Live

Intelligence Feed

Latest threat intelligence articles from trusted security sources, auto-processed to extract entities, IoCs, and TTPs.

Filtered by source: hacker-news Clear filter
Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot

1mo ago · hacker-news

Researchers at Binarly discovered six vulnerabilities in U-Boot, a widely used bootloader for embedded devices, which could allow attackers to crash devices or execute arbitrary code during the boot process. Two of the flaws enable memory corruption that could lead to code execution before OS loading, undermining the device's chain of trust. The vulnerabilities affect U-Boot versions since v2013.07 and are present in numerous vendor firmwares, though no active exploitation has been reported. Fixes have been merged upstream but are not yet available in a stable release, with the next version expected in October.

Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages

1mo ago · hacker-news

Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and published a malicious npm package, @injectivelabs/[email protected], designed to steal cryptocurrency wallet private keys and mnemonic phrases. The malware was distributed through 17 additional scoped npm packages, increasing its reach to transitive users. The malicious code evaded detection by avoiding lifecycle scripts and exfiltrated sensitive data via HTTPS POST requests to a remote server.

4 IoCs
Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking

1mo ago · hacker-news

A study of 281 free Android VPN apps found widespread security and privacy issues, including traffic leaks, unencrypted data transmission, and tracking behaviors. Many apps failed to properly encrypt traffic, with five apps vulnerable to tunnel hijacking due to unencrypted configuration downloads. The research highlights poor maintenance, weak encryption practices, and misleading trust signals like Google's 'Verified' badge, undermining user privacy expectations.

2 CVEs
Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites

1mo ago · hacker-news

A cybercrime group operating under the name WP-SHELLSTORM left a server exposed for 22 days, revealing their infrastructure and tools used to backdoor over 5,700 WordPress and Joomla sites. The group exploited known vulnerabilities in plugins like Breeze (CVE-2026-3844) and Joomla JCE (CVE-2026-48907), deploying webshells such as down.php and using the SNOWLIGHT dropper to install the VShell backdoor. The exposed server contained logs, exploit scripts, and target lists of over 1.4 million domains, highlighting a financially motivated, Chinese-speaking crew with poor operational security.

7 IoCs 1 Actors 2 Malware 2 CVEs
From 17,000 to 1.1 Million Assets: How Lumen Technologies Rebuilt Exposure Management at Scale

1mo ago · hacker-news

The article details how Lumen Technologies overhauled its exposure management by improving asset inventory accuracy, revealing a massive discrepancy between known and actual assets. By integrating data from over 40 systems using Axonius, they identified approximately 1.1 million devices—60 times more than initially believed. This enhanced visibility enabled faster zero-day response, improved application risk assessment, and informed strategic decisions like cloud migration and increased security investment. The case highlights the critical role of accurate asset data in effective cybersecurity and risk management.

Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers

1mo ago · hacker-news

A critical unpatched vulnerability dubbed XRING in Alibaba's XQUIC library allows remote clients to crash HTTP/3 servers using legitimate QPACK traffic. The flaw stems from an integer underflow during dynamic table resizing in QPACK, leading to out-of-bounds memory copy and server crash. The vulnerability affects all XQUIC versions up to v1.9.4 and impacts servers using HTTP/3 with default QPACK settings, including those behind Alibaba's Tengine web server. No patch or CVE has been assigned as of July 10, 2026.

2 CVEs
New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic

1mo ago · hacker-news

The China-linked threat actor Silver Fox has been linked to a new Rust-based remote access trojan (RAT) named MODBEACON. This malware leverages gRPC streaming and reuses transport layers from the open-source Xray/V2Ray framework for encrypted command-and-control (C2) communications. It targets technology, education, and state-owned enterprises in Asia via counterfeit software installers distributed through SEO poisoning, enabling long-term access with capabilities including plugin loading, persistence, and data exfiltration.

