Live

Intelligence Feed

Latest threat intelligence articles from trusted security sources, auto-processed to extract entities, IoCs, and TTPs.

Filtered by source: hacker-news Clear filter
Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes

1d ago · hacker-news

Dell has disclosed multiple critical vulnerabilities in its Container Storage Modules (CSM) affecting versions prior to 1.17.0, which were patched in version 1.18.0. The most severe flaws include CVE-2026-63688 and CVE-2026-63692, both with a CVSS score of 10.0, enabling unauthenticated remote attackers to gain administrative access to storage infrastructure and Kubernetes clusters. Exploitation of these vulnerabilities could allow full control over storage systems, privilege escalation to root, and unauthorized manipulation of access policies across tenants.

Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

1d ago · hacker-news

A China-nexus threat actor tracked as UAT-11587 has been conducting a cyber espionage campaign since September 2025, targeting government and policy organizations across Asia and Syria. The campaign uses a previously undocumented Rust-compiled Windows backdoor named Antino, which leverages Microsoft 365 services—specifically Outlook and OneDrive—for command-and-control (C2) communications. Initial access is achieved via spear-phishing emails with spoofed sender identities and a fake Gmail attachment preview widget, leading to a multi-stage infection chain culminating in the deployment of the Antino backdoor using DLL sideloading.

4 IoCs 3 Actors
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

1d ago · hacker-news

GitLab has patched a critical vulnerability, CVE-2026-90970, in its self-hosted AI Gateway that could allow a logged-in user with access to the Duo Agent Platform to execute arbitrary commands on the gateway via a crafted custom flow configuration. The flaw, rated 9.9 on the CVSS scale, stems from a prompt template sandbox escape in the AI Gateway's custom flow feature. Organizations hosting their own AI Gateway instances are advised to update immediately to fixed versions 19.2.4, 19.3.2, or 19.4.1, as no workaround is available and exploitation could lead to command execution on the underlying system.

Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

1d ago · hacker-news

A critical zero-day vulnerability, CVE-2026-104286, in Fortinet FortiMail has been actively exploited in the wild, allowing unauthenticated attackers to perform arbitrary file writes via path traversal and NULL byte injection. The flaw affects multiple versions of FortiMail, and CISA has added it to its Known Exploited Vulnerabilities catalog. Fortinet has provided workarounds, including disabling the IBE feature and restricting management interface access, while patches are pending for some versions. Indicators of compromise include specific malicious IP addresses and file modifications on affected systems.

9 IoCs
ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories

2d ago · hacker-news

Threat actors are exploiting a critical vulnerability in Unsloth Studio, an open-source library for fine-tuning LLMs, which allows arbitrary code execution during model inspection. The flaw, triggered by reading a model's config.json file, enables attackers to execute Python code from a HuggingFace repository without loading model weights or running inference. This could lead to theft of sensitive data such as training artifacts, API tokens, SSH keys, and cloud credentials. The vulnerability has been patched in version 2026.6.9, released on June 18, 2026. Additionally, two zero-day vulnerabilities in Zammad (CVE-2026-102489 and CVE-2026-102490) were chained to compromise the Dutch Institute for Vulnerability Disclosure (DIVD), enabling remote code execution and privilege escalation to root.

2 IoCs
Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft

2d ago · hacker-news

Cryptocurrency exchange Bitget suffered a $387.5 million theft after attackers exploited a zero-day vulnerability in a third-party security product, gaining access to internal credentials and deploying malicious tools to bypass risk controls. The attackers compromised multiple nodes by running hidden scripts to extract database credentials and laterally moved into Bitget's wallet environment using compromised security appliances. Forensic analysis by SlowMist and Mandiant linked the attack to North Korean threat actors, who used a custom tool to execute unauthorized withdrawals across 11 blockchains. The breach began as early as August 31, 2026, with command-and-control established via a web shell on security appliance B.

WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory

2d ago · hacker-news

A sophisticated WordPress backdoor named SC has been identified, utilizing a self-healing mesh of persistence mechanisms across files, database entries, and shared memory segments to resist removal. The malware, which hides using obfuscated code and a substitution cipher decoder, is capable of rebuilding itself from any surviving component, including hidden files, mu-plugins, themes, and System V shared memory. It can communicate with a C2 server via the Ethereum blockchain, create hidden admin accounts, inject malicious JavaScript, and execute arbitrary PHP code. The backdoor spreads identical payloads across multiple locations, ensuring reinfection even after partial cleanup.

