For you Ai Security Dev Cloud Hardware Startups Releases General

From The Hacker News · 40 stories

3 sources 4 reports 45d ago

City-Forum Campaign Targets Salesforce and ServiceNow Guest Users with Custom Tools

A campaign named 'City-Forum' is exploiting guest user access in Salesforce Experience Cloud (Aura and LWR implementations) and ServiceNow customer portals to steal data. The attacks use a custom multi-platform toolset and target telecommunications, banking, financial services, enterprise software vendors, and public-sector portals globally.

security salesforce servicenow vulnerability data breach
3 sources 3 reports 46d ago

New Mirai Variant "Evooo1Bot" Adds Stealth and Proxy Capabilities to Botnet Code

A new Mirai botnet variant, dubbed Evooo1Bot, has been actively exploiting vulnerabilities in internet-facing hardware for at least a month, according to FortiGuard Labs. This variant includes enhanced stealth features like SSH honeypot detection and a SOCKS proxy function, allowing attackers to conceal their origin and pivot into internal networks. The added capabilities make Evooo1Bot more sophisticated than previous Mirai-derived malware, posing a greater threat to network security.

security mirai botnet malware cybersecurity
3 sources 3 reports 51d ago

Russian Sandworm Hackers Target Ukrainian IT Workers with Malicious VPNs via Fake Job Offers

Russian military intelligence hackers, identified as Sandworm (UAC-0145), are posing as recruiters on Ukrainian job sites to trick IT professionals into installing malicious software. Active since at least May, the campaign aims to compromise systems by having victims download a modified VPN application during a fake recruitment process, allowing for command execution and further payload delivery.

security cybersecurity malware russia ukraine
3 sources 3 reports 55d ago

Atlassian Rovo AI Vulnerabilities Allowed Data Exfiltration; One Fixed, One Remains

Atlassian's Rovo AI assistant had vulnerabilities that allowed data exfiltration from Jira and Confluence. One method, dubbed RovoBlast by Varonis Threat Labs, involved a one-click malicious link and has been fixed. Another method, discovered by PromptArmor, used indirect prompt injection via uploaded files and remains unconfirmed as fixed by Atlassian.

security ai atlassian vulnerability rovo
3 sources 5 reports 57d ago

Anthropic's Claude Mythos AI Identifies Weaknesses in HAWK and Round-Reduced AES

Anthropic's Claude Mythos Preview AI model discovered new attack methods against the HAWK digital signature scheme and a faster attack on seven-round AES-128. The HAWK scheme, a candidate for post-quantum standardization, was subsequently withdrawn from NIST consideration by its developer. These findings demonstrate AI's capability in cryptanalysis, though neither attack affects current production systems.

security cryptography ai research post-quantum
3 sources 3 reports 58d ago

Adform Ad Platform Compromised to Steal Cryptocurrency via Malicious JavaScript

Online advertising firm Adform experienced a supply-chain attack where its JavaScript tracking script, 'trackpoint-async.js' served from 's2.adform.net', was compromised. The malicious code replaced Bitcoin, Ethereum, or TRON wallet addresses copied to users' clipboards or entered into form fields with attacker-controlled addresses, potentially redirecting cryptocurrency payments. Adform detected the incident on July 27, 2026, removed the code, and notified clients.

security supply-chain cryptocurrency adtech javascript
3 sources 3 reports 59d ago

UK Police and Education Data Breached by ExfilSquad, Ransom Demanded

The UK's Police National Legal Database (PNLD) and Department for Education (DfE) experienced separate data breaches, with the ExfilSquad extortion group claiming responsibility. The PNLD breach exposed contact information for over 100,000 police officers and criminal justice professionals, while the DfE incident involved over 600,000 lines of data from two portals. ExfilSquad is demanding a ransom for the data.

security cybersecurity data breach government extortion
3 sources 3 reports 63d ago

Amazon Attributes Multiple npm Package Hijacks to North Korea's Sapphire Sleet

Amazon Threat Intelligence has attributed the September 2025 hijacks of the npm packages debug and chalk, along with the March 2026 axios compromise and an earlier typo-crypto incident, to North Korea's Sapphire Sleet group. This attribution connects previously separate incidents of crypto theft and package compromise under a single threat actor, highlighting a consistent pattern of social engineering and supply chain attacks affecting widely used JavaScript libraries.

security npm north korea supply chain supply chain attack
3 sources 3 reports 66d ago

Fastjson 1.x RCE Vulnerability Actively Exploited, No Patch Available

Attackers are targeting a critical remote code execution (RCE) vulnerability in Alibaba's Fastjson 1.x library, affecting Spring Boot applications. The flaw, CVE-2026-16723, allows unauthenticated code execution and currently has no official patch from Alibaba for the 1.x branch. This impacts organizations using Fastjson 1.x in specific Spring Boot configurations, requiring immediate mitigation or migration to Fastjson2.

