RSS Amplifier

News source

Hacker News

Your Daily Dose of Cybersecurity Intelligence

hackernews.aeSource feed ↗32 articles

Live Last read · last published · next check

Written by

Latest articles

Lawmakers request watchdog review of federal hacking of Americans

Two members of Congress have formally requested that a government watchdog agency investigate the extent and oversight of federal agencies’ use of hacking tools, including spyware, against Americans. The lawmakers seek a public report detailing the findings. The request, sent Friday to the Government Accountability Office (GAO), was made by Senator Ron Wyden, a Democrat [...]

Cisco Addresses Critical Vulnerabilities in Crosswork and Secure Workload Software

Cisco has issued a new set of security advisories detailing critical vulnerabilities across its Crosswork platforms and Secure Workload Software. These updates are part of an ongoing, comprehensive internal security review by the networking giant. The identified security flaws, several with maximum or near-maximum CVSS scores, underscore the persistent threat landscape for enterprise security…

GitLab CVE-2026-19478 exploited days after disclosure

A critical GitLab vulnerability, identified as CVE-2026-19478, is being actively exploited in the wild shortly after its public disclosure. This severe code injection flaw allows unauthenticated attackers to compromise publicly accessible GitLab projects, enabling them to modify, delete, or rewrite project data without needing credentials or user interaction, according to a report by preemptive…

Microsoft Entra ID Vulnerability Exploited Remotely

Microsoft has issued a critical alert regarding a maximum-severity security flaw, CVE-2026-69836, within its Microsoft Entra ID service, formerly known as Azure Active Directory. The company confirmed that this remote code execution vulnerability has already been exploited in the wild, posing a significant threat. However, Microsoft has stated that no immediate action is required from [...]

Critical NetScaler Flaw Bypasses Authentication on Gateway and AAA Servers

Citrix has issued critical security updates to address two significant vulnerabilities affecting its NetScaler ADC and NetScaler Gateway products. The patches are particularly important for organizations using customer-managed NetScaler instances, as one of the flaws allows for a critical-severity authentication bypass, potentially granting unauthorized access. The vulnerabilities were disclosed…

Isolated VM vulnerability allows sandboxed JavaScript to escape to host for potential remote code execution.

A critical security vulnerability has been discovered in isolated-vm, a widely-used Node.js sandbox library, potentially allowing attackers to escape the confined environment. The flaw, identified by cybersecurity researchers, impacts numerous applications that rely on this library for running untrusted JavaScript code securely. This discovery highlights ongoing challenges in maintaining robust…

Researchers Discover Cryptographic Context Injection Attack Targeting Web Pages

AI security firm Adversa AI has disclosed a novel attack technique, codenamed “Cryptographic Context Injection,” that it claims can compel xAI’s Grok chatbot to leak sensitive user information to an attacker. This exploit reportedly allows an attacker to obtain a user’s name, approximate location, subscription tier, and current conversation prompts by tricking Grok into summarizing [...]

AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure

The U.S. government has issued a stark warning about an “active threat” leveraging artificial intelligence (AI) to generate exploit scripts targeting critical infrastructure organizations. This new wave of cyber activity specifically targets Siemens S7 Series Programmable Logic Controllers (PLCs) for reconnaissance and capability development, though the scope is believed to be broader than just…

Vulnerabilities disclosed include Gogs 10.0 RCE, n8n workflow-to-RCE, a $10M reward opportunity, and a GLM-5.3 AI exploit.

This week’s cybersecurity landscape is dominated by threats leveraging trusted components for malicious purposes, underscoring the persistent challenges in securing digital infrastructure. From the abuse of signed drivers to the exploitation of legitimate applications, attackers continue to find innovative ways to bypass defenses, making the need for robust cybersecurity measures more critical…

CDN Vulnerable to HTTP/3 Amplification Attacks

Cybersecurity researchers have uncovered a new threat dubbed “CDN Tsunami,” which exploits how major content delivery networks (CDNs) handle HTTP/3 traffic. These attacks can amplify low-bandwidth requests into massive floods directed at origin servers, potentially leading to significant service disruptions. The findings highlight a critical vulnerability in how CDNs bridge the gap between modern…

Retail theft bill sparks surveillance concerns

A bipartisan bill aimed at combating organized retail theft is gaining traction in Congress, though some advocacy groups warn it could lead to expanded surveillance powers. The Combating Organized Retail Crime Act, or CORCA, seeks to create a new coordination center within Immigration and Customs Enforcement (ICE) to share information and prosecute large-scale theft operations. [...]

