From The Hacker News · 40 stories
Russia Charges Telegram Founder Pavel Durov with Aiding Terrorism, Seeks Arrest
Russia's Federal Security Service (FSB) has charged Telegram founder Pavel Durov with aiding terrorist activity and placed him on an international wanted list. The FSB alleges Telegram failed to remove channels and bots used by Ukrainian special services and extremist organizations to coordinate sabotage and terrorism within Russia, resulting in casualties and financial damage. Durov has rejected the allegations, stating Russia is retaliating for his refusal to comply with demands for mass surveillance and censorship.
H96 TV Streaming Sticks Implicated in Ad Fraud and Proxy Network Operation
Bitsight researchers uncovered a widespread ad fraud operation, named Fuyao and attributed to Zhejiang Fengwo IoT Technology Co., Ltd., involving H96 TV streaming sticks. These devices spoof mobile phones to click ads on AI-generated websites and also function as SOCKS5 proxy exit nodes, while secretly collecting user hardware and installed app information. This activity highlights security vulnerabilities and fraudulent practices within generic streaming devices, impacting online advertising and user privacy.
Coordinated Cyberattack Impacts Over 30 Minnesota Water Systems
A coordinated cyberattack targeted the operational technology of more than 30 community water systems in Minnesota on July 26 and 27. The attack caused outages and communication failures, with Braham's water plant going offline and other cities like Plymouth, South St. Paul, and Maple Plain experiencing affected automated controls or cellular communication issues. The incident prompted a statewide cybersecurity response involving Minnesota IT Services (MNIT).
Dysphoria IoT Botnet Uses Blockchain for C2 After JackSkid Disruption
The Dysphoria IoT botnet has adopted blockchain-based name services and infected-device relays for command-and-control (C2) following a March law enforcement operation against its predecessor, JackSkid. Researchers from CNCERT and Qi'anxin's XLab estimate the botnet to have over 200,000 bots, using them for distributed denial of service (DDoS) attacks and traffic relay operations. This architectural change makes the botnet more resilient to disruption by obscuring the location of its controllers.
GitHub Restructures Bug Bounty Program, Reduces Public Payouts by July 2026
GitHub is restructuring its bug bounty program to prioritize quality over quantity, introducing a permanent, invite-only VIP program with higher payouts and direct access to its security engineering team. Starting July 27, 2026, public bug bounty payouts will be reduced by at least 50% across all severity levels, with fixed payments replacing previous ranges. This change aims to reduce the volume of submissions and reward established researchers more effectively.
Authorities Shut Down Kratos Phishing-as-a-Service Platform, Arrest Developer
German and U.S. authorities dismantled the Kratos phishing-as-a-service platform, used for Microsoft 365 phishing campaigns, and arrested its developer in Indonesia. The platform had 1,800 users running 15,000 campaigns monthly, significantly affecting global cybersecurity due to its ability to bypass multifactor authentication.
Qilin Ransomware Gang Exploits Patched PAN-OS VPN Vulnerability
The Qilin ransomware gang is exploiting a critical flaw (CVE-2026-0257) in Palo Alto Networks' PAN-OS GlobalProtect to gain unauthorized access and deploy ransomware. Despite the vulnerability being patched on May 13, 2026, attacks have led to network breaches and data encryption. The U.S. CISA has urged federal agencies to secure their GlobalProtect instances immediately.
Russian Hackers Use Security Cameras to Monitor NATO and Ukrainian Military Movements
Russian intelligence services are using internet-connected security cameras across Ukraine and NATO states to gather military intelligence. This operation involves exploiting cameras with default settings or security flaws, collecting data on military logistics and weapon shipments, and targeting Ukrainian troops. The breaches pose serious security risks across Europe and Ukraine.
7-Zip Version 26.02 Fixes High-Severity RCE Flaw in XZ Archive Processing
7-Zip released version 26.02 to address a remote code execution (RCE) vulnerability linked to XZ-compressed data. Discovered by Lunbun researcher Landon Peng, the flaw could be exploited if a user opened a specially crafted archive. This highlights the need for manual updates due to 7-Zip's lack of an automatic update feature, emphasizing user awareness and action.
