Live

Intelligence Feed

Latest threat intelligence articles from trusted security sources, auto-processed to extract entities, IoCs, and TTPs.

Filtered by source: hacker-news Clear filter
⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More

2w ago · hacker-news

Multiple active threats were reported this week, including exploitation of critical vulnerabilities in VMware, Apple macOS, and GeoServer, as well as ongoing campaigns by state-linked actors. A suspected China-nexus APT exploited CVE-2026-59310 in VMware vCenter to deploy Babuk-derived ransomware, likely as a forensic distraction. The Lazarus Group leveraged a Windows zero-day (CVE-2026-68820) in a campaign dubbed Operation Dream Job, targeting aerospace and defense sectors. GeoServer faced active exploitation of a critical SQL injection flaw prior to patching. Additionally, new macOS malware Amnesia Stealer enables real-time browser hijacking via Chrome DevTools Protocol, stealing authenticated sessions and sensitive data.

1 Actors 1 Malware
Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers

2w ago · hacker-news

SpecterOps has detailed a post-exploitation technique leveraging the Chrome DevTools Protocol (CDP) to hijack authenticated browser sessions in live Google Chrome or Microsoft Edge processes on Windows. The technique requires prior code execution and manipulates the running browser process to enable remote debugging via a Beacon Object File (BOF), allowing attackers to extract cookies, saved passwords, browsing history, and perform browser takeover. The method bypasses protections like App-Bound Encryption by operating within the victim's existing browser context, and relies on process injection into chrome.exe or msedge.exe, detectable via Sysmon Event IDs 8 and 10.

3 IoCs
Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth

2w ago · hacker-news

The threat actor Mustang Panda, also known as HoneyMyte, has updated its CoolClient backdoor with a signed Windows kernel-mode rootkit to enhance stealth. The rootkit, deployed as msagent.sys, is digitally signed with a certificate from Nanjing Ranyi Technology Co., Ltd. and enables hiding of malicious processes, files, registry entries, and C2 network activity. The malware is typically deployed after initial compromise via PlugX and uses DLL sideloading through a legitimate Sangfor executable to execute malicious components and establish persistence.

10 IoCs 1 Actors 2 Malware
Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware

2w ago · hacker-news

Threat actor Sable Squirrel has spent nearly $7 million acquiring expired domains to exploit their inherited reputation, traffic, and backlinks for illegal sports streaming, online gambling promotion, and malware distribution. The group operates a dual-purpose infrastructure where re-registered domains serve both as streaming platforms and command-and-control (C2) servers for malware such as Quasar RAT and HiddenTear ransomware. The operation targets users in Asia and Australia through social media and ad networks, using a traffic distribution system to redirect victims while evading detection. Additional scavenger actors like Stuffy Squirrel, Shady Squirrel, and Swiping Squirrel are also abusing expired domains for ad fraud, tech support scams, and traffic resale.

7 IoCs 6 Malware
Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner

2w ago · hacker-news

A critical authentication vulnerability in Apple macOS Screen Sharing, tracked as CVE-2026-65400 (CVSS 9.8), is under active exploitation to deploy Monero cryptominers on internet-exposed Mac systems. The flaw allows unauthorized remote authentication to the Screen Sharing service without valid credentials, enabling attackers to gain root access and install malware. The Netherlands NCSC reported confirmed attacks where systems with port 5900 exposed were compromised. Apple has released emergency patches in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. A separate but related pre-authentication flaw in the same component was also patched, both residing in the same codebase and exploitable with minimal effort.

1 Malware
SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch

2w ago · hacker-news

A critical vulnerability in SAP Commerce Cloud, tracked as CVE-2026-58231 and rated 10.0 on the CVSS scale, is being actively exploited just days after the patch was released. The flaw stems from insufficient authorization checks and input validation, allowing unauthenticated attackers to execute arbitrary code and compromise internal components. Exploitation attempts were detected by Defused Cyber on honeypot systems three days post-patch, despite the absence of a public proof-of-concept. SAP customers are urged to patch immediately or apply IP filtering as a temporary mitigation.

Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware

2w ago · hacker-news

A suspected China-nexus advanced persistent threat (APT) has exploited CVE-2026-59310, a critical directory traversal vulnerability in VMware vCenter, to gain remote code execution and deploy a Babuk-derived ransomware. The attackers used the flaw to execute arbitrary code as root, deploy backdoors such as 'linuxFile', establish persistence via cron and systemd, and create malicious accounts. The campaign targeted 361 unique IP addresses across 47 countries, with evidence of operational patterns aligned with the UTC+08:00 timezone and use of Chinese-language tools and artifacts.

12 IoCs
Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

2w ago · hacker-news

Security researchers at SSD Secure Disclosure disclosed a two-stage exploit chain that enables full Android kernel access on devices using Unisoc modem firmware via a VoLTE video call. The chain begins with a remote code execution vulnerability in the modem firmware (disclosed in March 2026), followed by a privilege escalation exploit that leverages improper isolation of shared resources (CWE-1189) to gain kernel-level access. The attacker must control a private 4G network and trick the victim into answering a video call. No CVE has been assigned, and no patch is available from Unisoc or device manufacturers. The vulnerability affects multiple Unisoc chipsets used in Motorola, Realme, and Xiaomi devices.

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

2w ago · hacker-news

Threat actors are actively exploiting a critical authentication bypass vulnerability in Microsoft SharePoint, tracked as CVE-2026-55040 (CVSS score: 9.1), following the public release of a proof-of-concept (PoC) exploit by Rapid7. The flaw allows unauthenticated attackers to forge JWT tokens and impersonate SharePoint users by exploiting weaknesses in the JWT validation pipeline, specifically within SPJsonWebSecurityTokenHandlerV2 and SPJsonWebSecurityBaseTokenHandlerV2 classes. Exploitation enables unauthorized access to files and data modification on vulnerable servers. Telemetry shows a spike in exploitation attempts originating from multiple countries, with 12 observed attempts as of mid-August 2026, eight of which occurred immediately after the PoC release.

8 IoCs
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

3w ago · hacker-news

The North Korean threat actor Lazarus Group has exploited a Windows zero-day vulnerability, CVE-2026-68820, in the AFD.sys driver to escalate privileges to SYSTEM and deploy a new in-memory backdoor named Troy. The attack is part of Operation Dream Job, a long-running cyber espionage campaign using fake job offers on LinkedIn to lure victims into downloading trojanized software or opening malicious PDFs. Two infection chains were observed: one using DLL side-loading with the malicious libmupdf.dll and another via a trojanized SecurityPDF viewer that triggers payload execution upon detecting a specific marker in a PDF. The attackers also use compromised legitimate infrastructure, including WordPress, SharePoint, and vulnerable Roundcube servers (CVE-2025-49113), to host C2 communications and distribute the ForestTiger (ScoringMathTea) backdoor.

7 IoCs 1 Actors 4 Malware 1 CVEs
737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One

3w ago · hacker-news

A large-scale campaign involving 737 malicious Chrome VPN and proxy extensions has been uncovered, primarily targeting Russian-speaking users. These extensions impersonate 66 legitimate VPN brands and route users' entire browser traffic through SOCKS5 proxies controlled by a single threat actor, enabling adversary-in-the-middle (AitM) monitoring of destinations, IP addresses, SNI values, and unencrypted HTTP traffic. The extensions bypass Chrome Web Store policies by submitting false claims, using code obfuscation, and performing post-approval code substitution to hide malicious behavior, including non-existent premium tiers and affiliate monetization schemes.

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

3w ago · hacker-news

A high-severity vulnerability, CVE-2026-20349, in Cisco Secure Firewall ASA and FTD software is being actively exploited in the wild to trigger remote denial-of-service (DoS) conditions. The flaw stems from insufficient error checking when processing crafted HTTP requests sent to the Remote Access SSL VPN service, allowing unauthenticated attackers to cause affected devices to reload. Cisco confirms the vulnerability was discovered internally and has been exploited, with no workarounds available. The U.S. CISA has added the flaw to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch by August 14, 2026.

