Security news

Latest security news

Tue, 8 Sept 2026

  1. WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls

    Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones. The person being called does not have to answer or touch their phone for it to work, but the caller must already be one of their WeChat contacts. Calif reported the flaw to Tencent in July and says the company has since

    The Hacker NewsAndroid
  2. What It Took to Reach 1 Billion Build Manifests

    In the last six months, Chainguard doubled its output from 500 million to more than 1 billion container build manifests. We also surpassed 3,000 unique container images and 675,000 image versions in our catalog. Those are the headline numbers, but I want to share what's actually behind them. The number itself is less interesting than the system that produced it, and why we had to fundamentally

    The Hacker News
  3. FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials

    A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system that determines who may log in across a Linux domain and maintains all identities in a 389 Directory Server database accessed via LDAP. The attack needs a second flaw in that database software. The

    The Hacker NewsLinux
  4. THost9 Android RAT Pairs Packed Loader With ADB Worm

    THost9 hides its payload and uses ADB to spread across exposed Android devices and containers

    Infosecurity MagazineAndroid
  5. CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED)

    Overview While conducting research into a recent N-able N-central authentication bypass vulnerability ( CVE-2026-18577 ), Rapid7 Labs discovered two new vulnerabilities affecting the latest version of N-central. When chained together, these two vulnerabilities allow a remote unauthenticated attacker to bypass authentication and create a new attacker-controlled System administrator account on an affected server. CVE ID Description CWE CVSSv4 CVE-2026-86206 Semicolon/Forwarded access-control bypass CWE-791 6.9 (Medium) CVE-2026-86207 UserTwoFactorLogin authentication bypass CWE-305 7.7 (High) Both CVE-2026-86206 and CVE-2026-86207 have been patched by the vendor via N-central 2026.3 Hotfix 3. Product description N-able N-central is an enterprise-grade Remote Monitoring and Management (RMM) platform designed for Managed Service Providers (MSPs) and IT departments to monitor, manage, and secure complex, large-scale networks from a centralized dashboard. Credit These vulnerabilities were discovered by Stephen Fewer, Senior Principal Security Researcher at Rapid7 , and are being disclosed in accordance with Rapid7's vulnerability disclosure policy . Technical analysis CVE-2026-86206 N-ce

    CriticalUsed in attacksRapid7 BlogN-able
  6. ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager

    We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload.

    Cisco Talos
  7. ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2

    Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim's browser session.

    Cisco TalosGoogle, Cisco
  8. MikroTik router flaws allow takeover without a password

    Attackers are exploiting critical RouterOS flaws to take control of routers with SSH exposed to the internet.

    Malwarebytes Labs
  9. BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials

    CloudSEK has uncovered BigBear 2.0, a new phishing-as-a-service operation targeting Microsoft 365

    Infosecurity MagazineMicrosoft
  10. Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

    Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. "This update resolves a critical

    CriticalUsed in attacksThe Hacker NewsAdobe

About this news

1,434
Stories
65
Added in the last 24 hours
11
Critical in the last 7 days
4
Reported by several outlets