-->
#1 Trusted Cybersecurity News Platform
Followed by 5.70+ million
The Hacker News Logo
Get the Latest News
cybersecurity

The Hacker News | #1 Trusted Source for Cybersecurity News

BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS

BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS

Sep 17, 2026 Vulnerability / DNS Security
The Internet Systems Consortium (ISC) has released  BIND 9.20.29 and 9.21.26  to fix fourteen security flaws it  disclosed  on 16 September in BIND 9, its open-source DNS server software. One of them affects any BIND server that answers DNS-over-HTTPS (DoH). A sender with no credentials can crash the server process, named, with a single request that carries an invalid SIG(0) signature, if the sender closes the connection before named finishes checking the signature. ISC said in its advisories that it is not aware of any of the fourteen being exploited. Which Release Fixes What The fixed releases, described in ISC's  release notes , are: BIND 9.20.29, on the current stable branch: fixes all fourteen BIND 9.21.26, on the development branch: fixes thirteen, because CVE-2026-19662 does not affect 9.21 BIND 9.20.29-S1, the Supported Preview Edition for support customers: fixes all fourteen ISC lists no workarounds for any of the...
Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records

Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records

Sep 17, 2026 Data Breach / Web Security
A security breach at Gyazo , Helpfeel's image-sharing service, exposed about 23.62 million user records, including email addresses and password hashes, the Kyoto-based company said in a  notice  published Wednesday. It also exposed about 490 million image metadata records, mostly for images from January 2019 or earlier, including the IDs that make up Gyazo image links. Helpfeel said those IDs could be used to view the images without permission, and that it has temporarily disabled viewing of some of them. Helpfeel asked every Gyazo user to change their password and to change it on any other service that uses the same or a similar one. It also asked users to watch for suspicious emails or messages related to the incident. The attacker gained access through a vulnerability in Gyazo's image upload server, ran arbitrary commands on Helpfeel's systems, and accessed Gyazo's database, the company said. It has not said what kind of flaw it was. Helpfeel said no pay...
Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

Sep 17, 2026 Vulnerability / Web Security
Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation. The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attacker to bypass authentication. "This vulnerability is due to insufficient authentication control on an API endpoint," Cisco said. "An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface." The issue affects Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC), regardless of device configuration. It has been addressed in the following versions -
cyber security

AI Security's Greatest Hits

websiteWizAI Security / Cheat Sheet
Get 7 of the most widely used AI security resources in one pack. Each asset provides practical tools for securing AI apps, models, and agents.
U.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacks

U.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacks

Sep 17, 2026 Cybercrime / DDoS-for-Hire
The U.S. Department of Justice (DoJ) on Tuesday announced the court-authorized seizure of internet domains associated with a distributed denial-of-service (DDoS)-for-hire service known as NightmareStresser. The domains in question are: nightmare-stresser[.]com and nightmarestresser[.]org. Visitors to the site are now greeted by a seizure banner that states - "This domain has been seized by the Federal Bureau of Investigation in accordance with a seizure warrant pursuant to 18 U.S.C. §§ 981(a)(1)(A) and (b), 982(b)(1), and 1030(i) (1)(A); and 21 U.S.C. § 853 issued by the United States District Court for the District of Alaska as part of a joint international law enforcement operation and action by: United States Attorney's Office for the District of Alaska, Federal Bureau of Investigation (FBI) Anchorage Field Office, [and] Royal Canadian Mounted Police (RCMP)." These so-called booter services are usually advertised as stress testing utilities but have been used to...
Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution

Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution

Sep 16, 2026 Vulnerability / Web Security
A critical security flaw in Issabel Framework , a web-based framework for the open-source unified communications PBX software, has come under active exploitation. The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote attacker to execute arbitrary operating system (OS) commands by taking advantage of a hard-coded JSON Web Token (JWT) signing key. The Issabel Framework "contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens," VulnCheck said in an alert. "Attackers can use the forged token to call the manager '/pbxapi/manager/originate' endpoint with the System application parameter, causing Asterisk to execute arbitrary OS commands as the Asterisk user." A patch for the vulnerability was pushed on August 1, 2026, and plugs the flaw by r...
cyber security

Free Assessment: Identify Hidden Internal Risk

websiteBitdefenderAttack Surface / Threat Detection
Discover unnecessary user access to risky tools, shadow IT, based on real user behavior.
Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers

Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers

Sep 16, 2026 Malware / Vulnerability
Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle , Hacking Cat , and Toy Ghouls , according to multiple reports from Kaspersky. The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a threat actor known to be active since at least 2023, that involve new techniques for persistence and lateral movement. "In most incidents, the attackers used compromised valid credentials to gain access to corporate VPNs," Kaspersky said in an analysis published today. "VPN connections originated from IP addresses in the Russian segment linked to Cloudflare WARP tunnels, as well as from IP addresses associated with European virtual infrastructure providers." The attacks, as highlighted in July 2025, involve the deployment of GhostContainer , a known modular backdoor that grants the operators complete access to a victim's Microsoft Exchange Server, as well as run arbitrary code, ...
One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude

One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude

Sep 16, 2026 Vulnerability / Browser Security
Security researchers at Forever Security have shown that one ordinary browser extension could take control of the AI assistants built into five Chromium-based products: Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon and the Claude in Chrome extension. Once the extension was installed, it could access each product's built-in AI with a single click. On Comet, Edge, Opera Neon, and Claude in Chrome, it could drive the AI agent to act on behalf of the attacker; on Chrome and Comet, it could read files from the user's computer, and on Chrome, it could also switch on the camera and microphone. The findings are researcher demonstrations, not attacks seen in the wild, and each requires the attacker's extension to be already running in the victim's browser. These products all work the same way. The AI has a "body" inside the browser that can see the screen, open files, use the camera, and take actions, and a "brain" that runs on th...
Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories

Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories

Sep 16, 2026 Artificial Intelligence / Software Security
Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread  Shai-Hulud  across about 100 internal code repositories. Before the repository spread, the assistant recommended software that the attacker had poisoned, and the recommendation was accepted. The worm stole repository secrets and source code for the company's products. The case appears in  Mandiant's September 2026 report . The public case study does not say when the intrusion happened or how the attacker took over the active coding-assistant session. How the Attack Unfolded After the recommendation was accepted, the attacker used the developer's active session to install an infostealer through a poisoned PyPI package. The attacker also stole GitHub OAuth tokens. The attacker then deployed the self-spreading Shai-Hulud worm across approximately 100 internal code repositories. The attacker also poisoned a package in the company...
Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix

Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix

Sep 16, 2026 Vulnerability / Endpoint Security
Parallels Desktop for Mac has a flaw that lets an ordinary local account run code as root, the highest level of access on a Mac, software company JFrog said this week. The attack needs code already running on the machine as a normal user, so it does not work over the network. JFrog says the fix is in Parallels Desktop 27, a version that Intel Macs cannot install. Yuval Moravchick, who leads JFrog's vulnerability research team,  published the finding  on Tuesday and calls it ParaShells. The flaw is tracked as  CVE-2026-90894 , an identifier JFrog assigned itself, and JFrog rates it 7.8 out of 10. Parallels Desktop runs Windows and Linux inside virtual machines on a Mac. It installs a background service called prl_disp_service that runs as root, because its work includes setting up host networking and unpacking virtual machine packages. The flaw is on the Mac side of the product, so the machine at risk is the Mac itself rather than the virtual machines on...
N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security

N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security

Sep 16, 2026 Identity Security / Web Security
N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate authentication flows. Successful attacks can give threat actors access to valid accounts without relying on obvious malware activity. From there, a single compromised identity can open the door to sensitive data, business systems, and additional cloud resources. The longer that access goes unnoticed, the greater the potential for wider compromise, operational disruption, and financial loss. N0va Is Reaching Organizations Across High-Risk Sectors N0va activity has been observed across organizations in government, technology, consulting, healthcare, and other sectors in North America and Europe. Its use of trusted business platforms and cloud services makes the campaign relevant across a wide range of organizations. N0va phishing campaign attack details Related activity can be traced in ANY.RUN’s Threat Intelligence Lookup using a chara...
Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation

Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation

Sep 16, 2026 Vulnerability / Mobile Security
Google has disclosed that a high-severity security flaw in its Pixel Cellular Modem has come under exploitation in the wild. The vulnerability, tracked as CVE-2026-58704 (CVSS score: 8.0), is a privilege escalation flaw. "In Cellular Modem, there is a possible permission bypass due to a logic error in the code," according to a description of the bug in the NIST National Vulnerability Database (NVD). "This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation." In an advisory issued Tuesday, Google acknowledged that it has found indications that "CVE-2026-58704 may be under limited, targeted exploitation" but stopped short of sharing any further details surrounding the nature of the attacks exploiting it, as well as the identity of the threat actor behind them. Besides CVE-2026-58704, Google has addressed 109 other security flaws as part of...
Threat Intelligence Alone Won't Close the Exploitation Gap

