The Hacker News Most trusted, widely-read independent cybersecurity news source for everyone; supported by hackers and IT professionals — Send TIPs to admin@thehackernews.com
- KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokensby info@thehackernews.com (The Hacker News) on September 15, 2026 at 6:54 pm
Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and
- Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalistsby info@thehackernews.com (The Hacker News) on September 15, 2026 at 4:29 pm
Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran’s intelligence service uses to spy on dissidents, journalists, and activists around the world. The malware is controlled via the Telegram messaging app and can copy a target’s emails and chat messages, take screenshots, and activate the microphone to record
- BambooToken Malware Uses MQTT to Control Windows and Linux Systemsby info@thehackernews.com (The Hacker News) on September 15, 2026 at 3:23 pm
Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems. The emerging malware family, codenamed BambooToken, is assessed to be active since at least February 2023 and put to use in attacks targeting organizations across Asia and South America.
- Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Secondsby info@thehackernews.com (The Hacker News) on September 15, 2026 at 11:52 am
With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new findings from Sysdig show that skilled human operators can move just as swiftly after gaining initial access. In one instance highlighted by the cloud security company, the threat actor pivoted from a vulnerable Marimo notebook to an SSH
- Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Pointby info@thehackernews.com (The Hacker News) on September 15, 2026 at 11:26 am
Introduction Security teams have gotten pretty good at testing against what can hurt them. Can this EDR agent catch this payload? Will my organization fail the phishing simulation? Does this SIEM rule fire on this particular technique? And, in more mature organizations, this testing happens continuously rather than as a one-off exercise. But no matter how much you validate against these
- Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Serversby info@thehackernews.com (The Hacker News) on September 15, 2026 at 11:12 am
Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data. The first is an automated effort aimed at internet-exposed Vite development servers that’s designed to steal cloud credentials, configurations from Amazon Web Services (AWS) and Microsoft Azure instances, and infrastructure state files, per F5 Labs. The
- LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Serverby info@thehackernews.com (The Hacker News) on September 15, 2026 at 6:52 am
A critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user gain root access on a shared-hosting server, cPanel warned in an advisory published on September 14. On such servers, many customers’ sites run on a single machine, and an attacker with one of those hosting accounts could exploit the flaw to access or alter other sites and the server itself,
- Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Executionby info@thehackernews.com (The Hacker News) on September 15, 2026 at 6:11 am
Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-76461, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as a case of insufficient validation in the email parsing logic that could allow an unauthenticated, remote attacker
- China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGEby info@thehackernews.com (The Hacker News) on September 15, 2026 at 5:31 am
A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE. Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026. “The
- New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computingby info@thehackernews.com (The Hacker News) on September 14, 2026 at 6:02 pm
Researchers have disclosed a new hardware attack, called DDRop, that breaks the memory protection in Intel and AMD confidential computing by silently dropping writes to a server’s memory, so the processor keeps reading old encrypted data as if it were current. The attack requires an attacker who already controls the server’s software and can briefly access the machine to insert a small circuit
- 3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentialsby info@thehackernews.com (The Hacker News) on September 14, 2026 at 6:01 pm
An attacker was operating inside the network of 3BB, one of Thailand’s largest broadband providers, and maintained remote control of internal machines using a legitimate management tool called MeshCentral, threat intelligence firm Hunt.io said. The company uncovered the intrusion by examining a server the attacker had left open on the internet, which held the attacker’s own tools and a list of
- Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exportsby info@thehackernews.com (The Hacker News) on September 14, 2026 at 5:58 pm
A flaw in Telegram Desktop let a bot’s message plant hidden JavaScript inside chats that users exported to HTML files, security researchers at ExPatch said in a writeup published on September 12. In Telegram, the message looked ordinary, with a link button, and the script ran only when someone opened the export file in a web browser. It could then copy every message in that file to
- Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countriesby info@thehackernews.com (The Hacker News) on September 14, 2026 at 4:56 pm
A suspected Chinese threat actor tracked as Red Heron has been attributed to the rapid exploitation of a recently disclosed security vulnerability in Gitea to compromise internet-facing instances as part of a multi-national campaign. “Red Heron scanned 1,386 Gitea instances across seven countries and maintained a separate dataset of 477 Taiwan-based systems,” Acronis Threat Research Unit (TRU)
- WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distributionby info@thehackernews.com (The Hacker News) on September 14, 2026 at 4:00 pm
WordPress has announced it’s launching an automated security review for every release of a plugin before it’s distributed through the WordPress.org update API so as to analyze it for potential security issues and ensure there are no risks involved. “New plugins are reviewed before they enter the directory, but updates ship continuously after that,” David Perez, WordPress Official Plugin
- âš¡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkitsby info@thehackernews.com (The Hacker News) on September 14, 2026 at 2:40 pm
AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job. Some models are also crossing lines on their own. That is not a great combination. The rest of the week is more familiar: old bugs still working, fresh exploit chains, exposed systems, weak defaults, and simple paths that should have been harder to abuse. A few of
- AI Changed the Exposure Problem. Validation Needs to Change With It.by info@thehackernews.com (The Hacker News) on September 14, 2026 at 11:58 am
There’s a lot of noise around AI and cybersecurity right now. What’s actually important is far simpler, if often lost in the hubbub. Vulnerability discovery is getting faster and happening at a much greater scale, while defenders still have to work out which findings actually deserve their action. In the first half of 2026, a whopping 35,853 CVEs were published, roughly 49% more than in the
- Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Usersby info@thehackernews.com (The Hacker News) on September 14, 2026 at 7:24 am
A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service. The extension, named “Twitch Enhanced Viewer | JeetBot,” lists HISHIMIRO/jeetbot.cc as its developer and has the following identifiers on the Google Chrome Web Store and Mozilla Firefox Add-Ons store – Chrome –
- Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Databy info@thehackernews.com (The Hacker News) on September 13, 2026 at 10:11 am
Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. The first campaign, per the tech giant, involved sending over a million scam emails between August 3 and 5, 2026, by masquerading as chief executive officers
- CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEVby info@thehackernews.com (The Hacker News) on September 12, 2026 at 3:54 pm
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. Details of the vulnerabilities are as follows – CVE-2026-42016 (CVSS score: 8.1) – An incorrect authorization
- When the Whole Company Adopts AI: What It Does to Your SOCby info@thehackernews.com (The Hacker News) on September 12, 2026 at 10:24 am
Over the past year, we watched a new class of alert appear in enterprise security operations centers and grow faster than anything else in the stream: alerts that were triggered by AI tools and agents. Not attacks against AI, but the ordinary, everyday footprint of an organization using it, from developers running coding agents and non-technical staff signing consumer AI tools into corporate
- OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Serversby info@thehackernews.com (The Hacker News) on September 12, 2026 at 9:07 am
The “major malicious attack” that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx. On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, disclosed details of a coordinated cyber attack that targeted the package manager for the
- GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosureby info@thehackernews.com (The Hacker News) on September 11, 2026 at 4:30 pm
GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under
- Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacksby info@thehackernews.com (The Hacker News) on September 11, 2026 at 4:15 pm
Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhipu), and MiniMax. Knowledge distillation by itself is a legitimate training method. It refers to a machine learning technique where a large, powerful AI model assumes the role of a “teacher” to
- Claude Used to Automate Exploitation and Data Theft Across Multiple Victimsby info@thehackernews.com (The Hacker News) on September 11, 2026 at 2:29 pm
Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and August 2026. The threat actors, which the artificial intelligence (AI) company has branded Generative Threat Groups (GTGs), span state-sponsored groups, financially motivated criminals, commercial
- Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detectionby info@thehackernews.com (The Hacker News) on September 11, 2026 at 2:10 pm
Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve. The operation has been attributed to a cyber espionage group it calls GTG-20006 (where “GTG” stands for Generative Threat Group), which aligns with broader reporting linking the cluster to Midnight






























