TECHZONE™
Kanalga Telegram’da o‘tish
TECHZONE CYBERNEWS && UPDATES Wᴇʟᴄᴏᴍᴇ Tᴏ TECHZONE™ ✔️Infosec Facts ✔️Cheatsheets ✔️Free Courses ✔️Open source tools ✔️Tech news
Ko'proq ko'rsatish572
Obunachilar
Ma'lumot yo'q24 soatlar
Ma'lumot yo'q7 kun
-330 kun
Ma'lumot yuklanmoqda...
O'xshash kanallar
Taglar buluti
Kirish va chiqish esdaliklari
---
---
---
---
---
---
Obunachilarni jalb qilish
Sentabr '26Sen '26
Sentabr '26
+5
0 kanalda
Avgust '26
+2
0 kanalda
Get PRO
Iyul '26
+1
0 kanalda
Get PRO
Iyun '26
+1
0 kanalda
Get PRO
May '26
+2
0 kanalda
Get PRO
Aprel '26
+1
0 kanalda
Get PRO
Mart '26
+1
0 kanalda
Get PRO
Fevral '26
+2
0 kanalda
Get PRO
Yanvar '26
+2
0 kanalda
Get PRO
Dekabr '250
0 kanalda
Get PRO
Noyabr '250
0 kanalda
Get PRO
Oktabr '250
0 kanalda
Get PRO
Sentabr '250
0 kanalda
Get PRO
Avgust '25
+1
0 kanalda
Get PRO
Iyul '25
+1
0 kanalda
Get PRO
Iyun '25
+1
0 kanalda
Get PRO
May '250
0 kanalda
Get PRO
Aprel '250
0 kanalda
Get PRO
Mart '250
0 kanalda
Get PRO
Fevral '25
+1
0 kanalda
Get PRO
Yanvar '250
0 kanalda
Get PRO
Dekabr '24
+1
0 kanalda
Get PRO
Noyabr '24
+1
0 kanalda
Get PRO
Oktabr '240
0 kanalda
Get PRO
Sentabr '24
+10
0 kanalda
Get PRO
Avgust '24
+4
0 kanalda
Get PRO
Iyul '240
0 kanalda
Get PRO
Iyun '24
+1
0 kanalda
Get PRO
May '24
+1
0 kanalda
Get PRO
Aprel '240
0 kanalda
Get PRO
Mart '24
+2
0 kanalda
Get PRO
Fevral '24
+9
0 kanalda
Get PRO
Yanvar '24
+2
0 kanalda
Get PRO
Dekabr '230
0 kanalda
Get PRO
Noyabr '230
0 kanalda
Get PRO
Oktabr '230
0 kanalda
Get PRO
Sentabr '230
0 kanalda
Get PRO
Avgust '230
0 kanalda
Get PRO
Iyul '230
0 kanalda
Get PRO
Iyun '230
0 kanalda
Get PRO
May '230
0 kanalda
Get PRO
Aprel '230
0 kanalda
Get PRO
Mart '23
+6
0 kanalda
Get PRO
Fevral '23
+6
0 kanalda
Get PRO
Yanvar '23
+10
0 kanalda
Get PRO
Dekabr '22
+12
0 kanalda
Get PRO
Noyabr '22
+42
0 kanalda
Get PRO
Oktabr '22
+55
0 kanalda
Get PRO
Sentabr '22
+135
0 kanalda
Get PRO
Avgust '22
+124
0 kanalda
Get PRO
Iyul '22
+103
0 kanalda
Get PRO
Iyun '22
+3
0 kanalda
Get PRO
May '22
+5
0 kanalda
Get PRO
Aprel '22
+7
0 kanalda
Get PRO
Mart '22
+7
0 kanalda
Get PRO
Fevral '22
+8
0 kanalda
Get PRO
Yanvar '22
+23
0 kanalda
Get PRO
Dekabr '21
+49
0 kanalda
Get PRO
Noyabr '21
+55
0 kanalda
Get PRO
Oktabr '21
+101
0 kanalda
Get PRO
Sentabr '21
+145
0 kanalda
Get PRO
Avgust '21
+230
0 kanalda
Get PRO
Iyul '21
+208
0 kanalda
Get PRO
Iyun '21
+315
0 kanalda
Get PRO
May '21
+232
0 kanalda
Get PRO
Aprel '21
+84
0 kanalda
Get PRO
Mart '21
+18
0 kanalda
Get PRO
Fevral '21
+29
0 kanalda
Get PRO
Yanvar '21
+35
0 kanalda
Get PRO
Dekabr '20
+1 038
0 kanalda
| Sana | Obunachilarni jalb qilish | Esdaliklar | Kanallar | |
| 29 Sentabr | 0 | |||
| 28 Sentabr | 0 | |||
| 27 Sentabr | 0 | |||
| 26 Sentabr | 0 | |||
| 25 Sentabr | 0 | |||
| 24 Sentabr | +1 | |||
| 23 Sentabr | 0 | |||
| 22 Sentabr | +1 | |||
| 21 Sentabr | 0 | |||
| 20 Sentabr | 0 | |||
| 19 Sentabr | +1 | |||
| 18 Sentabr | 0 | |||
| 17 Sentabr | 0 | |||
| 16 Sentabr | 0 | |||
| 15 Sentabr | 0 | |||
| 14 Sentabr | 0 | |||
| 13 Sentabr | 0 | |||