Threat Intelligence Alone Won't Close the Exploitation Gap

Sep 16, 2026 Threat Intelligence / Security Validation
A leaked credential shows up in a criminal marketplace, or a vulnerability gets a disclosure advisory, and either one can be weaponized against a real target before most security teams have triaged the alert. Attackers are combining that kind of intelligence with AI-assisted exploitation to accelerate the path from exposure to breach faster than most security programs are built to react. Intelligence is still the earliest signal defenders get, and a leaked credential turning up in a feed is proof of how useful that signal has become. The problem sits one step later, in what happens after the signal arrives. The Queue Where Risk Accumulates In most organizations, a high-value indicator waits in a queue instead of getting acted on right away, until someone with the offensive skill to test it actually has the time to determine whether it's exploitable in that specific environment, on that specific day. That queue, more than any shortage of intelligence, is where exposure builds...
Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks

Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks

Sep 16, 2026 Vulnerability / Linux
Acronis has warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the wild. The vulnerability, tracked as CVE-2026-87886 (CVSS score: 7.8), is described as a case of local privilege escalation due to insecure file permissions. It affects the following versions - Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021 - Fixed in 1.9.3 HF3 Acronis Backup extension for Plesk (Linux) before build 1.8.11.638 Successful exploitation of the flaw could allow an attacker with low privileges to escalate their permissions on a susceptible Linux version, potentially enabling them to perform unauthorized actions or run arbitrary code that could impact the confidentiality and integrity of the application. "This update contains fixes for 1 high-severity security vulnerability and should be installed immediately by all users," Acronis noted in a separate advisory for 1.9.3 HF3...
Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

Sep 16, 2026 Vulnerability / Web Security
Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs. "This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution," Wordfence said . The WordPress security company said it has blocked over 100,000 exploit attempts targeting the vulnerability since June 2026, with 99 of those attack attempts recorded over the past 24 hours. The vulnerability is tracked as CVE-2026-27540 (CVSS score: 9.8). The issue is a case of arbitrary file uploads due to missing file type validation in an AJAX action named "wwlc_file_upload_handler" that impacts all versions of the plugin up to, and including, 2.0.3.1. This opens the door for an unauthenticated attacker to upload arbitrary files on the affected site's server, paving the way for remote code execution. In the attack obse...
Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

Sep 16, 2026 Vulnerability / API Security
A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr. The vulnerability, tracked as CVE-2026-5430 (CVSS score: 9.8/10.0), is a case of improper verification of a cryptographic signature that could result in account takeover. Hacktron Team has been credited with discovering and reporting the flaw. "JWT authentication can be bypassed when a token is signed using an unsupported algorithm, allowing unauthorized access," according to an advisory released by WSO2 in May 2026. "Successful exploitation of the vulnerability may lead to unauthorized access, including potential compromise of administrative accounts and full account takeover." The shortcoming affects the following products - WSO2 API Control Plane: 4.6.0, 4.5.0 WSO2 API Manager: 4.6.0, 4.5.0, 4.4.0, 4.3.0, 4.2.0, 4.1.0 WSO2 Traffic Manager: 4.6.0, 4.5.0 WSO2 Universal Gateway: 4.6.0, 4.5.0 Fixes are available...
KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Sep 15, 2026 Cybercrime / Browser Security
Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN . Elastic Security Labs is tracking the activity under the moniker REF9334 . Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and Microsoft Edge. "The KREMLIN malware ecosystem employs multi-stage JavaScript loaders, custom C++ installers, and malicious browser extensions to steal credentials, session tokens, and sensitive data," security researchers Cyril François and Andrew Pease said in a technical report shared with The Hacker News. "Malicious browser extensions bypass Chromium integrity mechanisms by manipulating Secure Preferences and regenerating required HMACs, and App-Bound encrypted hashes." A defining aspect of the operation is the use of blockchain to conceal the threat actor-controlled...
⚡ Top Stories This Week
Expert Insights Articles Videos
Cybersecurity Resources