/2026/08/deadlock-ransomware-uses-polygon-smart.html
It uses Polygon smart contracts to rotate victim-chat proxies, Session for encrypted communications, and blockchain-hosted leak content.
See how it works: https://thehackernews.com/2026/08/deadlock-ransomware-uses-polygon-smart.html
π₯7π5
π No SharePoint credentials needed to impersonate an admin and run code.
Researchers chained two flaws, CVE-2026-55040 and CVE-2026-63520, to go from unauthenticated user impersonation to code execution on the server.
Read details here: https://thehackernews.com/2026/08/researchers-disclose-ai-assisted.html
Researchers chained two flaws, CVE-2026-55040 and CVE-2026-63520, to go from unauthenticated user impersonation to code execution on the server.
Read details here: https://thehackernews.com/2026/08/researchers-disclose-ai-assisted.html
π€10π4π₯2
β οΈ Fake job interviews are delivering a VPN that can run commands.
CERT-UA says Sandworm-linked UAC-0145 is targeting Ukrainian IT workers with recruiter lures, then pushing a modified WireGuard client that can execute commands and fetch a second-stage payload.
Read more: https://thehackernews.com/2026/08/sandworm-linked-uac-0145-uses-fake-job.html
CERT-UA says Sandworm-linked UAC-0145 is targeting Ukrainian IT workers with recruiter lures, then pushing a modified WireGuard client that can execute commands and fetch a second-stage payload.
Read more: https://thehackernews.com/2026/08/sandworm-linked-uac-0145-uses-fake-job.html
π₯6π5