The Hacker News
βœ”
162K subscribers
3.84K photos
25 videos
4 files
9.83K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
[Video] AI agents are keeping access long after they're needed.

There are 109 non-human identities for every human. 82% of organizations have found unapproved shadow AI, and only 21% have a proper way to shut agents down.

See how identity controls the full AI agent lifecycle: https://thehackernews.com/videos/2026/08/ai-agent-lifecycle-risks.html
πŸ”₯3πŸ‘1
🚨 Fake crypto startup hires three suspected North Korean IT workers.

Researchers created Ballena Azul, interviewed the candidates, signed them as employees, and gave them work VMs. No exploit was needed. The access came through the hiring process.

See how they got hired: https://thehackernews.com/2026/08/researchers-built-fake-crypto-startup.html
πŸ‘8πŸ”₯2
‼️ A malicious SIM can take over the modem from inside the device.

Researchers found 9 of 26 tested phones and cellular modules accept RUN AT commands from the SIM, including 6 of the 8 modules. On one commercial EV charger, they chained the interface to code execution.

Here's how the attack works - https://thehackernews.com/2026/08/a-malicious-sim-card-can-run-attacker.html
πŸ‘7πŸ”₯4⚑2
🚨 Mozilla revoked the Firefox and Thunderbird Linux signing key after an unencrypted copy was accidentally committed to a private repo.

No unauthorized access was found, but older downloads can stop verifying and some Firefox RPM updates may fail.

Read: https://thehackernews.com/2026/08/mozilla-revokes-firefox-and-thunderbird.html
πŸ‘8πŸ”₯3
πŸ”₯ OpenAI just released a more cyber-permissive GPT-5.6.

GPT-5.6-Cyber is built for vulnerability research, penetration testing, incident response, and exploit development, with reduced refusals for some higher-risk dual-use tasks.

Read the full story: https://thehackernews.com/2026/08/openai-launches-gpt-56-cyber-with.html
πŸ”₯14πŸ‘5πŸ€”5😁2
⚑ ICYMI: One click from a logged-in #WordPress admin can trigger a chain from pre-auth XSS to PHP code execution.

CVE-2026-64638 affects all WordPress versions, and the login-page XSS itself requires no authentication.

Patch now:
https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html
πŸ‘6πŸ”₯4πŸ‘2
Only 45% of security teams consolidate asset and exposure data into one view.

New Ponemon research with Axonius shows how fragmented visibility weakens prioritization and remediation, and the five fundamentals that can fix it.

Download the playbook: https://thn.news/asset-playbook-guide
πŸ‘7
🚨 DeadLock ransomware is making its extortion infrastructure harder to disrupt.

It uses Polygon smart contracts to rotate victim-chat proxies, Session for encrypted communications, and blockchain-hosted leak content.

See how it works: https://thehackernews.com/2026/08/deadlock-ransomware-uses-polygon-smart.html
πŸ”₯7πŸ‘5
πŸ›‘ No SharePoint credentials needed to impersonate an admin and run code.

Researchers chained two flaws, CVE-2026-55040 and CVE-2026-63520, to go from unauthenticated user impersonation to code execution on the server.

Read details here: https://thehackernews.com/2026/08/researchers-disclose-ai-assisted.html
πŸ€”10πŸ‘4πŸ”₯2
⚠️ Fake job interviews are delivering a VPN that can run commands.

CERT-UA says Sandworm-linked UAC-0145 is targeting Ukrainian IT workers with recruiter lures, then pushing a modified WireGuard client that can execute commands and fetch a second-stage payload.

Read more: https://thehackernews.com/2026/08/sandworm-linked-uac-0145-uses-fake-job.html
πŸ”₯6πŸ‘5
‼️ WARNING: One Zoom attendee could take over every other attendee's computer.

Three flaws in Zoom's annotation feature could be exploited from inside a meeting, with no click, download, or prompt required from the victim.

Make sure your software is up to date.

