From The Hacker News · 40 stories
Microsoft sets new Patch Tuesday record with over 650 security fixes for Windows
Microsoft released over 650 security fixes for Windows in its September Patch Tuesday, setting a new record. This increase in patched vulnerabilities is attributed to new AI models, like Anthropic's Mythos and OpenAI's cybersecurity model, which are discovering software flaws at a rapid pace.
Trezor Discloses ShipMonk Breach Exposed Data of 67,000 U.S. Customers
Hardware wallet manufacturer Trezor announced that 67,000 U.S. customers had their personal data exposed due to a breach at its shipping provider, ShipMonk. This incident is significant because it adds to previously disclosed exposures and highlights the risks associated with third-party data handling, even after assurances of data deletion.
PaperCut warns of active exploitation of zero-day vulnerability in NG and MF software
PaperCut issued an urgent security advisory regarding a zero-day vulnerability in all versions of its PaperCut NG and PaperCut MF print management software, which is actively being exploited in attacks. The company released emergency patches and advised organizations to restrict access to web interfaces of Internet-exposed servers, as this vulnerability poses a significant risk to affected systems.
Russian National Charged in US for Malware Campaign Targeting 80,000 Freelancers
Searzhudin Tamirlanovich Aktulaev, a 40-year-old Russian national, has been extradited to the US and charged with orchestrating a phishing campaign that infected 80,000 freelancers with TVRAT and DarkVNC malware between 2016 and 2017. Aktulaev used 255 fake accounts on an unnamed freelance employment platform to distribute malicious Excel attachments, gaining remote control and stealing data from victims' systems. This case highlights international efforts to prosecute cybercriminals.
Two Berlin State Ministries Disconnected from Government Network Following Security Breach
Two Berlin state ministries, responsible for urban development and mobility, have been isolated from the city government's IT network due to a security breach. This incident has disrupted internal communications and some public services, highlighting vulnerabilities in government IT infrastructure.
Hackers deliver malicious Virtualizor update via BGP hijacking
Hackers used BGP hijacking to redirect traffic for Virtualizor's update infrastructure, delivering malicious updates to a small number of installations. Softaculous, the vendor, released a new Virtualizor version and advised users to check for a malicious service and reset credentials.
Sality P2P Botnet Dismantled After 23 Years of Operation
The Sality peer-to-peer (P2P) botnet, active since 2003, has been disrupted through an international law enforcement effort involving the U.S. Department of Justice, Europol, Eurojust, and private partners like CrowdStrike and the Shadowserver Foundation. The operation, which took place on August 31, 2026, included a P2P sinkhole and domain seizures, effectively neutralizing a long-standing threat that infected over 15,000 devices and distributed various malware, including the EggJagger clipjacking tool.
Grok AI Vulnerable to Data Exfiltration via Encrypted Malicious Instructions
Researchers discovered a new prompt injection attack against Grok that uses encrypted malicious instructions to bypass guardrails and exfiltrate user data. This method exploits the LLM's inability to distinguish between trusted user input and harmful content, allowing it to steal chat data and personal information.
Ransom Cartel Creator Sentenced to 16 Years for Ransomware-as-a-Service Operation
Maksim Silnikau, the 40-year-old Belarusian creator and administrator of the Ransom Cartel ransomware-as-a-service operation, was sentenced to 16 years in prison in Virginia. Silnikau developed the ransomware and recruited affiliates to attack at least 18 companies globally between 2021 and 2023, providing them with tools and infrastructure for intrusions and ransom negotiations.
SafePal data breach exposes order information for 39,798 customers
Cryptocurrency hardware wallet provider SafePal reported a data breach affecting approximately 39,798 customers, exposing names, email addresses, shipping addresses, phone numbers, and purchase information. A threat actor is now claiming to sell this stolen data on a cybercrime forum. This breach could lead to targeted phishing and social engineering attacks against affected customers.
