ZeroHour

Search: “Hacking Team”

26 stories in the last 7d

Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers

Kaspersky details NightEagle, Hacking Cat, and Toy Ghouls targeting Russian enterprises with Exchange backdoors, Gorilla RAT, and destructive Monkey ransomware.

Kaspersky reports three threat clusters targeting Russian enterprises: NightEagle (APT-Q-95), the pro-Ukrainian hacktivist group Hacking Cat, and Toy Ghouls. NightEagle uses compromised VPN credentials and the GhostContainer modular backdoor to fully compromise Microsoft Exchange servers, chaining CVE-2020-0688 exploitation, BlueKeep (CVE-2019-0708), Active Directory vulnerabilities, and DCSync to seize domain controllers. Hacking Cat exploits Exchange flaws including CVE-2021-26855 and CVE-2026-42897 to deliver the Gorilla RAT and multiple Monkey ransomware variants written in Rust, .NET, C++, and Golang targeting Windows, Linux, and VMware ESXi, with some variants acting as wipers that never store the encryption key.

The Hacker Newsupdated · 40m agofirst · 1d agoThreat actor in the wild 6 sourcesCVE-2020-0688CVE-2019-0708CVE-2021-26855+1 CVEs2

Major Cyber Threat Detection Vendors Shift from MITRE to UK Testing Program

SE Labs launched PIVOT, a six-month vendor detection testing program backed by CrowdStrike, Fortinet, Palo Alto Networks and Sophos, as major vendors exit MITRE evaluations.

SE Labs unveiled PIVOT on September 15, a six-month testing program in which its ethical hackers replicate nation-state and criminal attack chains against participating vendor products, with results due January 2027. Broadcom (Symantec/Carbon Black), CrowdStrike, Fortinet, Palo Alto Networks and Sophos have confirmed participation, and Gartner and Forrester analysts will verify the underlying evidence before publication. The launch follows declining participation in MITRE Engenuity ATT&CK Evaluations: Enterprise, which fell from 30 vendors in 2023 to 11 in 2025 after public withdrawals by Microsoft, SentinelOne and Palo Alto Networks.

Infosecurity Magazine · 2d agoIndustry1

A heap overflow and SSO misconfiguration to compromise OpenAI internal repos

Hacktron researchers chained a libheif heap overflow in Discourse with an OpenAI SSO flaw to take over employee ChatGPT/Codex accounts and access internal repositories.

On July 25, 2026, Hacktron researchers chained a heap buffer overflow in libheif 1.19.7/1.19.8 (missing Debian security backports, upstream fix never assigned a CVE), reached through Discourse image uploads processed by ImageMagick, to gain remote code execution on community.openai.com. Combined with an SSO identity misconfiguration in the 'Sign in with OpenAI' flow, they took over employees' ChatGPT/Codex accounts with connected GitHub, Slack, and email access, and proved it by opening PR #1186742 in OpenAI's internal openai/openai monorepo. They reported the issues for coordinated patching, received a $6,500 bounty from OpenAI, and Debian shipped fixed libheif packages on August 8, 2026. The team used Claude Opus 4.8 and Claude Opus 5 to locate the missing backport and autonomously develop working x86-64/ARM64 exploits.

Hacker News · securityupdated · 34m agofirst · 11h agoResearch in the wild 9 sourcesHN 334↑ · 128 comments1

America's Driver's License Breach Is a National Security Disaster

Dark web service Nexus sells 153 million US/Canadian driver's licenses linked to a breach of identity verifier IDScan.

Krebs on Security revealed a dark web service, Nexus, selling access to 153 million driver's licenses and 3 million travel documents from US and Canadian citizens, roughly 63 percent of all US licenses. Circumstantial evidence links the data to identity verification firm IDScan, which confirmed it is investigating a breach, and the FBI is probing the incident. Licenses belonging to senior US officials, including Pete Hegseth, an FBI assistant director, and Krebs's own contacts were verified as genuine. The exfiltration appears ongoing, with the database growing by nearly 400,000 licenses in a single day, and the data carries significant national security value for foreign intelligence services.

Hacker News · security · 2d agoData breachHN 26↑ · 4 comments3· 1 read

Strong fundamentals make next-gen security possible

A former CISO for Hyatt and United Airlines argues foundational controls—asset inventory, identity, resilience—outperform repeatedly buying new security tools.

