es
Feedback
TECHZONE™

TECHZONE™

Ir al canal en Telegram

TECHZONE CYBERNEWS && UPDATES Wᴇʟᴄᴏᴍᴇ Tᴏ TECHZONE™ ✔️Infosec Facts ✔️Cheatsheets ✔️Free Courses ✔️Open source tools ✔️Tech news

Mostrar más
575
Suscriptores
Sin datos24 horas
-37 días
-1630 días
Atraer Suscriptores
agosto '26
agosto '26
+2
en 0 canales
julio '26
+1
en 0 canales
Get PRO
junio '26
+1
en 0 canales
Get PRO
mayo '26
+2
en 0 canales
Get PRO
abril '26
+1
en 0 canales
Get PRO
marzo '26
+1
en 0 canales
Get PRO
febrero '26
+2
en 0 canales
Get PRO
enero '26
+2
en 0 canales
Get PRO
diciembre '250
en 0 canales
Get PRO
noviembre '250
en 0 canales
Get PRO
octubre '250
en 0 canales
Get PRO
septiembre '250
en 0 canales
Get PRO
agosto '25
+1
en 0 canales
Get PRO
julio '25
+1
en 0 canales
Get PRO
junio '25
+1
en 0 canales
Get PRO
mayo '250
en 0 canales
Get PRO
abril '250
en 0 canales
Get PRO
marzo '250
en 0 canales
Get PRO
febrero '25
+1
en 0 canales
Get PRO
enero '250
en 0 canales
Get PRO
diciembre '24
+1
en 0 canales
Get PRO
noviembre '24
+1
en 0 canales
Get PRO
octubre '240
en 0 canales
Get PRO
septiembre '24
+10
en 0 canales
Get PRO
agosto '24
+4
en 0 canales
Get PRO
julio '240
en 0 canales
Get PRO
junio '24
+1
en 0 canales
Get PRO
mayo '24
+1
en 0 canales
Get PRO
abril '240
en 0 canales
Get PRO
marzo '24
+2
en 0 canales
Get PRO
febrero '24
+9
en 0 canales
Get PRO
enero '24
+2
en 0 canales
Get PRO
diciembre '230
en 0 canales
Get PRO
noviembre '230
en 0 canales
Get PRO
octubre '230
en 0 canales
Get PRO
septiembre '230
en 0 canales
Get PRO
agosto '230
en 0 canales
Get PRO
julio '230
en 0 canales
Get PRO
junio '230
en 0 canales
Get PRO
mayo '230
en 0 canales
Get PRO
abril '230
en 0 canales
Get PRO
marzo '23
+6
en 0 canales
Get PRO
febrero '23
+6
en 0 canales
Get PRO
enero '23
+10
en 0 canales
Get PRO
diciembre '22
+12
en 0 canales
Get PRO
noviembre '22
+42
en 0 canales
Get PRO
octubre '22
+55
en 0 canales
Get PRO
septiembre '22
+135
en 0 canales
Get PRO
agosto '22
+124
en 0 canales
Get PRO
julio '22
+103
en 0 canales
Get PRO
junio '22
+3
en 0 canales
Get PRO
mayo '22
+5
en 0 canales
Get PRO
abril '22
+7
en 0 canales
Get PRO
marzo '22
+7
en 0 canales
Get PRO
febrero '22
+8
en 0 canales
Get PRO
enero '22
+23
en 0 canales
Get PRO
diciembre '21
+49
en 0 canales
Get PRO
noviembre '21
+55
en 0 canales
Get PRO
octubre '21
+101
en 0 canales
Get PRO
septiembre '21
+145
en 0 canales
Get PRO
agosto '21
+230
en 0 canales
Get PRO
julio '21
+208
en 0 canales
Get PRO
junio '21
+315
en 0 canales
Get PRO
mayo '21
+232
en 0 canales
Get PRO
abril '21
+84
en 0 canales
Get PRO
marzo '21
+18
en 0 canales
Get PRO
febrero '21
+29
en 0 canales
Get PRO
enero '21
+35
en 0 canales
Get PRO
diciembre '20
+1 038
en 0 canales
Fecha
Crecimiento de Suscriptores
Menciones
Canales
28 agosto0
27 agosto0
26 agosto0
25 agosto0
24 agosto0
23 agosto0
22 agosto0
21 agosto+1
20 agosto0
19 agosto0
18 agosto0
17 agosto0
16 agosto0
15 agosto0
14 agosto0
13 agosto0
12 agosto0
11 agosto0
10 agosto0
09 agosto0
08 agosto+1
07 agosto0
06 agosto0
05 agosto0
04 agosto0
03 agosto0
02 agosto0
01 agosto0
Publicaciones del Canal
Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network https://thehackernews.com/2026/08/berlin-refuses-to-pay-hackers-who-stole.html Berlin's state government has confirmed that it is the target of an extortion attempt following the August compromise of the city's state administrative network, and said it will not meet the extortionists' demands. The same statement disclosed that forensic work had found further data outflows in the portfolio of the Senate Department for Mobility, Transport, Climate Protection and Environment