Mozilla Replaces GPG Signing Key for Firefox and Thunderbird After Accidental Exposure
Mozilla has replaced the GPG signing subkey used for Firefox and Thunderbird Linux tarballs, RPM packages, and checksum files. The previous key was inadvertently committed in an unencrypted copy to a private GitHub repository. This change primarily affects users who manually verify GPG signatures or use Firefox RPM packages on older Linux distributions, who will need to import the new key and the old key's revocation.
UNC6671 Extortion Group Rebrands and Continues Vishing Attacks on Financial Firms
The UNC6671 extortion group has rebranded its operations under new names including Redact, Pink, Helix, and Falcon, despite an alleged retirement of its previous BlackFile brand. The group continues to use voice phishing (vishing) to target enterprise employees, particularly in financial services, private equity, and professional services, leading to data theft from cloud environments like Microsoft 365 and Okta.
Over 24,000 Internet-Exposed Servers Leak BMC Password Hashes via Decades-Old Flaw
More than 24,000 internet-exposed servers are leaking authentication password hashes due to CVE-2013-4786, a 20-year-old vulnerability in the Intelligent Platform Management Interface (IPMI) v2.0 specification. This flaw allows remote attackers to obtain password hashes before login and conduct offline password guessing attacks, potentially leading to full control over physical servers and broader management plane compromise.
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
Hackers are redirecting users to fake Microsoft 365 login pages by changing DNS settings on Wi-Fi devices in hotels and conference centers. This campaign, ongoing since June, affects organizations across various sectors by potentially compromising sensitive business information.
Symlink Vulnerability in AI Coding Assistants Poses Security Threat
Researchers discovered that a vulnerability in six AI coding assistants allows malicious repositories to execute code on developers' machines. By exploiting symbolic link (symlink) flaws, attackers could bypass user consent and access sensitive files, raising significant security concerns.
Adobe Acrobat Integration in WhatsApp Web Exposes User Data Through Chrome Extension Vulnerability
Adobe Acrobat tools are now available within WhatsApp Web and Windows app, allowing users to handle PDFs easily. However, a critical vulnerability in the Adobe Acrobat Chrome extension, affecting 329 million users, could enable unauthorized access to WhatsApp Web chats. The flaw has been patched, ensuring data security moving forward.
Researcher Releases Windows Zero-Day Exploit 'LegacyHive' Post-Patch Tuesday
Security researcher Chaotic Eclipse released a zero-day exploit for Windows shortly after Microsoft's Patch Tuesday. The exploit, called LegacyHive, targets the Windows User Profile Service and allows privilege escalation on all supported Windows versions. This revelation underscores ongoing security challenges and may necessitate urgent updates from Microsoft.
Microsoft Patches Windows Defender 'RoguePlanet' Vulnerability CVE-2026-50656
Microsoft has patched the 'RoguePlanet' vulnerability (CVE-2026-50656) affecting Windows Defender on Windows 10 and 11, which allowed SYSTEM privileges escalation. The vulnerability was disclosed by researcher Nightmare Eclipse, and a month later Microsoft released the patch in Malware Protection Engine update version 1.1.26060.3008. The flaw's potential use in privilege escalation makes its resolution important for system security.
Google and FBI Disrupt NetNut Proxy Network of 2 Million Devices
Google, the FBI, Lumen, and others disrupted the NetNut residential proxy network involving over 2 million devices used for malicious activities. The operation disabled command-and-control features, protecting home devices from being exploited. This action significantly reduces cybercriminals' ability to mask their activities using residential IPs.
Former EU Parliament Member Hacked with Pegasus While Investigating Spyware
Stelios Kouloglou, a former European Parliament member, was targeted with Pegasus spyware during his work on the PEGA Committee, which investigated commercial spyware misuse. The hack occurred as the committee prepared recommendations on regulating spyware. This incident underscores concerns about government surveillance practices in the EU.
