[Video] AI agents are keeping access long after they're needed.
There are 109 non-human identities for every human. 82% of organizations have found unapproved shadow AI, and only 21% have a proper way to shut agents down.
See how identity controls the full AI agent lifecycle: https://thehackernews.com/videos/2026/08/ai-agent-lifecycle-risks.html
There are 109 non-human identities for every human. 82% of organizations have found unapproved shadow AI, and only 21% have a proper way to shut agents down.
See how identity controls the full AI agent lifecycle: https://thehackernews.com/videos/2026/08/ai-agent-lifecycle-risks.html
π₯3π1
π¨ Fake crypto startup hires three suspected North Korean IT workers.
Researchers created Ballena Azul, interviewed the candidates, signed them as employees, and gave them work VMs. No exploit was needed. The access came through the hiring process.
See how they got hired: https://thehackernews.com/2026/08/researchers-built-fake-crypto-startup.html
Researchers created Ballena Azul, interviewed the candidates, signed them as employees, and gave them work VMs. No exploit was needed. The access came through the hiring process.
See how they got hired: https://thehackernews.com/2026/08/researchers-built-fake-crypto-startup.html
π8π₯2
βΌοΈ A malicious SIM can take over the modem from inside the device.
Researchers found 9 of 26 tested phones and cellular modules accept RUN AT commands from the SIM, including 6 of the 8 modules. On one commercial EV charger, they chained the interface to code execution.
Here's how the attack works - https://thehackernews.com/2026/08/a-malicious-sim-card-can-run-attacker.html
Researchers found 9 of 26 tested phones and cellular modules accept RUN AT commands from the SIM, including 6 of the 8 modules. On one commercial EV charger, they chained the interface to code execution.
Here's how the attack works - https://thehackernews.com/2026/08/a-malicious-sim-card-can-run-attacker.html
π7π₯4β‘2
π¨ Mozilla revoked the Firefox and Thunderbird Linux signing key after an unencrypted copy was accidentally committed to a private repo.
No unauthorized access was found, but older downloads can stop verifying and some Firefox RPM updates may fail.
Read: https://thehackernews.com/2026/08/mozilla-revokes-firefox-and-thunderbird.html
No unauthorized access was found, but older downloads can stop verifying and some Firefox RPM updates may fail.
Read: https://thehackernews.com/2026/08/mozilla-revokes-firefox-and-thunderbird.html
π8π₯3
π₯ OpenAI just released a more cyber-permissive GPT-5.6.
GPT-5.6-Cyber is built for vulnerability research, penetration testing, incident response, and exploit development, with reduced refusals for some higher-risk dual-use tasks.
Read the full story: https://thehackernews.com/2026/08/openai-launches-gpt-56-cyber-with.html
GPT-5.6-Cyber is built for vulnerability research, penetration testing, incident response, and exploit development, with reduced refusals for some higher-risk dual-use tasks.
Read the full story: https://thehackernews.com/2026/08/openai-launches-gpt-56-cyber-with.html
π₯14π5π€5π2
β‘ ICYMI: One click from a logged-in #WordPress admin can trigger a chain from pre-auth XSS to PHP code execution.
CVE-2026-64638 affects all WordPress versions, and the login-page XSS itself requires no authentication.
Patch now:
https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html
CVE-2026-64638 affects all WordPress versions, and the login-page XSS itself requires no authentication.
Patch now:
https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html
π6π₯4π2
Only 45% of security teams consolidate asset and exposure data into one view.
New Ponemon research with Axonius shows how fragmented visibility weakens prioritization and remediation, and the five fundamentals that can fix it.
Download the playbook: https://thn.news/asset-playbook-guide
New Ponemon research with Axonius shows how fragmented visibility weakens prioritization and remediation, and the five fundamentals that can fix it.
Download the playbook: https://thn.news/asset-playbook-guide
π7
π¨ DeadLock ransomware is making its extortion infrastructure harder to disrupt.
It uses Polygon smart contracts to rotate victim-chat proxies, Session for encrypted communications, and blockchain-hosted leak content.
See how it works: https://thehackernews.com/2026/08/deadlock-ransomware-uses-polygon-smart.html
It uses Polygon smart contracts to rotate victim-chat proxies, Session for encrypted communications, and blockchain-hosted leak content.