The author, a former security leader at Hyatt and United Airlines, argues that mastering foundational controls delivers more impact than cycling through expensive new tools. The piece highlights asset discovery with a single source of truth, identity hardening via MFA and passkeys, and risk-based prioritization using frameworks like CIS CSC. It also stresses resilience and recovery planning, including secure backups and regularly practiced incident processes.

CSO Online · 5h agoIndustry

“Zero-Code Cloaking”: Attackers Weaponize Google Search and Hacked .ac.th Domain to Bypass Ad Moderation

Attackers chain Google search results, a hacked Thai .ac.th domain, and redirects to push illegal casino ads past moderation, at industrialized scale across gov/edu sites.

ADEX researchers documented a 'zero-code cloaking' technique in which an ad's destination URL loads a Google search results page whose poisoned top result is a casino page planted on the compromised Thai university domain km.chpc.ac.th, which then redirects users to illegal gambling sites. Because every visitor receives identical content, ad-verification tools that inspect only the declared landing URL detect nothing malicious. ADEX cites data showing roughly 30 million gambling URLs across about 1,000 Thai public-sector sites, hundreds of blocked gov/edu domains in Indonesia, and underground markets selling access to more than 15,000 compromised .gov and .edu domains. Google's site reputation abuse policy offers little coverage because hacked site owners are victims rather than willing participants.

GBHackers · 1d agoPhishing & fraud in the wild 2 sources

CISA Releases Guidance on Deploying Cyber Decoys

CISA issued guidance on deploying honeypots, honeytokens, and decoy systems to detect adversaries and gather threat intelligence in critical infrastructure.

CISA released guidance on deploying cyber decoys, including lures, tripwires, decoy artifacts, honeytokens, and honeypots, within critical infrastructure organizations to complement Zero Trust models. The guidance outlines a three-phase operational process of preparation, execution, and understanding, advising decoys be placed where users rarely interact and configured to produce high-fidelity alerts. It aims to help defenders detect adversaries who use legitimate credentials, native tools, and living-off-the-land techniques, while enabling cost-effective threat intelligence collection.

SecurityWeek · 1d agoAdvisory

Virtual Event Today: Attack Surface Management Summit

SecurityWeek's 2026 Attack Surface Management Summit runs today as a virtual event covering asset discovery, SBOMs, red teaming, and pen-testing.

SecurityWeek is hosting its fully virtual 2026 Attack Surface Management Summit from 11AM-3PM, focused on continuous asset discovery, prioritization, and risk reduction. Sessions cover proving exploitability, SBOM and AIBOM software supply chain risk with Dr. Allan Friedman, demos from Wiz and Horizon3's NodeZero, and the roles of red teaming, bug bounty, and penetration testing in enterprise defense.

SecurityWeek · 1d agoIndustry

Critical ScreenConnect flaw now actively exploited in attacks

CISA confirms active exploitation of critical ConnectWise ScreenConnect flaw CVE-2026-84869, ordering federal agencies to mitigate within three days.

ConnectWise's ScreenConnect flaw CVE-2026-84869, an improper privilege management and missing authorization bug, lets attackers with basic privileges transfer or execute files through active remote sessions in low-complexity attacks without user interaction. It is patched in ScreenConnect 26.6.5; CISA added it to the KEV catalog and ordered US federal agencies to secure systems within three days. Shadowserver tracks over 1,000 unpatched exposed instances, mostly in North America (758) and Europe (180). This is the fourth actively exploited ScreenConnect flaw since 2024; earlier issues were abused by Kimsuky and ransomware gangs.

BleepingComputerupdated · 1d agofirst · 2d agoExploit / PoC in the wild 4 sourcesCVE-2026-84869CVE-2024-1709CVE-2025-3935+1 CVEs1

SilkParasite Infrastructure Links SpiceRAT to Central Asian Targets

Hunt.io linked SpiceRAT, NodeEdgeRAT, and NomadRAT C2 servers to the SilkParasite campaign targeting Central Asian governments since mid-2022.

Hunt.io and researcher Guy Yasur mapped C2 infrastructure tying three of seven RAT families from Bitdefender's SilkParasite report through shared TLS certificates, parent domains, and a cloned RTX Corporation homepage. One certificate spoofing Uzbekistan's state railway was issued by TLC, a CA funded by China's CAICT, and domains impersonate state entities in Turkmenistan, Uzbekistan, Tajikistan, and Kyrgyzstan. Passive DNS pushes the campaign back to mid-2022, and the infrastructure overlaps China-nexus activity including FamousSparrow and IndigoZebra.

