Register and share your invite link to earn from video plays and referrals.

The Hacker News
@TheHackersNews
The #1# trusted source for cybersecurity news, insights, and analysis — built for defenders and trusted by decision-makers.
2K Following    2.4M Followers
🚨 Kiteworks tells customers to shut systems down for nine hours after federal intelligence warned that a threat actor may target some of its systems. The company says it has found no evidence of compromise and recommends upgrading to version 9.5.1. Read:
Show more
‼️ Mini Shai-Hulud came back without a new attacker update. Two compromised GitHub Actions became reachable again while their tags still pointed to malicious commits, letting downstream workflows resume executing the credential stealer. 🔗 Here's how the attack reactivated:
Show more
PamStealer now needs its C2 server to unlock the macOS payload. The new variant uses an X25519 key exchange, a fake Wavel wallet lure, and redundant persistence, including global Git hooks. Read:
Show more
AI can turn a failed privilege-escalation attempt into another test within minutes. Attackers get faster troubleshooting and script fixes. SOC teams still lose evidence, confidence, and context across handoffs, forcing analysts to rebuild the same incident. That speed gap is the real problem →
Show more
Bitget says suspected North Korean hackers stole $351.6 million after compromising a backend wallet system. The attackers spoofed transaction data and triggered Bitget’s authorization process to move funds. Withdrawals are temporarily suspended while the breach is investigated. What Bitget says happened:
Show more
🚨 Attackers are exploiting a Roundcube pre-auth SQL injection flaw patched in May. CVE-2026-48842 can expose mail credentials and stored messages through the virtuser_query plugin. Read:
Show more
‼️ Next.js patched a critical ImageResponse flaw that can lead to server code execution. "CVE-2026-94545" affects 16.2.0 through 16.3.5 on Node.js when attacker-controlled values reach generated SVG. The fix is 16.3.6. Inside the bug:
Show more
‼️ Two chained SSH flaws gave attackers full admin on MikroTik routers — one of them using -2 as a username. No password. No SSH key. No authentication at all. CERT Polska says it was exploited before patches shipped. Learn how it works ↓
Show more
0
16
551
147
Forward to community
‼️ You can commit code to a GitLab repo by emailing it. Every GitLab user gets a private address for filing issues. Hidden inside is a non-expiring account token. If that address leaks, someone can send a patch that GitLab commits as you and, with your permissions, target main or trigger CI/CD. Incoming email also bypasses 2FA and IP restrictions. Read:
Show more
WSO2 and Adobe Commerce flaws are being exploited in attacks. The WSO2 bug can lead to remote code execution through unrestricted file upload. The Adobe flaw can switch a customer session to another account. CISA has added both to KEV, with federal agencies given until Sept. 27 to patch. What attackers can exploit:
Show more
‼️ OnePlus confirmed a stock phone could be rooted by an installed app. Then it warned the researcher not to publish. The app needs no special permissions. OnePlus confirmed the two flaws in May, but no fix was available when the researcher disclosed them. No real-world exploitation is known. How the root chain works →
Show more
‼️ The attacks worth watching this week barely look like attacks. >> A search result >> A coding tool >> A software update >> One normal-looking link Behind them: AI search poisoning, leaked source code, malicious updates, supply-chain attacks, EDR evasion, and one-click code execution. 16 stories in this week’s ThreatsDay:
Show more
‼️third-party[.]com is now serving Windows users a ClickFix lure disguised as a Cloudflare check. The domain is referenced as a placeholder across 1,700+ repositories. The lure copies a PowerShell command to the clipboard, while non-Windows visitors see a decoy. 🔗 here’s how it works →
Show more
⚠️ AI-assisted commits leak secrets at roughly twice the rate of human-written ones. Coding agents can read .env files and MCP configs, while the same credentials may persist across CI/CD, tickets, and collaboration tools. 🔗 How the sprawl happens →
Show more
🚨 Attackers use hacked Ukrainian sites to serve fake Cloudflare CAPTCHAs for Psychedelic Stealer. The ClickFix lure copies an msiexec command and tells users to run it. The stealer targets passwords, tokens, and crypto-wallet data. 🔗 Read →
Show more
Every unpatched CVE is a bet that no one exploits it before you fix it. And for teams stuck on older versions of Java, the odds get worse every year you put off patching. We’re talking 242 new CVEs published daily, up 80% from 2025 👀 If you're stuck on hard-to-upgrade Java versions, pulling a backported version keeps your application secure while you focus on shipping what’s next. Chainguard Libraries for Java now includes CVE remediation, letting you stay safe while you plan your next major upgrade. Learn More →
Show more
Corp MDM spyware steals new SMS and can redirect calls on Android devices. The logistics-focused campaign delivers it through fake Google Play pages. Once sideloaded and granted SMS and phone permissions, the app hides its launcher and sends new inbound texts to attacker infrastructure. How it works:
Show more
Corp MDM spyware steals new SMS and can redirect calls on Android devices. The logistics-focused campaign delivers it through fake Google Play pages. Once sideloaded and granted SMS and phone permissions, the app hides its launcher and sends new inbound texts to attacker infrastructure. How it works:
Show more
Your AI productivity gain has a hidden headcount cost. @ActiveState's new report, The AI Remediation Bill, puts a number on AI's downstream cost: engineers spend a conservative floor of 6.7% of their time fixing or revisiting AI-assisted development, about 139 hours a year, which for a 500-engineer org is nearly 34 full-time engineers. Join the waitlist →
Show more
‼️ You can commit code to a GitLab repo by emailing it. Every GitLab user gets a private address for filing issues. Hidden inside is a non-expiring account token. If that address leaks, someone can send a patch that GitLab commits as you and, with your permissions, target main or trigger CI/CD. Incoming email also bypasses 2FA and IP restrictions. Read:
Show more