The Hacker News
βœ”
162K subscribers
3.01K photos
20 videos
4 files
8.96K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
🚨 One shared key. Every deployment at risk.

Attackers exploited CVE-2026-5426 in the KnowledgeDeliver LMS to gain unauthenticated RCE through hard-coded ASP-NET machineKeys, deploy the Godzilla (BLUEBEAM) web shell, and deliver Cobalt Strike Beacon on vulnerable internet-facing systems.

Read πŸ ’ https://thehackernews.com/2026/05/knowledgedeliver-lms-flaw-exploited-to.html
πŸ”₯8🀯4😁2πŸ‘1
⚠️ Cybercriminals are flooding the web with FIFA World Cup 2026 scams β€” before the tournament even starts.

https://thehackernews.com/expert-insights/2026/05/before-whistle-ctm360-reveals-how.html

Security firm CTM360 uncovered over 7,000 themed domains, with 4,500+ registered in just the last 5 months. Already 1,000+ malicious sites and 1,000+ fake social accounts are live.

Don’t get scammed before the first whistle.
πŸ”₯4πŸ‘1
🚨 Iranian hackers deployed a new AI-assisted backdoor called MiniFast.

https://thehackernews.com/2026/05/iranian-hackers-deploy-minifast-and.html

IRGC-linked group Nimbus Manticore targeted aviation, software, telecom, and energy sectors across the U.S., Europe, and the Middle East.

The campaigns used:
β€’ Phishing lures
β€’ SEO poisoning
β€’ Trojanized Zoom and SQL Developer installers
β€’ Fake meeting invites
β€’ AppDomain hijacking

Activity was tracked between February and April 2026.
πŸ€”15⚑6πŸ‘5πŸ‘1
🚨 India’s CERT-In has directed organizations to patch known exploited vulnerabilities in internet-facing systems within 12 hours where feasible as AI tools accelerate cyber attacks.

The guidance cites faster vulnerability discovery, phishing, malware generation, and exploitation workflows.

Read: https://thehackernews.com/2026/05/cert-in-mandates-12-hour-patching-for.html
😁9πŸ€”5πŸ‘2😱2
Your "second factor" isn't as safe as you think.

Attackers don’t need to steal your MFA code anymore β€” they just exhaust you until you approve it.

MFA Prompt Bombing is quietly becoming one of the most effective attacks right now.

Read β†’ https://thehackernews.com/2026/05/mfa-prompt-bombing-why-your-second.html
😱6⚑2πŸ‘1
⚠️ SharePoint RCE Vulnerability.

Details β†’ https://thehackernews.com/2026/05/microsoft-patches-sharepoint-rce-flaw.html

CVE-2026-45659 allows authenticated attackers with only Site Member permissions to execute code remotely on SharePoint Server.

The CVSS 8.8 flaw affects SharePoint Server 2016, 2019, and Subscription Edition.
πŸ‘3πŸ‘2
The Zero Knowledge vault myth is over.

ETH Zurich (USENIX β€˜26) identifies 27 attacks against cloud password managers. Storing secrets = a $150M+ systemic risk.

Unixi uSSO kills the vault via KDA:
πŸ”ΉNo central DB
πŸ”ΉNo phishing
πŸ”Ή100% enforcement

Details: https://thn.news/centralization-risk
πŸ”₯5πŸ€”3πŸ‘1
⚑AI is making DDoS attacks faster and smarter β€” helping attackers find weak spots, create new attack vectors, and scale attacks more efficiently.

Watch this WEBINAR to see how it works β†’ https://thehackernews.com/2026/05/new-ai-ddos-attacks-are-smarter-learn.html

What you’ll get:
β€’ Real examples of today’s AI-enhanced attacks
β€’ How to find & fix hidden weaknesses fast
β€’ Practical defenses you can apply immediately
😁7πŸ‘5⚑2😱2
🚨 MuddyWater hit 9 countries.

Read β†’ https://thehackernews.com/2026/05/muddywater-uses-dll-side-loading-in.html

The Iranian hacking group targeted 9 organizations using signed Fortemedia and SentinelOne binaries to sideload malware, steal Chrome data, and quietly maintain access inside victim networks.

One intrusion lasted a full week inside a major South Korean electronics company.
πŸ”₯10😱3πŸ‘2⚑1
AI uncovered a 27-year-old bug in OpenBSD that survived decades of human audits.

RunSafe Security’s CEO Joseph M. Saunders warns: you can’t patch your way out of this anymore.

With AI flooding teams with discoveries and EU CRA regulations incoming, remediation backlogs just became unmanageable.

Full insights here: https://thehackernews.com/expert-insights/2026/05/you-cant-patch-your-way-out-of-this-one.html
πŸ‘13πŸ‘5😱4⚑1
🚨 AI chatbots are pushing cryptojacking malware.

Read β†’ https://thehackernews.com/2026/05/ai-chatbot-recommendations-redirect.html

Attackers poisoned AI software recommendations to redirect users searching for tools like CrystalDiskInfo and HWMonitor to malicious download sites distributing ScreenConnect, rogue DLLs, and GPU mining malware.

