The Hacker News

thehackernews.com · EN

Most trusted, widely-read independent cybersecurity news source for everyone; supported by hackers and IT professionals — Send TIPs to admin@thehackernews.com

Latest posts

  1. Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

    · thehackernews.com · info@thehackernews.com (The Hacker News)

    A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus's own software to gain root access, the highest level of control over an Android phone. OnePlus told him…

  2. ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories

    · thehackernews.com · info@thehackernews.com (The Hacker News)

    This week, the dangerous stuff keeps arriving dressed as something boring. An update. A login box. A search answer. A coding tool. A link you have clicked a hundred times before. That is the thread running through the pile. Trusted paths get poisoned. Old bugs find new jobs. AI tools leak more than…

  3. Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content

    · thehackernews.com · info@thehackernews.com (The Hacker News)

    The "third-party[.]com" domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users. "third-party[.]com has been a generic documentation placeholder for years, the same role example.com plays,"…

  4. Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer

    · thehackernews.com · info@thehackernews.com (The Hacker News)

    An active ClickFix campaign has been observed compromising legitimate Ukrainian business websites to inject bogus Cloudflare verification pages and trick victims into downloading a previously undocumented information stealer called Psychedelic. "When a visitor interacts with the page, the lure…

  5. Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls

    · thehackernews.com · info@thehackernews.com (The Hacker News)

    The logistics sector has become the target of a new malicious cyber campaign that distributes an Android spyware codenamed Corp MDM. According to Have I Been Squatted, the campaign uses fake Google Play pages branded as CEVA and TKW Logistics to distribute an Android Package Kit (APK) file that's…

  6. Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore

    · thehackernews.com · info@thehackernews.com (The Hacker News)

    AI coding agents are changing how quickly developers can build and ship software as well as how quickly credentials can become exposed. According to GitGuardian’s 2026 State of Secrets Sprawl Report, commits identified as AI-assisted are leaking secrets at approximately twice the rate of…

  7. 17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360

    · thehackernews.com · info@thehackernews.com (The Hacker News)

    ClickFix has become the most common way attackers get into enterprise networks, and it does it without an exploit, an attachment, or a file on disk. Our new global threat report traces the technique from a novelty in late 2023 to a subscription product with on-chain infrastructure and a…

  8. OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files

    · thehackernews.com · info@thehackernews.com (The Hacker News)

    An AI agent on an internal OpenAI research task bypassed access controls on an Australian government Medicare statistics portal in June, Prime Minister Anthony Albanese said. The portal publishes aggregate figures, such as spending, and is separate from the systems that handle Medicare claims and…

  9. TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords

    · thehackernews.com · info@thehackernews.com (The Hacker News)

    Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts across 28 Microsoft 365 tenants. According to Proofpoint, the activity has primarily focused on Chilean retail and financial institutions. It…

  10. Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

    · thehackernews.com · info@thehackernews.com (The Hacker News)

    Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure. The vulnerability in question is CVE-2026-87902 (CVSS score: 9.2), which could allow an unauthenticated attacker to obtain remote code execution (RCE). "An unauthenticated attacker…

  11. Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

    · thehackernews.com · info@thehackernews.com (The Hacker News)

    Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads. According to Aikido, the list of…

  12. A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You

    · thehackernews.com · info@thehackernews.com (The Hacker News)

    The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start CI/CD jobs that run as you. GitLab shows each user this address behind a button…

  13. MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

    · thehackernews.com · info@thehackernews.com (The Hacker News)

    Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication. The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an…

  14. This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move

    · thehackernews.com · info@thehackernews.com (The Hacker News)

    A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22. The models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data. Talos has not seen this setup…

  15. Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

    · thehackernews.com · info@thehackernews.com (The Hacker News)

    Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS. According to reports from Aikido, SafeDep, Socket, and…

  16. New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control

    · thehackernews.com · info@thehackernews.com (The Hacker News)

    A flaw in cPanel's CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take "full control of the server," the company said on September 22. A second bug in the WP Toolkit plugin, used to install and manage WordPress sites, allows an account holder to change…

  17. 545 Hackers Tested It First. Now XRanges for AI Scores Your Security Agent

    · thehackernews.com · info@thehackernews.com (The Hacker News)

    Autonomous security agents are getting good at finding bugs. Nobody has a good way to measure how good. Point one at a realistic target and what comes back is a report the agent wrote about itself: confident prose, a list of findings, and no way to tell which of them happened. Someone with a…

  18. Anthropic and OpenAI Models Still Attempt Restricted Actions in Safety Tests

    · thehackernews.com · info@thehackernews.com (The Hacker News)

    Anthropic and OpenAI on Tuesday announced new models, with both artificial intelligence (AI) companies noting that they are continuing to invest in improving alignment to combat risky behavior. Opus 5.5, per Anthropic, is a "major step up from Opus 5," and "achieves the best scores of any model to…

  19. Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape

    · thehackernews.com · info@thehackernews.com (The Hacker News)

    A use-after-free in the Linux kernel's AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22. The flaw, tracked as CVE-2026-80521 (CVSS score: 7.8), was fixed upstream on August 6, but Ubuntu has not…

  20. F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

    · thehackernews.com · info@thehackernews.com (The Hacker News)

    Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to applications. F5…

In the directory since 25 Sept 2026 · last checked 25 Sept 2026 · RSS

Report a problem with this feed