Security Affairs · 23h agoThreat actor in the wild 3 sources

CISA promotes a fresh way to deter cyberattackers: Lie to them

CISA issued first-time guidance advising critical infrastructure operators to deploy honeypots, honeytokens, and decoys to detect and distract intruders.

CISA published 'Using Cyber Decoys to Strengthen Detection and Response,' a 22-page guide marking the agency's first guidance on decoys such as honeypots and honeytokens. Acting executive director Chris Butera described decoys as a low-cost, high-fidelity way to detect adversaries already inside networks, complementing zero-trust and assume-compromise approaches. The guidance covers decoy principles, definitions, deployment scenarios, and is aimed especially at resource-constrained critical infrastructure sectors.

CyberScoop · 1d agoAdvisory

Phishing Research Challenges Conventional Security Awareness Testing

Pistachio's 2.47 million phishing simulations across 1,200 organizations show click rates alone mislead, with 30% of IT staff clicking and leak rates more predictive.

Between June 2025 and May 2026, Pistachio sent 2.47 million simulated phishing attempts to more than 123,000 employees at over 1,200 organizations, analyzing click, credential-leak and reporting behavior. Click rates ranged from 26% in Design to 41% in Construction; 30% of tech development and IT staff clicked at least once, while financial services were the most resilient sector. The report argues that click rate alone creates a false sense of security and that combined click, leak and report trends are better resilience indicators.

SecurityWeek · 6d agoResearch

We got admin access to Baseten's production GitHub in 25 minutes

Strix autonomous hacking agent extracted a working GitHub token with repo admin rights from Baseten's public Harbor image; Baseten rotated it next day.

Strix, an autonomous hacking agent, scanned *.baseten.co without credentials and found a public Harbor container registry project anonymously exposing the baseten/baseten-app image. A GitHub personal access token for basetenbot, embedded in Docker build history since March 2023, still worked in July 2026 and granted admin/push rights to basetenlabs/baseten, flux-cd, and homebrew-tap plus read/write on private customer repos. Baseten, valued at $13 billion, confirmed the issue as critical and rotated the token within a day.

Check Point Fixes Critical CVE-2026-91843 Allowing Root Code Execution

Check Point patched CVE-2026-91843 (CVSS 9.8), a pre-authentication root RCE in Security Management and Log Servers; no exploitation observed.

Check Point fixed CVE-2026-91843 (CVSS 9.8), an unauthenticated stack overflow in the Security Management and Log Server login process that enables remote code execution as root. The attack path requires the Trusted Clients setting governing SmartConsole access and affects versions from R80 through R82.20 below listed hotfix takes. The fix ships via LivePatch under advisory sk1000155; Censys observed 3,836 hosts with the management role and no public PoC as of September 16.

Security Affairsupdated · 4h agofirst · 6h agoVulnerability 10 sourcesCVE-2026-91843

Horizon3 Announces Integration with CrowdStrike Falcon® Next-Gen SIEM

Horizon3 announces NodeZero integration pushing validated exposure findings into CrowdStrike Falcon Next-Gen SIEM for correlated investigations.

Horizon3 announced an integration enabling validated NodeZero findings to flow into CrowdStrike Falcon Next-Gen SIEM, available now in the CrowdStrike Marketplace. Security teams can ingest and correlate exposure data with endpoint, identity, cloud, and other telemetry during investigations. CrowdStrike claims Falcon Next-Gen SIEM delivers up to 150x faster search than legacy SIEMs at up to 80% lower total cost of ownership.

Horizon3.ai · 3d agoTools

Week in review: Linux rootkit deployed on F5 BIG-IP APM devices, Cisco FMC bugs exploited

Weekly roundup: Cisco FMC and N-able N-central zero-days exploited in the wild, MikroTik RouterOS hijacks, Microsoft Patch Tuesday ships two exploited zero-days.

State-sponsored and financially-motivated attackers are actively exploiting CVE-2026-20079, a critical authentication bypass in Cisco Secure Firewall Management Center (FMC), alongside CVE-2026-20316. N-able issued an emergency hotfix for CVE-2026-86218, a critical pre-auth RCE in the N-central RMM platform exploited in the wild. CERT Polska disclosed six RouterOS vulnerabilities being chained to hijack internet-exposed MikroTik devices. Microsoft's September 2026 Patch Tuesday shipped a record patch count including two zero-days, while roughly 67,000 Trezor customers faced phishing after a shipping-partner breach and researchers privately disclosed a zero-click WeChat worm to Tencent.

