All News
The Hacker News
The Hacker News
August 1, 2026
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
A Coldcard firmware flaw weakens wallet seed generation across five models, while Galaxy links a 1,196-address, $70.2 million sweep to the b...
The Hacker News
August 1, 2026
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
Attackers altered Adform's trackpoint-async.js to replace Bitcoin, Ethereum, and Tron wallet addresses across customer sites.
The Hacker News
August 1, 2026
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
Adobe patches CVE-2026-48449, a CVSS 10.0 Campaign Classic flaw that could allow code execution without user interaction, plus eight Bridge...
The Hacker News
August 1, 2026
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
Microsoft links hijacked hotel Wi-Fi to fake updates that deliver CornFlake, steal cloud tokens, and abuse device codes to target travelers.
The Hacker News
July 31, 2026
Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
Suspected Chinese-speaking hackers use OctLurk and SilkLurk to target Central Asian governments with in-memory plugins and credential theft.
The Hacker News
July 31, 2026
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
HollowFrame and Matryoshka use DLL side-loading and GitHub C2 to gain a persistent foothold on two law firm endpoints.
The Hacker News
July 31, 2026
Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
Fuyao turns cheap Android TV boxes into fake phones for ad fraud and SOCKS5 exit nodes on owners’ broadband.
The Hacker News
July 31, 2026
Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined
Google fixed 1,072 Chrome flaws in versions 149 and 150, more than the prior 23 milestones combined, as AI-driven discovery accelerates bug...
The Hacker News
July 31, 2026
Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw
Researchers found 84 flaws in seven open-source 4G and 5G cores that could enable DoS or session hijacking when internal interfaces become r...
The Hacker News
July 31, 2026
6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
Push tracks 25-plus device code phishing kits that bypass passkeys; Barracuda counted 7 million attacks in four weeks.
The Hacker News
July 31, 2026
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
Chinese-speaking actor used DeepSeek through Hermes Agent to launch attacks after one Telegram instruction in a 460-plus-target operation.
The Hacker News
July 31, 2026
Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations
Anthropic says 3 Claude models breached real organizations after misconfigured CTF evaluations exposed them to the open internet and product...
The Hacker News
July 30, 2026
DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
DPRK-linked macOS malvertising uses fake updates and ClickFix to install a backdoor that fetches a stealer targeting 157 crypto wallets.
The Hacker News
July 30, 2026
ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories
This week's cybersecurity landscape reveals alarming trends as artificial intelligence becomes weaponized for large-scale hacking operations...
The Hacker News
July 30, 2026
Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database
Azure Cosmos DB's Gremlin flaw let Wiz escape the sandbox and retrieve an account key. Microsoft found no unauthorized activity outside Wiz'...
The Hacker News
July 30, 2026
Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents
Microsoft 365 Copilot prompt injection can alter report figures and copy hidden instructions into generated files, letting them affect later...
The Hacker News
July 30, 2026
The Network Has Become the Control Plane for AI Security Jul 30, 2026 Network Security / AI Security Network firewalls are the workhorses of modern cybersecurity. They are trusted to protect the network, blocking malicious traffic and preventing intrusions and breaches. And for decades, network security teams have built controls around a relatively stable model: users connect to applications, applications exchange data, and security tools inspect packets, protocols, and destinations. Firewalls became exceptionally good at understanding where traffic was going and whether it should be allowed. But just as AI is reshaping every aspect of the business world, it's also had a monumental impact o
The Network Has Become the Control Plane for AI Security Jul 30, 2026 Network Security / AI Security Network firewalls are the workhorses o...
The Hacker News
July 30, 2026
SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT
Silver Fox uses a three-driver BYOVD framework, DLL sideloading, and dual watchdogs to keep ValleyRAT running at a Japanese manufacturing or...
The Hacker News
July 30, 2026
Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts
Sophisticated threat actors linked to state-sponsored operations have leveraged compromised South Korean web servers as distribution vectors...
The Hacker News
July 30, 2026
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
Russian hackers exploit CVE-2026-42897 in OWA to deploy OWAReaper, a browser implant that persists through credential rotation and device re...
The Hacker News
July 30, 2026
FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks
FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks | Read more hacking news on The Hacker News cybersecurity news w...
The Hacker News
July 30, 2026
Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet
Amazon links the 2025 debug and chalk npm hijack to Sapphire Sleet with medium confidence, but does not show which evidence ties the inciden...
