TECHZONE™
رفتن به کانال در Telegram
TECHZONE CYBERNEWS && UPDATES Wᴇʟᴄᴏᴍᴇ Tᴏ TECHZONE™ ✔️Infosec Facts ✔️Cheatsheets ✔️Free Courses ✔️Open source tools ✔️Tech news
نمایش بیشتر575
مشترکین
اطلاعاتی وجود ندارد24 ساعت
-37 روز
-1630 روز
آرشیو پست ها
575
What the Data Says About AI in Security Operations in 2026
https://thehackernews.com/2026/08/what-data-says-about-ai-in-security.html
AI is officially mainstream in security operations. According to Prophet Security's State of AI in Security Operations 2026 report (produced from ViB’s survey of 250+ cybersecurity pros), 40% of security teams now use AI daily. Another 56% are currently testing it out, and only 4% have no plans to adopt it.
For the teams already using AI, what is actually changing? Here are the ten biggest
575
Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools
https://thehackernews.com/2026/08/spark-rat-targets-cambodia-abuses.html
Individuals and organizations in Cambodia have emerged as the target of a new campaign that delivers an open-source remote access trojan (RAT) called Spark RAT.
"The samples employ diverse lure themes, suggesting an effort to appeal to a broad range of potential victims. These include government notices, public health materials, real estate-related content, and other topics," Acronis Threat
575
GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address
https://thehackernews.com/2026/08/gocaracal-malware-uses-ethereum-smart.html
Threat actors linked by Arctic Wolf to Dark Caracal with medium confidence deployed a previously undocumented Go-based malware framework, GoCaracal, during a June 2026 intrusion at an unnamed communications organization in Venezuela.
GoCaracal provides operators with remote shell access and payload execution, while the extended profile adds browser data theft, keylogging, remote desktop control
575
New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access
https://thehackernews.com/2026/08/gputhor-rowhammer-defeats-ecc-on-nvidia.html
Academic researchers have disclosed a Rowhammer attack impacting NVIDIA workstation GPUs with GDDR6 memory that defeats error correction codes (ECC), the mitigation NVIDIA recommends against GPU Rowhammer, and enables denial-of-service (DoS) and privilege escalation to a root shell.
Dubbed GPUThor, the attack was developed by researchers at the University of Toronto, who hammered four DRAM
575
CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs
https://thehackernews.com/2026/08/cisa-adds-six-exploited-flaws-to-kev.html
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation.
The vulnerabilities are listed below -
CVE-2019-1068 - A remote code execution vulnerability in
575
FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
https://thehackernews.com/2026/08/fbi-disrupts-china-linked-qtfy.html
The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country.
The activity has been attributed to a Chinese state-sponsored group known as QTFY, employed by Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司).&
575
Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler
https://thehackernews.com/2026/08/nimbus-manticore-expands-toolset-with.html
Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC).
Group-IB, in a new analysis published today, described the cyber espionage actor as among the most active Iranian APT groups in 2026. Nimbus Manticore (aka
575
OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation
https://thehackernews.com/2026/08/openai-bans-russian-chatgpt-accounts.html
OpenAI on Tuesday said it banned a cluster of Russian ChatGPT accounts that used VPNs to bypass access restrictions and run an influence operation, which relied on its artificial intelligence (AI) tool to generate social media posts and comments that were shared on Substack, Telegram, X, Facebook and LinkedIn.
The accounts "were being used to promote the International Burke Institute (IBI), a
575
INTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud Crackdown
https://thehackernews.com/2026/08/interpol-operation-jackal-iv-arrests-58.html
An eight-month INTERPOL operation targeting West African organized crime groups has led to arrests of 58 people and the identification of 263 suspects.
"The operation, which brought together 22 countries from six continents, is a response to the escalating global threat posed by West African criminal networks – such as the Black Axe and other similar groups," INTERPOL said.
"These groups are
575
New SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode
https://thehackernews.com/2026/08/newly-sleepwalker-backdoor-waits-for.html
An independent malware researcher has documented a previously unreported Windows backdoor, dubbed SLEEPWALKER, that stays inert in memory until a specifically crafted network packet reaches the machine and then runs commands written in a 23-instruction language of its own design.
The sample is an unsigned 64-bit Windows dynamic-link library (DLL) of 59,904 bytes, built to be side-loaded into&
575
Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload
https://thehackernews.com/2026/08/critical-gitea-rce-actively-exploited.html
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea.
The vulnerability in question is CVE-2026-60004 (CVSS score: 9.8), a case of remote code execution that allows an attacker with ordinary write access to a repository to execute arbitrary shell commands as the
575
Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes
https://thehackernews.com/2026/08/fake-apple-support-ai-calls-target.html
Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple's Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask for their device passcode.
SOCRadar Threat Research Unit (STRU) said the platform, which it tracks as AnonyMousKIT, is credit-metered and drives lures across
575
U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches
https://thehackernews.com/2026/08/us-sanctions-iran-linked-hackers-behind.html
The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an "unprecedented, whole-of-government, economic campaign" against the nation and its enablers.
"We are launching an economic onslaught against Iran's financial connections around the globe. Our objective is to sever every economic lifeline that sustains this tyrannical regime
575
A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw
https://thehackernews.com/2026/08/a-malicious-webpage-could-poison-your.html
Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden instructions inside the model itself.
The findings were shared with The Hacker News ahead of publication, and the report says Oasis Security reported them to NVIDIA's Product Security Incident
575
Frontier AI: Vulnerability Management's Systemic Revolution
https://thehackernews.com/2026/08/frontier-ai-vulnerability-managements.html
Vulnerability management has been a staple of security programs since the dawn of the cybersecurity discipline. The symbiotic relationship between vulnerability and patch management teams has also existed for that time and has gone through waves of contention and thankfulness. While this relationship required thoughtful care and feeding from both sides, both sides were aiming to work toward a
575
Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access
https://thehackernews.com/2026/08/attackers-target-miniorange-saml-flaws.html
Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators.
The vulnerabilities, as disclosed by Patchstack, are listed below -
CVE-2026-61979 (CVSS score: 8.1) - An unauthenticated privilege escalation
575
Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
https://thehackernews.com/2026/08/actively-exploited-oracle-weblogic-flaw.html
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
The vulnerability, tracked as CVE-2026-21962 (CVSS score: 10.0), allows an unauthenticated attacker with network access via HTTP to
575
Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning
https://thehackernews.com/2026/08/weedhack-malware-spreads-via-fake.html
Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft clients.
McAfee Labs said it detected and blocked more than 6,300 attempts to access malicious sites, adding that it found lookalike gaming websites designed to mimic legitimate projects, including branding, feature lists, FAQs,
575
⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
https://thehackernews.com/2026/08/weekly-recap-ai-powered-plc-attacks.html
A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet.
That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes exploit work cheaper, and researchers keep finding attacks that sound harder than they actually are.
Plenty to clean up. Here’s the short version.
⚡ Threat of the Week
U.S.
575
WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
https://thehackernews.com/2026/08/wordlistloader-delivers-amatera-via.html
Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that's used to deliver next-stage payloads and likely sell access to ransomware groups.
According to findings from Gen Digital, WordlistLoader is being used to deliver Amatera Stealer (aka ACR Stealer or AcridRain Stealer) via ClearFake campaigns, which employ the ClickFix (aka FakeCaptcha)
