tomcat
If olive oil comes from olives 🫒 where does baby oil come from? 🤔 🥸
‼️ Check Point is warning customers about a newly disclosed Security Management Server zero-day exploited in targeted attacks in July.
CVE-2026-93616 lets an attacker who can reach the web service upload and run scripts without logging in. A fix landed Sept. 22.
Here's what admins should hunt for: https://thehackernews.com/2026/09/check-point-warns-of-management-server.html
🚨 North Korea’s Contagious Interview campaign compromised 30,000+ devices across 100+ countries and stole at least $10.71M in crypto.
Fake job offers and coding tests trigger malware infections; funds or credentials were siphoned from 7,000+ wallets.
Inside the chain: https://thehackernews.com/2026/09/contagious-interview-campaign.html
‼️ PEEP turns Chrome and Edge into host-level backdoors after compromise.
With prior admin or code-execution access, the Smart Bookmarks extension steals session cookies and credentials, then uses Chromium native messaging to run host commands.
Read: https://thehackernews.com/2026/09/peep-turns-chrome-and-edge-into-post.html
⚠️ North Korean Jade Sleet is linked to a breach of an Indian IT provider via a DevOps engineer’s Apple Silicon MacBook.
FLATROOF and ROOFDECK were found on the system, with capabilities for command execution, remote shell access, persistence, and data theft.
Inside the MacBook compromise: https://thehackernews.com/2026/09/jade-sleet-linked-to-indian-it-provider.html
🚨 A hard-coded static key in SolarWinds ARM can enable unauthenticated RCE.
CVE-2026-28326 affects ARM 2026.2 and earlier and is fixed in 2026.2.1. SolarWinds did not report in-the-wild exploitation.
Read: https://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.html
‼️ Claude Opus 5 helped three researchers build an image exploit that took over OpenAI's public help forum server.
A flaw in OpenAI's own login then let them take over staff ChatGPT/Codex accounts and reach an internal code repo — in under 72 hours.
Here's how the chain worked → https://thehackernews.com/2026/09/claude-opus-5-helped-researchers-take.html
‼️ ALERT - Critical Docker Sandboxes flaw lets malicious guest code escape the shared workspace and read or modify files across a macOS host.
CVE-2026-77179 crosses the virtio-fs boundary with the host account’s rights.
Read how the escape works → https://thehackernews.com/2026/09/critical-docker-sandboxes-flaw-lets.html
‼️ Attackers are exploiting a critical Issabel Framework flaw.
CVE-2026-89026 uses a hard-coded JWT signing key, letting unauthenticated remote attackers forge tokens and execute OS commands as the Asterisk user. A fix is available.
How the flaw works: https://thehackernews.com/2026/09/attackers-exploit-issabel-framework.html
🚨 KREMLIN banking malware bypasses Chromium integrity checks to install a Chrome and Edge extension that steals credentials and session tokens.
It also uses Ethereum smart contracts to rotate C2 and payload locations.
How the attack chain works: https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html
🚨 Fake passkey updates are being used to take over Microsoft cloud accounts.
Once inside, threat actors add their own MFA methods and pull data from SharePoint, OneDrive, and mailboxes.
Inside the passkey phishing chain → https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html
⚠️ Nearly 31,000 Twitch users had live OAuth tokens sent to operator-controlled proxies by a malicious browser extension.
JeetBot put the credentials in request URLs, exposing them in proxy logs. Older installs keep sending them until updated.
Read: https://thehackernews.com/2026/09/malicious-twitch-browser-extension.html
🚨 Attackers chained two JFrog Artifactory flaws to gain admin control and plant backdoors.
Only unupdated self-hosted servers were open to that chain. A separate critical auth bypass also drew 406,000 exploitation attempts in one day.
How the attacks work: https://thehackernews.com/2026/09/attackers-chain-jfrog-artifactory-flaws.html
🚨 151 million Claude exchanges in one Alibaba-affiliated distillation campaign.
Anthropic says it was part of a broader operation involving seven China-based AI labs, with some using proxy networks, fraudulent accounts, and rerouted user requests to harvest Claude capabilities.