Unpatched Flaw in Shark Vacuums Allows Unauthorized Control Across AWS Region
A vulnerability in Shark robot vacuums allows attackers to control devices across an AWS region using leaked certificates. This unpatched flaw exposes live camera feeds, home maps, and Wi-Fi credentials while presenting significant privacy risks to users. The issue has been known to SharkNinja since March without a patch.
OkoBot Malware Targets Cryptocurrency Wallets via Seed Phrase Phishing
OkoBot, a malware framework active since April 2025, targets cryptocurrency wallet users by injecting phishing pages into legitimate wallet apps like Ledger and Trezor. Kaspersky reports hundreds of victims globally, particularly in Brazil, Vietnam, Canada, Mexico, and Türkiye. The malware delivers over 20 payloads to steal credentials and sensitive data, posing a significant threat.
Critical RabbitMQ Vulnerabilities Risk Exposing OAuth Secrets and Tenant Data
A critical vulnerability in RabbitMQ, CVE-2026-5721, exposes OAuth secrets, enabling unauthorized access to sensitive information. An additional flaw can allow logged-in users to access cross-tenant data. These flaws, present since early 2024, have been patched in recent updates. These vulnerabilities underscore the importance of applying security updates to prevent unauthorized access risks.
Forg365 Phishing-as-a-Service Targets Microsoft 365 with Sophisticated Methods
Forg365, a new phishing-as-a-service platform, targets Microsoft 365 accounts with advanced techniques such as adversary-in-the-middle attacks, AI-generated lures, and device code phishing. This operation is notable for its complexity and capability to execute persistent access while leveraging legitimate email services for delivery.
Attackers Use Dormant GitHub Accounts for Reconnaissance via API
Datadog Security Labs has identified multiple attack campaigns exploiting dormant GitHub accounts for organizational reconnaissance. Attackers use these accounts with automated tools to gather data, occasionally accessing private repositories. This is significant due to potential risks of further targeted attacks.
Six Vulnerabilities Found in U-Boot Bootloader Threaten Device Security at Boot
Six vulnerabilities in the U-Boot bootloader, used in devices from routers to servers, have been identified. These flaws enable attackers to execute arbitrary code or crash devices during boot, compromising security before the operating system verifies software. This poses significant risks due to U-Boot's widespread deployment in various embedded systems.
Injective SDK npm Package Compromised to Steal Cryptocurrency Keys
A version of the Injective SDK npm package was compromised, leading to the theft of cryptocurrency wallet private keys via a malicious version. Hackers accessed Injective Labs' GitHub to publish the harmful package, affecting developers in the decentralized finance space.
AI Agents Expose Gaps in Enterprise Identity Governance Systems
AI agents are increasing machine identities in enterprises, highlighting gaps in identity governance. Traditional identity access management (IAM) systems were not designed for autonomous AI, often causing security risks due to over-privileged access. Addressing this issue is critical for secure enterprise operations.
GigaWiper: New Sophisticated Windows Backdoor with Destructive Capabilities
Microsoft has uncovered GigaWiper, a sophisticated malware targeting Windows machines. This backdoor combines older destructive programs to offer disk wiping, fake ransomware, and spyware functions, showcasing a shift in wiper malware to extortion activities. Its likely connections to cyber threats against Israeli organizations highlight the need for vigilance and strong cyber defenses.
Suspected China-Linked Hackers Target Roundcube Vulnerabilities in U.S. and Canadian Universities
A China-linked threat group named UNK_MassTraction has exploited a critical Roundcube webmail vulnerability to infiltrate physics and engineering departments in U.S. and Canadian universities, stealing credentials and deploying malware. The targeted campaign, identified by Proofpoint, has significant implications for national security and academic research.