| 12 Sentabr | 0 | |||
| 11 Sentabr | 0 | |||
| 10 Sentabr | +1 | |||
| 09 Sentabr | 0 | |||
| 08 Sentabr | +1 | |||
| 07 Sentabr | 0 | |||
| 06 Sentabr | 0 | |||
| 05 Sentabr | 0 | |||
| 04 Sentabr | 0 | |||
| 03 Sentabr | 0 | |||
| 02 Sentabr | 0 | |||
| 01 Sentabr | 0 |
Kanal postlari
Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
https://thehackernews.com/2026/09/apple-patches-coregraphics-flaw.html
Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks.
The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write impacting the CoreGraphics component that could lead to arbitrary code execution when processing a maliciously crafted file.
The iPhone maker said the
| 2 | Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks
https://thehackernews.com/2026/09/hackers-use-needymantis-to-maintain.html
Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis.
The malware has been seen in a small number of targeted intrusions at telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Its use goes back to at least | 2 |
| 3 | IAM for AI agents: A Practical Enterprise Framework
https://thehackernews.com/2026/09/iam-for-ai-agent.html
What is IAM for AI agents?
AI agents authenticate, invoke tools, and act across enterprise systems with delegated authority. IAM for AI Agents is the identity-control architecture that governs those actors. This guide covers the limits of conventional provisioning, the components that matter, how to evaluate framework choices, and what runtime evidence proves an agent behaved as intended. | 1 |
| 4 | Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M
https://thehackernews.com/2026/09/bitget-says-attacker-exploited-third.html
The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday.
The attacker exploited the flaw to obtain high-level internal credentials and then, on September 24, used them to send fraudulent withdrawal commands to Bitget's wallet system.
Exchanges keep most | 1 |
| 5 | RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims
https://thehackernews.com/2026/09/rathat-android-malware-console-uses.html
RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy.
The console stores what the malware collects from each phone, | 2 |
| 6 | ⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats
https://thehackernews.com/2026/09/weekly-recap-387m-crypto-hack-citrix.html
A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week this was: forgotten assumptions turning into live attack surface.
Elsewhere, weak service accounts, old bugs, exposed systems, phishing kits, and strangely easy exploit paths kept doing useful work for attackers. Nothing | 7 |
| 7 | Webinar: How to Govern AI Agents, Reduce Excessive Access, and Control Shadow AI
https://thehackernews.com/2026/09/webinar-how-to-govern-ai-agents-reduce.html
AI agents are moving into production faster than security teams can govern them. They are connecting to apps, handling data, calling APIs, and acting across business systems—often without the same controls applied to human users.