See how it works: https://thehackernews.com/2026/08/deadlock-ransomware-uses-polygon-smart.html
π₯7π5
π No SharePoint credentials needed to impersonate an admin and run code.
Researchers chained two flaws, CVE-2026-55040 and CVE-2026-63520, to go from unauthenticated user impersonation to code execution on the server.
Read details here: https://thehackernews.com/2026/08/researchers-disclose-ai-assisted.html
Researchers chained two flaws, CVE-2026-55040 and CVE-2026-63520, to go from unauthenticated user impersonation to code execution on the server.
Read details here: https://thehackernews.com/2026/08/researchers-disclose-ai-assisted.html
π€10π4π₯2
β οΈ Fake job interviews are delivering a VPN that can run commands.
CERT-UA says Sandworm-linked UAC-0145 is targeting Ukrainian IT workers with recruiter lures, then pushing a modified WireGuard client that can execute commands and fetch a second-stage payload.
Read more: https://thehackernews.com/2026/08/sandworm-linked-uac-0145-uses-fake-job.html
CERT-UA says Sandworm-linked UAC-0145 is targeting Ukrainian IT workers with recruiter lures, then pushing a modified WireGuard client that can execute commands and fetch a second-stage payload.
Read more: https://thehackernews.com/2026/08/sandworm-linked-uac-0145-uses-fake-job.html
π₯6π5
βΌοΈ WARNING: One Zoom attendee could take over every other attendee's computer.
Three flaws in Zoom's annotation feature could be exploited from inside a meeting, with no click, download, or prompt required from the victim.
Make sure your software is up to date.
Read more: https://thehackernews.com/2026/08/zoom-annotation-flaws-could-let-meeting.html
Three flaws in Zoom's annotation feature could be exploited from inside a meeting, with no click, download, or prompt required from the victim.
Make sure your software is up to date.
Read more: https://thehackernews.com/2026/08/zoom-annotation-flaws-could-let-meeting.html
π₯13π4π3π€―2
β οΈ Kimwolf v7 makes DDoS traffic harder to distinguish from real browsing.
The Android and IoT botnet now builds complete browser fingerprints for HTTP/2 floods, uses ENS and Tor to harden its C2, and targets Android TV boxes through exposed ADB.
Read more: https://thehackernews.com/2026/08/kimwolf-v7-android-botnet-makes-http2.html
The Android and IoT botnet now builds complete browser fingerprints for HTTP/2 floods, uses ENS and Tor to harden its C2, and targets Android TV boxes through exposed ADB.
Read more: https://thehackernews.com/2026/08/kimwolf-v7-android-botnet-makes-http2.html
π₯9π€―6π2
π 398 fixes. One exploited Windows zero-day. Four unauthenticated 9.8 RCEs.
Microsoftβs August Patch Tuesday fixes CVE-2026-68820, which can elevate an attacker with existing code execution to SYSTEM.
It also closes the RCE half of a SharePoint exploit chain.
Hereβs what to patch first β https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html
Microsoftβs August Patch Tuesday fixes CVE-2026-68820, which can elevate an attacker with existing code execution to SYSTEM.
It also closes the RCE half of a SharePoint exploit chain.
Hereβs what to patch first β https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html
π10π₯10
π Exploited Cisco firewall flaw can remotely crash affected devices.
CVE-2026-20349 affects certain ASA and FTD configurations. A crafted HTTP request can force a device reload and cause a denial-of-service condition.
Cisco says exploitation is already underway and no workaround exists.
Patch now: https://thehackernews.com/2026/08/cisco-asa-and-ftd-flaw-exploited-in.html
CVE-2026-20349 affects certain ASA and FTD configurations. A crafted HTTP request can force a device reload and cause a denial-of-service condition.
Cisco says exploitation is already underway and no workaround exists.
Patch now: https://thehackernews.com/2026/08/cisco-asa-and-ftd-flaw-exploited-in.html
π₯9π2π1
βΌοΈ Microsoft patched RoguePlanet. Now the researcher has dropped another zero-day that claims to bypass the fix.
ShieldBreak is said to fully bypass Defenderβs CVE-2026-50656 patch. The underlying flaw can lead to SYSTEM-level privileges.