33 IoCs
Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

3w ago · hacker-news

Threat actors are actively exploiting CVE-2026-59310, a critical directory traversal vulnerability in VMware vCenter, to achieve remote code execution and establish persistence via malicious cron jobs. The attackers deploy reverse_ssh, an open-source tool, to create reverse SSH connections to their infrastructure, enabling them to bypass inbound security controls. Forensic evidence from QUIRSO confirms successful compromises beginning August 3, with 361 victim IPs across 47 countries. While the specific actor is not identified, the campaign exhibits characteristics consistent with an advanced persistent threat, and exploitation closely follows public disclosure of the vulnerability.

2 IoCs 1 Actors 1 Malware
Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

3w ago · hacker-news

Adobe has released security updates to address multiple critical vulnerabilities in ColdFusion, Commerce, and Campaign Classic. The most severe flaws include three with a CVSS score of 10.0, which could allow arbitrary code execution or privilege escalation if exploited. These vulnerabilities affect on-premise and hybrid deployments of Campaign Classic, while Adobe-hosted instances have already been patched. Although no active exploitation has been observed, Adobe assigns a Priority 1 rating to these updates due to their high risk, urging administrators to apply patches within 72 hours.

OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning

3w ago · hacker-news

A vulnerability in reasoning APIs used by OpenAI, Anthropic, and Google allowed attackers to recover hidden internal reasoning and sensitive data such as API keys, passwords, and private keys from encrypted reasoning blocks. The flaw enabled cross-session and cross-model replay attacks, where encrypted reasoning objects from one session could be replayed in another, even using weaker models as 'fuzzy decoders' to extract secrets. Researchers analyzed 6,708 public agent trajectories and recovered 704 distinct privacy artifacts, including 62 API keys and 33 passwords, primarily from unsanitized published logs. While vendors have implemented mitigations, the research highlights ongoing risks from already-published reasoning blocks and the potential for invisible prompt injection attacks.

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

3w ago · hacker-news

Malicious versions 1.82.7 and 1.82.8 of the open-source LiteLLM package were uploaded to PyPI on March 24, 2026, and remained available for approximately 40 minutes before being quarantined. These compromised releases contained a credential-stealing payload that collected environment variables, SSH keys, cloud credentials, Kubernetes tokens, and database passwords, exfiltrating them to the domain models.litellm[.]cloud. The incident is part of the broader TeamPCP supply-chain campaign, linked to the earlier compromise of Aqua Security's Trivy scanner, which allowed attackers to gain access to PyPI publishing tokens. The attack potentially exposed over 2,100 organizations, with stolen data including sensitive CI/CD secrets that remain exploitable if not rotated.

6 IoCs 1 CVEs
ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access

3w ago · hacker-news

Security researcher Chaotic Eclipse has released a proof-of-concept (PoC) exploit called ShieldBreak, which demonstrates a full patch bypass for CVE-2026-50656 (RoguePlanet), a previously patched Microsoft Defender for Windows vulnerability. The original flaw was a race condition in the Microsoft Malware Protection Engine (mpengine.dll) that could allow privilege escalation to SYSTEM-level access. ShieldBreak allegedly achieves 100% success in bypassing the fix on Windows 11 25H2 and Windows Server 2025, indicating the patch was incomplete. Microsoft is investigating follow-up reports of data leakage during file operations, and the vulnerability remains exploitable despite prior remediation efforts.

SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

3w ago · hacker-news

SAP has patched a critical vulnerability, CVE-2026-58231, in SAP Commerce Cloud (Data Hub Adapter) that allows unauthenticated attackers to execute arbitrary code due to insufficient authorization checks and input validation. The flaw enables exploitation by abusing a default authentication client and submitting crafted input, leading to compromise of internal components with high impact on confidentiality, integrity, and availability. SAP recommends applying the patch and re-deploying the updated version, or implementing an IP Filter Set as a temporary mitigation. Three additional critical vulnerabilities were also addressed in the same update, including code injection and memory corruption flaws in other SAP products.

DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt

3w ago · hacker-news

The DeadLock ransomware group has adopted a resilient, decentralized infrastructure leveraging Polygon blockchain smart contracts to manage victim communications and data leak operations, making takedown efforts more difficult. The ransomware encrypts files with the '.dlock' extension, uses hybrid encryption (Curve25519 and XChaCha20), and drops an HTML-based interactive recovery note (RECOVERY_CHAT.<UID>.html) that enables end-to-end encrypted chat and access to a blockchain-hosted data leak blog. The HTML note retrieves proxy server addresses via JavaScript interacting with Polygon smart contracts, allowing for censorship-resistant communication. The attackers also use geofencing to avoid certain regions, employ resource throttling, erase logs, and leverage AnyDesk for remote access.