security fastjson rce vulnerability java
3 sources 3 reports 66d ago

Clop Ransomware Exploits PTC Windchill and FlexPLM Vulnerability for Data Theft

The Clop ransomware group is exploiting a critical vulnerability (CVE-2026-12569) in PTC Windchill and FlexPLM to exfiltrate data from targeted companies. This exploitation has led to extortion campaigns and prompted urgent warnings from cybersecurity agencies and authorities.

security ransomware vulnerability data theft ptc
3 sources 3 reports 73d ago

HollowGraph Malware Utilizes Microsoft 365 Calendars for C2 Communications

HollowGraph, a new malware, uses Microsoft 365 calendar events dated to 2050 for command-and-control and data exfiltration. This method disguises traffic as legitimate, targeting Israeli entities and linked to Iranian threat actors.

security malware microsoft365 espionage microsoft
3 sources 4 reports 73d ago

Critical ServiceNow Flaw Exploited Despite Patch Release

A critical remote code execution vulnerability (CVE-2026-6875) in ServiceNow's AI Platform is being actively exploited, allowing attackers to execute code remotely. Despite the July patches, attacks were observed shortly thereafter. This issue highlights the urgency for self-hosted customers to apply updates promptly to prevent system compromise.

security vulnerabilities patches software servicenow
3 sources 3 reports 73d ago

OpenSSL HollowByte Flaw Exposes Servers to Memory Exhaustion with Minimal Payload

A vulnerability in OpenSSL, known as HollowByte, allows attackers to trigger a denial-of-service condition by sending an 11-byte payload. The flaw causes vulnerable servers to pre-allocate memory for incomplete TLS handshake messages. Fixed versions without official CVEs or advisories include OpenSSL 4.0.1 and others released on June 9. Upgrading is crucial to prevent potential server freezes.

security openssl vulnerability dos
3 sources 3 reports 77d ago

Claude for Chrome Vulnerability Exposes User Data to Rogue Extensions

A vulnerability in Claude for Chrome allows rogue extensions to trigger sensitive tasks without user consent. Discovered by Manifold Security, the flaw enables malicious extensions to access Gmail, Google Docs, Calendar, and Salesforce, posing a significant security risk. This issue persists in version 1.0.80, with no current patch.

security chrome vulnerabilities data exposure cloud
3 sources 3 reports 78d ago

Zoom Patches Critical Vulnerability Allowing Account Takeovers

Zoom has patched a critical vulnerability (CVE-2026-53412) in its Windows applications, rated 9.8 on the CVSS scale, which enabled potential account takeovers. The flaw affected Zoom Workplace, Zoom VDI Client, and Zoom Meeting SDK for Windows prior to version 7.0.0. This vulnerability impacts user security and necessitates immediate updates to prevent unauthorized account access.

security zoom vulnerability account takeover windows
3 sources 3 reports 78d ago

Microsoft Revokes Vulnerable UEFI Shims Allowing Secure Boot Bypass

Microsoft has revoked the signatures of 11 old UEFI shims signed by them, which could bypass Secure Boot on Windows and Linux systems. This security flaw, discovered by ESET, existed due to old firmware remaining signed and trusted despite vulnerabilities. Addressing this issue is critical for preventing the unauthorized execution of code during the system boot process.

security uefi malware secure boot microsoft
3 sources 3 reports 78d ago

Critical Vulnerability in Cursor IDE Allows Arbitrary Code Execution on Windows

A vulnerability in Cursor IDE enables arbitrary code execution by executing malicious git binaries in project roots. Reported by Mindgard in December 2025, the issue remains unpatched, affecting over 7 million users. The flaw involves Cursor executing 'git.exe' files in repository roots without user interaction, posing significant security risks.

security cursor vulnerability development git
3 sources 5 reports 79d ago

Progress Software Confirms Zero-Day Vulnerability in ShareFile Storage Zone Controllers

Progress Software advised ShareFile users to shut down Storage Zone Controllers due to a zero-day vulnerability. The high-severity path traversal flaw, affecting versions 5.x and 6.x, led to precautionary account access suspension and patches release. No customer data compromise has been reported.

security cloud general sharefile software
3 sources 4 reports 79d ago

xAI's Grok CLI Tool Exposed for Uploading Entire Repositories Without Consent

xAI's Grok Build CLI tool was found transmitting entire code repositories, including sensitive files, to its cloud storage, causing privacy concerns. After researcher cereblab's disclosure, xAI altered the tool silently. Elon Musk said all uploaded data would be deleted to maintain privacy standards.

