fa
Feedback
TECHZONE™

TECHZONE™

رفتن به کانال در Telegram

TECHZONE CYBERNEWS && UPDATES Wᴇʟᴄᴏᴍᴇ Tᴏ TECHZONE™ ✔️Infosec Facts ✔️Cheatsheets ✔️Free Courses ✔️Open source tools ✔️Tech news

نمایش بیشتر
598
مشترکین
-124 ساعت
-37 روز
-1030 روز
آرشیو پست ها
BTMOB: A stealthy RAT burrowing deep into Android devices https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/ The malware pairs remote access capabilities with ready-made campaign tools, lowering the barrier for full device compromise

MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries https://thehackernews.com/2026/05/muddywater-uses-dll-side-loading-in.html The Iranian hacking group known as MuddyWater has been linked to a new campaign affecting at least nine organizations across nine countries on four continents in the first quarter of 2026. The activity targeted industrial and electronics manufacturing, education and public-sector bodies, financial services, and professional services, per the Threat Hunter Team from Symantec and Carbon Black.

New AI DDoS Attacks Are Smarter. Learn How to Fight Back in This Webinar https://thehackernews.com/2026/05/new-ai-ddos-attacks-are-smarter-learn.html Every single day, hackers are finding new ways to crash websites and steal data. But right now, something has changed. Hackers are no longer working alone. They are now using powerful Artificial Intelligence (AI) tools to make their attacks faster, stronger, and much harder to stop. According to recent updates from The Hacker News, bad actors are using AI to find weak spots in systems and

Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions https://thehackernews.com/2026/05/microsoft-patches-sharepoint-rce-flaw.html Microsoft has rolled out updates to fix a remote code execution vulnerability impacting SharePoint that could be exploited by bad actors in attacks without requiring any specialized conditions to be met. The vulnerability, tracked as CVE-2026-45659, carries a CVSS score of 8.8. It has been assigned an important severity. "Deserialization of untrusted data in Microsoft Office SharePoint allows

MFA Prompt Bombing: Why Your Second Factor Isn't Saving You https://thehackernews.com/2026/05/mfa-prompt-bombing-why-your-second.html Multi-factor authentication (MFA) was supposed to close a critical gap in identity security. It meant that, even if an attacker possessed the account credentials, they couldn't log in without the second factor. While that logic was sound, attackers have now figured out that they don't need to steal the second factor: they just need the user to hand it over. If your workforce authenticates with

CERT-In Mandates 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks https://thehackernews.com/2026/05/cert-in-mandates-12-hour-patching-for.html The Indian Computer Emergency Response Team (CERT-In) has issued new guidelines requiring organizations to patch critical security vulnerabilities in internet-exposed systems within 12 hours of being flagged where "feasible" to safeguard against potential threats stemming from threat actors' abuse of artificial intelligence (AI) tools and large language models (LLMs) to automate vulnerability

Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO Poisoning https://thehackernews.com/2026/05/iranian-hackers-deploy-minifast-and.html The Iranian state-sponsored threat actor known as Nimbus Manticore (aka Screening Serpens and UNC1549) has been attributed to a fresh campaign using lures impersonating organizations in the aviation and software sectors across the U.S., Europe, and the Middle East following the joint U.S.-Israeli military campaign against the country in late February 2026. The activity, besides embracing

KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike https://thehackernews.com/2026/05/knowledgedeliver-lms-flaw-exploited-to.html A now-patched high-severity security flaw affecting Digital Knowledge KnowledgeDeliver, a Learning Management System (LMS) popular in Japan, was exploited as a zero-day to deliver the Godzilla web shell and ultimately facilitate the deployment of Cobalt Strike Beacon. The vulnerability, tracked as CVE-2026-5426 (CVSS score: 7.5), stems from the use of hard-coded ASP.NET machine keys, leading to

⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos https://thehackernews.com/2026/05/weekly-recap-linux-flaws-defender-0.html Monday recap. Same mess, new week. A sketchy dev tool got people pwned, old bugs came back from the dead, and security products somehow needed protecting from themselves. A bunch of companies spent the week checking old boxes and forgotten servers they should've patched years ago. Good times. Phishing crews are getting smarter too - less obvious scam junk, more targeted stuff that actually

Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks https://thehackernews.com/2026/05/ghost-cms-cve-2026-26980-exploited-to.html Threat actors are exploiting a recently disclosed critical security flaw in Ghost CMS to inject malicious JavaScript code with an aim to fuel ClickFix attacks. According to QiAnXin XLab, the activity involves the exploitation of CVE-2026-26980 (CVSS score: 9.4), an SQL injection vulnerability in Ghost's Content API that could allow an unauthenticated attacker to read arbitrary data from the

The Alert Firehose Finally Meets Its Match https://thehackernews.com/2026/05/the-alert-firehose-finally-meets-its.html Ask a cybersecurity pro about Network Detection and Response (NDR) and you might still hear "Noisy," "Too much data." But ask the teams running NDR that includes agentic AI capabilities and you'll hear they're actually using it to catch threats earlier, triage faster, and chase fewer false positives. The old complaint lingers in part because reputations are sticky, and because NDR has evolved

Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms https://thehackernews.com/2026/05/lazarus-deploys-remotepe-memory-only.html Cybersecurity researchers have shed light on a cross-platform malware called RemotePE that has been put to use by the North Korea-linked Lazarus Group in attacks targeting financial and cryptocurrency organizations. RemotePE, per NCC Group subsidiary Fox-IT, is part of a multi-stage attack chain that involves two loaders tracked as DPAPILoader and RemotePELoader. "DPAPILoader decrypts and

TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO https://thehackernews.com/2026/05/trapdoor-supply-chain-attack-spreads.html A new coordinated cross-ecosystem software supply chain attack campaign has targeted npm, PyPI, and Crates.io to distribute credential-stealing malware. The campaign, codenamed TrapDoor, spans more than 34 malicious packages across over 384 versions. The earliest activity was recorded on May 22, 2026, at 8:20 p.m. UTC, with new packages published to the ecosystems in waves from a cluster of

npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks https://thehackernews.com/2026/05/npm-adds-2fa-gated-publishing-and.html GitHub has rolled out new controls for npm to improve the security of the software supply chain, giving maintainers the ability to explicitly approve a release prior to the packages becoming publicly available for installation. Called staged publishing, the feature is now generally available on npm. It mandates that a human maintainer pass a two-factor authentication (2FA) challenge to approve

Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware https://thehackernews.com/2026/05/packagist-supply-chain-attack-infects-8.html A new "coordinated" supply chain attack campaign has impacted eight packages on Packagist including malicious code designed to run a Linux binary retrieved from a GitHub Releases URL. "Although the affected packages were all Composer packages, the malicious code was not added to composer.json," Socket said. "Instead, it was inserted into package.json, targeting projects that ship JavaScript

Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software https://thehackernews.com/2026/05/claude-mythos-ai-finds-10000-high.html Anthropic on Friday disclosed that Project Glasswing has helped uncover more than 10,000 high- or critical-severity vulnerabilities across some of the most "systemically" important software across the world since the cybersecurity initiative went live last month. Project Glasswing is a defensive effort launched by the artificial intelligence (AI) company to secure critical global software

Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer https://thehackernews.com/2026/05/laravel-lang-php-packages-compromised.html Cybersecurity researchers have flagged a fresh software supply chain attack campaign that has targeted multiple PHP packages belonging to Laravel-Lang to deliver a comprehensive credential-stealing framework. The affected packages include - laravel-lang/lang laravel-lang/http-statuses laravel-lang/attributes laravel-lang/actions "The timing and pattern of the newly published tags

LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root https://thehackernews.com/2026/05/litespeed-cpanel-plugin-cve-2026-48172.html A maximum-severity security vulnerability impacting LiteSpeed User-End cPanel Plugin has come under active exploitation in the wild. The flaw, tracked as CVE-2026-48172 (CVSS score: 10.0), relates to an instance of incorrect privilege assignment that an attacker could abuse to run arbitrary scripts with elevated permissions. "Any cPanel user (including an attacker or a compromised account) may

Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV https://thehackernews.com/2026/05/drupal-core-sql-injection-bug-actively.html The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a recently patched critical security flaw impacting Drupal Core to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerability in question is CVE-2026-9082 (CVSS score: 6.5), an SQL injection vulnerability affecting all supported versions of Drupal Core. "Drupal Core

Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise https://www.welivesecurity.com/en/cybersecurity/foul-play-fake-fifa-world-cup-websites-tickets/ Watch out for bogus World Cup websites that mimic official ticket and merchandise flows to steal money and personal data