4 IoCs 2 Malware
Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client

3w ago · hacker-news

Zoom addressed three critical vulnerabilities in its annotation feature that could allow a meeting participant to hijack another attendee's client without any user interaction. The flaws include a buffer overflow (CVE-2026-53413), a buffer over-read (CVE-2026-53414), and a use-after-free (CVE-2026-53415), all of which could be exploited remotely in a zero-click scenario. The vulnerabilities affect multiple Zoom clients and were patched in versions released in June and July 2026, though no exploitation has been observed in the wild. The research was conducted by A Security, which demonstrated rapid exploit development using publicly available AI models.

Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

3w ago · hacker-news

Palo Alto Networks Unit 42 discovered a new version of the Kimwolf/AISURU Android and IoT botnet, dubbed Kimwolf v7, in February 2026. This version enhances operational resilience by using HTTP/2-based DDoS floods that mimic legitimate browsing through complete browser fingerprints, making detection more difficult. It employs a tiered C2 infrastructure leveraging Ethereum Name Service (ENS), a hard-coded Tor .onion address, and a local proxy for traffic routing, while offloading initial access to external loaders and focusing on DDoS and proxy relay functions.

3 IoCs 1 Malware
Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

3w ago · hacker-news

Microsoft's August 2026 security update addresses 398 vulnerabilities, including CVE-2026-68820, a Windows kernel driver zero-day under active exploitation for privilege escalation. The flaw exists in afd.sys and allows attackers with initial code execution to escalate to SYSTEM privileges. Check Point Research attributes the exploitation to the Lazarus Group in their 'Operation Dream Job' campaign. Four additional critical unauthenticated remote code execution flaws in Windows DNS Server, Windows Deployment Services, Microsoft QUIC, and HPC Pack are also patched but were not under active attack at release. The update also completes a SharePoint exploit chain by fixing CVE-2026-63520, the RCE component that, when combined with July's authentication bypass (CVE-2026-55040), enabled unauthenticated RCE.

1 Actors
Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

3w ago · hacker-news

Researchers at Rapid7 discovered an exploit chain enabling unauthenticated remote code execution (RCE) on on-premises Microsoft SharePoint servers. The chain begins with CVE-2026-55040, a vulnerability in SharePoint's JWT validation pipeline that allows an unauthenticated attacker to impersonate any user given their SID or UPN. This is combined with CVE-2026-63520, an unsafe .NET type instantiation in Business Connectivity Services, to achieve RCE as the server's Windows service account. The attack affects SharePoint Server Subscription Edition, 2019, and 2016, as well as Project Server 2013 SP1 and Office Web Apps 2013 SP1. The July 2026 updates reportedly break the exploit chain, though the August patch containing the fix had not yet been publicly released at the time of disclosure.

Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands

3w ago · hacker-news

Russian nation-state threat actor UAC-0145, linked to Sandworm (APT44), is conducting a social engineering campaign targeting Ukrainian IT workers through fake job interviews. The attackers pose as recruiters from legitimate IT companies and lure victims into installing a malicious custom VPN client called SopraVPN, hosted on SourceForge. The backdoored WireGuard-based client allows attackers to execute arbitrary PowerShell commands on compromised systems by decrypting malicious scripts using modified configuration files. The malware also establishes persistence via scheduled tasks on Windows or cURL downloads on Linux to retrieve secondary payloads.

4 IoCs 1 Actors
Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks

3w ago · hacker-news

Gunra ransomware, a Conti-derived operation, has been actively targeting critical infrastructure sectors globally, including healthcare, financial services, and government facilities. The group exploits known vulnerabilities in Fortinet (CVE-2025-24472) and Schneider Electric (CVE-2024-5559) devices to gain initial access, then uses Impacket tools for lateral movement and credential dumping. Gunra employs a double extortion model, exfiltrating data before encryption, and has listed 51 victims on its leak site since April 2025, primarily in South Korea, Brazil, and Europe. The group has ties to affiliate programs, uses WhatsApp for negotiations, and has demonstrated advanced capabilities such as MFA bypass and session hijacking via SSL-VPN manipulation.