Inside the operation: https://thehackernews.com/2026/09/anthropic-says-seven-china-based-ai.html
🚨 Thousands of deceptive Android apps are abusing a Google Play trust gap: Early Access apps have no public reviews or star ratings.
Fake casino and reward apps are promoted through social ads, including AI-generated celebrity deepfakes.
How the scheme works: https://thehackernews.com/2026/09/google-play-early-access-abused-to-push.html
🔥 U.S. authorities disrupted Xinbi Guarantee and froze $52.8 million in crypto linked to the scam marketplace.
Xinbi then shifted about $2.8 million from USDT to USDD, which lacks USDT’s built-in wallet-freezing feature.
Read: https://thehackernews.com/2026/09/us-disrupts-xinbi-guarantee-scam.html
🛑 A WeChat call from a contact could take over your account without an answer.
Researchers demonstrated the zero-click worm spreading across three iPhone and Android test phones.
How the chain worked: https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over.html
🚨 JSCeal V8 malware can bypass Google authentication using stolen browser cookies.
It can also modify Binance, Bybit, and Ledger traffic through a local proxy.
How analysts decoded its hidden capabilities: https://thehackernews.com/2026/09/jsceal-malware-can-bypass-google.html
⚠️ Researchers uncover four previously unreported, persistent programs linked to REVSTEALER.
Wallet theft, clipboard hijacking, proxying and mining. The miner can disable Windows Update and add Defender exclusions after elevation.
What each program does > https://thehackernews.com/2026/09/four-revstealer-linked-modules-disable.html
‼️ BREAKING - Attackers are exploiting an unpatched Magento and Adobe Commerce ZERO-DAY to backdoor online stores.
No login required. No published CVE. No Adobe patch yet.
Here's what to do and how the attack works: https://thehackernews.com/2026/09/unpatched-magento-and-adobe-commerce.html
CrashStealer uses a signed and Apple-notarized macOS dropper to pass Gatekeeper checks.
Once launched, it can steal browser credentials, wallet data, password manager records, files, and keychain material.
How the attack chain works: https://thehackernews.com/2026/07/crashstealer-macos-malware-uses.html
⚡ UPDATE: #wp2shell now has two CVEs, and a working proof-of-concept is public.
CVE-2026-63030 breaks REST batch routing CVE-2026-60137 injects SQL
Chained, they give an anonymous attacker code execution on affected WordPress sites.
How the exploit path works: https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html
🛑 Two Scattered Spider hackers have been sentenced to 5.5 years each for the £29 million TfL attack.
The intrusion left 148 systems inoperable, disrupted Dial-a-Ride and payment services, and forced all 27,000 employees into the office for password resets.
Here's how investigators tied them to the attack: https://thehackernews.com/2026/07/two-scattered-spider-hackers-get-55.html
⚠️ Researchers found raw LLM reasoning and an AI safety disclaimer left inside TuxBot v3 Evolution.
The unfinished IoT botnet packs 1,496 Telnet credential pairs and exploit code for more than 30 device families.
What already works: https://thehackernews.com/2026/07/tuxbot-v3-evolution-shows-signs-of-llm.html
🔥 Microsoft patched a record 622 CVEs, including two exploited zero-days in SharePoint Server and AD FS.
The SharePoint flaw allows remote, unauthenticated privilege escalation. The AD FS bug lets authenticated attackers elevate privileges locally.
Here's what to patch first: https://thehackernews.com/2026/07/microsoft-patches-record-622-flaws.html
🚨 Zimbra has fixed a critical stored XSS flaw in its Classic Web Client.
A crafted email could run malicious code when opened and expose mailbox information, session data, or account settings.
Read the full story on THN 🠖 https://thehackernews.com/2026/07/critical-zimbra-flaw-could-let-crafted_0483473395.html
Zimbra has not reported in-the-wild exploitation. Update to version 10.1.19.
🛑 WARNING - Meta’s new Muse Image tool can let others use your public #Instagram photos in AI-generated images UNLESS you opt out.
Users can @-mention public Instagram accounts in Meta AI to pull public photos into new visuals, and existing AI creations may not be deleted after you disable reuse.
Here’s how to turn it off 🠖 https://thehackernews.com/2026/07/metas-new-ai-image-tool-lets-others-use.html