The Hacker News
βœ”
162K subscribers
3.75K photos
24 videos
4 files
9.73K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
‼️ Rust supply chain attack hits three crates, including 245 million-download arrayref.

A compromised maintainer account pushed malicious releases that pulled in typosquatted proc-macro1, whose build script fetches and runs a remote payload during compilation.

Check your Cargo cache and pinned versions now: https://thehackernews.com/2026/08/rust-supply-chain-attack-puts-build.html
😁14⚑4
⚠️ A CVSS 10.0 Entra ID flaw was exploited in the wild.

CVE-2026-69836 allows an unauthorized attacker to remotely execute code through unsafe deserialization.

Microsoft says the flaw is fully mitigated and no customer action is required. How attackers exploited it remains undisclosed.

Read more: https://thehackernews.com/2026/08/microsoft-entra-id-flaw-cvss-100.html
😱10πŸ”₯4⚑1
πŸ”» Attackers are exploiting a GitLab flaw days after disclosure.

CVE-2026-19478 lets unauthenticated attackers modify or delete public projects and rewrite their data under certain conditions. watchTowr says it saw in-the-wild exploitation against its honeypots.

Running self-hosted GitLab? Patch now: https://thehackernews.com/2026/08/gitlab-cve-2026-19478-comes-under.html
πŸ”₯7😁4⚑2
‼️ Five CVSS 10.0 flaws affect Cisco Crosswork and Secure Workload.

They’re among nine vulnerabilities Cisco patched, covering SQL injection, missing authentication, access control, path traversal, and other security failures.

Read: https://thehackernews.com/2026/08/cisco-patches-nine-crosswork-and-secure.html
πŸ‘5πŸ”₯4
Wazuh now uses Claude to automate scheduled SOC reports.

Wazuh AI Analyst processes cloud security data through Amazon Bedrock and Claude, then reports on alerts, protected endpoints, active vulnerabilities, and security posture.

Teams can also plug Wazuh into self-hosted Llama 3 or Claude 3.5 Haiku.

See how it works: https://thehackernews.com/2026/08/wazuh-and-ai-for-enhanced-soc-workflows.html
πŸ”₯15😁6πŸ€”3
⚠️ Android car head units are getting malware through built-in updaters.

Attackers abused DoFun’s update channel to deliver malware for ad fraud and proxy botnet activity. It can also download and run arbitrary code.

Full details: https://thehackernews.com/2026/08/android-car-malware-spreads-through.html
😁15πŸ”₯10πŸ‘2😱2⚑1
‼️ Attackers can weaponize Defender’s own signed driver to delete security software at boot.

BTR.sys runs from Ring 0 before Defender’s user-mode services start. Check Point showed it deleting the full Defender stack on Windows 11 25H2 with Tamper Protection enabled.

See how it works: https://thehackernews.com/2026/08/microsoft-defenders-own-driver-can-be.html
πŸ”₯10😁6⚑2
‼️ 14 npm packages drop RedC2 4.0 on Linux.

The packages work as advertised, but also launch its RedShell beacon on import. RedC2 includes an LLM-backed agent that turns natural-language instructions into beacon commands.

Read - https://thehackernews.com/2026/08/14-trojanized-npm-packages-drop-redc2.html
πŸ€”15⚑1
⚑ TikTok will pay $400 million over child privacy allegations.

The U.S. case accused TikTok of knowingly allowing children under 13 to create accounts, collecting data from Kids Mode users, and failing to honor parental deletion requests.

Read the details: https://thehackernews.com/2026/08/tiktok-agrees-to-400-million-settlement.html
πŸ‘29😁14πŸ‘5🀯3⚑1
⚠️ UAT-10147 is using AI to scale server attacks.

The group uses AI across exploitation and post-compromise activity, then deploys SPECTRE.

β€” On Windows, SPECTRE can blind EDR.
β€” On Linux, it loads a persistent kernel rootkit.

See how it works: https://thehackernews.com/2026/08/uat-10147-uses-ai-to-scale-server.html
😁10πŸ‘8
🚨 Fake graduation invites are delivering a Go backdoor in Myanmar.

Recent Operation QUICSILVER samples use a malicious LNK inside a VHD, abuse Windows ftp.exe, then deploy QUICAgent, which communicates with its C2 over QUIC on UDP 443.

Read: https://thehackernews.com/2026/08/operation-quicsilver-targets-myanmar.html
πŸ”₯9πŸ‘2
Nearly half of enterprise AI chats use personal identities.

Akamai found 47.11% happen outside corporate-managed accounts, while the top 5% of users interact with AI at 12Γ— the rate of the bottom half.

Shadow AI risk is concentrated among a small group of heavy users.

Read the findings: https://thehackernews.com/2026/08/the-outsized-shadow-why-5-of-ai-users.html
😁5🀯2πŸ‘1
‼️ A critical Keycloak flaw could let attackers take over any account.

CVE-2026-18963 lets an unauthenticated attacker reset a user’s password without the emailed action token, including for admin accounts.

Read more: https://thehackernews.com/2026/08/critical-keycloak-password-reset-flaw.html
πŸ”₯8🀯6πŸ‘1
🚨 Fake CAPTCHA prompts are delivering Amatera Stealer.

WordlistLoader powers the ClearFake ClickFix chain on compromised websites.

Separately, Microsoft Teams phishing delivers SynkLoader. Its fake Windows lock screen can capture login passwords.

Read: https://thehackernews.com/2026/08/wordlistloader-delivers-amatera-via.html
😁6πŸ”₯2πŸ‘1
⚑ Shipping code 10–50Γ— faster? Security has to keep up.

AI coding is adding open-source dependencies faster, and remediation debt can pile up behind them.

See what 300 enterprise leaders found, where controls are falling short, and which governance models are working.

Join the webinar: https://thehackernews.com/2026/08/shipping-more-ai-code-than-you-can.html
πŸ‘7
⚑ This week in cybersecurity:

πŸ€– AI PLC Attacks
🚨 GitLab Exploited
πŸ“¦ npm Backdoors
πŸ’³ Zombie Card Fraud
πŸ”‘ Auth Flow Hijacks
☁️ Cloud Spectre Leak
πŸ•ΈοΈ Windchill Web Shells
πŸ“± Android Kernel Flaw
πŸ’° Stripe Keys Leaked
πŸ–₯️ ScreenConnect Abuse
🎣 DCRat Phishing
πŸ“ Find My Tracking
🎧 Audio Fingerprinting

Catch up on everything that mattered this week - https://thehackernews.com/2026/08/weekly-recap-ai-powered-plc-attacks.html
πŸ”₯11πŸ‘3😁2
⚠️ Fake Minecraft clients are spreading Weedhack malware through search results.

Spoofed sites for Xenon, Nova, and other clients can outrank legitimate sources. Weedhack JARs can steal data and add Microsoft Defender exclusions.

How it spreads: https://thehackernews.com/2026/08/weedhack-malware-spreads-via-fake.html
πŸ”₯5πŸ‘2🀯2😱1