The Hacker News
548 articles tracked since Apr 8 · 13:50 UTC. 19 in the last 7 days, 91 in the last 30.
Top coverage areas
Most-mentioned entities
Aggregated across the most recent 200 articles from The Hacker News.
Recent articles
- 16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
Cybersecurity researchers flagged a new typosquatting campaign targeting RubyGems users using a Windows-based information stealer. This campaign steals browser credentials and crypto wallets. OpenSourceMalware discovered the threat, which is currently being tracked under the moniker StubMaker.
- One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025
A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year. According to research published by agent security platform Reco, this activity was named the City Forum campaign and traces back to server 158.220.87.79.
- SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers
SafePal disclosed that an authorization flaw in an order-tracking plug-in exposed personal data belonging to approximately 39,798 customers. The exposed information included names, email addresses, shipping addresses, phone numbers, and purchase details. Affected customers were individually notified via email on August 16.
- CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical flaw affecting Ray to its Known Exploited Vulnerabilities catalog due to evidence of active exploitation. This vulnerability can potentially trigger a browser-based RCE. Ray is described as an open-source, Python-native distributed computing framework used for scaling AI and machine learning workloads.
- Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies
Cybersecurity researchers flagged a previously undocumented Linux botnet family called Evooo1Bot. This malware derives its core functionality from the Mirai botnet source code and can turn internet-facing devices into SOCKS proxies. Although it reuses the DDoS engine, the botnet extends the original framework with numerous capabilities.
- Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
Threat actors are exploiting a newly disclosed Microsoft SharePoint vulnerability, CVE-2026-55040 (CVSS score: 9.1), after the release of a public proof-of-concept code. This critical flaw involves weak authentication and was patched by Microsoft during its July 2026 Patch Tuesday updates.
- Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws
Adobe released updates addressing multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic. The patches cover flaws including a CVSS 10.0 command injection vulnerability in ColdFusion. These issues could allow for arbitrary code execution and privilege escalation.
- Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
Threat actors have begun exploiting a critical security flaw in Broadcom VMware vCenter, according to findings from QUIRSO. The vulnerability, identified as CVE-2026-59310, is a directory-traversal flaw that allows malicious actors with network access to execute arbitrary code.
- Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
Two malicious LiteLLM releases were found on PyPI for about 40 minutes, containing code designed to steal credentials such as cloud keys, SSH keys, and database passwords from installed systems. A threat intelligence firm, CloudSEK, obtained a dataset built from approximately 434,000 captured files, which maps potential exposure to over 2,100 organizations.
- SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code
SAP has released patches addressing a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter). This vulnerability, designated CVE-2026-58231 and rated 10.0 on the CVSS scoring system, allows unauthenticated attackers to execute arbitrary code through insufficient authorization checks and input validation.
- ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access
Security researcher Chaotic Eclipse released a proof-of-concept (PoC) detailing ShieldBreak, a new Microsoft zero-day vulnerability. This weakness is rooted in Microsoft Defender for Windows and demonstrates a patch bypass capability. The exploit targets CVE-2026-50656, which has a CVSS score of 7.8 and is also known as RoguePlanet.
- Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS
Cisco warned that a high-severity vulnerability impacting ASA Software and FTD Software has been exploited in the wild. The flaw, tracked as CVE-2026-20349, involves insufficient error checking when processing HTTP requests that could allow an unauthenticated, remote attacker to trigger a Remote DoS.
- A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices
A malicious SIM card has the capability to force a connected device to run commands chosen by an attacker. This vulnerability affects cellular modules in devices such as electric-vehicle chargers, industrial routers, and car telematics units. Researchers at the University of Birmingham and Fuzzware tested 26 phones and cellular modules for this threat.
- Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo
Mozilla has scrapped the cryptographic signing key used for Firefox and Thunderbird downloads on Linux. This action was necessary after an unencrypted copy of the key was mistakenly committed to one of the company's private code repositories. Previously, this key allowed users and Linux distributions to confirm that downloaded Firefox tarballs originated from Mozilla and were untampered with.
- Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers
Security researchers created a cryptocurrency startup and hired three suspected North Korean IT workers as part of their investigation. The company's virtual machines were recording every action, and one hire claimed to live in Pasadena, Texas, while providing credentials from California and New York.
- Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11
Researchers discovered a vulnerability where Windows Plug and Play can be abused to execute privileged installation components on fully updated Windows 11 machines, leading to SYSTEM access. This exploit path can also be triggered remotely over Remote Desktop if supported Plug and Play or low-level USB redirection is active.
- Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
Malicious MCP Servers connected to an AI coding assistant pose a threat by allowing data exfiltration without requiring one obviously harmful instruction. The attack targets sensitive information, including SSH keys, source code, environment secrets, and customer data. To bypass defenses, the malicious tool splits requests into fragments that appear routine and places them in channels already used by the assistant.
- Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine
Hackers breached a Polish combined heat and power plant by entering its private cellular network used for remote equipment access. The intruders shut down a steam turbine and the process-water treatment system, but recovery started before customers lost heat.
- BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
A supply chain compromise impacted WordPress plugin vendor BdThemes, leading the CMS platform's plugins team to temporarily disable their downloads. Cybersecurity researchers issued warnings regarding this issue. However, they noted that zero source code files were modified within the official WordPress.org repository.
- Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
Cybersecurity researchers flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro ("solidity-pro"). This extension was observed delivering a browser wallet and credential stealer. The specific extensions identified as malicious include helper-beeps.solidity-pro and web3devtoolsx.solidity-pro.
The Nexus tracks 230+ news outlets plus 48 government data feeds. View the full source index or read today’s briefing for synthesis across all of them.