Read more: https://thehackernews.com/2026/08/zoom-annotation-flaws-could-let-meeting.html
πŸ”₯13πŸ‘4😁3🀯2
⚠️ Kimwolf v7 makes DDoS traffic harder to distinguish from real browsing.

The Android and IoT botnet now builds complete browser fingerprints for HTTP/2 floods, uses ENS and Tor to harden its C2, and targets Android TV boxes through exposed ADB.

Read more: https://thehackernews.com/2026/08/kimwolf-v7-android-botnet-makes-http2.html
πŸ”₯9🀯6😁2
πŸ›‘ 398 fixes. One exploited Windows zero-day. Four unauthenticated 9.8 RCEs.

Microsoft’s August Patch Tuesday fixes CVE-2026-68820, which can elevate an attacker with existing code execution to SYSTEM.

It also closes the RCE half of a SharePoint exploit chain.

Here’s what to patch first ➝ https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html
πŸ‘10πŸ”₯10
πŸ›‘ Exploited Cisco firewall flaw can remotely crash affected devices.

CVE-2026-20349 affects certain ASA and FTD configurations. A crafted HTTP request can force a device reload and cause a denial-of-service condition.

Cisco says exploitation is already underway and no workaround exists.

Patch now: https://thehackernews.com/2026/08/cisco-asa-and-ftd-flaw-exploited-in.html
πŸ”₯9πŸ‘2πŸ‘1
‼️ Microsoft patched RoguePlanet. Now the researcher has dropped another zero-day that claims to bypass the fix.

ShieldBreak is said to fully bypass Defender’s CVE-2026-50656 patch. The underlying flaw can lead to SYSTEM-level privileges.

Read more: https://thehackernews.com/2026/08/shieldbreak-zero-day-poc-claims.html
πŸ”₯22😁9
⚠️ Warning: SAP Commerce Cloud flaw could enable arbitrary code execution.

CVE-2026-58231 carries a CVSS 10.0 score and can be triggered by an unauthenticated attacker abusing a default authentication client with crafted input.

SAP has released a fix. Patch and redeploy.

Read: https://thehackernews.com/2026/08/sap-commerce-cloud-flaw-could-let.html
πŸ”₯5😁5🀯2
‼️ BREAKING: A 40-minute LiteLLM PyPI compromise potentially exposed 2,100+ organizations.

Tied to Trivy's supply-chain attack, the malicious releases stole cloud, SSH, Kubernetes, and database credentials. Researchers later obtained roughly 434,000 captured files mapping potential exposure across thousands of organizations.

See what the stolen data reveals: https://thehackernews.com/2026/08/malicious-litellm-releases-tied-to.html
πŸ”₯6😱2😁1
🚨 Watch out: Attackers are exploiting VMware vCenter for persistence.

After exploiting CVE-2026-59310, they planted a malicious cron job running reverse_ssh to maintain access. Researchers identified up to 361 victim IPs across 47 countries.

Read more: https://thehackernews.com/2026/08/attackers-exploit-vmware-vcenter.html
πŸ”₯6
🚨 Three Adobe flaws hit CVSS 10.0 and could enable code execution.

Adobe patched the maximum-severity bugs in ColdFusion and Campaign Classic, plus a CVSS 9.1 Commerce flaw that could allow privilege escalation. No exploitation has been seen in the wild.

Read: https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html
πŸ”₯8😁5πŸ‘2
‼️ Researchers found a way to make a weaker AI decode a stronger model's hidden reasoning.

They extracted hidden traces from OpenAI, Anthropic, and Google APIs, recovering secret API keys and passwords, along with other credentials, in publicly shared agent logs.

Read more: https://thehackernews.com/2026/08/openai-anthropic-google-api-flaw-let.html
πŸ‘9πŸ‘4πŸ€”2🀯1
Once attackers get inside, defenses stop just 37%.

Across 338M+ attack simulations, reconnaissance was stopped only 10% of the time, while just 14% of simulated attacks triggered an alert.

The quiet moves are getting through.

Read more: https://thehackernews.com/2026/08/enterprise-defenses-recovered-at-edge.html
πŸ”₯4πŸ‘2πŸ€”1