fa
Feedback
TECHZONE™

TECHZONE™

رفتن به کانال در Telegram

TECHZONE CYBERNEWS && UPDATES Wᴇʟᴄᴏᴍᴇ Tᴏ TECHZONE™ ✔️Infosec Facts ✔️Cheatsheets ✔️Free Courses ✔️Open source tools ✔️Tech news

نمایش بیشتر
574
مشترکین
اطلاعاتی وجود ندارد24 ساعت
-37 روز
-1730 روز
آرشیو پست ها
Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload https://thehackernews.com/2026/08/critical-gitea-rce-actively-exploited.html The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea. The vulnerability in question is CVE-2026-60004 (CVSS score: 9.8), a case of remote code execution that allows an attacker with ordinary write access to a repository to execute arbitrary shell commands as the

Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes https://thehackernews.com/2026/08/fake-apple-support-ai-calls-target.html Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple's Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask for their device passcode. SOCRadar Threat Research Unit (STRU) said the platform, which it tracks as AnonyMousKIT, is credit-metered and drives lures across

U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches https://thehackernews.com/2026/08/us-sanctions-iran-linked-hackers-behind.html The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an "unprecedented, whole-of-government, economic campaign" against the nation and its enablers. "We are launching an economic onslaught against Iran's financial connections around the globe. Our objective is to sever every economic lifeline that sustains this tyrannical regime

A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw https://thehackernews.com/2026/08/a-malicious-webpage-could-poison-your.html Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden instructions inside the model itself. The findings were shared with The Hacker News ahead of publication, and the report says Oasis Security reported them to NVIDIA's Product Security Incident

Frontier AI: Vulnerability Management's Systemic Revolution https://thehackernews.com/2026/08/frontier-ai-vulnerability-managements.html Vulnerability management has been a staple of security programs since the dawn of the cybersecurity discipline. The symbiotic relationship between vulnerability and patch management teams has also existed for that time and has gone through waves of contention and thankfulness. While this relationship required thoughtful care and feeding from both sides, both sides were aiming to work toward a

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access https://thehackernews.com/2026/08/attackers-target-miniorange-saml-flaws.html Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators. The vulnerabilities, as disclosed by Patchstack, are listed below - CVE-2026-61979 (CVSS score: 8.1) - An unauthenticated privilege escalation

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data https://thehackernews.com/2026/08/actively-exploited-oracle-weblogic-flaw.html The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-21962 (CVSS score: 10.0), allows an unauthenticated attacker with network access via HTTP to

Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning https://thehackernews.com/2026/08/weedhack-malware-spreads-via-fake.html Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft clients. McAfee Labs said it detected and blocked more than 6,300 attempts to access malicious sites, adding that it found lookalike gaming websites designed to mimic legitimate projects, including branding, feature lists, FAQs,

⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More https://thehackernews.com/2026/08/weekly-recap-ai-powered-plc-attacks.html A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet. That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes exploit work cheaper, and researchers keep finding attacks that sound harder than they actually are. Plenty to clean up. Here’s the short version. ⚡ Threat of the Week U.S.

WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords https://thehackernews.com/2026/08/wordlistloader-delivers-amatera-via.html Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that's used to deliver next-stage payloads and likely sell access to ransomware groups. According to findings from Gen Digital, WordlistLoader is being used to deliver Amatera Stealer (aka ACR Stealer or AcridRain Stealer) via ClearFake campaigns, which employ the ClickFix (aka FakeCaptcha)

Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt https://thehackernews.com/2026/08/shipping-more-ai-code-than-you-can.html If your developers are using AI coding tools, you are probably already seeing the upside: faster development, more code, and less time spent on routine work. The harder part is what comes after. AI can also introduce open-source packages at a pace your security team was never built to handle. More dependencies mean more vulnerabilities to review, more remediation work, and a backlog that can

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account https://thehackernews.com/2026/08/critical-keycloak-password-reset-flaw.html Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a password reset. The vulnerability, assigned the CVE identifier CVE-2026-18963, is rated 9.1 on the CVSS scoring system by Red Hat, which acts as

Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor https://thehackernews.com/2026/08/operation-quicsilver-targets-myanmar.html Cybersecurity researchers have flagged a cyber espionage campaign targeting Myanmar that uses graduation ceremony invitation lures to deliver a Go backdoor called QUICAgent. The campaign, codenamed Operation QUICSILVER, has been found to target government and information technology sectors, per Seqrite Labs. The activity is assessed to be the work of a China-nexus threat actor with moderate

The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk https://thehackernews.com/2026/08/the-outsized-shadow-why-5-of-ai-users.html Big security risks come in small packages. While enterprise security teams focus on policing the proliferation of employees using ChatGPT and Claude for quick drafting tasks, a more urgent threat is posed by a handful of AI super-adopters who are quietly hardcoding unvetted tools into critical business operations. According to new research published by Akamai, the top 5% of enterprise power

UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit https://thehackernews.com/2026/08/uat-10147-uses-ai-to-scale-server.html Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors. The vast majority of the targets are located in Brazil, Bolivia, China, Canada, and Vietnam. Details of the threat activity came to light following the discovery of an open

TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit https://thehackernews.com/2026/08/tiktok-agrees-to-400-million-settlement.html The U.S. Department of Justice (DoJ) announced on Friday that ByteDance-owned TikTok will pay $400 million to settle a 2024 lawsuit accusing the company of violating child privacy laws in the country. As part of the settlement, the social media platform will pay $300 million immediately, and an additional $100 million "upon entry of an order vacating a prior consent decree entered against

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2 https://thehackernews.com/2026/08/14-trojanized-npm-packages-drop-redc2.html Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2 4.0. "When the module loads, it locates the bundled binary, marks it executable, and launches it as a detached background process," TrendAI, Trend Micro's

Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot https://thehackernews.com/2026/08/microsoft-defenders-own-driver-can-be.html Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine. The driver, BTR.sys (Boot Time Removal Tool), is a

Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet https://thehackernews.com/2026/08/android-car-malware-spreads-through.html Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. Kaspersky, which discovered the threat in June 2026, said the end goal of the malware is to serve a multi-stage downloader to enable ad fraud and creation of a proxy botnet. "The malware spread through the built-in updaters of

Wazuh and AI For Enhanced SOC Workflows https://thehackernews.com/2026/08/wazuh-and-ai-for-enhanced-soc-workflows.html Artificial Intelligence (AI) has become one of this decade's defining technologies. From healthcare and finance to manufacturing and education, organizations increasingly rely on AI to automate repetitive tasks, uncover patterns hidden within large datasets, and support faster decision-making. Cybersecurity has experienced a similar transformation. While attackers employ AI to automate