2
Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable https://thehackernews.com/2026/08/cosmos-evm-flaw-exploited-after-cosmos.html Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. The vulnerability, designated GHSA-7g4w-cg88-2cq2, is rated Critical by Cosmos Labs and was published without a CVE identifier, a weakness classification, or a CVSS score. Affected versions are < 0.6.2 and >=
1
3
Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication https://thehackernews.com/2026/08/attackers-chain-two-papercut-flaws-to.html Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening. "This vulnerability gives an unauthenticated attacker remote control over PaperCut's trusted configuration, which could be used to execute arbitrary Java code inside the application's
1
4
Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers https://thehackernews.com/2026/08/android-17-adds-os-wide-ech-to-hide.html Google on Thursday announced new network security protections in Android 17 to bolster connection privacy, address cellular vulnerabilities, and safeguard the privacy of users' home networks. Topping the list is support for Encrypted Client Hello (ECH), a privacy standard that prevents networks from eavesdropping on which websites a user is visiting. "This new privacy standard works in tandem
1
5
ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body https://thehackernews.com/2026/08/snowflake-github-actions-flaw-lets.html The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting ownCloud to its Known Exploited Vulnerabilities (KEV) catalog following reports that a Chinese-speaking threat actor weaponized the vulnerability to target a nuclear research body in the Philippines. The vulnerability, tracked as CVE-2023-49105 (CVSS score: 9.8), is a case of
1
6
19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities. The extensions, per Socket security researcher Karlo Zanki, share similarities in code and tradecraft, with evidence indicating that the campaign may have been active
3
7
Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth https://thehackernews.com/2026/08/two-unitree-g1-edu-humanoid-robot-flaws.html Security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU, including a Bluetooth Low Energy (BLE) path that can reach root on the robot's Locomotion PC. The flaws are tracked as CVE-2026-76639 and CVE-2026-76640, with the first involving a network-adjacent path through chat_go and bashrunner and the
4
8
Key Reasons Why Identity Fabric Matters in 2026 https://thehackernews.com/2026/08/key-reasons-why-identity-fabric-matters.html An Identity Fabric knits fragmented identity systems into a coherent layer that observes how identities behave across applications, APIs, and infrastructure. As enterprise access spans more cloud services and automated workloads, identity security depends less on static configuration and more on runtime visibility. This article covers the architecture, the risks of unmanaged identities, and
4
9
Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL https://thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.html ServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring system and exploitable, in certain circumstances, by an unauthenticated attacker. The company said it deployed a security update to hosted instances and provided the update to its partners and self-hosted customers, which leaves organizations that run their
3
10
China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access https://thehackernews.com/2026/08/china-made-zbt-routers-ship-with-two.html VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT), each of which gives an unauthenticated remote attacker the ability to run commands as root on affected devices. The implants, named SPEAKINGSTONE and DARKLANTERN by the company's zero-day research team, are tracked as CVE-2026-74232 and CVE-2026-74233.
3
11
Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server https://thehackernews.com/2026/08/critical-cpanel-flaw-could-let-one.html cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user. The vulnerability, assigned the CVE identifier CVE-2026-65643, impacts all supported versions of cPanel & WHM. cPanel described the issue as a critical security vulnerability and said that an
3
12
PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions https://thehackernews.com/2026/08/papercut-zero-day-exploited-in-attacks.html PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. The company has released an emergency patch for v25 and v26 to address the issue. It said it's "aware of confirmed customer incidents and is treating this matter with the highest priority." An
3
13
APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations https://thehackernews.com/2026/08/apt28-linked-hookedge-backdoor-targets.html Cybersecurity researchers have flagged a fresh set of campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026. These campaigns, per Recorded Future Insikt Group, have led to the deployment of a previously undocumented backdoor dubbed HOOKEDGE, a lightweight Windows batch script that's distributed via
2
14
AI-assisted reconnaissance: Why everyone could be a viable target for fraud https://www.welivesecurity.com/en/privacy/ai-powered-osint-why-everyone-viable-target-fraud/ It’s getting cheaper and easier for cybercriminals to research potential victims. Here’s what’s still in your control.
4
15
OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face https://thehackernews.com/2026/08/openai-says-reward-hacking-drove-ai.html OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, adding that it found evidence of misaligned behavior as early as late May. The incident, the company said, took place during cybersecurity evaluations of several OpenAI models, and that it was mainly fueled by what it described as a "highly capable
4
16
Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE https://thehackernews.com/2026/08/nextjs-patches-critical-avif-and.html Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting servers that use a Windows filesystem. The Windows path traversal, tracked as CVE-2026-75604&
6
17
ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories https://thehackernews.com/2026/08/threatsday-296k-iot-botnet-100-water.html A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine. The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting before showing their real behavior, exposed systems getting scanned, and exploit windows shrinking again. Different
6
18
Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers https://thehackernews.com/2026/08/amazon-kiro-prompt-injection-can.html Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via prompt injection and Kiro Powers. The security flaw, which does not have a CVE identifier, works against Kiro IDE 0.7.45 on Windows, according to Mindguard. The latest version of
6
19
Learn How to Build Security Operations Ready for AI-Powered Attacks https://thehackernews.com/2026/08/learn-how-to-build-security-operations.html Security teams have spent years trying to detect threats faster. AI is changing the harder part: how much time defenders have left to act. Advanced AI models can now help attackers discover vulnerabilities, generate exploit code, and move through weaknesses faster than traditional security processes were built to handle. The challenge is no longer just finding another vulnerability or
6
20
Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks https://thehackernews.com/2026/08/alleged-teampcp-hackers-charged-in.html The Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences over their alleged role in TeamPCP, the cybercrime group behind the March 2026 compromise of the open-source security scanners Trivy and Checkmarx KICS and the AI gateway LiteLLM. Louis Michael Gaebler, 23, and Ruben Ian Thomson, 21, appeared in Perth Magistrates Court on August 27,
6