The Hacker News
July 30, 2026
Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
Cisco FMC flaw CVE-2026-20316 is under active exploitation, letting unauthenticated attackers use static credentials to access sensitive dat...
The Hacker News
July 29, 2026
Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
CVE-2026-66066 could expose Rails server files through image uploads, leaking secrets that may enable RCE or lateral movement.
The Hacker News
July 29, 2026
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
A critical vulnerability in Ruflo's MCP bridge infrastructure allows unauthenticated attackers to execute arbitrary commands on target syste...
The Hacker News
July 29, 2026
Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
Broadcom has addressed three significant security vulnerabilities affecting VMware infrastructure, including two critical flaws in vCenter t...
The Hacker News
July 29, 2026
Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline
A coordinated cyberattack targeted more than 30 Minnesota water systems, disrupting a plant and cellular links while affecting automated con...
The Hacker News
July 29, 2026
Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments
A fraud campaign active since 2017 uses nearly 100 clone domains to steal advance payments from international B2B buyers.
The Hacker News
July 29, 2026
Mythos Asks the Right Question. It Doesn't Answer It.
50,000 findings sorted by CVSS isn't a priority list. See the 12 that reach a crown-jewel asset.
The Hacker News
July 29, 2026
Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
Nebula says CVE-2026-10702 lets a malicious webpage compromise Tor Browser and start an Android 17 root chain.
The Hacker News
July 29, 2026
73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack
A 2026 survey of 600 security leaders finds 73% of organizations are not fully ready for a major cyberattack, despite widespread planning.
The Hacker News
July 29, 2026
Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity
Russia charges Telegram founder Pavel Durov with aiding terrorist activity over channels it says were used to plan sabotage and terrorism.
The Hacker News
July 29, 2026
Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
A critical authentication vulnerability in Check Point SmartConsole has been publicly exposed, enabling remote attackers to completely bypas...
The Hacker News
July 29, 2026
New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands
Gitea fixes CVE-2026-60004, a 9.8 RCE that lets repository writers turn malicious patches into Git hooks and run commands.
The Hacker News
July 29, 2026
Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates
Flying Eagle Android RAT source code is circulating on Telegram, while Hunt.io links its infrastructure fingerprints to 170 internet servers...
The Hacker News
July 29, 2026
OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach
An OpenAI agent exploited an Artifactory zero-day, escaped its sandbox, and accessed four third-party accounts during a Hugging Face breach.
The Hacker News
July 29, 2026
Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js
Two @joyfill npm beta packages run an import-time implant that uses Tron, Aptos, and BSC to deliver a DEV#POPPER-linked Node.js RAT.
The Hacker News
July 28, 2026
Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack
Anthropic says Claude recovered HAWK-256 signing material and sped up a seven-round AES-128 attack, but neither affects production systems.
The Hacker News
July 28, 2026
Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
Tengu abuses Linux hardware watchdogs to reboot devices after its main process is killed, letting other persistence mechanisms relaunch it.
The Hacker News
July 28, 2026
24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login
Researchers find 24,650 exposed BMCs disclose IPMI authentication hashes before login, enabling offline password cracking.
The Hacker News
July 28, 2026
JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
JFrog confirms OpenAI models exploited Artifactory during a sealed test; a separate path later breached Hugging Face.
The Hacker News
July 28, 2026
Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
OpenWrt 24.10.8 fixes CVE-2026-53921, a critical odhcpd stack overflow triggered by crafted DHCPv6 requests that could enable code execution...
The Hacker News
July 28, 2026
Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
Iranian state-backed Nimbus Manticore deploys NightLedger and two WebSocket tunnelers to maintain covert access across three regions.
The Hacker News
July 28, 2026
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
CVE-2026-63077 could let unauthenticated attackers bypass TeamCity checks and run OS commands; JetBrains patched all on-premises versions.
The Hacker News
July 28, 2026
Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit
Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit | Read more hacking news on The Hacker News cybersecurity new...
The Hacker News
July 28, 2026
Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost
Microsoft launches MAI-Cyber-1-Flash inside MDASH, routing up to 90% of tasks to the model while GPT-5.4 handles the hardest 10%.
The Hacker News
July 28, 2026
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
Hackers are exploiting CVE-2026-16812 in on-prem Arista VeloCloud Orchestrator, a command injection bug that may extend access to managed Ed...
The Hacker News
July 27, 2026
NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework
NVIDIA and 36 partners form the Open Secure AI Alliance and release NOOA, while governance and joint deliverables remain undisclosed.
The Hacker News
July 27, 2026