Researchers Demonstrate Zombie Card Attack to Reactivate Expired Visa Cards for Contactless Payments

Researchers at the University of Massachusetts Amherst have uncovered a significant security vulnerability in Visa contactless credit cards, demonstrating a method to revive expired cards for real-world purchases by manipulating the expiration date read by point-of-sale (POS) terminals. This “Zombie Card” attack, as it’s been dubbed, bypasses cryptographic protections, raising concerns about the…

Elementor Pro Vulnerability Allows Unauthenticated Code Execution

Cybersecurity researchers have revealed a critical vulnerability in the popular Elementor Pro WordPress plugin, identified as CVE-2026-32475. This flaw, carrying a severe CVSS score of 9.0, could allow unauthenticated attackers to execute arbitrary code remotely on vulnerable websites. The vulnerability stems from an issue within the Forms module’s File Upload field, specifically how it handles…

Cloudflare Workers Vulnerable to Spectre Attack, Leaking JWTs at Low Data Rates

Cybersecurity researchers have successfully demonstrated a remote Spectre attack targeting Cloudflare Workers, achieving a significant increase in data leakage speed. This advanced attack, detailed in a recent paper, managed to exfiltrate a JSON Web Token (JWT) from a co-located Worker in Cloudflare’s production environment at a rate of up to 12 bits per second. This [...]

Hackers compromise over 14,500 Dahua devices

Cybersecurity researchers at Hunt.io have detailed a large-scale attack campaign, codenamed Operation CameraSwarm, that compromised over 14,530 Dahua devices between June and July 2026. The campaign leveraged a combination of credential attacks, two critical authentication-bypass vulnerabilities, and a peer-to-peer (P2P) relay technique to gain unauthorized access to surveillance systems. The…

Serious Vulnerabilities in macOS, SharePoint, vCenter, and Microsoft IKE Under Active Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, citing active exploitation in the wild. This move highlights the ongoing threat posed by these security flaws, particularly for organizations that have not yet applied the available patches. The inclusion signifies that these vulnerabilities…

Clop-linked Windchill web shell decrypts credentials and maps engineering data.

A sophisticated, custom-built JavaServer Pages (JSP) web shell has been discovered deployed by threat actors targeting critical vulnerabilities in PTC Windchill and FlexPLM servers. Cybersecurity firm ReliaQuest has detailed how this bespoke tool, specifically crafted for Product Lifecycle Management (PLM) software, acts as a powerful extortion platform, enabling extensive data theft and remote…

Attackers exploit MLflow SSRF flaw to steal cloud credentials and secrets

Critical vulnerabilities affecting open-source artificial intelligence (AI) platform MLflow and operational technology (OT) software FUXA are currently under active malicious scanning and exploitation. These security weaknesses, identified as CVE-2026-64849 in MLflow and CVE-2026-25895 in FUXA, pose significant risks to organizations relying on these platforms for machine learning operations and…

Microsoft Copilot security vulnerabilities may allow data exfiltration from connected applications.

Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal, collectively named CoSnitch, which could allow attackers to silently exfiltrate data from connected applications with a single click on a crafted link. The flaws leverage an undocumented URL parameter that the AI assistant itself revealed during Varonis’s security research. Microsoft was notified of the [...]

SafePal Hardware Wallet Manufacturer Reports Data Exposure for Approximately 40,000 Users

Hardware wallet manufacturer SafePal has confirmed a significant data breach affecting approximately 39,798 customers. An authorization flaw within an order-tracking plug-in led to the exposure of sensitive customer information, including names, email addresses, shipping addresses, and phone numbers. The company has begun notifying all affected individuals via email, urging vigilance against…

CISA Alerts to Active Exploitation of Ray Vulnerability Enabling Browser-Based Remote Code Execution

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has officially added a critical vulnerability affecting the open-source distributed computing framework Ray to its Known Exploited Vulnerabilities (KEV) catalog, confirming evidence of active exploitation. This designation for CVE-2025-62593, carrying a CVSS score of 9.4, highlights a significant risk for organizations utilizing Ray…

GitLab GraphQL vulnerability allows unauthenticated attackers to delete public projects

GitLab has released urgent security updates to address a critical vulnerability (CVE-2026-19478) in its self-managed Community Edition (CE) and Enterprise Edition (EE) software. This flaw, rated Critical with a CVSS score of 9.4, could permit an unauthenticated attacker to remotely alter or delete public projects and user data. The company issued this patch outside its [...]