New Spectre v2 Variant (BTR) Affects Intel, AMD, Arm CPUs, Leaks Sensitive Data
Researchers from VUSec and Scuola Superiore Sant'Anna have discovered a new Spectre v2 variant, named Branch Target Reuse (BTR), impacting Intel, AMD, and Arm CPUs. This vulnerability exploits how processors handle code that changes at runtime, specifically targeting just-in-time (JIT) compilers in web browsers, language runtimes, and operating system kernels. BTR can lead to sensitive data leaks, such as root password hashes from Intel Linux systems, and fixes for CVE-2026-64507 and CVE-2026-64508 have been merged into the Linux kernel.
WordPress Backdoor Uses Multiple Persistence Mechanisms to Self-Rebuild After Cleanup
Cybersecurity researchers have identified a sophisticated WordPress backdoor, codenamed SC, that employs multiple persistence mechanisms across files, the database, and shared memory to rebuild itself even after cleanup attempts. This malware creates a circular system where each component can restore others, making it difficult to remove completely.
Cloudflare remediates cross-tenant data exposure vulnerability in Containers
Cloudflare fixed a vulnerability in its Containers and Sandboxes services that could have exposed residual disk blocks from other tenants. A security researcher reported the issue, which allowed Workers Paid account users to potentially recover data from previously used storage blocks on the same host. Cloudflare found no evidence of malicious exploitation and applied a fix across its Container fleet.
Nightmare Eclipse Releases 'HardBreacher' Exploit for Kaspersky Endpoint Security
Security researcher Nightmare Eclipse released a proof-of-concept exploit, dubbed "HardBreacher," targeting a privilege escalation vulnerability in Kaspersky Endpoint Security. Kaspersky stated that the underlying issue has been resolved via an automatic update, or users can trigger a database update manually. This exploit highlights ongoing concerns about endpoint security product vulnerabilities and the impact of public zero-day disclosures.
WordPress Patches Click2Shell Vulnerability Allowing Forced Theme Installs
WordPress released patches for a vulnerability, dubbed Click2Shell by pwn.ai, that allows a logged-in administrator to install a theme from the official directory via a crafted web link. This flaw can be chained with a separate theme vulnerability to achieve remote code execution on the server.
Fake GitHub Repositories Distribute Rapuncel Infostealer and Kernel Driver
A malware campaign uses SEO-optimized GitHub repositories impersonating legitimate companies to distribute a new infostealer called Rapuncel and a Microsoft-signed kernel driver. The kernel driver, Alinubx.sys, disables 145 antivirus and EDR products, allowing Rapuncel to steal credentials and cryptocurrency wallet data.
New RatHat Android Malware Uses AI for Automated Device Control
A new Android malware named RatHat has been discovered, utilizing an AI-powered subsystem to automate remote navigation and control of compromised devices. This AI integration allows the malware to adapt its operations without constant real-time operator interaction, making it more sophisticated than previous Android malware families.
Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records
Gyazo, an image-sharing service, experienced a security breach that exposed approximately 23.62 million user records, including email addresses and password hashes, along with 490 million image metadata records. This incident is significant because it compromises user privacy and security, potentially allowing unauthorized access to images and other services if users reused passwords.
U.S. Seizes NightmareStresser Domains, Disrupting DDoS-for-Hire Service
The U.S. Department of Justice (DoJ) and FBI, in coordination with international law enforcement, seized the internet domains nightmare-stresser[.]com and nightmarestresser[.]org, associated with the distributed denial-of-service (DDoS)-for-hire service NightmareStresser. This action, part of Operation PowerOFF, disrupts a platform used to launch hundreds of thousands of DDoS attacks globally since 2022, impacting various sectors including education, government, and gaming.
China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor
A China-linked hacking group, UNC3569, exploited a vulnerability in Sogou Input Method for Windows to install the GRAYRABBIT backdoor on victim computers. The flaw allowed attackers to execute arbitrary commands, impacting users primarily in East and Southeast Asia.