Read more: https://thehackernews.com/2026/08/shieldbreak-zero-day-poc-claims.html
ShieldBreak is said to fully bypass Defenderβs CVE-2026-50656 patch. The underlying flaw can lead to SYSTEM-level privileges.
Read more: https://thehackernews.com/2026/08/shieldbreak-zero-day-poc-claims.html
π₯22π9
β οΈ Warning: SAP Commerce Cloud flaw could enable arbitrary code execution.
CVE-2026-58231 carries a CVSS 10.0 score and can be triggered by an unauthenticated attacker abusing a default authentication client with crafted input.
SAP has released a fix. Patch and redeploy.
Read: https://thehackernews.com/2026/08/sap-commerce-cloud-flaw-could-let.html
CVE-2026-58231 carries a CVSS 10.0 score and can be triggered by an unauthenticated attacker abusing a default authentication client with crafted input.
SAP has released a fix. Patch and redeploy.
Read: https://thehackernews.com/2026/08/sap-commerce-cloud-flaw-could-let.html
π₯5π5π€―2
βΌοΈ BREAKING: A 40-minute LiteLLM PyPI compromise potentially exposed 2,100+ organizations.
Tied to Trivy's supply-chain attack, the malicious releases stole cloud, SSH, Kubernetes, and database credentials. Researchers later obtained roughly 434,000 captured files mapping potential exposure across thousands of organizations.
See what the stolen data reveals: https://thehackernews.com/2026/08/malicious-litellm-releases-tied-to.html
Tied to Trivy's supply-chain attack, the malicious releases stole cloud, SSH, Kubernetes, and database credentials. Researchers later obtained roughly 434,000 captured files mapping potential exposure across thousands of organizations.
See what the stolen data reveals: https://thehackernews.com/2026/08/malicious-litellm-releases-tied-to.html
π₯6π±2π1
π¨ Watch out: Attackers are exploiting VMware vCenter for persistence.
After exploiting CVE-2026-59310, they planted a malicious cron job running reverse_ssh to maintain access. Researchers identified up to 361 victim IPs across 47 countries.
Read more: https://thehackernews.com/2026/08/attackers-exploit-vmware-vcenter.html
After exploiting CVE-2026-59310, they planted a malicious cron job running reverse_ssh to maintain access. Researchers identified up to 361 victim IPs across 47 countries.
Read more: https://thehackernews.com/2026/08/attackers-exploit-vmware-vcenter.html
π₯6
π¨ Three Adobe flaws hit CVSS 10.0 and could enable code execution.
Adobe patched the maximum-severity bugs in ColdFusion and Campaign Classic, plus a CVSS 9.1 Commerce flaw that could allow privilege escalation. No exploitation has been seen in the wild.
Read: https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html
Adobe patched the maximum-severity bugs in ColdFusion and Campaign Classic, plus a CVSS 9.1 Commerce flaw that could allow privilege escalation. No exploitation has been seen in the wild.
Read: https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html
π₯8π5π2
βΌοΈ Researchers found a way to make a weaker AI decode a stronger model's hidden reasoning.
They extracted hidden traces from OpenAI, Anthropic, and Google APIs, recovering secret API keys and passwords, along with other credentials, in publicly shared agent logs.
Read more: https://thehackernews.com/2026/08/openai-anthropic-google-api-flaw-let.html
They extracted hidden traces from OpenAI, Anthropic, and Google APIs, recovering secret API keys and passwords, along with other credentials, in publicly shared agent logs.
Read more: https://thehackernews.com/2026/08/openai-anthropic-google-api-flaw-let.html
π9π4π€2π€―1
Once attackers get inside, defenses stop just 37%.
Across 338M+ attack simulations, reconnaissance was stopped only 10% of the time, while just 14% of simulated attacks triggered an alert.
The quiet moves are getting through.
Read more: https://thehackernews.com/2026/08/enterprise-defenses-recovered-at-edge.html
Across 338M+ attack simulations, reconnaissance was stopped only 10% of the time, while just 14% of simulated attacks triggered an alert.
The quiet moves are getting through.
Read more: https://thehackernews.com/2026/08/enterprise-defenses-recovered-at-edge.html
π₯4π2π€1