8 IoCs
Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers

2d ago · hacker-news

KillSec, a ransomware group active since at least 2021, transitioned to ransomware operations in October 2023 and began offering its tools as a ransomware-as-a-service in June 2024. The group extorted victims by stealing sensitive data, threatening to publish it unless ransoms were paid, and leveraging AI for infrastructure and victim identification. In September 2026, law enforcement in Spain, Germany, the UK, Romania, and Puerto Rico arrested three suspects, including a 16-year-old suspected administrator, and seized the group's leak site, servers, domains, and over 110 TB of data. The investigation uncovered approximately 500 confirmed successful attacks out of around 1,000 suspected incidents globally, with evidence of ransom payments in cryptocurrency.

1 IoCs
Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks

3d ago · hacker-news

Threat actors are conducting phishing campaigns using socially engineered lures to distribute a maliciously repackaged, digitally signed MSP360 RMM installer. Once executed, the installer establishes initial access and persistence, then deploys ConnectWise ScreenConnect to create a redundant remote access channel. This dual-RMM approach allows attackers to blend malicious activity with legitimate remote administration traffic, enabling post-compromise tool deployment and credential access. The same attack pattern has also been observed using Faronics Deploy Agent instead of MSP360, indicating a broader tactic of abusing legitimate remote management tools.

4 IoCs
Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets

3d ago · hacker-news

Threat actors are exploiting a patched command injection vulnerability, CVE-2026-73570, in Zimbra Collaboration Suite (ZCS) to achieve remote code execution without authentication. The flaw is triggered via a crafted SMTP request when SNMP notifications are enabled and the zimbra-snmp package is installed. Upon exploitation, attackers deploy JSP web shells, establish reverse shells, escalate privileges, and harvest authentication secrets including LDAP credentials and service account data. They also perform lateral movement using Zimbra's SSH identity and exfiltrate mailbox data, sometimes using cloud tools like AzCopy targeting Azure Blob storage.

6 IoCs 1 CVEs
Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs

2d ago · hacker-news

Threat actors are actively exploiting CVE-2026-88771, a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and Gateway, to execute arbitrary commands and deploy post-exploitation payloads. The attackers use malicious authentication attempts with usernames containing 'pitboss' and 'NSPPE' strings to trigger the vulnerability and drop web shells. Second-stage payloads include a Perl script that creates a privileged account, exfiltrates configuration data, and deploys a PHP web shell mapped to CSS-like URLs, as well as a Python script that establishes a reverse shell and kills specific processes. These actions enable persistent access, remote command execution, and data theft, with infrastructure tied to multiple malicious IPs.

6 IoCs
Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path

2d ago · hacker-news

Security researchers from Calif have published a proof-of-concept for CVE-2026-86950, a vulnerability in Apple's CoreGraphics framework that can be triggered by a malicious PDF containing a crafted embedded font, leading to a crash due to an out-of-bounds write. The flaw affects unpatched versions of iOS and macOS and was patched by Apple on September 28, 2026, after being reported by Meta Product Security. While no active exploit has been demonstrated, the vulnerability could serve as part of a zero-click attack chain, with circumstantial evidence suggesting WhatsApp as a potential delivery vector due to changes in its attachment scanning logic.

1 IoCs
CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV

2d ago · hacker-news

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-76504, a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager, to its Known Exploited Vulnerabilities (KEV) catalog due to active exploitation observed in the wild. The flaw, which carries a CVSS score of 9.8, allows unauthenticated remote attackers to bypass authentication by sending a crafted HTTP request to the API, gaining admin-level access. Organizations are urged to apply patches immediately and review specific log files for signs of compromise, including suspicious POST requests to URL-encoded variants of '/j_security_check' and activity involving user accounts starting with 'viptela-reserved-'.

2 IoCs
OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates

2d ago · hacker-news

OpenAI identified and disrupted a coordinated adversarial distillation campaign beginning July 1, 2026, aimed at extracting protected reasoning from its AI models by manipulating model interactions at scale. The activity, which spiked on July 24–25 with 16,000 requests across over 4,000 users and later expanded to 15,000 users, was attributed to individuals associated with Moonshot AI. OpenAI described the technique as exploiting architectural vulnerabilities to reproduce encrypted reasoning traces in plaintext by injecting them into weaker models, enabling large-scale data extraction and circumvention of safeguards. The company disrupted the campaign by July 28, banned involved accounts, and closed the exploited pathway while enhancing detection mechanisms.

Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution

3d ago · hacker-news

A critical buffer overflow vulnerability, CVE-2026-88772, in Citrix NetScaler ADC and Gateway has been actively exploited in the wild. The flaw exists in the Datagram Transport Layer Security (DTLS) protocol handling within the NetScaler Packet Processing Engine (NSPPE), where an inconsistency in fragment size validation leads to a heap-based buffer overflow. This allows unauthenticated remote attackers to execute arbitrary shellcode with root privileges by triggering memory corruption during packet reassembly. The vulnerability enables remote code execution due to improper bounds checking, and exploitation techniques have been demonstrated using mprotect() to bypass NX protections.

OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted

3d ago · hacker-news

OpenSSL has addressed a high-severity vulnerability, CVE-2026-84782, affecting DTLS implementations that can lead to heap memory leakage in unencrypted handshake data or cause a program crash. The flaw occurs when a DTLS handshake message is resent while a larger message is partially sent, resulting in the use of incorrect buffer positioning and potential exposure of sensitive memory contents. The vulnerability impacts multiple OpenSSL branches, with public fixes available for newer versions and only premium support customers receiving updates for older versions like 3.0, 1.1.1, and 1.0.2.

1 CVEs
Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager

3d ago · hacker-news

Cisco has confirmed active exploitation of a critical zero-day authentication bypass vulnerability, CVE-2026-76504, in its Catalyst SD-WAN Manager. The flaw allows unauthenticated remote attackers to bypass authentication and access the system's API as an admin user by exploiting improper URI encoding handling in HTTP requests. The vulnerability affects all on-premises SD-WAN Manager installations regardless of configuration, with a CVSS score of 9.8, and no workaround exists other than applying fixed software releases. Cisco advises customers to restrict internet access to the Manager and check specific log files for signs of compromise involving URI-encoded paths like /%6a_security_check.

3 IoCs
Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

1w ago · hacker-news

Threat actor UNC6240, linked to ShinyHunters, is exploiting CVE-2026-35273, a critical unauthenticated remote code execution vulnerability in Oracle PeopleSoft, to deploy web shells and establish persistent access. The attackers bypass web application firewall (WAF) protections by URL-encoding the 'P' character as '%50' in requests to the vulnerable PSEMHUB endpoint. Exploitation leads to fileless command execution, deployment of JSP web shells, and installation of the SIDEEYE backdoor and Neo-reGeorg tunneling toolkit for data exfiltration and lateral movement. Targets span multiple sectors including education, healthcare, government, and technology, with the threat actor demonstrating root- and SYSTEM-level access on compromised systems.

6 IoCs 1 Actors
Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

1w ago · hacker-news

Lunex Stealer, also known as Psychedelic Stealer, is a malware-as-a-service platform distributing information-stealing malware through compromised Ukrainian websites using fake CAPTCHA pages via ClickFix. The attack chain uses a malicious AMD driver (PDFWKRNL.sys) exploiting CVE-2023-20598 to bypass security monitoring via the BYOVD technique, enabling privilege escalation and evasion of EDR solutions. The malware steals credentials from multiple Chromium-based browsers, exfiltrates cryptocurrency wallet data, and establishes persistent remote access through a PowerShell-based Chrome Native Messaging Host. Command-and-control infrastructure includes multiple panels across 13 countries, with phishing domains linked to at least one Turkish-hosted panel.

6 IoCs
SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild

1w ago · hacker-news

CISA has added two vulnerabilities to its Known Exploited Vulnerabilities catalog due to active in-the-wild exploitation. CVE-2026-65660 is a code injection flaw in Microsoft Office SharePoint that allows authenticated attackers to achieve remote code execution, which Microsoft initially classified as a spoofing issue. The second vulnerability, CVE-2026-67279, affects MikroTik RouterOS and enables unauthenticated attackers to open a session channel, which when combined with CVE-2026-86060 (an argument injection flaw), forms the 'MikroTrick' exploit chain allowing full administrative takeover of vulnerable routers without credentials.

Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link

1w ago · hacker-news

A high-severity CSRF vulnerability in Elementor Website Builder WordPress plugin versions 4.3.0 and 4.3.1 allows unauthenticated attackers to take over WordPress sites by tricking an authenticated administrator into clicking a crafted link. The flaw bypasses CSRF protection for cookie-authenticated REST API requests when the string 'elementor/v1/events/' appears in the request URI, enabling actions like creating rogue administrator accounts. The vulnerability affects over 2 million sites and has been patched in version 4.3.2.

1 IoCs
Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise

1w ago · hacker-news

Cryptocurrency exchange Bitget suffered a $351.6 million theft from its hot and warm wallets, attributed to suspected North Korean threat actors. The attackers compromised a critical backend system, spoofed transaction data, and triggered unauthorized fund transfers. While customer balances remain intact and cold wallets were unaffected, withdrawals have been suspended during a security review. Bitget has engaged Mandiant and SlowMist for investigation and is collaborating with blockchain foundations to freeze hacker-controlled wallet addresses. The attack pattern aligns with known North Korean hacking groups based on IP behavior and on-chain analysis.

PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

1w ago · hacker-news

A new variant of the PamStealer macOS malware has been identified, featuring live command-and-control (C2) payload decryption and multi-layer persistence mechanisms. The malware is distributed via a fake cryptocurrency wallet website (wavel[.]app), which delivers a malicious disk image containing a compiled AppleScript that executes a JXA dropper. The dropper initiates a key exchange with the C2 server using X25519 to decrypt the payload, preventing static analysis. The malware employs four persistence methods, including LaunchAgent, shell hooks, and Git hooks, and ultimately deploys a Swift-based stealer to harvest credentials, browser data, keychain items, and system metadata.

5 IoCs
Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

1w ago · hacker-news

Two compromised GitHub Actions, 'actions-cool/issues-helper' and 'actions-cool/maintain-one-comment', were reactivated on September 16, 2026, after being previously disabled due to their involvement in the Mini Shai-Hulud supply chain attack campaign. The repositories resumed serving malicious code that had been introduced on May 18, 2026, allowing credential harvesting from CI/CD pipelines without any new attacker action. The malicious payloads were re-downloaded and executed by workflows referencing the affected version tags, highlighting the risk of mutable version tags in supply chain security. The incident is linked to the Mini Shai-Hulud activity cluster, which also targeted npm packages under the @antv ecosystem.

4 IoCs
WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

1w ago · hacker-news

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog due to evidence of active exploitation. CVE-2026-5430 is a path traversal flaw in WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway that enables unrestricted file upload and remote code execution. CVE-2026-71362 is an incorrect authorization vulnerability in Adobe Commerce and Magento that allows attackers to escalate privileges and access sensitive customer data without user interaction. Exploitation of both vulnerabilities has been observed in the wild, with attacks detected as early as September 10, 2026.

1 CVEs
Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data

1w ago · hacker-news

Cloudflare patched a vulnerability in its Containers and Sandboxes services that allowed a customer's container to read leftover disk data from previously deleted containers on the same server. The issue stemmed from thin-provisioned disks that were not properly wiped before reallocation, enabling data remnants—including SQLite databases, .env files, and browser profiles—to be recovered. The flaw was reported by researcher Oren Yomtov via Cloudflare's bug bounty program and was fixed by re-enabling block wiping and retiring all running container disks and caches. Cloudflare found no evidence of exploitation beyond authorized testing.

Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

1w ago · hacker-news

A pre-authentication SQL injection vulnerability in Roundcube Webmail, tracked as CVE-2026-48842, is being actively exploited in the wild. The flaw exists in the virtuser_query plugin of versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1, allowing unauthenticated attackers to inject arbitrary SQL and potentially access mail account credentials and stored messages. The Canadian Centre for Cyber Security and SentinelOne have confirmed active exploitation, though specific threat actor details remain limited. Patches were released in May 2026, but over 500,000 Roundcube instances remain internet-exposed, with at least 10 identified as vulnerable as of late September 2026.

1 Malware 3 CVEs
Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls

1w ago · hacker-news

A malicious Android spyware dubbed Corp MDM is targeting logistics firms by distributing fake Google Play pages impersonating CEVA and TKW Logistics. The malware, delivered as a trojanized APK with package name 'com.corp.mdm', steals newly received SMS messages, redirects calls, and maintains a hidden foreground service. It communicates with a command-and-control server at 69.55.61.82 via HTTP, exfiltrating SMS content and device identifiers while supporting remote commands such as call forwarding and self-destruction. The campaign is suspected to be financially motivated, with links to a Russian-Armenian threat actor operating a phishing-as-a-service platform called Global Profit.

4 IoCs
Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer

1w ago · hacker-news

A threat campaign dubbed ClickFix is compromising legitimate Ukrainian business websites to serve fake Cloudflare verification pages that trick users into executing a malicious command. The command downloads an MSI installer delivering Psychedelic Stealer, a previously undocumented information stealer that exfiltrates browser credentials, cryptocurrency wallets, and account tokens. The attackers also use a lure management panel hosted on uasputnik.com, and the malware establishes persistence via scheduled tasks and communicates with C2 servers. A second malware chain delivers RemotePanel, a remote access tool, and BoundSiphon, a .NET stealer, using similar social engineering lures.

13 IoCs
Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content

1w ago · hacker-news

The domain third-party[.]com, historically used as a documentation placeholder in code and technical writing, has been registered by an attacker and is now serving a ClickFix social engineering lure targeting Windows users. When accessed from Windows, the site poisons the clipboard with a malicious PowerShell command intended for execution via the Run dialog, while showing a benign or unsupported message to other platforms like macOS. The domain is referenced in over 1,700 public GitHub repositories, including AI agent skills and API documentation, amplifying exposure. Additionally, two other placeholder domains—yoursite[.]com and your-domain[.]com—are actively serving scams and scareware, particularly targeting macOS users with fake security alerts and fraudulent investment offers.

14 IoCs
Next →