Cyber News

    Dashboard / Cyber News

    Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon
    in
    [email protected] (The Hacker News)-8 days ago

    Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon

    The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a proof-of-concept (PoC) for a privilege escalation flaw impacting Crowdstrike Falcon. "FalconFlank is a 0-day privilege escalation that abuses the office malicious macros remediation in CrowdStrike Falcon Sensor," the researcher said in
    BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access
    in
    [email protected] (The Hacker News)-9 days ago

    BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access

    Virtualizor said hackers used a Border Gateway Protocol (BGP) hijack to divert Softaculous traffic. The hackers then used the diverted update traffic to deliver a malicious Virtualizor package to some installations. A hosting-provider account separately said 5 of its 34 checked Virtualizor hypervisors sustained root-level compromise. The incident window ran from approximately August 28 at 20:57
    GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends
    in
    [email protected] (The Hacker News)-9 days ago

    GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

    Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals. The project shipped fixes in versions 4.4.12 and 4.2.17 on July 8, 2026, and published the vulnerability details on August 31. GeoNetwork originated at the United Nations Food and
    Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads
    in
    [email protected] (The Hacker News)-9 days ago

    Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads

    The U.S. Department of Justice (DoJ) on Tuesday announced the takedown of a long-standing peer-to-peer (P2P) botnet known as Sality as part of a coordinated law enforcement operation. The effort was undertaken on August 31, 2026, by authorities from the U.S., Bulgaria, Hungary, and Romania, in collaboration with private industry partners CrowdStrike and the Shadowserver Foundation. To that
    Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests
    in
    [email protected] (The Hacker News)-10 days ago

    Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests

    The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote access trojans (RATs) developed using Node.js and JavaScript. Russian cybersecurity company Kaspersky is tracking the
    Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity
    in
    [email protected] (The Hacker News)-10 days ago

    Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity

    Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck. The vulnerabilities in question are listed below - CVE-2026-0768 (CVSS score: 9.8) - A lack of proper validation of a user-supplied input vulnerability that could be exploited to execute arbitrary Python code in the context of the root user. CVE-2026-66066 aka