Ubiquiti Releases Critical Security Patch Updates for UniFi OS Suite
Ubiquiti has issued patches for seven critical vulnerabilities in its UniFi OS software suite, affecting applications like UniFi Connect, Talk, Access, and Protect. These security flaws, including CVE-2026-50746, allow command injection and privilege escalation attacks. Users are strongly advised to update their systems to secure versions to mitigate potential breaches.
Google Patches Critical Flaw in Dialogflow CX Chatbot Platform
Google has patched a critical vulnerability in its Dialogflow CX platform that could have allowed attackers with specific permissions to compromise multiple chatbots within a single Google Cloud project. Dubbed 'Rogue Agent' by Varonis, the issue involved the execution of shared Code Blocks, which allowed unauthorized data access and message manipulation. No attacks exploiting this flaw were reported, and it was primarily a risk from insiders or compromised accounts.
Git Commit Signature Malleability Allows Tampered Verified Commit Hashes
Research has revealed Git commit hash malleability, enabling distinct commits with identical content, metadata, and valid signatures. The "hash chain malleability" flaw impacts systems relying on commit hash integrity, like dependency management and reproducible builds, leading to potential integrity risks.
Union County, Ohio Paid $1 Million to Cyber Group to Prevent Data Leak
Union County, Ohio paid $1 million to Kairos to prevent the release of stolen data after a May 2025 breach. This marks a significant data extortion case as there was no ransomware involved, emphasizing vulnerabilities in government data security without direct system lock-ups.
Cordyceps Vulnerability Exposes Over 300 GitHub Repositories to Supply-Chain Attacks
Researchers from Novee Security have identified a CI/CD vulnerability, named Cordyceps, affecting over 300 GitHub repositories. This issue allows unauthenticated users to execute harmful code, potentially impacting major organizations like Microsoft, Google, Apache, and Cloudflare. The flaw, due to weak CI/CD configurations, raises significant supply chain security concerns.
Iranian APT Group Targets Israeli Organizations with New C2 Framework
An Iranian hacking group linked to the Ministry of Intelligence and Security is targeting Israeli IT and government entities using a new command-and-control framework, Cavern C2. This development, attributed to the Cavern Manticore cluster, suggests evolving threats in cybersecurity, potentially influencing strategies in these sectors.
BeyondTrust Patches Critical Vulnerabilities in Remote Support Products
BeyondTrust has patched critical vulnerabilities in its Remote Support and Privileged Remote Access software. These flaws, identified as CVE-2026-40138 and CVE-2026-40139, could allow unauthenticated attackers to bypass authentication controls and gain unauthorized access, risking elevated privilege accounts. The company urges users to apply the patches promptly.
VEIL#DROP Malware Chain Uses Blogger to Deliver PureLogs Stealer
The VEIL#DROP malware delivery chain employs compromised Blogspot pages to deploy the PureLogs Stealer through multi-stage execution involving JavaScript and PowerShell. The use of trusted platforms like Google's Blogspot allows attackers to sidestep traditional defenses. Researchers have identified the sophisticated use of this infrastructure to access victims' sensitive information.
Armored Likho Targets Government and Power Sectors with Malware Attacks
The newly discovered Armored Likho group targets government and electric power sectors in Russia, Brazil, and Kazakhstan. The group uses malware, including the BusySnake Stealer, for cyber espionage and financial motives. This poses significant threats to critical infrastructure security in the affected regions.
North Korean Hackers Launch Supply Chain Attack with Malicious Software Packages
North Korean hackers have launched the PolinRider campaign, targeting open source developers and cryptocurrency sectors through malicious software packages. The attack involves 108 unique packages and extensions, including npm libraries, Go modules, and a Chrome extension. This campaign is ongoing and poses significant risks by compromising maintainer accounts and using backdoors and information stealers.
Researchers Uncover Security Flaws in Apple AirDrop and Samsung Quick Share
Security researchers have identified six vulnerabilities in Apple's AirDrop and Samsung's Quick Share affecting billions of devices. These flaws enable nearby attackers to crash file-sharing services without user interaction. Apple has patched one of the AirDrop vulnerabilities, and investigation is ongoing for the others.