Help Net Security · 5d agoExploit / PoC in the wildCVE-2026-20079CVE-2026-20316CVE-2026-862182· 1 read

Security through obscurity is dead, and AI delivered the fatal blow

AI agents are killing security through obscurity, accelerating vulnerability discovery and patch-gap exploitation, experts warn, with OT/ICS systems most at risk.

An opinion/analysis piece arguing AI has made security through obscurity obsolete, citing record vulnerability disclosure volumes after Microsoft's Patch Tuesday addressed 974 CVEs. FBI Cyber Division assistant director Brett Leatherman said latest AI models found significant vulnerabilities in open source libraries running on most web servers. The article cites at least four espionage crews (most suspected China-linked) exploiting Chromium's patch-gap window with a rapid exploit kit, and a five-agency advisory on AI-generated exploitation scripts breaching internet-exposed Siemens S7 Series PLCs at water, manufacturing, and energy facilities. Experts including John Hultquist, Chris Inglis, and Katie Moussouris warn AI erodes the expertise barrier protecting obscure OT/ICS systems while defensive AI patching lags, with studies showing AI-generated patches fail more than half the time.

The Register · Security · 5d agoIndustry

Flock cameras are riddled with security vulnerabilities and hardcoded creds

Leaked Flock ALPR camera firmware reveals EOL Android 8.1, a 2017 Linux kernel, and hardcoded API keys granting access to production credentials.

DDoSecrets published filesystem images from an in-use Flock ALPR camera, obtained by the hacker collective stegan0gram and investigated by 404 Media and Wired. Micah Lee's analysis shows the camera runs Android 8.1 with a security patch level of 2018-06-05 and Linux kernel 3.18.71, missing roughly eight years of Android fixes. The firmware exposes a hardcoded API key for Flock's hpnotiq backend that can retrieve Auth0 client credentials for any camera by MAC address, with credentials stored in plaintext. Likely unpatched flaws include CVE-2021-1905 (Qualcomm Adreno use-after-free) and CVE-2018-9568 (WrongZone kernel socket type confusion); Flock says it received no reports via its disclosure policy.

Hacker News · securityupdated · 19h agofirst · 1d agoVulnerability 6 sourcesHN 35↑ · 3 commentsCVE-2021-1905CVE-2018-9568

Should you care about an “AI slowdown?”

Cisco Talos argues an AI slowdown would barely affect cybersecurity, urging focus on fundamentals and Qilin ransomware trends in Japan.

Cisco Talos' newsletter opines that an AI development slowdown would have limited security impact since current models already uncover substantial vulnerabilities. It highlights Talos findings that Japan's ransomware incidents rose nearly 5 percent in H1 2026, driven by The Gentlemen RaaS group and Qilin, which uses LLMs to generate destructive scripts and targets SMBs with double extortion. The newsletter also recaps headlines including an Android app-cloning campaign, Apple's 200-patch release, ClickFix lures, and VectraRAT.

Cisco Talosupdated · 6h agofirst · 20h agoIndustry 4 sources

Conti Hacker Who Built Malware and Attacked Victims Gets Four-Year Sentence

Ukrainian lawyer and Conti malware developer Oleksii Lytvynenko was sentenced to four years in U.S. prison for wire fraud conspiracy tied to Conti ransomware.

Lytvynenko, 44, admitted coding a loader for Conti and holding stolen data from eight U.S. and four overseas victims; prosecutors linked his actions to attacks on at least 12 companies. Conti infected more than 1,000 organizations across 47 U.S. states and 31 countries between 2020 and 2022, with victim payouts exceeding $150 million. Arrested in County Cork in July 2023 with Cobalt Strike running and an active Rocket.Chat session over Tor, forensic evidence showed his ransomware activity continued after Conti's 2022 collapse.

Security Affairs · 5d agoPolicy & legal

Chosen Brick, Iran’s Surveillance Malware

UK, US, and Dutch agencies warn Iranian CHOSEN BRICK malware targets dissidents and journalists via Telegram, harvesting contacts, emails, and messages since 2025.

The UK NCSC, FBI, and Dutch AIVD jointly attributed the CHOSEN BRICK Windows malware family to Iranian intelligence services, used since at least 2025 against dissidents, journalists, and activists worldwide, including in the UK, US, and Netherlands. Operators build rapport over WhatsApp or Telegram, impersonating known contacts or platform support, then deliver lures disguised as installers for Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, or KeePass, or fake MRI results. The malware persists via registry Run keys, adds Microsoft Defender exclusions, and uses per-victim Telegram bot IDs for C2, with newer versions adding HTTPS or SOCKS5 proxies. Some victims' data appeared on pro-Iranian leak sites, raising harassment and physical-safety risks.