More than 150 malicious domains were identified.
⚑5πŸ‘1
🚨 Gitea flaw exposes private container images without authentication.

https://thehackernews.com/2026/05/gitea-vulnerability-exposes-private.html

CVE-2026-27771 affects all Gitea versions before 1.26.2 and likely impacts 30,000+ deployments worldwide. Attackers can pull private images without an account or password.

Update now or enable REQUIRE_SIGNIN_VIEW as a temporary workaround.
😁8πŸ”₯1
🧐 β€œMicrosoft Teams” download from X? It’s likely malware.

Read: https://thehackernews.com/2026/05/weekly-recap-linux-flaws-defender-0.html#:~:text=Fake%20Microsoft%20Teams%20Sites%20Deliver%20ValleyRAT

Fake sites push trojanized ZIPs. NSIS installer drops real Teams (looks clean) + uses legit Tencent GameBox.exe to sideload Utility.dll β†’ deploys ValleyRAT (SilverFox group).

Adds Defender exclusions, in-memory decryption, hidden files, and _CCGDAT service for persistence.
😁8⚑4πŸ‘2πŸ”₯1
πŸ”₯ GlassWorm disrupted.

Read - https://thehackernews.com/2026/05/glassworm-malware-takedown-disrupts.html

The malware poisoned 300+ GitHub repositories through:

β€’ Malicious VS Code extensions
β€’ Compromised npm packages
β€’ Trojanized Python packages

Its infrastructure used Solana, BitTorrent DHT, Google Calendar, and VPS servers as resilient C2 layers β€” all now neutralized.
πŸ”₯7πŸ‘1
Media is too big
VIEW IN TELEGRAM
AI agents aren't taking over humanity… yet. But they are multiplying in places you probably can't see, especially if you’re relying only on API-based agent discovery.

That limitation stops today. Nudge Security is the first solution provider to offer browser-based agentic AI discovery, extending agent visibility to more of the platforms where your teams are building agents.

With Nudge Security you can:
βœ… Discover agents across 20+ platforms
βœ… Inventory agent permissions, resources, and capabilities
βœ… Surface risky integrations, publicly accessible agents, hardcoded credentials, and other risks
βœ… Nudge agent creators to confirm purpose, justify use, and remediate risks

Take control of agentic AI risks with a free trial of Nudge Security. Get started here: https://thn.news/ai-agent-discovery
πŸ”₯5πŸ‘1
Employees are secretly using 3–5 AI tools every day β€” most unapproved by IT.

They’re connecting straight to company emails, docs & drives via OAuth, bypassing security entirely.

Smart fix: Don’t ban it. Build a fast, safe approval path instead.

Get new 5-step playbook to manage Shadow AI without slowing teams down β†’ https://thehackernews.com/2026/05/5-steps-to-managing-shadow-ai-tools.html
πŸ‘1
Malware that can’t be taken down?

Void Botnet β€” Rust loader using Ethereum smart contracts for seizure-resistant C2.

https://thehackernews.com/2026/05/weekly-recap-linux-flaws-defender-0.html#:~:text=Void%20Botnet%20Uses%20Ethereum%20Smart%20Contracts%20for%20C2

Built by TheVoidStl, sold on crime forums. ~1.5MB Windows binary with dual modes:

πŸ”Έ Blockchain: Commands via smart contract, bots poll RPCs (3-5 min)
πŸ”Έ Direct: Web panel (<30s)
πŸ”₯3πŸ‘1
⚠️ WARNING - A malicious npm package was caught stealing files from Claude AI users’ /mnt/user-data directories and uploading them to attacker-controlled GitHub repositories.

Check your installed packages: https://thehackernews.com/2026/05/malicious-npm-package-stole-files-from.html

The package, β€œmouse5212-super-formatter,” used npm postinstall scripts, hard-coded GitHub tokens, and fake network logs to hide the theft.

Downloaded 676 times so far.
πŸ‘1
Most breaches slip in as β€œnormal” activity.

Top SOCs shrink uncertainty before it becomes an incident using 3 steps:

◾️ Fresh sandbox IOCs (domains, C2s) auto-updating SIEM/EDR
◾️ One-click alert context: malware family, behavior & execution chain
◾️ Automated sandbox reports with AI summaries & visual chains

Prevention happens before the incident gets a name.
Read the full 3 steps β†’ https://thehackernews.com/2026/05/3-soc-steps-that-shut-down-incident.html
πŸ‘2
πŸ›‘ Banking malware is hiding in WebRTC traffic on Windows while Android RATs spread via fake Google Play pages.

Read - https://thehackernews.com/2026/05/grandoreiro-malware-and-btmob-rat.html

β€’ Grandoreiro targets Portugal, Spain, and Mexico using DLL side-loading.

β€’ BTMOB targets Brazil with phishing, remote control, and banking theft features.
πŸ€”5⚑2