Critical Vulnerabilities Found in Cursor AI Code Editor, Prompt Urgent Update
Two critical vulnerabilities, CVE-2026-50548 and CVE-2026-50549, were discovered in the Cursor AI code editor, potentially allowing remote code execution by bypassing its security sandbox. These flaws, identified by Cato AI Labs, affect all versions before Cursor 3.0 and have been patched in the new release. The vulnerabilities could impact many Fortune 500 companies that use the editor, highlighting the urgency for affected users to update to version 3.0 to mitigate security risks.
Citrix Patches Six Critical NetScaler Vulnerabilities, Including HTTP/2 Bomb
Citrix released patches for six vulnerabilities in NetScaler ADC and Gateway, including a critical HTTP/2 Bomb exploit. These flaws, affecting versions 14.1 and 13.1, pose severe risks like denial-of-service attacks and data breaches. Organizations using these configurations should urgently update to protect against active threats.
LayerX Reveals AI Browser Vulnerability Exploited by 'BioShocking' Attack
Security firm LayerX has discovered a vulnerability in AI-driven browsers, known as the 'BioShocking' attack, where browsers can be tricked into leaking user credentials. The attack uses game-like puzzle contexts to manipulate AI agents into bypassing security protocols, potentially exposing sensitive data. This discovery raises concerns about the security of AI-assisted browsing applications.
ChocoPoC Malware Targets Cybersecurity Researchers via Trojanized PoC Exploits
ChocoPoC, a Python-based remote access trojan, is being distributed through trojanized proof-of-concept (PoC) exploit repositories on GitHub. The malware targets cybersecurity researchers by installing malicious dependencies from PyPI, enabling attackers to execute commands and steal sensitive data. This highlights security risks associated with using unofficial PoCs in vulnerability research.
Password Spray Attack Targets Microsoft Azure CLI, Compromising 78 Accounts
An automated password spray attack on Microsoft's Azure CLI attempted over 81 million logins, affecting 78 accounts across 64 organizations. The attackers exploited a deprecated OAuth flow, bypassing security measures like Conditional Access policies and multi-factor authentication (MFA). This incident underscores vulnerabilities in prevalent security configurations within cloud environments.
Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks
Microsoft has warned of phishing campaigns distributing MSP360 Remote Monitoring and Management (RMM) software to gain initial access to systems. Attackers then use this foothold to install ConnectWise ScreenConnect, establishing redundant remote access channels for further malicious activity.
OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory or Crash Programs
OpenSSL released fixes for a high-severity DTLS flaw, CVE-2026-84782, that can leak heap memory or crash programs during handshake message resends. The vulnerability affects software using OpenSSL for DTLS and is patched in versions 4.0.3, 3.6.5, 3.5.9, and 3.4.8, with premium support required for older branches.
Financial Services Face Increased Software Supply Chain Vulnerability Risks
Financial services companies are facing new pressures to modernize their software supply chains due to advanced AI models that can rapidly exploit dormant vulnerabilities. Historically, these firms accepted vulnerability backlogs for stability, but exploitation has now surpassed phishing as the primary initial access vector for breaches in the sector. This shift necessitates a re-evaluation of long-standing risk management strategies.
Device Code Phishing Emerges as a Rapidly Growing Threat, Bypassing MFA
Device code phishing, which exploits the OAuth 2.0 device authorization grant to steal access tokens, has rapidly industrialized into a major threat. This method bypasses all forms of multi-factor authentication, including passkeys, by targeting the authorization layer rather than the login process itself.
Need for Multi-Layered Detection in Modern Security Operations Centers
Modern cybersecurity faces challenges as AI-driven attacks outpace traditional defenses. The increase in malware-free attacks demands a shift toward multi-layered detection, emphasizing real-time monitoring and unified data from various security domains to improve incident response.