The RSS Reader
Choose your news feed
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
Growing Up The Hard Way
Open Source had a great childhood.For two decades it got to be a kid.
It ran around barefoot, gave everything away, trusted strangers, and
never once thought about who was watching. It ran the kind of lemonade
stand that took IOUs from anyone who wandered up — take what you need,
pay me back whenever, no need to leave a name. It was idyllic. It was
also, in retrospect, a little feral.Then,
https://thehackernews.com/2026/08/growing-up-hard-way.html
18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
A use-after-free bug in Linux's SCTP networking code can be turned
into full root on a host, and Tencent researchers say they used it to
escape a container and reach the machine underneath.The flaw has
existed since 2008. The fix already shipped: stable kernels 7.1.6,
6.18.42, 6.12.101 and 6.6.148, released August 3, close it. Anyone
running an older kernel with SCTP reachable should update.
https://thehackernews.com/2026/08/18-year-old-linux-sctp-flaw-could-let.html
New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables
Security researcher Malcolm Stagg has disclosed a new attack class
called NatJack that manipulates network address translation
(NAT) connection state to hijack active TCP sessions, spoof DNS
responses, expose mapped ports, and exhaust NAT tables.Presented at
Black Hat USA 2026, the research found affected behavior across
independently developed implementations, including Windows and
https://thehackernews.com/2026/08/new-natjack-attacks-hijack-tcp-sessions.html
Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
Cybersecurity researchers have called attention to an active
"widespread email-driven phishing campaign" that employs adversary-in-
the-middle (AitM) techniques to take control of Microsoft 365 accounts
with an aim to identify key personnel involved in financial workflows
and gather related email."The campaign uses residential proxies to
disguise malicious sign-ins as ordinary consumer traffic,
https://thehackernews.com/2026/08/microsoft-365-aitm-phishing-hijacks.html
AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day
PortSwigger says HTTP Terminator, an artificial intelligence
(AI)-assisted research system built by James Kettle, generated and
proved new HTTP desynchronization techniques after exploring 30,000
candidate desync vectors.PortSwigger said a separate human-guided
discovery cascade also exposed a zero-day in Apache Traffic Server.
Kettle said HTTP Terminator tested 30,000 websites where
https://thehackernews.com/2026/08/ai-assisted-http-terminator-finds-novel.html
Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
Entra ID researcher Dirk-jan Mollema demonstrated that malware already
running in a signed-in Windows session can silently use the victim's
Windows Hello for Business key to authenticate to Microsoft Entra
ID.The attacker can then establish longer-term cloud access, register
a device it controls, obtain a Primary Refresh Token (PRT), and add
further authentication methods where tenant policies
https://thehackernews.com/2026/08/malware-can-abuse-windows-hello-for.html
Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
A GitHub issue opened by an account with no repository privileges was
enough to execute code on the CI runners behind Anthropic's and
Google's own coding-agent repositories. On OpenAI's, it was enough to
hijack the next agent run.Novee Security ran the attack against each
vendor's agent in the configuration that the vendor ships by default,
and presented the work at Black Hat USA on August 5.
https://thehackernews.com/2026/08/claude-code-and-gemini-cli-flaws-let.html
TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign
A new analysis has uncovered that the threat actor tracked as TeamPCP
has been active on the cybercrime scene as far back as 2020,
indicating the group has been compromising internet-facing
infrastructure for years before training their sights on the software
supply chain."The connection is supported by overlapping domains,
malware deployment paths, staging techniques, backend infrastructure,
https://thehackernews.com/2026/08/teampcp-linked-to-redis-attacks-dating.html
New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts
Zapscape, a new Linux kernel vulnerability, could allow an attacker
with kernel privileges inside an L1 guest virtual machine (VM) to
escape KVM isolation and execute code on the host. The risk applies
when nested virtualization is exposed to untrusted guests.The flaw is
tracked as CVE-2026-64561 and affects KVM/x86's shadow
memory management unit (MMU), which manages shadow page
https://thehackernews.com/2026/08/new-zapscape-kvm-flaw-could-let.html
Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.9 CVSS Score Bugs
Cisco has rolled out updates to address multiple critical security
vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part
of a comprehensive internal security review.The security issues affect
Cisco Catalyst SD-WAN Software, regardless of device configuration,
and Cisco IOS XE Software when it is running in autonomous or
controller mode."These vulnerabilities were found
https://thehackernews.com/2026/08/cisco-patches-12-sd-wan-and-ios-xe.html
New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs
An unprivileged Linux program can time a hardware interrupt to land in
the gap between a processor sanitizing its branch predictor and the
kernel using it, re-poisoning the predictor after the defense has
run.MIT CSAIL researchers Daniël Trujillo and Mengjia Yan named the
technique INTERRUPT INJECTION. On an AMD Zen 2 machine running Linux
6.14 with every default Spectre v2 mitigation on,
https://thehackernews.com/2026/08/new-interrupt-injection-attack-can.html
ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories
Apparently, opening the thing is now enough. A repo can run before the
first prompt, a package can hide among hundreds, and a harmless-
looking PDF can finish the job.This week runs on cheap leverage:
exposed servers, recycled bugs, poisoned agent instructions, remote-
access tools dressed as support software, and trusted defaults doing
attackers a favor.Nothing here is especially mystical.
