Search the Portal

Recent Articles

OCT9
P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands

Cybersecurity researchers have disclosed details of a previously unseen variant of the DarkSword iOS exploit kit called P7 DarkSword. "Compared with the variants we usually observe, P7 reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and adds two way C2 communication with the attacker's infrastructure," iVerify said in a new report published Thursday. The name

The Hacker News by info@thehackernews.com (The Hacker News)
OCT9
TP-Link Sued by Four More U.S. States Over Router Security and China Ties

Four more U.S. states sued router maker TP-Link Systems on October 6, bringing the total to five, with Texas filing a suit in February. Florida, Iowa, Montana and Nebraska allege the California company misled buyers about how secure its routers are and how separate it is from China. TP-Link denies the claims and says it will fight them in court. TP-Link Systems is based in

The Hacker News by info@thehackernews.com (The Hacker News)
OCT9
Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access

Security researchers have published a full working exploit for a pre-authentication remote code execution flaw in AnyDesk Linux that gives attackers root access before anyone approves the connection. AnyDesk patched the flaw in version 8.0.3 in June, but its changelog described the fix only as "fixed a bug that could lead to a crash," with no CVE assigned and no security

The Hacker News by info@thehackernews.com (The Hacker News)
OCT9
Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects

Anthropic on Thursday unveiled OSS Scanner as an opt-in vulnerability scanner to help secure the open-source ecosystem using artificial intelligence (AI). "It's an opt-in service informed by our experience using Claude to find vulnerabilities during Project Glasswing," Anthropic said. "Projects that join will receive thorough, periodic security scans by our strongest models at no cost."

The Hacker News by info@thehackernews.com (The Hacker News)
OCT9
Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge

Threat actors have been observed exploiting two recently disclosed flaws in the AhsayCBS backup utility to seize control of affected devices and deploy web shells and XMRig cryptocurrency miners. Details of the flaws are below - CVE-2026-105133 (CVSS v4 score: 5.5) - An improper authentication vulnerability in the checkSysPwd() function in the "com/ahsay/obs/api/ApiStructsAction.java"

The Hacker News by info@thehackernews.com (The Hacker News)
OCT9
Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog, following their abuse by a China-linked threat actor known as Flax Typhoon. The vulnerabilities in question are listed below - CVE-2015-3306 (CVSS score: 10.0) - An improper access control vulnerability in ProFTPD that could allow

The Hacker News by info@thehackernews.com (The Hacker News)
OCT9
In Other News: AI Used in Korean Bank Breaches, Poem-Guided Botnet, Empire Admin Gets 40 Years

Noteworthy stories that might have slipped under the radar: Tensorlake npm SDK compromised, Empire Market co-founder gets 40 years, exposed NVIDIA GPU monitors leak telemetry. The post In Other News: AI Used in Korean Bank Breaches, Poem-Guided Botnet, Empire Admin Gets 40 Years appeared first on SecurityWeek.

Security Week by SecurityWeek News
OCT9
Google Domains Impacted by Recent ccTLD Hijacks

Hackers hijacked the .gh, .sl, and .as ccTLDs and obtained HTTPS certificates for several Google domains. The post Google Domains Impacted by Recent ccTLD Hijacks appeared first on SecurityWeek.

Security Week by Ionut Arghire
OCT9
The AI Velocity Paradox: Why Security Is Decades Behind AI Ambition

As enterprises race to deploy autonomous AI agents to accelerate business, a new report reveals they are tethered to security architectures built for a different era. The "Horizons of Identity Security" report from SailPoint highlights a critical “velocity paradox,” in which organizations invest in AI-speed business operations while continuing to rely on human-speed security controls, creating a

The Hacker News by info@thehackernews.com (The Hacker News)
OCT9
Unpatched AhsayCBS Vulnerabilities Exploited in the Wild

The flaws, CVE-2026-105133 and CVE-2026-105134, allow attackers to bypass authentication and inject OS commands. The post Unpatched AhsayCBS Vulnerabilities Exploited in the Wild appeared first on SecurityWeek.

Security Week by Ionut Arghire
OCT9
Pre-Baked Firmware Malware Hits Budget Android Devices in 150+ Countries

Midnight Mimosa is the name given to a malware campaign primarily running preinstalled on low-cost Android devices. The post Pre-Baked Firmware Malware Hits Budget Android Devices in 150+ Countries appeared first on SecurityWeek.

Security Week by Kevin Townsend
OCT9
GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys

A bug in GoBalance, a tool many dark-web sites use to stay reachable during attacks, lets anyone work out the secret key that controls a site's .onion address using only public information, and then take that address over. Searchlight Cyber, which disclosed the flaw on October 8, says an attacker who recovers the key can redirect the site's visitors to a copy of the site they control.

The Hacker News by info@thehackernews.com (The Hacker News)
OCT9
US Disrupts Chinese State-Sponsored Hacking Tools

Flax Typhoon and other APTs used MicroScan and FishHub to scan and hack US and foreign critical infrastructure. The post US Disrupts Chinese State-Sponsored Hacking Tools appeared first on SecurityWeek.

Security Week by Ionut Arghire
OCT9
Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own

Three research teams broke into Google's Pixel 10 on October 8 at Pwn2Own Ireland, a hacking contest in Cork whose rules require every target to be fully patched. The contest pays researchers to show working exploits and passes the flaws to the vendors. One of the three Pixel exploits earned Ikotas Labs $300,000, the contest's top prize, and made the team the overall winner. Trend Micro's Zero

The Hacker News by info@thehackernews.com (The Hacker News)
OCT9
Anthropic Fast-Tracks AI Bug Reports to OSS Maintainers, Taps 11 Firms for OT Security

OSS Scanner sends unreviewed, model-generated vulnerability reports to open source maintainers that opt in. The post Anthropic Fast-Tracks AI Bug Reports to OSS Maintainers, Taps 11 Firms for OT Security appeared first on SecurityWeek.

Security Week by Eduard Kovacs