Skip to content

News

World Cybersecurity News

RSS The Hacker News
  • RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall September 18, 2026
    Cybersecurity researchers have flagged a new Android malware called RatHat that's assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices. "Distributed primarily via targeted smishing (SMS/text phishing) and malvertising campaigns leading to deceptive third-party download portals, RatHat uses
  • Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root September 17, 2026
    A critical vulnerability in Check Point's Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network. The Security Management Server is the system that controls firewall policy and administrator access. Check Point has released a fix through its LivePatch update channel and […]
  • ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories September 17, 2026
    Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them. This week, those keys sit in AI tools, exposed services, old bugs, weak logins, and software sold like a monthly subscription. Some attacks use new tricks. Others just reuse what was already lying around. Both work often enough. […]
  • Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files September 17, 2026
    Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the host, Docker warns in a security announcement on September 15. The escape runs with the rights of the host account that runs the virtual machine. The flaw, CVE-2026-77179, is rated […]
  • Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords September 17, 2026
    The Iran-linked "hacktivist" persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE. "HEAVYGRAM offers builtin commands supporting remote command execution, system, network and process information discovery, data and Telegram session files exfiltration, screenshot capture, DLL sideloading,
  • Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone September 17, 2026
    Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday. An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution. Unbound 1.26.1, released the same day, fixes the bug, tracked as CVE-2026-81642, […]
  • Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar September 17, 2026
    A new CVE drops. Your scanner finds it. The severity score looks ugly. But that still does not answer the question that matters: Can it actually be exploited in your environment? Mythos-class AI is compressing the time between disclosure and working exploitation, while many security programs still validate risk on weekly or quarterly cycles. The […]
  • CISO's Expert Guide to Agentic Pentesting for Websites September 17, 2026
    Attackers now weaponize new vulnerabilities in about five days (Mandiant, part of Google Cloud). The median organization takes 43 days to patch one (Verizon DBIR 2026). A new free guide explains how autonomous AI agents are closing that gap, and what security leaders must demand before pointing one at production. TL;DR Exploitation is now the […]
  • China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America September 17, 2026
    The China-aligned state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in attacks targeting multiple countries in Latin America since at least August 2025. "SparroWocky is a modular, C++ backdoor," ESET security researchers Alexandre Côté Cyr and Romain Dumont said in a technical report shared with The Hacker […]
  • OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads September 17, 2026
    OpenAI on Wednesday disclosed six new instances of "unexpected or concerning model behavior" that took place over the past six months, while sharing a new framework for reporting, tracking, investigating, and disclosing model misalignment in a bid to improve transparency. "As AI systems grow more advanced and more widely deployed, we need to build a […]
RSS Cybercrime Magazine
  • AI Hackers Are Dumb And They Can Wreak Havoc September 17, 2026
    This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Sep. 17, 2026 – Watch the Video “It’s never been tougher for a practitioner to secure their environment,” Snehal Antani, CEO at Horizon3, told Cybercrime Magazine at the Black Hat USA 2026 The post AI Hackers Are Dumb And They Can Wreak […]
    Amanada Glassner
  • Blake Benthall aka “Defcon”, Former Operator of Silk Road 2.0, Tells His Story September 16, 2026
    This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Sep. 16, 2026 – Listen to the Podcast Silk Road 2.0 was a dark web marketplace launched in Nov. 2013, approximately five weeks after the FBI shut down the original Silk Road and arrested its The post Blake Benthall aka “Defcon”, Former Operator of Silk […]
    Amanada Glassner
  • 6 of the Best Autonomous Penetration Testing Companies in 2026 September 15, 2026
    This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Sep. 15, 2026 – Read the full story from BreachLock Six vendors run autonomous penetration testing as a standalone product today: BreachLock (Breach360): Trains its AI on 40,000+ real pentests to chain The post 6 of the Best Autonomous Penetration Testing Companies […]
    Taylor Fox
  • Adopting Exposure Management in the Age of AI September 14, 2026
    The rules of cyber warfare are changing faster than most organizations can adapt. –Christopher Hogan, Vice President, Vulnerability Management, Mastercard San Jose, Calif. – Sep. 14, 2026 The cybersecurity landscape in 2026 can best be described as volatile, shaped by evolving geopolitical tensions and the The post Adopting Exposure Management in the Age of AI […]
    Taylor Fox
  • The CISO Gap Is A Huge SMB Cybersecurity Opportunity For MSSPs September 14, 2026
    This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Sep. 14, 2026 – Read the Full Story in Forbes AI has fundamentally changed what a cyberattack looks like. A Forbes article reports that tools, speed and sophistication that once required nation-state resources are The post The CISO Gap Is A Huge SMB Cybersecurity […]
    Taylor Fox
  • Digital Executive Protection: Agentic Powered External Identity Security September 11, 2026
    This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Sep. 11, 2026 – Watch the YouTube Video External identity is the personal data of executives, employees, and their families that attackers can find and exploit outside company systems. VanishID is tackling that exposure The post Digital Executive Protection: Agentic Powered External Identity Security […]
    Taylor Fox
  • Project Blocks Cameras, Allows People To Escape Detection And Surveillance September 10, 2026
    This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Sep. 10, 2026 – Listen to the Episode TechCrunch reports that Bill Swearingen has spent the past year running largely the same test, over and over again. The goal was to produce a computer-generated pattern The post Project Blocks Cameras, Allows People To Escape Detection […]
    Taylor Fox
  • Ransomware Is The New Normal: Cybersecurity Considerations for Fiduciaries September 9, 2026
    This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Sep. 9, 2026 – Read the Full Story from J.S. Held Court-appointed receivers, chief restructuring officers, distressed asset investors, and lenders should realize that cybersecurity is now a fiduciary duty and should The post Ransomware Is The New Normal: Cybersecurity Considerations for […]
    Taylor Fox
  • The Numbers Behind CISO Burnout And Turnover September 8, 2026
    This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Sep. 8, 2026 – Read the Report The 2026 CISO Report from Cybercrime Magazine in partnership with Sophos looks at how security Chiefs are faring in one of the most stressful tech jobs. “For The post The Numbers Behind CISO Burnout And Turnover appeared […]
    Taylor Fox
  • Early Bird Registration For Black Hat Europe 2026 In London September 4, 2026
    This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Sep. 4, 2026 Black Hat Europe returns to the Excel in London with a four-day program, Dec. 7-10. The event will open with two-and four-day options of specialized cybersecurity Trainings, with courses of The post Early Bird Registration For Black Hat Europe 2026 […]
    Taylor Fox

Cyberthreat Real Time Map

For more detailed map and information click here