Security Affairsupdated · 1d agofirst · 1d agoMalware in the wild 10 sources

Thorough reorganization at NSA will create five 'mission centers,' including cyber and AI

NSA is reorganizing into five mission centers covering China, cybersecurity, AI, combat support and global intelligence, with full capability targeted by January.

NSA Director Gen. Joshua Rudd announced a sweeping reorganization replacing existing directorates with five mission centers focused on China, cybersecurity, artificial intelligence, combat support, and global intelligence. A 30-day implementation clock has started, and the centers are expected to reach full operational capability by January. Officials acknowledge the rapid realignment will 'break things' in the agency's bureaucracy; this is the largest restructuring since the NSA21 effort roughly a decade ago, which was widely viewed as a failure.

The Record · 4d agoPolicy & legal

Cisco warns customers of actively exploited zero-day in email gateways

Actively exploited Cisco Secure Email Gateway zero-day CVE-2026-76461 allows unauthenticated root command execution; CISA added it to KEV.

Cisco disclosed CVE-2026-76461, a zero-day in AsyncOS for Cisco Secure Email Gateway that was exploited before disclosure and lets unauthenticated remote attackers execute commands with root privileges on cloud and on-premises instances. CISA promptly added the flaw to its Known Exploited Vulnerabilities catalog, and Cisco has directly contacted cloud customers with indicators of compromise while deploying mitigations. Rapid7 and VulnCheck warn compromised gateways could enable silent email monitoring and internal pivoting from on-premises deployments.

CyberScoopupdated · 2d agofirst · 2d agoExploit / PoC in the wild 17 sourcesCVE-2026-76461

Cyberattacks on Oil Tankers Put Maritime Critical Infrastructure at Risk

Cyberattacks hit two Texas-bound oil tankers including VL Prosperity, disrupting communications ~30 hours and raising maritime OT risk concerns.

US Coast Guard and FBI boarded two tankers after cyberattacks struck them en route to Texas in August 2026; the VL Prosperity supertanker carrying 2.3 million barrels was reportedly hit near Gibraltar on August 7. Iranian state media claimed hackers accessed propulsion, navigation, and cargo systems, but attribution remains unverified. Coast Guard Cyber Command confirmed malicious cyber activity aboard the vessels, and officials warn connected ships could threaten ports handling $5.4 trillion in annual US commerce.

Security Affairs · 19h agoExploit / PoC in the wild 4 sources

ENISA: Frontier AI Is Changing the Speed of Cyberattacks. Europe Needs to Catch Up

ENISA warns frontier AI compresses attack lifecycles to minutes, with exploits possible within 15 minutes of disclosure and median 72-minute breach-to-exfiltration times.

ENISA's July 2026 paper 'ENISA's view on Cybersecurity in the Frontier AI Era' argues AI-assisted attackers may weaponize vulnerabilities within 15 minutes of disclosure and achieve initial-access-to-data-exfiltration in a median 72 minutes, creating a 'negative time-to-exploit' problem. The report cites one organisation whose CVE volume rose from roughly 80 in Q1 2025 to almost 500 in Q1 2026, then about 500 reports per day when frontier-AI tools were used. ENISA recommends machine-speed defence under 'Cybersecurity as Code', EPSS and VEX-based prioritisation, AI-assisted incident response with human oversight, and an assume-breached architecture.

Security Affairs · 3d agoAdvisory

Beyond the Perimeter: Building Resilience Against Cloud and SaaS Supply-Chain Attacks

ShinyHunters exploited an Oracle PeopleSoft zero-day to steal data and extort roughly 100 organizations, including the Council of Europe, for up to $2.3M.

Between May and early June 2026, the ShinyHunters group exploited a critical zero-day in Oracle PeopleSoft across about 100 organizations and 300 instances worldwide, per reports cited by The Register. Stolen records included employee and student personal data, payroll, tax, financial and health information, plus immigration and passport documents. AgentCypher.ai estimates extortion demands of $400,000 to $2.3 million per victim, typically in Bitcoin; the Council of Europe refused to pay. The article uses the incident to argue for Zero Trust, supply-chain risk management, rapid patching, encrypted distributed backups and defined recovery-time objectives.

Cyber Security News · 6d agoData breach in the wild2