The Hacker News

Syndikovat obsah
The Hacker News has been internationally recognized as a leading news source dedicated to promoting awareness for security experts and [email protected]
Aktualizace: 15 min 48 sek zpět

CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners

3 Září, 2026 - 07:19
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers' crosshairs. The vulnerabilities are as follows - CVE-2026-83548 (CVSS score: 10.0) - A server-side request forgery vulnerability in SonicWall SMA 1000 Appliances that could allow a remote unauthenticated
Kategorie: Hacking & Security

CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners

3 Září, 2026 - 07:19
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers' crosshairs. The vulnerabilities are as follows - CVE-2026-83548 (CVSS score: 10.0) - A server-side request forgery vulnerability in SonicWall SMA 1000 Appliances that could allow a remote [email protected]
Kategorie: Hacking & Security

Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs

2 Září, 2026 - 20:27
Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program. "The Fairwind Program gives high-priority defenders (like governments, healthcare providers, and telecommunications services) early access to advanced models that help them
Kategorie: Hacking & Security

Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs

2 Září, 2026 - 20:27
Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program. "The Fairwind Program gives high-priority defenders (like governments, healthcare providers, and telecommunications services) early access to advanced models that help them Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

2 Září, 2026 - 18:41
An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers. "The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users," Microsoft
Kategorie: Hacking & Security

Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

2 Září, 2026 - 18:41
An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers. "The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users," MicrosoftRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

2 Září, 2026 - 16:06
Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine, four of them still unpatched at publication. The command executes as the user, outside the agent's sandbox and without an approval prompt, and exploitation requires the repository to arrive
Kategorie: Hacking & Security

Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

2 Září, 2026 - 16:06
Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine, four of them still unpatched at publication. The command executes as the user, outside the agent's sandbox and without an approval prompt, and exploitation requires the repository to arrive Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages

2 Září, 2026 - 15:44
A Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run by Brazilian government and educational institutions, and using them to divert visitors to attacker-controlled pages promoting online gambling and sports betting. Check Point Research said it has tracked the campaign since mid-2025. The modules
Kategorie: Hacking & Security

Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages

2 Září, 2026 - 15:44
A Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run by Brazilian government and educational institutions, and using them to divert visitors to attacker-controlled pages promoting online gambling and sports betting. Check Point Research said it has tracked the campaign since mid-2025. The modules Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access

2 Září, 2026 - 15:12
Virtualizor said hackers used a Border Gateway Protocol (BGP) hijack to divert Softaculous traffic. The hackers then used the diverted update traffic to deliver a malicious Virtualizor package to some installations. A hosting-provider account separately said 5 of its 34 checked Virtualizor hypervisors sustained root-level compromise. The incident window ran from approximately August 28 at 20:57
Kategorie: Hacking & Security

BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access

2 Září, 2026 - 15:12
Virtualizor said hackers used a Border Gateway Protocol (BGP) hijack to divert Softaculous traffic. The hackers then used the diverted update traffic to deliver a malicious Virtualizor package to some installations. A hosting-provider account separately said 5 of its 34 checked Virtualizor hypervisors sustained root-level compromise. The incident window ran from approximately August 28 at 20:57Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control

2 Září, 2026 - 14:22
Cybersecurity researchers have disclosed details of a new Android banking trojan called StreamRat that was promoted to Spanish-speaking users through a fake television-streaming campaign on Meta and can give operators near-complete control of infected devices. ThreatFabric said the campaign's advertisement focused on Spain and reached an estimated 570,950 Meta accounts in the European Union
Kategorie: Hacking & Security

Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control

2 Září, 2026 - 14:22
Cybersecurity researchers have disclosed details of a new Android banking trojan called StreamRat that was promoted to Spanish-speaking users through a fake television-streaming campaign on Meta and can give operators near-complete control of infected devices. ThreatFabric said the campaign's advertisement focused on Spain and reached an estimated 570,950 Meta accounts in the European Union [email protected]
Kategorie: Hacking & Security

How to Secure Enterprise AI: From Adoption to Incident Readiness

2 Září, 2026 - 13:30
The debate about whether AI delivers business value is over. The challenge now is implementing it at scale and securely across every function while meeting board-level pressure to move fast. Organizations must focus on adopting AI at business speed without losing control of cyber risk. Download the full eBook here.  The Business Reality  In Sygnia’s 2026 CISO Survey Report, which
Kategorie: Hacking & Security

How to Secure Enterprise AI: From Adoption to Incident Readiness

2 Září, 2026 - 13:30
The debate about whether AI delivers business value is over. The challenge now is implementing it at scale and securely across every function while meeting board-level pressure to move fast. Organizations must focus on adopting AI at business speed without losing control of cyber risk. Download the full eBook here.  The Business Reality  In Sygnia’s 2026 CISO Survey Report, which [email protected]
Kategorie: Hacking & Security

Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

2 Září, 2026 - 12:53
SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks. The vulnerabilities, discovered internally by SonicWall's William Perry and Adam Babis, are listed below - CVE-2026-83548 (CVSS score: 10.0) -  A pre-authentication SSRF vulnerability in the Appliance
Kategorie: Hacking & Security

Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

2 Září, 2026 - 12:53
SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks. The vulnerabilities, discovered internally by SonicWall's William Perry and Adam Babis, are listed below - CVE-2026-83548 (CVSS score: 10.0) -  A pre-authentication SSRF vulnerability in the Appliance Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

2 Září, 2026 - 11:18
Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals. The project shipped fixes in versions 4.4.12 and 4.2.17 on July 8, 2026, and published the vulnerability details on August 31. GeoNetwork originated at the United Nations Food and
Kategorie: Hacking & Security

GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

2 Září, 2026 - 11:18
Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals. The project shipped fixes in versions 4.4.12 and 4.2.17 on July 8, 2026, and published the vulnerability details on August 31. GeoNetwork originated at the United Nations Food and Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security