TECHZONE™
Open in Telegram
TECHZONE CYBERNEWS && UPDATES Wᴇʟᴄᴏᴍᴇ Tᴏ TECHZONE™ ✔️Infosec Facts ✔️Cheatsheets ✔️Free Courses ✔️Open source tools ✔️Tech news
Show more573
Subscribers
No data24 hours
-17 days
-1430 days
Posts Archive
573
This month in security with Tony Anscombe – August 2026 edition
https://www.welivesecurity.com/en/videos/month-security-tony-anscombe-august-2026/
Details about the Hugging Face hack, critical infrastructure under attack, a spoofed in-flight Wi-Fi network, and more of this month's cybersecurity news
573
North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales
https://thehackernews.com/2026/08/north-korean-job-fraud-expands-beyond.html
Threat actors with ties to the Democratic People's Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying suspected workers employed in sales and marketing and the medical profession.
The ongoing insider threat is part of what has been described as the IT worker scheme,
573
⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More
https://thehackernews.com/2026/08/weekly-recap-chinese-spy-proxy-ai.html
The boring parts caused most of the trouble.
A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. Old bugs formed new attack chains. Even an AI agent decided its assigned task was optional.
Elsewhere, fake apps, helpful support calls, cheap banking kits, exposed systems, and weak defaults kept
573
ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
https://thehackernews.com/2026/08/valleyrat-backdoor-hides-in-signed.html
The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their antivirus exclusions.
Russian cybersecurity vendor Kaspersky said the attackers built the disguise around QN Wallpaper, a genuine Chinese desktop-wallpaper tool
573
Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets
https://thehackernews.com/2026/08/aurora-ransomware-operators-use-cursor.html
Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX's artificial intelligence (AI)-powered coding assistant Cursor to break into target networks, according to findings from CloudSEK and Gambit Security.
The two independent analyses are based on exposed infrastructure associated with the Russian-speaking cybercrime group, leading to the discovery of its
573
Securing Claude Code: The New Compliance API, Local Visibility, and Identity Governance
https://thehackernews.com/2026/08/securing-claude-code-new-compliance-api.html
Claude Code reads files, runs shell commands, invokes MCP tools, and acts through the credentials available on a developer’s machine. Anthropic’s new Compliance API endpoints give security teams their clearest view yet into that activity. They also expose a larger problem: activity logs alone cannot tell you whether an agent’s access is legitimate.
AI has moved from the browser tab to the
573
China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
https://thehackernews.com/2026/08/china-linked-fire-ant-hijacks-cisco.html
A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linux management hosts used to route, authenticate, and manage high-value networks.
Sygnia, the incident response firm that investigated the intrusion, said the actor
573
DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims
https://thehackernews.com/2026/08/doj-corrects-china-hacking-claim-says.html
The U.S. Department of Justice (DoJ) on Friday corrected a previously issued press statement that several of its agencies were victims of attacks carried out by Chinese threat actors, instead now pointing out that they were among those targeted.
Last week, the DoJ said the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department
573
TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
https://thehackernews.com/2026/08/terminalfix-uses-fake-cloudflare.html
Microsoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that aims to trick users into running a malicious command in Windows Terminal or PowerShell.
"While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the same technique but direct users to Windows Terminal or PowerShell instead, increasing the likelihood that complex
573
Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
https://thehackernews.com/2026/08/five-critical-wordpress-plugin-and.html
Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution.
The vulnerabilities, according to Wordfence and Patchstack, are listed below -
CVE-2026-76581 (CVSS score: 9.8) - An authentication bypass flaw in
573
Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network
https://thehackernews.com/2026/08/berlin-refuses-to-pay-hackers-who-stole.html
Berlin's state government has confirmed that it is the target of an extortion attempt following the August compromise of the city's state administrative network, and said it will not meet the extortionists' demands.
The same statement disclosed that forensic work had found further data outflows in the portfolio of the Senate Department for Mobility, Transport, Climate Protection and Environment
573
Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable
https://thehackernews.com/2026/08/cosmos-evm-flaw-exploited-after-cosmos.html
Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026.
The vulnerability, designated GHSA-7g4w-cg88-2cq2, is rated Critical by Cosmos Labs and was published without a CVE identifier, a weakness classification, or a CVSS score.
Affected versions are < 0.6.2 and >=
573
Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication
https://thehackernews.com/2026/08/attackers-chain-two-papercut-flaws-to.html
Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening.
"This vulnerability gives an unauthenticated attacker remote control over PaperCut's trusted configuration, which could be used to execute arbitrary Java code inside the application's
573
Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers
https://thehackernews.com/2026/08/android-17-adds-os-wide-ech-to-hide.html
Google on Thursday announced new network security protections in Android 17 to bolster connection privacy, address cellular vulnerabilities, and safeguard the privacy of users' home networks.
Topping the list is support for Encrypted Client Hello (ECH), a privacy standard that prevents networks from eavesdropping on which websites a user is visiting.
"This new privacy standard works in tandem
573
ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body
https://thehackernews.com/2026/08/snowflake-github-actions-flaw-lets.html
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting ownCloud to its Known Exploited Vulnerabilities (KEV) catalog following reports that a Chinese-speaking threat actor weaponized the vulnerability to target a nuclear research body in the Philippines.
The vulnerability, tracked as CVE-2023-49105 (CVSS score: 9.8), is a case of
573
19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code
https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html
Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities.
The extensions, per Socket security researcher Karlo Zanki, share similarities in code and tradecraft, with evidence indicating that the campaign may have been active
573
Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth
https://thehackernews.com/2026/08/two-unitree-g1-edu-humanoid-robot-flaws.html
Security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU, including a Bluetooth Low Energy (BLE) path that can reach root on the robot's Locomotion PC.
The flaws are tracked as CVE-2026-76639 and CVE-2026-76640, with the first involving a network-adjacent path through chat_go and bashrunner and the
573
Key Reasons Why Identity Fabric Matters in 2026
https://thehackernews.com/2026/08/key-reasons-why-identity-fabric-matters.html
An Identity Fabric knits fragmented identity systems into a coherent layer that observes how identities behave across applications, APIs, and infrastructure. As enterprise access spans more cloud services and automated workloads, identity security depends less on static configuration and more on runtime visibility. This article covers the architecture, the risks of unmanaged identities, and
573
Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL
https://thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.html
ServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring system and exploitable, in certain circumstances, by an unauthenticated attacker.
The company said it deployed a security update to hosted instances and provided the update to its partners and self-hosted customers, which leaves organizations that run their
573
China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access
https://thehackernews.com/2026/08/china-made-zbt-routers-ship-with-two.html
VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT), each of which gives an unauthenticated remote attacker the ability to run commands as root on affected devices.
The implants, named SPEAKINGSTONE and DARKLANTERN by the company's zero-day research team, are tracked as CVE-2026-74232 and CVE-2026-74233.
