Cybersecurity News
Global headlines curated by our intelligent agents.
Latest News
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
Trojanized npm packages launch RedC2 4.0 on Linux at import time, giving operators shell access, credential theft, and payload execution.
Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
New malware abuses DoFun Android head unit updaters to deliver JarService, run ad fraud, and download the Zhima reverse proxy module.
Wazuh and AI For Enhanced SOC Workflows
Wazuh AI Analyst uses Amazon Bedrock and Claude to turn Wazuh Cloud security data into scheduled reports with posture and vulnerability insights.
GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
GitLab CVE-2026-19478 is under active exploitation, with unauthenticated attacks able to modify or delete public projects under certain conditions.
Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution
Microsoft says CVE-2026-69836, a CVSS 10.0 Entra ID RCE flaw, has been exploited in the wild but is fully mitigated with no user action required.
Malware Disguised as Leaked GTA 6 Copies Are Popping Up on Piracy Sites
No, despite claims online, there is not a downloadable and playable build of GTA 6 floating around on piracy sites.
Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
Rust deletes malicious releases of three crates after a proc-macro1 build script downloaded and ran a remote payload during compilation.
ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More
ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More | Read more hacking news on The Hacker News cybersecurity news website and learn how to protect against cyberattacks and software vulnerabilities.
AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure
U.S. agencies warn AI-generated exploit scripts target Siemens S7 PLCs, with exposed, outdated devices at risk across critical infrastructure.
Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE
Isolated-vm's ExternalCopy type confusion lets sandboxed code corrupt host memory and potentially reach host RCE; fixes are in 6.2.0 and 7.0.1.
Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers
Citrix fixes NetScaler CVE-2026-19490, a CVSS 9.3 authentication bypass affecting certain Gateway, AAA, and SAML configurations.
Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution
Attackers exploit CVE-2026-73570 on Zimbra servers with zimbra-snmp installed and SNMP notifications enabled, allowing unauthenticated RCE.
CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification
CDN Tsunami abuses HTTP/3-to-HTTP/1.1 translation at six major CDNs to amplify origin traffic up to 350x and exhaust connections.
Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices
Manic Android malware targets 169 apps and can relay collected data through nearby infected devices when the source phone is offline.
ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud
ToxicPanda 2.0 adds 167 remote commands, targets 349 financial institutions, and uses Android accessibility to harvest PINs.
Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code
Elementor Pro CVE-2026-32475 lets unauthenticated attackers bypass file checks and upload PHP for remote code execution.
Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second
Researchers leak a JWT from a co-located Cloudflare Worker via Spectre at up to 12 bits per second; Cloudflare says the attack is mitigated.
ClarityCheck people-finder left millions of face photos exposed, likely without their knowledge
ClarityCheck, a facial-identification tool for which it’s hard to think of many legitimate uses, reportedly left millions of face photos...
It Ends Review
It Ends, the latest indie-horror-thriller-that-could, is both creepy and amusing thanks to its likable cast and filmmaker Alexander Ullom’s ability to exploit minimal resources to maximum effect.
GTA 6 Leak Forces Stop Killing Games Movement to Distance Itself From Hacker Manifesto
The Stop Killing Games movement has distanced itself from the manifesto published by the alleged group behind last night’s GTA 6 leak, and cast doubt on their motivations.
Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P
Researchers say Operation CameraSwarm compromised 14,530+ Dahua devices using credential attacks, auth bypass flaws, and P2P relays.
Phishing 3.0: The Fight Moves to Agent Versus Agent
Attackers run AI agents that research your company, write the lure, and hold conversations. The only defense that keeps pace runs agents of its own.
StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data
StopAndProtect uses close to 2,000 hacked WordPress sites to deliver malware and run C2, compromising 6,000+ unique IP addresses.
Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
CISA adds four critical flaws to KEV after active exploitation, with FCEB agencies ordered to patch by August 21, 2026