The Hacker News

Syndikovat obsah
The Hacker News has been internationally recognized as a leading news source dedicated to promoting awareness for security experts and [email protected]
Aktualizace: 59 min 14 sek zpět

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

26 Srpen, 2026 - 08:27
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea. The vulnerability in question is CVE-2026-60004 (CVSS score: 9.8), a case of remote code execution that allows an attacker with ordinary write access to a repository to execute arbitrary shell commands as the
Kategorie: Hacking & Security

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

26 Srpen, 2026 - 08:27
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea. The vulnerability in question is CVE-2026-60004 (CVSS score: 9.8), a case of remote code execution that allows an attacker with ordinary write access to a repository to execute arbitrary shell commands as the Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes

26 Srpen, 2026 - 07:47
Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple's Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask for their device passcode. SOCRadar Threat Research Unit (STRU) said the platform, which it tracks as AnonyMousKIT, is credit-metered and drives lures across
Kategorie: Hacking & Security

Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes

26 Srpen, 2026 - 07:47
Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple's Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask for their device passcode. SOCRadar Threat Research Unit (STRU) said the platform, which it tracks as AnonyMousKIT, is credit-metered and drives lures across Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches

25 Srpen, 2026 - 20:17
The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an "unprecedented, whole-of-government, economic campaign" against the nation and its enablers. "We are launching an economic onslaught against Iran's financial connections around the globe. Our objective is to sever every economic lifeline that sustains this tyrannical regime
Kategorie: Hacking & Security

U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches

25 Srpen, 2026 - 20:17
The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an "unprecedented, whole-of-government, economic campaign" against the nation and its enablers. "We are launching an economic onslaught against Iran's financial connections around the globe. Our objective is to sever every economic lifeline that sustains this tyrannical regime Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

25 Srpen, 2026 - 16:07
Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden instructions inside the model itself. The findings were shared with The Hacker News ahead of publication, and the report says Oasis Security reported them to NVIDIA's Product Security Incident
Kategorie: Hacking & Security

A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

25 Srpen, 2026 - 16:07
Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden instructions inside the model itself. The findings were shared with The Hacker News ahead of publication, and the report says Oasis Security reported them to NVIDIA's Product Security Incident Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security