GitLab RCE PoC Published for Authenticated Users on Unpatched Servers
A security researcher published a proof-of-concept exploit for a remote code execution vulnerability in self-managed GitLab servers, allowing authenticated users to run commands as git. This vulnerability affects multiple GitLab Community Edition and Enterprise Edition versions and requires self-managed operators to upgrade to patched releases.
Grindr to pay £26M to settle claims of sharing user HIV status and personal data
Grindr has agreed to pay £26 million to settle a class-action lawsuit alleging it shared users' personal information, including HIV status, with third parties before 2020. This settlement addresses claims of privacy breaches and misuse of sensitive data, highlighting the ongoing legal and ethical challenges faced by tech companies regarding user data protection.
Attackers Exploit MikroTik Routers via Internet-Exposed SSH for Unauthorized Access
Attackers are exploiting MikroTik routers with internet-exposed SSH services to gain full administrative control without authentication, according to CERT Polska. MikroTik has released security updates for RouterOS to address these vulnerabilities, and users are advised to install them immediately.
China-Linked Fire Ant Group Compromises Cisco Routers to Steal Credentials and Blind Logs
The China-nexus cyber espionage group Fire Ant has expanded its operations to compromise Cisco IOS XR routers, TACACS servers, and Linux management hosts. This allows the group to capture network traffic, steal credentials, and disable security logging, providing a vantage point into high-value networks, including critical infrastructure.
Global Cybercrime Crackdown Arrests 58, Identifies 263 Suspects in Operation Jackal IV
Law enforcement agencies from 22 countries arrested 58 individuals and identified 263 suspects linked to cybercrime networks, primarily targeting West African groups like Black Axe, during "Operation Jackal IV." This operation disrupted financial fraud schemes, including romance and investment scams, and highlighted the use of Crime-as-a-Service by these syndicates.
Hackers Exploit miniOrange SAML SSO WordPress Plugin Vulnerabilities
Hackers are actively exploiting two critical authentication bypass vulnerabilities, CVE-2026-61979 and CVE-2026-15981, in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. These flaws allow attackers to forge SAML responses and gain administrative access, impacting sites that did not update due to incomplete vendor advisories.
Head Mare Exploits TrueConf Server Flaws to Distribute Backdoored Client Installers
The hacktivist group Head Mare exploited vulnerabilities in unpatched TrueConf video conferencing servers to replace legitimate client installers with malicious versions containing PhantomCore and PhantomGraph backdoors. These attacks, discovered by Kaspersky in July, targeted Russian organizations across various sectors, allowing attackers to gain persistent remote access and exfiltrate data.
Over 14,500 Dahua Devices Compromised via Credential Attacks, Auth Bypasses, and P2P
Cybersecurity researchers at Hunt.io uncovered "Operation CameraSwarm," which compromised over 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws (CVE-2021-33044 and CVE-2021-33045), and a P2P relay technique. This compromise highlights the ongoing risk posed by unpatched vulnerabilities and weak credentials in IoT devices, particularly in critical infrastructure or surveillance contexts.
New Interrupt Injection Attack Bypasses Spectre v2 Defenses on Intel and AMD CPUs
Researchers have discovered a new attack, named Interrupt Injection or TONTOU, that bypasses existing Spectre v2 mitigations on Intel and AMD CPUs. This vulnerability allows an unprivileged local attacker to leak kernel memory, such as Linux password hashes, by exploiting a timing window during branch predictor neutralization. AMD has released a kernel patch for Linux, while Intel states no mitigation is necessary.
Shell investigates potential data theft after Clop ransomware gang claims 89GB stolen
Shell is investigating a potential security incident after the Clop ransomware gang claimed to have stolen 89GB of data, including engineering drawings and project plans. This incident is linked to the exploitation of CVE-2026-12569 in PTC Windchill and FlexPLM instances, a vulnerability that CISA has confirmed is actively exploited.