According to Okta’s Global CISO Insights 2026 report, only 47% of CISOs are confident they can identify every AI agent in their environment. Even among those who feel | 8 |
| 8 | Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent
https://thehackernews.com/2026/09/carbonato-botnet-compromises-docker.html
Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that's targeting exposed Docker daemons to deploy an open-source artificial intelligence (AI) agent framework called Hermes Agent.
"The implant installs the framework unchanged, then overwrites its SOUL.md persona file," ThreatDown said. "The 39-line prompt directs it to execute tasks received through | 7 |
| 9 | JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources
https://thehackernews.com/2026/09/jadepuffer-linked-attackers-used.html
The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals.
Microsoft, which is tracking the activity under the name Storm-3168, has called it an evolution of the threat actor's tradecraft. The attack took place in early June 2026 over a period of about 18 hours.
"The destructive operations | 7 |
| 10 | CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally
https://thehackernews.com/2026/09/cisa-says-attackers-are-exploiting-two.html
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation.
The vulnerabilities are listed below -
CVE-2026-88771 (CVSS score: 9.5) - An improper input validation vulnerability that could allow an unauthenticated attacker to | 7 |
| 11 | Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
https://thehackernews.com/2026/09/warning-two-unpatched-citrix-netscaler.html
Two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that allow remote code execution are being actively exploited in the wild, security firm watchTowr said on September 26.
Citrix has not confirmed the flaws or published a fix. Some administrators say they have taken appliances offline rather than wait for one to be available.
NetScaler ADC and | 6 |
| 12 | Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
https://thehackernews.com/2026/09/lunex-stealer-abuses-amd-driver-to.html
The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex.
The new findings come from Ontinue, which described the activity as a four-stage attack chain aimed at targeting Ukrainian-speaking users.
"The attack chain begins with a fake CAPTCHA page and | 6 |
| 13 | Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
https://thehackernews.com/2026/09/attackers-bypass-wafs-to-exploit-oracle.html
Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally.
The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score: 9.8), a critical security flaw that could result in unauthenticated remote code execution.
The vulnerability was first exploited as a zero-day | 5 |
| 14 | Zero Trust for AI Agents Starts With Fixing Zero Visibility
https://thehackernews.com/2026/09/zero-trust-for-ai-agents-starts-with.html
The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift. While earlier discourse focused on how quickly organizations could stand up agents and how much productivity they could promise, a string of recent incidents, including a widely discussed intrusion at Hugging Face during an evaluation of OpenAI agents, has spurred organizations to | 5 |
| 15 | Is that vibe coded app safe? 5 checks before you download
https://www.welivesecurity.com/en/mobile-security/is-new-vibe-coded-app-safe-5-questions-ask-first/
As AI lets anyone build software, here’s how to vet that shiny new app before it exposes your data | 7 |
| 16 | Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
https://thehackernews.com/2026/09/elementor-csrf-flaw-lets-attackers-take.html
Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control of a site.
The cross-site request forgery (CSRF) vulnerability, which has yet to be assigned a CVE identifier, carries a CVSS score of 8.8 out of 10.0. It only affects versions | 6 |
| 17 | SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
https://thehackernews.com/2026/09/sharepoint-rce-and-mikrotik-routeros.html
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
The vulnerabilities in question are as follows -
CVE-2026-65660 (CVSS score: 8.8) - A code injection vulnerability in Microsoft Office SharePoint | 7 |
| 18 | Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack
https://thehackernews.com/2026/09/kiteworks-urges-customers-to-shut-down.html
Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received threat intelligence about an imminent cyber attack.
"Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems," said Frank Balonis, Chief | 6 |
| 19 | Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware
https://thehackernews.com/2026/09/compromised-github-actions-came-back.html
Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign.
The affected GitHub Actions are listed below -
actions-cool/issues-helper
actions-cool/maintain-one-comment
Visiting either of the repositories now shows the message: "Access to this | 8 |
| 20 | PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
https://thehackernews.com/2026/09/pamstealer-macos-malware-adds-live-c2.html
Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain.
The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method.
"Where earlier variants embedded their payload key material | 7 |
