The Hacker News
562 articles tracked since Apr 8 · 13:50 UTC. 19 in the last 7 days, 83 in the last 30.
Top coverage areas
Most-mentioned entities
Aggregated across the most recent 200 articles from The Hacker News.
Recent articles
- Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt
While AI coding tools offer upsides such as faster development and more code, they pose challenges for security teams. The rapid introduction of open-source packages via AI can result in managing numerous dependencies. This increases vulnerabilities, leading to a growing backlog and increased remediation work.
- Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
Red Hat and the Keycloak project released patches addressing a critical security flaw in the open-source identity and access management server. This vulnerability, identified as CVE-2026-18963, could allow an unauthenticated remote attacker to take over any user account by forcing a password reset. Red Hat assigned this flaw a 9.1 rating on the CVSS scoring system.
- Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor
Cybersecurity researchers identified Operation QUICSILVER, a cyber espionage campaign targeting Myanmar's government and information technology sectors. This campaign uses graduation ceremony invitation lures to deliver a Go backdoor named QUICAgent. Seqrite Labs assessed that this activity originates from a China-nexus threat actor.
- The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk
A more urgent security threat comes from AI super-adopters who are hardcoding unvetted tools into critical business operations. While enterprise security teams focus on general employee usage of tools like ChatGPT and Claude, new research published by Akamai warns about this specific risk posed by the top 5% of enterprise power users.
- UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
Cybersecurity researchers disclosed details of UAT-10147, a Chinese-speaking cybercrime group that targets Windows and Linux web servers globally. The attacks span multiple sectors including education, media, technology, and gaming. The vast majority of the targeted systems are located in Brazil, Bolivia, China, Canada, and Vietnam.
- GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
A newly disclosed security flaw in GitLab, identified as CVE-2026-19478, is under active exploitation shortly after public disclosure. This vulnerability is a code injection that permits an unauthenticated attacker to modify or delete publicly accessible projects and rewrite their data on GitLab under specific conditions.
- Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution
Microsoft issued a warning about a maximum-severity security flaw in Entra ID, which was reportedly exploited in the wild. The vulnerability, tracked as CVE-2026-69836 and assigned a CVSS score of 10.0, allows for remote code execution impacting Microsoft's cloud-based identity and access management service.
- NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands
Security researchers at Cycode disclosed a chain of flaws in AIT-GUI, the operator console for NASA/JPL's open-source AMMOS Instrument Toolkit. These flaws allow an unauthenticated attacker to issue arbitrary commands to the software’s spacecraft and instrument command bus. The vulnerability was tracked as GHSA-p9r8-2q67-fp86 and rated 9.4 on CVSS v3.1.
- ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud
Cybersecurity researchers identified an updated version of ToxicPanda 2.0, also known as TgToxic, featuring significant enhancements including a set of 167 remote commands and expanded global targeting. The Android malware specifically features a PIN harvesting workflow that targets over 140 banking and cryptocurrency applications.
- Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code
Cybersecurity researchers disclosed a critical flaw in the Elementor Pro WordPress plugin that could allow unauthenticated attackers to upload PHP and execute code. The vulnerability, designated CVE-2026-32475, has a CVSS score of 9.0 out of 10.0 and involves an unrestricted file upload mechanism within the Forms module.
- StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data
Cybersecurity researchers flagged a global cybercrime operation that abuses thousands of hacked WordPress websites. This infrastructure is used to spread malware and steal data, commandeering infected hosts. The criminals store stolen documents, screenshots, and activity logs using an entire toolkit of criminal software.
- Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
CISA added four critical vulnerabilities related to macOS, SharePoint, vCenter, and Microsoft IKE to its Known Exploited Vulnerabilities catalog. CISA stated that these shortcomings are being exploited in the wild. One specific vulnerability noted is CVE-2026-65400, which is an improper authentication flaw impacting Apple macOS.
- Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure
Microsoft Defender Experts linked over 30 web domains to MacSync Stealer, a macOS-focused information stealer. The investigation correlated recurring endpoint and network behaviors across changing infrastructure, allowing tracking of the malware's process from payload retrieval through data collection, staging, and exfiltration.
- Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
New findings revealed a JavaServer Pages (JSP) web shell targeting enterprise Product Lifecycle Management (PLM) software, specifically connected to PTC Windchill and FlexPLM servers. This web shell was deployed after exploiting a critical security flaw and is characterized as an extortion platform capable of mapping sensitive data.
- 16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
Cybersecurity researchers flagged a new typosquatting campaign targeting RubyGems users using a Windows-based information stealer. This campaign steals browser credentials and crypto wallets. OpenSourceMalware discovered the threat, which is currently being tracked under the moniker StubMaker.
- One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025
A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year. According to research published by agent security platform Reco, this activity was named the City Forum campaign and traces back to server 158.220.87.79.
- SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers
SafePal disclosed that an authorization flaw in an order-tracking plug-in exposed personal data belonging to approximately 39,798 customers. The exposed information included names, email addresses, shipping addresses, phone numbers, and purchase details. Affected customers were individually notified via email on August 16.
- CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical flaw affecting Ray to its Known Exploited Vulnerabilities catalog due to evidence of active exploitation. This vulnerability can potentially trigger a browser-based RCE. Ray is described as an open-source, Python-native distributed computing framework used for scaling AI and machine learning workloads.
- Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies
Cybersecurity researchers flagged a previously undocumented Linux botnet family called Evooo1Bot. This malware derives its core functionality from the Mirai botnet source code and can turn internet-facing devices into SOCKS proxies. Although it reuses the DDoS engine, the botnet extends the original framework with numerous capabilities.
- Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
Threat actors are exploiting a newly disclosed Microsoft SharePoint vulnerability, CVE-2026-55040 (CVSS score: 9.1), after the release of a public proof-of-concept code. This critical flaw involves weak authentication and was patched by Microsoft during its July 2026 Patch Tuesday updates.
The Nexus tracks 230+ news outlets plus 48 government data feeds. View the full source index or read today’s briefing for synthesis across all of them.