Latest CVE

The Hacker News

  • FBI Arrests Another ShinyHunters Suspect Reportedly Involved in Its Jobs Portal Hack

    @ (The Hacker News)
    The FBI has arrested another suspected co-conspirator of ShinyHunters, FBI Director Kash Patel said on October 9 in a post on X.

    ShinyHunters is the extortion group that said in September it had breached the FBI's jobs portal and stolen sensitive data on almost all FBI agents and job applicants. The FBI has not named the suspect, and no charges have been made public.

    The
  • P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands

    @ (The Hacker News)
    Cybersecurity researchers have disclosed details of a previously unseen variant of the DarkSword iOS exploit kit called P7 DarkSword.

    "Compared with the variants we usually observe, P7 reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and adds two way C2 communication with the attacker's infrastructure," iVerify said in a new report published Thursday.

    The name
  • TP-Link Sued by Four More U.S. States Over Router Security and China Ties

    @ (The Hacker News)
    Four more U.S. states sued router maker TP-Link Systems on October 6, bringing the total to five, with  Texas filing a suit in February. Florida, Iowa, Montana and Nebraska allege the California company misled buyers about how secure its routers are and how separate it is from China. TP-Link denies the claims and says it will fight them in court.

    TP-Link Systems is based in
  • Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access

    @ (The Hacker News)
    Security researchers have published a full working exploit for a pre-authentication remote code execution flaw in AnyDesk Linux that gives attackers root access before anyone approves the connection.

    AnyDesk patched the flaw in version 8.0.3 in June, but its changelog described the fix only as "fixed a bug that could lead to a crash," with no CVE assigned and no security
  • Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects

    @ (The Hacker News)
    Anthropic on Thursday unveiled OSS Scanner as an opt-in vulnerability scanner to help secure the open-source ecosystem using artificial intelligence (AI).

    "It's an opt-in service informed by our experience using Claude to find vulnerabilities during Project Glasswing," Anthropic said. "Projects that join will receive thorough, periodic security scans by our strongest models at no cost."
  • Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge

    @ (The Hacker News)
    Threat actors have been observed exploiting two recently disclosed flaws in the AhsayCBS backup utility to seize control of affected devices and deploy web shells and XMRig cryptocurrency miners.

    Details of the flaws are below -


    CVE-2026-105133 (CVSS v4 score: 5.5) - An improper authentication vulnerability in the checkSysPwd() function in the "com/ahsay/obs/api/ApiStructsAction.java"
  • Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies

    @ (The Hacker News)
    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog, following their abuse by a China-linked threat actor known as Flax Typhoon.

    The vulnerabilities in question are listed below -


    CVE-2015-3306 (CVSS score: 10.0) - An improper access control vulnerability in ProFTPD that could allow
  • The AI Velocity Paradox: Why Security Is Decades Behind AI Ambition

    @ (The Hacker News)
    As enterprises race to deploy autonomous AI agents to accelerate business, a new report reveals they are tethered to security architectures built for a different era. The "Horizons of Identity Security" report from SailPoint highlights a critical “velocity paradox,” in which organizations invest in AI-speed business operations while continuing to rely on human-speed security controls, creating a
  • GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys

    @ (The Hacker News)
    A bug in GoBalance, a tool many dark-web sites use to stay reachable during attacks, lets anyone work out the secret key that controls a site's .onion address using only public information, and then take that address over.

    Searchlight Cyber, which disclosed the flaw on October 8, says an attacker who recovers the key can redirect the site's visitors to a copy of the site they control.
  • Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own

    @ (The Hacker News)
    Three research teams broke into Google's Pixel 10 on October 8 at Pwn2Own Ireland, a hacking contest in Cork whose rules require every target to be fully patched. The contest pays researchers to show working exploits and passes the flaws to the vendors. One of the three Pixel exploits earned Ikotas Labs $300,000, the contest's top prize, and made the team the overall winner.

    Trend Micro's Zero
| Date published: Fri, 09 Oct 2026 23:18:20 +0530
Back to newsfeed list