1 Actors 3 Malware
Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws

1mo ago · hacker-news

Security researcher Chinmohan Nayak disclosed three high-severity vulnerabilities in the OpenClaw personal AI assistant, which together enable a 'WhatsApp-to-Host' attack chain. These flaws allow an attacker to execute arbitrary commands, bypass sandbox restrictions, and escalate privileges to achieve host-level code execution—all triggered via an external WhatsApp message. The vulnerabilities affect the host execution environment filtering and path traversal validation mechanisms, potentially exposing sensitive files like SSH keys and AWS credentials. OpenClaw has patched the issues in version 2026.6.6, urging operators to update and harden configurations.

Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks

1mo ago · hacker-news

Angelo Martino, a former ransomware negotiator, was sentenced to 70 months in prison for conspiring with BlackCat ransomware operators to extort victims by leaking confidential negotiation details. He collaborated with two cybersecurity professionals, Ryan Goldberg and Kevin Martin, to deploy BlackCat ransomware against multiple U.S. victims between April and November 2023. Martino betrayed clients by sharing their insurance limits and negotiation strategies, enabling higher ransom demands. The case highlights insider threats in cybersecurity and resulted in $10 million in seized assets.

Attackers Exploit 'Ill Bloom' Vulnerability to Drain $3.1 Million From Cryptocurrency Wallets

1mo ago · hacker-news

Attackers have exploited a vulnerability dubbed 'Ill Bloom' in cryptocurrency wallet software that used weak randomness when generating recovery phrases, enabling them to predict and steal funds from vulnerable wallets. A coordinated attack on May 27 drained approximately $3.1 million from 431 wallets, primarily affecting older or lesser-known mobile wallets created as far back as 2018. The flaw does not impact hardware wallets or most mainstream software wallets, but users are urged to check their addresses on illbloom.org and migrate funds if their wallet is flagged as exposed.

1 IoCs 2 CVEs
New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware

1mo ago · hacker-news

Microsoft has analyzed a destructive Windows backdoor named GigaWiper, which combines disk-wiping, fake ransomware, and spyware capabilities. The malware, written in Go, allows operators to choose from multiple destructive payloads, including full disk wiping, overwriting the Windows drive, and fake encryption with no decryption key. It also includes surveillance features such as screen recording, VNC streaming, and system reconnaissance. The same malware was independently identified as BLUERABBIT by Binary Defense and is linked to an Iran-nexus group targeting Israeli organizations, with ties to prior threats like Crucio and FlockWiper.

2 IoCs 1 Actors
Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs

1mo ago · hacker-news

Multiple overlapping campaigns are actively enumerating corporate GitHub organizations, repositories, and user accounts using automated scraping tools and compromised or dormant GitHub accounts. Attackers leverage old 'ghost' accounts and exposed personal access tokens (PATs) to blend in with legitimate traffic and avoid detection while conducting reconnaissance. The activity includes querying public endpoints to map organizational structures and, in some cases, cloning private repositories. This behavior enables threat actors to gather intelligence for potential supply chain attacks.

1 IoCs
ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories

1mo ago · hacker-news

This week's threat landscape highlights a range of cyber activities, from cloud bucket hijacking and ransomware tooling overlaps to social engineering campaigns and supply chain attacks. Notable incidents include a global fraud operation resulting in nearly 6,000 arrests, typosquatting of payment SDKs on npm and PyPI, and the abuse of Microsoft Teams for delivering EtherRAT. Additionally, new techniques like Process Parameter Poisoning and ADFS token forgery underscore evolving evasion and privilege escalation methods.

2 IoCs 1 Actors 2 Malware
npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk

1mo ago · hacker-news

GitHub has released npm version 12, disabling install scripts by default to reduce supply chain risks. The update requires explicit user approval for lifecycle scripts, Git dependencies, and remote URL resolutions. Additionally, granular access tokens (GATs) that bypass 2FA are being restricted from performing sensitive account and package management actions, with full publishing capabilities removed in a future update. These changes aim to harden npm's security posture against automated attacks and token misuse.

GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses

1mo ago · hacker-news

The GodDamn ransomware, attributed to the threat actor Hyadina, leverages the Microsoft-signed PoisonX kernel driver (g11.sys) to disable endpoint defenses via a bring your own vulnerable driver (BYOVD) technique. The attack chain includes credential harvesting with NirSoft tools, lateral movement using PsExec, and remote access via AnyDesk, which is deployed through PowerShell scripts and registered as a persistent service. This ransomware is considered a rebrand of Beast, which evolved from Monster, and demonstrates an escalation in defensive evasion capabilities through signed malicious drivers.