https://thehackernews.com/2026/08/threatsday-odysseus-rce-samsung-one.html
Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities
Forescout found 22 internet-facing Rockwell Automation programmable
logic controllers (PLCs) in cities hit by recent cyberattacks on US
water utilities. Nineteen used the same mobile carrier network.Its
August 3 scan counted 4,407 exposed Rockwell controllers worldwide,
including 2,844 in the United States, but Forescout could not confirm
any were compromised. That figure counts exposed
https://thehackernews.com/2026/08/over-4400-rockwell-plcs-exposed-online.html
CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps
Coinspect has identified CryptoJS.lib.WordArray.random() as the weak
random number generator behind the Ill Bloom wallet drains.Introduced
in the JavaScript cryptography library 12 years ago, the function
supplied weak entropy that affected wallet apps used to generate
recovery phrases. Coinspect's on-chain analysis puts the measured
theft across two sweeps since late May at a lower bound of
https://thehackernews.com/2026/08/cryptojs-weak-rng-behind-57-million-in.html
Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses
Cybersecurity researchers have disclosed a security issue with Apple's
iCloud Private Relay tool that can expose a user's real IP
address.Introduced with iOS 15, iCloud Private Relay employs a dual-
hop architecture to ensure users' privacy by routing their Safari web
traffic through two relays so that no single third-party, including
Apple, can determine where the request is originating from
https://thehackernews.com/2026/08/webkit-proxy-bypasses-can-expose-real.html
AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory
A new class of prompt injection is spreading across commercial
websites. It requires no malware, no stolen credentials, and no zero-
day exploit. It abuses a standard feature built into almost every
major AI assistant: pre-filled deep links.We observed production
websites embedding hidden prompt injection payloads inside "Ask AI"
buttons on marketing and competitor comparison pages. When a user
https://thehackernews.com/2026/08/ai-recommendation-poisoning-how-ask-ai.html
Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access
Attackers broke into an organization's Oracle database through a SQL
injection flaw in a public-facing web application, then installed a
post-exploitation toolkit without writing an executable to disk. They
fed Java source code to the database, let Oracle compile it into
stored schema objects, and ran commands from inside the database
engine.Huntress, which tracks the toolkit as khunt,
https://thehackernews.com/2026/08/attackers-compile-khunt-inside-oracle.html
AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model
Security flaws in agent infrastructure from Amazon Web Services (AWS),
Google, and Vercel let untrusted or forged instructions reach an
agent's tools with no check that a model turn had authorized them.In
several of the attack paths, the model never ran at all, so system
prompts, content filters, and model-level guardrails never got a
chance to intervene.The affected products include Amazon
https://thehackernews.com/2026/08/aws-google-and-vercel-patch-agent-flaws.html
Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells
Cybersecurity researchers have disclosed details of a "factory-shipped
backdoor" implanted in at least 20 Chinese router models from
Zbtlink.According to a new report from VulnCheck, the implant appears
in all 21 firmware images currently available from Zbtlink that span
more than 2 years. The backdoors are designed such that they start
automatically and attempt to beacon to Chinese
https://thehackernews.com/2026/08/chinese-made-zbtlink-routers-ship-with.html
Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service
A federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to
16 years in prison on August 5 for creating and running Ransom Cartel,
the ransomware-as-a-service operation he stood up in 2021.Between 2021
and 2023, Ransom Cartel conspirators attacked at least 18 companies,
including firms in California, New York and Nebraska, and others
abroad, according to the Justice Department.
https://thehackernews.com/2026/08/ransom-cartel-creator-gets-16-years-in.html
CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild
A newly patched security flaw impacting on-premise versions of
JetBrains TeamCity has come under active exploitation in the wild,
according to the U.S. Cybersecurity and Infrastructure Security Agency
(CISA).The vulnerability in question is CVE-2026-63077 (CVSS score:
9.8), a case of deserialization of untrusted data that could allow an
unauthenticated attacker with access to a TeamCity server
https://thehackernews.com/2026/08/cisa-flags-teamcity-cve-2026-63077-rce.html
Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People
Connor Riley Moucka pleaded guilty in Seattle federal court on
Wednesday to computer fraud, wire fraud, aggravated identity theft and
a related conspiracy over the 2024 breaches of Snowflake customer
accounts.The intrusions reached at least 165 organizations and exposed
records belonging to at least 100 million people. Moucka, 26, of
Kitchener, Ontario, personally took at least $495,000 from
https://thehackernews.com/2026/08/snowflake-hacker-pleads-guilty-over.html
Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures
A macOS ClickFix operation spanning more than 250 front-end domains
now fingerprints visitors before deciding whether to show them a
malware lure, a change Microsoft Threat Intelligence tracked on
infrastructure it had been watching for weeks.The server-side gate
hides the malicious page from crawlers and sandboxes while presenting
selected Mac users with a fake software download. Microsoft
https://thehackernews.com/2026/08/over-250-clickfix-domains-use-browser.html
OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes
OpenAI said it disrupted a Cambodia-based scam operation that used its
generative artificial intelligence (AI) chatbot ChatGPT to facilitate
a wide range of investment, romance, gambling, and law enforcement
impersonation schemes.To that end, it banned a coordinated network of
ChatGPT accounts likely originating from Southeast Asia and operating
from the city of Poipet, a region with extensive
https://thehackernews.com/2026/08/openai-disrupts-poipet-scam-network.html