3 IoCs 3 Actors 3 Malware
A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices

3w ago · hacker-news

Researchers from the University of Birmingham and Fuzzware discovered that malicious SIM cards can exploit the RUN AT proactive command to execute attacker-controlled code on vulnerable cellular IoT devices. The attack affects devices using certain Quectel modules and select smartphones like the OPPO Reno 14 F 5G and ASUS Zenfone 9, all running Qualcomm communication processors. By issuing AT commands through a hostile SIM, attackers can achieve code execution, downgrade network connections to insecure 2G, or exfiltrate files via TFTP and SMTP. A specific vulnerability in the Quectel EC25AFXDGA module's atfwd_daemon enables remote code execution due to an unsafe format string and insufficient character filtering. The issue has been disclosed to vendors, but no public advisories or patches are widely available yet.

2 IoCs
Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11

3w ago · hacker-news

Researchers Alejandro Hernando and Borja Martinez demonstrated a privilege escalation technique called 'Plug And Pwn' that abuses Windows Plug and Play (PnP) auto-install functionality to achieve SYSTEM-level code execution on fully updated Windows 11 systems. The attack chain involves emulating a Sierra Wireless USB device to trigger installation of SwiService.exe, a SYSTEM service used to manipulate DNS settings, followed by emulating a Sony FeliCa reader that downloads configuration over HTTP, enabling a path-traversal vulnerability to drop a malicious DLL into System32. Reconnecting the Sierra device loads the DLL via a privileged service, resulting in SYSTEM compromise. A remote variant using RDP with USB redirection enabled abuses a similar path via Intel RealSense software and a CRYPTBASE.dll search-order hijacking from a user-writable directory.

3 IoCs
Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine

3w ago · hacker-news

In December 2025, attackers breached a Polish combined heat and power (CHP) plant by exploiting a private cellular network (APN) used by the grid operator. The intrusion originated from a compromised wind farm's FortiGate firewall, which had internet-exposed VPN services without multi-factor authentication. From there, attackers pivoted via SSH tunneling through a Teltonika RUTX50 router to access a WAGO PFC200 controller with default credentials, ultimately gaining control of Siemens PLCs and shutting down critical systems including a steam turbine and water treatment. No malware was used; destructive actions were carried out using legitimate device functions. The attack highlights risks in misconfigured private APNs and poor credential hygiene in operational technology environments.

BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

3w ago · hacker-news

A supply chain attack on WordPress plugins distributed by BdThemes exploited a cross-site scripting (XSS) vulnerability in a remote JSON data stream used by the 'Biggopti' component. Attackers compromised a DigitalOcean Spaces bucket to inject malicious JavaScript payloads that execute in the browser of logged-in administrators, creating rogue admin accounts and deploying a PHP web shell. The attack does not modify plugin source code but instead poisons JSON responses, enabling silent exploitation on every wp-admin page load. Two payloads were identified: one retrieves targeting instructions from a C2 server, while the other generates deterministic credentials based on the victim's hostname, allowing attackers to access compromised sites without centralized credential storage.

4 IoCs
⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors

3w ago · hacker-news

A zero-day vulnerability in Metabase, a business intelligence platform, is being exploited in the wild, allowing unauthenticated remote attackers to perform SQL injection and gain full administrator access to affected instances. This enables attackers to steal database credentials, exfiltrate data, and modify configurations. The vulnerability has a CVSS score of 10.0 but lacks a CVE identifier. One confirmed victim is Framework. Additionally, Chinese-made Zbtlink routers were found shipping with a factory-installed backdoor that phones home to Chinese C2 servers every 35 seconds, affecting at least 20 models. The backdoor enables remote command execution. Separately, the threat actor UNC6671 is conducting vishing attacks against financial firms, using voice phishing to capture credentials and MFA tokens via adversary-in-the-middle infrastructure, then deploying scripts for data exfiltration from cloud environments.

2 IoCs 1 Actors
← Previous Next →