The Hacker News Most trusted, widely-read independent cybersecurity news source for everyone; supported by hackers and IT professionals — Send TIPs to admin@thehackernews.com
- Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoorsen 11 de septiembre de 2026
Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted […]
- China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdooren 11 de septiembre de 2026
A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a […]
- PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flawsen 11 de septiembre de 2026
PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two […]
- Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomwareen 11 de septiembre de 2026
Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure […]
- ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Storiesen 10 de septiembre de 2026
A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes […]
- Google Play Early Access Abused to Push Thousands of Deceptive Android Appsen 10 de septiembre de 2026
Bad actors are misusing Google Play's Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content. […]
- Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCEen 10 de septiembre de 2026
Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow […]
- PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instancesen 10 de septiembre de 2026
A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair […]
- Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checksen 10 de septiembre de 2026
The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it, […]
- CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadlineen 10 de septiembre de 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known […]
- Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Keyen 10 de septiembre de 2026
Nearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM's own […]
- Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6en 10 de septiembre de 2026
Anthropic on Wednesday disclosed a fourth incident in which its artificial intelligence (AI) model broke into real third-party systems, marking the latest in a […]
- U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Cryptoen 9 de septiembre de 2026
The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam […]
- Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Weeken 9 de septiembre de 2026
Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together […]
- Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFAen 9 de septiembre de 2026
Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools […]














