ar
Feedback
TECHZONE™

TECHZONE™

الذهاب إلى القناة على Telegram

TECHZONE CYBERNEWS && UPDATES Wᴇʟᴄᴏᴍᴇ Tᴏ TECHZONE™ ✔️Infosec Facts ✔️Cheatsheets ✔️Free Courses ✔️Open source tools ✔️Tech news

إظهار المزيد
574
المشتركون
لا توجد بيانات24 ساعات
-47 أيام
-1730 أيام
أرشيف المشاركات
Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server https://thehackernews.com/2026/08/critical-cpanel-flaw-could-let-one.html cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user. The vulnerability, assigned the CVE identifier CVE-2026-65643, impacts all supported versions of cPanel & WHM. cPanel described the issue as a critical security vulnerability and said that an

PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions https://thehackernews.com/2026/08/papercut-zero-day-exploited-in-attacks.html PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. The company has released an emergency patch for v25 and v26 to address the issue. It said it's "aware of confirmed customer incidents and is treating this matter with the highest priority." An

APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations https://thehackernews.com/2026/08/apt28-linked-hookedge-backdoor-targets.html Cybersecurity researchers have flagged a fresh set of campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026. These campaigns, per Recorded Future Insikt Group, have led to the deployment of a previously undocumented backdoor dubbed HOOKEDGE, a lightweight Windows batch script that's distributed via

AI-assisted reconnaissance: Why everyone could be a viable target for fraud https://www.welivesecurity.com/en/privacy/ai-powered-osint-why-everyone-viable-target-fraud/ It’s getting cheaper and easier for cybercriminals to research potential victims. Here’s what’s still in your control.

OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face https://thehackernews.com/2026/08/openai-says-reward-hacking-drove-ai.html OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, adding that it found evidence of misaligned behavior as early as late May. The incident, the company said, took place during cybersecurity evaluations of several OpenAI models, and that it was mainly fueled by what it described as a "highly capable

Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE https://thehackernews.com/2026/08/nextjs-patches-critical-avif-and.html Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting servers that use a Windows filesystem. The Windows path traversal, tracked as CVE-2026-75604&

ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories https://thehackernews.com/2026/08/threatsday-296k-iot-botnet-100-water.html A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine. The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting before showing their real behavior, exposed systems getting scanned, and exploit windows shrinking again. Different

Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers https://thehackernews.com/2026/08/amazon-kiro-prompt-injection-can.html Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via prompt injection and Kiro Powers. The security flaw, which does not have a CVE identifier, works against Kiro IDE 0.7.45 on Windows, according to Mindguard. The latest version of

Learn How to Build Security Operations Ready for AI-Powered Attacks https://thehackernews.com/2026/08/learn-how-to-build-security-operations.html Security teams have spent years trying to detect threats faster. AI is changing the harder part: how much time defenders have left to act. Advanced AI models can now help attackers discover vulnerabilities, generate exploit code, and move through weaknesses faster than traditional security processes were built to handle. The challenge is no longer just finding another vulnerability or

Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks https://thehackernews.com/2026/08/alleged-teampcp-hackers-charged-in.html The Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences over their alleged role in TeamPCP, the cybercrime group behind the March 2026 compromise of the open-source security scanners Trivy and Checkmarx KICS and the AI gateway LiteLLM. Louis Michael Gaebler, 23, and Ruben Ian Thomson, 21, appeared in Perth Magistrates Court on August 27,

What the Data Says About AI in Security Operations in 2026 https://thehackernews.com/2026/08/what-data-says-about-ai-in-security.html AI is officially mainstream in security operations. According to Prophet Security's State of AI in Security Operations 2026 report (produced from ViB’s survey of 250+ cybersecurity pros), 40% of security teams now use AI daily. Another 56% are currently testing it out, and only 4% have no plans to adopt it. For the teams already using AI, what is actually changing? Here are the ten biggest

Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools https://thehackernews.com/2026/08/spark-rat-targets-cambodia-abuses.html Individuals and organizations in Cambodia have emerged as the target of a new campaign that delivers an open-source remote access trojan (RAT) called Spark RAT. "The samples employ diverse lure themes, suggesting an effort to appeal to a broad range of potential victims. These include government notices, public health materials, real estate-related content, and other topics," Acronis Threat

GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address https://thehackernews.com/2026/08/gocaracal-malware-uses-ethereum-smart.html Threat actors linked by Arctic Wolf to Dark Caracal with medium confidence deployed a previously undocumented Go-based malware framework, GoCaracal, during a June 2026 intrusion at an unnamed communications organization in Venezuela. GoCaracal provides operators with remote shell access and payload execution, while the extended profile adds browser data theft, keylogging, remote desktop control

New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access https://thehackernews.com/2026/08/gputhor-rowhammer-defeats-ecc-on-nvidia.html Academic researchers have disclosed a Rowhammer attack impacting NVIDIA workstation GPUs with GDDR6 memory that defeats error correction codes (ECC), the mitigation NVIDIA recommends against GPU Rowhammer, and enables denial-of-service (DoS) and privilege escalation to a root shell. Dubbed GPUThor, the attack was developed by researchers at the University of Toronto, who hammered four DRAM

CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs https://thehackernews.com/2026/08/cisa-adds-six-exploited-flaws-to-kev.html The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2019-1068 - A remote code execution vulnerability in 

FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations https://thehackernews.com/2026/08/fbi-disrupts-china-linked-qtfy.html The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country. The activity has been attributed to a Chinese state-sponsored group known as QTFY, employed by Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司).&

Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler https://thehackernews.com/2026/08/nimbus-manticore-expands-toolset-with.html Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC). Group-IB, in a new analysis published today, described the cyber espionage actor as among the most active Iranian APT groups in 2026. Nimbus Manticore (aka

OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation https://thehackernews.com/2026/08/openai-bans-russian-chatgpt-accounts.html OpenAI on Tuesday said it banned a cluster of Russian ChatGPT accounts that used VPNs to bypass access restrictions and run an influence operation, which relied on its artificial intelligence (AI) tool to generate social media posts and comments that were shared on Substack, Telegram, X, Facebook and LinkedIn. The accounts "were being used to promote the International Burke Institute (IBI), a

INTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud Crackdown https://thehackernews.com/2026/08/interpol-operation-jackal-iv-arrests-58.html An eight-month INTERPOL operation targeting West African organized crime groups has led to arrests of 58 people and the identification of 263 suspects. "The operation, which brought together 22 countries from six continents, is a response to the escalating global threat posed by West African criminal networks – such as the Black Axe and other similar groups," INTERPOL said. "These groups are

New SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode https://thehackernews.com/2026/08/newly-sleepwalker-backdoor-waits-for.html An independent malware researcher has documented a previously unreported Windows backdoor, dubbed SLEEPWALKER, that stays inert in memory until a specifically crafted network packet reaches the machine and then runs commands written in a 23-instruction language of its own design. The sample is an unsigned 64-bit Windows dynamic-link library (DLL) of 59,904 bytes, built to be side-loaded into&

TECHZONE™ - إحصائيات وتحليلات قناة تيليجرام @techzoner