Forminator WordPress Vulnerability Allows Unauthenticated Remote Code Execution

A critical security flaw discovered in the Forminator Forms WordPress plugin, which boasts over 600,000 active installations, could enable unauthenticated attackers to execute arbitrary code on vulnerable websites. This significant vulnerability, designated CVE-2026-15748, carries a severe CVSS score of 9.8 out of 10.0, highlighting its potential for widespread damage. The flaw was identified and…

Financial firms targeted in recent BlackFile cyberattacks

A cybercrime group known as BlackFile continues to target organizations across various sectors, including financial services, with a persistent wave of voice-phishing and extortion attacks. The group, tracked by Google Threat Intelligence Group as UNC6671 and associated with the broader threat actor The Com, has been actively seeking new victims as of late last week, [...]

Snowflake GitHub Actions Vulnerability Permits Command Injection via Crafted Issues

Cybersecurity researchers have identified a significant vulnerability within Snowflake’s public snowflakedb/snowflake-connector-net GitHub Actions workflow, a flaw that could have allowed attackers to execute commands using internal Jira credentials. The issue, present in a specific workflow file, was discovered by Wiz and reported to Snowflake on June 23, 2026. While Snowflake has since patched…

Weekly cybersecurity recap: VMware vulnerabilities, Windows zero-day, MCP attacks, browser hijacking, and other threats.

The cybersecurity landscape remains a dynamic battleground, with sophisticated threats continually emerging. This past week has highlighted a persistent reality: even seemingly minor vulnerabilities can be exploited to cause significant damage. From critical infrastructure to everyday applications, attackers are leveraging a mix of novel exploits and well-trodden paths to compromise systems and…

Unisoc VoLTE exploit chain grants attackers Android kernel access

Security researchers have detailed a sophisticated two-stage exploit chain targeting Unisoc modem firmware, a critical component in many Android smartphones. This vulnerability, achieved through a VoLTE video call, grants attackers full access to the Android kernel. As of August 2026, the chipset maker, Unisoc, has yet to issue a fix for this severe security flaw, [...]

MCP Servers Pose Enterprise Security Risk

As organizations increasingly integrate artificial intelligence (AI) agents into their operations, a significant vulnerability is emerging within the Model Context Protocol (MCP) server infrastructure. These servers, designed to enable AI agents to access and interact with enterprise tools and data, are inadvertently becoming prime targets for attackers. MCP servers can expose critical enterprise…

Evooo1Bot Linux Botnet Leverages Unpatched Vulnerabilities for Edge Device Proxying

A newly identified Linux botnet, dubbed Evooo1Bot, is actively exploiting known vulnerabilities to compromise internet-facing devices, turning them into SOCKS proxies and bolstering botnet capabilities with features derived from the Mirai malware. Cybersecurity researchers at Fortinet FortiGuard Labs have detailed the botnet’s operations, which have been observed in the wild since July 2026.…

Suspected China-Linked Actor Exploits VMware vCenter Vulnerability, Deploys Babuk Ransomware

Cybersecurity researchers have identified a sophisticated attack campaign exploiting a critical vulnerability in Broadcom VMware vCenter, with evidence pointing towards a China-linked advanced persistent threat (APT) group. The exploitation of this newly patched flaw, identified as CVE-2026-59310, presents a significant risk to organizations relying on VMware’s virtualization software. The attacks…

SAP Commerce Cloud Exploited After Vulnerability Patch Released

A critical security vulnerability affecting SAP Commerce Cloud, identified as CVE-2026-58231, is currently facing active exploitation attempts. This severe flaw, rated a perfect 10.0 on the CVSS scoring system, stems from insufficient authorization checks and input validation within the SAP Commerce Cloud platform. Security researchers are urging immediate patching and mitigation efforts to…

macOS Screen Sharing Vulnerability Exploited for Monero Miner Installation

A critical security vulnerability in Apple’s macOS, identified as CVE-2026-65400, is currently being actively exploited in the wild to deploy a Monero cryptocurrency miner, according to a warning issued by the Netherlands National Cyber Security Centre (NCSC). The authentication flaw affects the built-in Screen Sharing component, potentially allowing attackers already on the network to gain [...]