162 000подписчиков сейчас
Публикации всего: 148
🚨 Berlin refuses to pay hackers after data was stolen from the city’s state network.
Rhysida ransomware crew claims 5.79 TB of data and personal information on 12,076 people on its leak site, while Berlin officials say personal or other non-public data may be among what was taken.
Read: https://thehackernews.com/2026/08/berlin-refuses-to-pay-hackers-who-stole.html
👍 5 🔥 1
Перейти к публикации →
‼️ A patch for a fund-draining flaw in Cosmos EVM, software used by multiple blockchains, was public in May but didn’t reach a release until Aug. 19.
Cosmos Labs says six blockchains were exploited after it had already confirmed all Cosmos EVM chains were affected.
Attackers sold ~$2.87M on DEXs and an estimated $2.85M on CEXs.
Read: https://thehackernews.com/2026/08/cosmos-evm-flaw-exploited-after-cosmos.html
😁 3 👍 2 🔥 1 · всего 8
Перейти к публикации →
19 Chrome and Edge extensions were turned into crypto-stealing tools.
The actor buys legitimate extensions or builds clean ones, waits for them to gain users, then pushes malicious updates capable of stealing wallet secrets, credentials, and draining crypto.
How the trusted-extension strategy works: https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html
🤯 5 😁 4 🔥 1
Перейти к публикации →
An ownCloud flaw was exploited to steal 176 files from a Philippine nuclear research body.
The 372 MB haul included nuclear-material records, strategic plans, employee data, BitLocker keys, and a KeePass database. CISA has added CVE-2023-49105 to its KEV catalog.
Read: https://thehackernews.com/2026/08/snowflake-github-actions-flaw-lets.html
🤯 6 😁 4 🔥 1
Перейти к публикации →
Android 17 can hide the sites you visit from network providers.
Google is bringing ECH across the OS, obscuring destination domain names for supported sites and apps. Android 17 also adds local-network permission prompts and carrier-controlled 2G blocking.
How the new privacy protections work: https://thehackernews.com/2026/08/android-17-adds-os-wide-ech-to-hide.html
👏 7 😁 4 🔥 2 · всего 15
Перейти к публикации →
Attackers are exploiting two PaperCut flaws to gain unauthenticated RCE.
Huntress has confirmed limited exploitation in two customer environments, where attackers executed commands and deployed a Java class file on compromised servers.
How the two flaws are chained: https://thehackernews.com/2026/08/attackers-chain-two-papercut-flaws-to.html
🚨 Two vulnerabilities in the Unitree G1 EDU humanoid robot enable root RCE.
One chain abuses path traversal. The other starts over Bluetooth and reaches a Wi-Fi provisioning buffer overflow for root execution on the Locomotion PC.
How both chains reach root → https://thehackernews.com/2026/08/two-unitree-g1-edu-humanoid-robot-flaws.html
😁 6 🤔 3 😱 2 · всего 12
Перейти к публикации →
Identity Fabric shows what identities actually do, not just what access policy allows.
It connects activity across apps, APIs, cloud infrastructure, and identity systems to expose runtime gaps across human, machine, and AI identities.
How it closes the visibility gap: https://thehackernews.com/2026/08/key-reasons-why-identity-fabric-matters.html
‼️ Three new critical ServiceNow flaws score a maximum CVSS 10.0 and require no authentication.
They can enable arbitrary code execution, privilege escalation, or arbitrary SQL against an instance. ServiceNow says it is not aware of exploitation.
Details here: https://thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.html
👏 2 🔥 1
Перейти к публикации →
🚨 China-made ZBT routers ship with two factory implants.
One accepts unauthenticated commands over an internet-exposed UDP service to run commands as root. The other can exfiltrate PPPoE credentials, alter DNS hijack lists, and open reverse SSH tunnels.
How the implants work → https://thehackernews.com/2026/08/china-made-zbt-routers-ship-with-two.html
🔥 4 🤔 2 ⚡ 1 · всего 10
Перейти к публикации →