security grok xai data privacy dev
3 sources 4 reports 79d ago

Microsoft 365 Users Targeted in Voice Phishing Campaign for Fake Entra Passkey Enrollment

A voice phishing campaign is exploiting Microsoft 365 users to unwittingly enroll fake Entra passkeys, giving attackers unauthorized account access and facilitating potential data extortion. Initiated by the group O-UNC-066, the campaign began in April and spans multiple industries, highlighting vulnerabilities in the passkey adoption process Microsoft implemented. Okta reported the attacks, which utilize convincing phishing kits mimicking Microsoft's passkey enrollment portal.

security microsoft phishing cybersecurity passkey
3 sources 3 reports 80d ago

U.S. Sanctions VPN and Malware Providers for Ransomware Support

The U.S. Treasury sanctioned First VPN Service and its administrator for aiding ransomware activities against American infrastructure. Ukrainian Dmytro Rashevskyi, associated with the VPN, and Belarusian Yegeniy Silayev, a cryptor seller, were named in the sanctions. The sanctions prevent U.S. entities from transacting with them, underscoring a broader crackdown on cybercriminal support networks.

security vpn ransomware cybersecurity government
3 sources 3 reports 82d ago

China and India-Linked Hackers Infiltrate Balochistan Police Networks

Chinese and Indian cyberespionage groups targeted the Balochistan Police from February 2024 to April 2026. The attackers accessed sensitive systems, including biometric data and criminal records. This exposes significant regional security vulnerabilities tied to geopolitical tensions.

security cybersecurity espionage malware regional-tensions
3 sources 7 reports 83d ago

Critical Linux Kernel Vulnerabilities: DirtyClone, Bad Epoll, and GhostLock

Three critical Linux kernel vulnerabilities, DirtyClone (CVE-2026-43503), Bad Epoll (CVE-2026-46242), and GhostLock (CVE-2026-43499), have been disclosed, each allowing privilege escalation. DirtyClone targets cloned network packets, Bad Epoll exploits a race condition, while GhostLock leverages a 15-year-old use-after-free flaw. Each vulnerability has a patch available, emphasizing the need for prompt system updates to mitigate exploitation risks.

security linux vulnerability kernel malware
3 sources 3 reports 83d ago

Critical Gitea Docker Vulnerability CVE-2026-20896 Faces Active Exploitation

Gitea Docker images are subject to a critical authentication bypass vulnerability (CVE-2026-20896) now under active exploitation. The flaw allows attackers to impersonate any user, including administrators, via reverse proxy authentication with default configurations. It affects versions before 1.26.3 and about 6,200 instances globally.

security devops docker vulnerabilities gitea
3 sources 3 reports 85d ago

Chinese APT UAT-7810 Develops New Malware to Expand ORB Network

Chinese APT group UAT-7810 has advanced its Operational Relay Box (ORB) network with new malware, including LONGLEASH, DOGLEASH, and JARLEASH. These tools exploit known router vulnerabilities to enhance the group's cyber espionage capabilities, posing potential risks to critical infrastructure.

security malware cybersecurity threat UAT-7810
3 sources 3 reports 86d ago

GitHub Agentic Workflows Vulnerable to Prompt Injection, Exposing Private Repos

Noma Labs identified a prompt injection vulnerability, named GitLost, in GitHub's Agentic Workflows, enabling data leaks from private repositories. Attackers can manipulate AI agents to disclose private content through crafted public issues. This highlights security concerns in using AI-driven workflows in GitHub's system.

security github ai data leakage vulnerability
3 sources 3 reports 91d ago

FortiBleed Campaign Compromises Fortinet Devices, Linked to Ransomware Groups

The FortiBleed campaign has been connected to the INC and Lynx ransomware groups, compromising credentials from Fortinet devices. Researchers found the operation entailed scanning 11,250 FortiGate portals and compromised 354 targets, leading to 12 ransomware deployments. The breach highlights significant cybersecurity risks, affecting organizations globally.

security ransomware credential-theft fortinet fortibleed
2 sources 2 reports 29d ago

Shai-Hulud Worm Evolves to Automate Package Registry Compromises and Credential Theft

A series of self-propagating worms, starting with Shai-Hulud in September 2025, have demonstrated the ability to automatically publish malicious package versions to registries like npm, steal credentials, and bypass security measures. The latest variant, ChainDrop, compromised over 400 packages in hours by exploiting legitimate, cryptographically signed release pipelines, highlighting a critical vulnerability in software supply chain security.

security supply chain npm malware infostealer
2 sources 3 reports 65d ago

AI Technology Reduces Vulnerability Exploitation Time, Increasing Security Concerns