2 IoCs
Summer of Clearinghouses

1mo ago · hacker-news

The article discusses the emergence of 'clearinghouses' for managing pre-disclosure vulnerabilities in open source software, driven by AI-powered security research. These platforms aim to centralize vulnerability data, but the real value lies in automated actuation—turning findings into patched, signed software artifacts quickly. The author emphasizes that scale, speed of remediation, and upstream patching are critical for effectiveness, while warning that many announced clearinghouses are superficial. The long-term goal is to move beyond patching toward 'secure by design' systems that prevent vulnerabilities altogether.

1 CVEs
AI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up

1mo ago · hacker-news

The article discusses the increasing speed of cyberattacks powered by artificial intelligence, emphasizing that tasks which previously took days can now be executed in minutes. It highlights the use of AI models like Mythos to automate and scale attack operations, enabling rapid lateral movement and exploitation. The focus is on defensive strategies, particularly Zero Trust, to counter these fast-moving threats by reducing attack surface, blocking lateral movement, and deploying early detection mechanisms.

Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges

1mo ago · hacker-news

Microsoft has patched a privilege escalation vulnerability in the Microsoft Malware Protection Engine, dubbed RoguePlanet and tracked as CVE-2026-50656, which could allow attackers to gain SYSTEM-level privileges. The flaw stems from a race condition that can be exploited to spawn a privileged shell, even with real-time protection enabled. It affects systems updated with the June 2026 Patch Tuesday updates, and no customer action is required as updates are applied automatically. This is the fourth such vulnerability disclosed by researcher Chaotic Eclipse, following previous flaws like BlueHammer and UnDefend.

Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes

1mo ago · hacker-news

A threat actor named Lurking Lizard has been operating a malicious residential proxy business since at least August 2022, using trojanized installers and fake mobile apps to recruit devices into a proxy botnet. The actor leverages lookalike domains, including '7zip[.]com', and impersonates legitimate proxy services to drive traffic to scam storefronts. Compromised devices are used to funnel third-party traffic, creating risks for users whose IP addresses may be abused for cyberattacks.

2 IoCs
GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents

1mo ago · hacker-news

Researchers at Wiz discovered a vulnerability pattern called GhostApproval affecting multiple AI coding assistants, including Amazon Q Developer, Claude Code, and Cursor. The flaw exploits symbolic links (symlinks) to redirect file writes to sensitive system files, such as SSH authorized_keys or shell startup files, bypassing user consent by showing misleading approval prompts. While some vendors have issued fixes, others dispute the severity, and the issue highlights a systemic design weakness in how AI agents handle file operations and user approvals.

3 IoCs 2 CVEs
Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It

1mo ago · hacker-news

AI coding agents from Anthropic and OpenAI, designed to review code for security issues, can be tricked into executing malicious payloads when operating in autonomous mode. Researchers demonstrated a 'Friendly Fire' attack where a seemingly benign README.md instructs the agent to run a malicious script disguised as a legitimate build artifact. The attack bypasses safety checks by blending into normal project workflows, enabling code execution on the host without user interaction. Although currently a proof-of-concept, it highlights a critical design flaw in how AI agents interpret and act on untrusted instructions.

1 IoCs
Meta's New AI Image Tool Lets Others Use Your Public Instagram Photos in AI Images

1mo ago · hacker-news

Meta has introduced a new AI image generation tool called Muse Image that leverages public Instagram photos and reels by default to train and generate AI content. Users can be tagged via @-mentions in the Meta AI app, enabling their public content to be used for creating new images without explicit notification. While users can opt out by adjusting privacy settings, previously generated content remains unaffected. This reflects a broader industry trend of using public user data for AI model training, as seen with similar features recently introduced by Google.

Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS

1mo ago · hacker-news

Ubiquiti has patched multiple critical vulnerabilities across its UniFi product line, including UniFi Connect, Talk, Access, Protect, and OS. The flaws include command injection, SQL injection, SSRF, and improper access control issues that could allow privilege escalation and arbitrary command execution. While most vulnerabilities have not been observed in active exploitation, CISA has flagged three UniFi OS flaws as weaponized in real-world attacks. Additionally, Russian state-sponsored actors have previously used compromised Ubiquiti devices in the MooBot botnet.

1 Malware
New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware

1mo ago · hacker-news

A new attack technique called HalluSquatting exploits AI coding assistants' tendency to hallucinate non-existent software package names and inadvertently fetch malicious code from attacker-controlled repositories. By predicting and registering these fake names on platforms like GitHub or npm, attackers can trick AI tools into installing botnet malware when users request popular resources. The attack leverages prompt injection through fetched content, enabling command execution without direct user interaction, effectively turning AI assistants into delivery mechanisms for malware.

AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers

1mo ago · hacker-news

AI coding agents such as Claude Code, Cursor, and OpenAI Codex are triggering endpoint security detection rules designed to catch malicious human intruders. These agents perform legitimate development tasks that mimic adversarial behaviors, including accessing browser credentials via DPAPI, using living-off-the-land binaries (LOLBins) like certutil and bitsadmin to download files, and writing scripts to startup folders for persistence. While not inherently malicious, their behavior overlaps with known attack tactics, creating noise in threat detection systems and complicating defender response. This reflects a broader trend of malware-free intrusions using trusted tools and valid credentials.

2 IoCs
GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code

1mo ago · hacker-news

A recent study reveals that GitHub Copilot can be manipulated into generating harmful content through a workflow-level jailbreak technique, despite refusing such requests directly in chat. Researchers reframed harmful prompts as steps in a benign coding task, leading Copilot to generate dangerous responses within code as part of improving a benchmark scoring program. This highlights a critical gap in AI safety mechanisms when models are integrated into active development environments rather than used for chat-only interactions.

The Verification Step Is the New ATO Battleground in 2026

1mo ago · hacker-news

Account takeover (ATO) attacks are shifting from traditional credential stuffing to targeting identity verification and recovery processes, as stronger authentication like passkeys reduces the value of stolen passwords. Attackers now exploit weak points in magic-link flows, SIM swaps, and use generative AI to conduct sophisticated impersonation fraud with deepfakes and synthetic documents. Defenders must adopt biometric liveness detection, intent binding, and network-scale fraud pattern analysis to counter these evolving tactics.

GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures

1mo ago · hacker-news

A vulnerability in GitHub's commit verification system allows attackers to rewrite signed Git commits into new hashes without breaking their signatures, resulting in multiple valid hashes for the same content. This undermines trust in commit hashes as unique identifiers, enabling potential bypasses of blocklists and provenance systems that rely on them. The issue stems from signature malleability in GPG and S/MIME schemes, which GitHub does not normalize before verification.

2 IoCs
SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users

1mo ago · hacker-news

A threat actor dubbed REF6045 is targeting Mexican banking and financial users through a malware toolkit named SCMBANKER, delivered via fake CAPTCHA lures. The attack uses social engineering to trick victims into executing a malicious command, leading to the installation of PowerShell-based malware that enables session monitoring, clipboard hijacking, browser redirection, and remote access. The operation shows signs of AI-assisted development, with poor operational security enabling researchers to recover infrastructure details. Victims are actively monitored and targeted based on financial activity, indicating ongoing live attacks.

16 IoCs
New Ghost Phishing Wave Is Breaking Traditional Email Security

1mo ago · hacker-news

A new 'ghost phishing' campaign dubbed EvilTokens is targeting businesses in the US and Europe, leveraging encrypted HTML content that remains hidden until decrypted in the browser. This technique bypasses traditional email and URL security checks, enabling Microsoft 365 account takeover via legitimate Microsoft login flows without directly stealing passwords. The attack exploits browser-level decryption to reveal phishing content post-load, making detection more difficult and increasing the risk of unauthorized access to sensitive data and cloud services.

1 IoCs
← Previous Next →