The rapid increase in newly reported vulnerabilities, and the use of AI in exploit development, has significantly reduced the time it takes for cyber threats to be operationalised. This has created a larger 'exposure window' between vulnerability discovery and remediation, placing pressure on security teams. With CVEs published at an unprecedented rate, prompt response times are becoming crucial to mitigate potential breaches.

security vulnerabilities CVE pentesting exploitation
1 source 1 report 58d ago

Linux Kernel Open vSwitch Flaw Allows Local Root Privilege Escalation

A memory corruption vulnerability, CVE-2026-64531 (OVSwrap), in the Linux kernel's Open vSwitch datapath allows local users to gain root privileges on default-configured distributions. This flaw affects systems where the OVS kernel datapath is available and unprivileged user namespaces are enabled, with a public exploit already existing.

security linux vulnerability openvswitch
1 source 1 report 71d ago

Windmill Security Flaw Exploited to Access Sensitive Server Files

A high-severity security vulnerability (CVE-2026-29059) in Windmill allows unauthenticated attackers to read arbitrary server files. The flaw, related to path traversal in the 'get_log_file' endpoint, has been actively exploited, exposing sensitive information across 170 vulnerable systems worldwide.

security windmill vulnerability cybersecurity
1 source 1 report 72d ago

Flaw in Azure DevOps MCP Allows AI Review Hijacking via Hidden Comments

A vulnerability in Azure DevOps MCP allows hidden comments in pull requests to manipulate AI coding agents, granting unauthorized access to source code and secrets. This flaw exposes a critical gap in Microsoft's prompt-injection safeguards, risking information leakage during code review processes.

security azure devops flaw
1 source 1 report 72d ago

AWS Kiro Flaw Allowed Remote Code Execution via Malicious Web Pages

A vulnerability in AWS's Kiro IDE enabled attackers to execute code on a developer's machine by altering its configuration file. This flaw, discovered by Intezer and Kodem Security, bypassed the required user approval for risky actions and has since been patched, though no CVE has been assigned.

security aws vulnerability
1 source 1 report 73d ago

AI Speeds Up Exploit Development Post-Patching, Threatening Cybersecurity

Anthropic's AI, Claude Mythos, can reverse-engineer patches into exploits in under an hour, disrupting traditional timelines for vulnerability exploitation. This significant shift means defenders have far less time to secure systems before attackers can exploit known vulnerabilities, raising serious concerns about the effectiveness of current patching strategies.

security ai
1 source 1 report 73d ago

Researchers Present Bit2Watt Attack Threatening Power Grids via Cloud GPUs

Three researchers from Zhejiang University revealed the Bit2Watt attack, enabling cloud tenants to destabilize power grids using GPU workloads without requiring exploits. This method poses a significant risk as it leverages legitimate compute functions to create controlled power oscillations that can threaten infrastructure stability.

security cloud
1 source 1 report 74d ago

Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic Computers

A Russian-speaking hacker named 'bandcampro' leveraged Google's open-source Gemini CLI to control a botnet consisting of eight PCs at a dental clinic. This incident highlights the evolving use of AI in cybercrime, enabling sophisticated operations that can rapidly adapt and proliferate.

security ai botnet cybercrime
1 source 1 report 74d ago

SleeperGem Malicious RubyGems Target Dev Machines in Supply Chain Attack

A new cyber attack, codenamed SleeperGem, has been identified, affecting the Ruby ecosystem through three malicious RubyGems. This attack poses a significant risk to developers by potentially compromising their machines and extending to other packages.

security ruby malware
1 source 1 report 74d ago

F5 Releases Patches for Critical NGINX Vulnerability Allowing Remote Code Execution

F5 has released security patches for a critical vulnerability in NGINX (CVE-2026-42533) that allows remote attackers to trigger a heap buffer overflow, potentially leading to remote code execution and denial of service. This vulnerability affects numerous NGINX versions and some configurations, which could expose many installations unless updated.

security nginx vulnerability patches
1 source 1 report 76d ago

Seven Malicious Vite npm Packages Employ Blockchain C2 for RAT Delivery

Seven malicious npm packages targeting the Vite ecosystem have been uncovered, linked to a software supply chain attack dubbed ViteVenom. The packages employ a complex blockchain-based command-and-control system, enhancing their stealth and effectiveness in delivering a remote access trojan.

security npm vite malware
1 source 1 report 76d ago

NadMesh Botnet Targets Exposed AI Services for Cloud Credentials

NadMesh, a Go botnet, was discovered targeting exposed AI services in cloud environments, claiming over 3,800 AWS keys. The botnet systematically scans platforms like ComfyUI and n8n to extract cloud credentials and Kubernetes tokens, posing significant security risks to cloud deployments and AI tools.

security botnet cloud
More stories →