# Archive

Browse past daily curated stories

Jul 25 Jul 24 Jul 23 Jul 22 Jul 21 Jul 19 Jul 18 Jul 17 Jul 16 Jul 15 Jul 14 Jul 12 Jul 11 Jul 10 Jul 09 Jul 08 Jul 07 Jul 05 Jul 04 Jul 03 Jul 02 Jul 01 Jun 30 Jun 27 Jun 26 Jun 25 Jun 24 Jun 23 Jun 21 Jun 20

Saturday, July 25, 2026

  1. 1
    0
    The Hacker News general
    Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

    Russian state-sponsored group 'Laundry Bear' exploited a Zimbra zero-day for five months before a July 2025 patch, using a zero-click 'half-click' phishing technique requiring only that a victim open or preview a message. The payload exfiltrates the last 90 days of email, the full organizational email directory, browser-saved passwords, and 2FA recovery codes. NSA, CISA, and partner agencies issued a joint advisory, making this a critical defensive priority for any organization running Zimbra webmail.

  2. 2
    0
    The Hacker News general
    Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

    Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 for 'Certighost,' a flaw allowing low-privileged Active Directory users to obtain a Domain Controller certificate and authenticate as that machine account. The resulting Kerberos credential can then perform a DCSync attack to retrieve the krbtgt secret, enabling full domain compromise. This Active Directory privilege escalation path represents a critical risk for enterprise environments running misconfigured AD Certificate Services.

  3. 3
    0
    The Hacker News general
    Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers

    XBOW researchers discovered that crafted SVG files submitted to Bing Image Search executed commands as NT AUTHORITY\SYSTEM on Windows and as root on Linux within Microsoft's production image-processing worker fleet, affecting multiple hosts across different network ranges. Microsoft issued two critical CVEs — CVE-2026-32194 and a second unspecified CVE — to address the vulnerabilities. The server-side RCE impact on Microsoft's production infrastructure makes this a significant supply-chain and cloud security incident.

  4. 4
    0
    The Hacker News general
    Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say

    Kimi K3 AI agents independently discovered zero-day vulnerabilities in Redis and produced working authenticated RCE proof-of-concept exploits targeting stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0 — all requiring the RESTORE command, with some chains also needing EVAL, XGROUP, or the bundled RedisBloom module. Redis shipped seven security releases on July 23, patching to versions 6.2.23, 7.2.15, and 7.4.10. The incident demonstrates that AI-assisted vulnerability discovery is now capable of producing exploitable zero-days in widely deployed infrastructure software.

  5. 5
    0
    The Hacker News general
    Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry

    A threat actor deployed the open-source Hermes AI agent in unattended 'YOLO' mode — disabling safety confirmation prompts — on a rented server and directed it autonomously against Thailand's Ministry of Finance, which manages the country's treasury and tax systems. The agent independently conducted post-exploitation activities including host enumeration, privilege escalation attempts, and filesystem reconnaissance without human oversight. This marks a documented case of an AI agent being weaponized for autonomous offensive cyber operations against a national government target.

  6. 6
    0
    BleepingComputer general
    Clop ransomware targets Windchill, FlexPLM in data theft attacks

    The Clop ransomware gang (Cl0p) has launched a new data theft extortion campaign targeting internet-exposed instances of PTC Windchill (PLM software) and FlexPLM, continuing their pattern of exploiting enterprise software platforms for mass data theft without encrypting files. This follows Clop's prior campaigns exploiting MOVEit and GoAnywhere vulnerabilities. Organizations running internet-facing PTC Windchill or FlexPLM instances should treat these as actively targeted and audit exposure immediately.

  7. 7
    0
    BleepingComputer general
    Check Point warns of SmartConsole zero-day exploited in attacks

    Check Point Software patched an actively exploited zero-day (CVE-2026-16232) in SmartConsole, the GUI admin panel used to manage Check Point security gateways, affecting customers with certain configurations. The flaw was being weaponized in the wild before a patch was available. Security teams running Check Point environments should apply the fix immediately given that SmartConsole provides direct access to firewall and network security policy management.

  8. 8
    0
    The Hacker News general
    Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files

    Accomplish AI researchers discovered a sandbox escape vulnerability in Anthropic's Claude Cowork product that allows a malicious or manipulated AI agent to break out of its Linux VM and read or write files anywhere on the host macOS filesystem. The vulnerability affects approximately 500,000 macOS users running the Claude Cowork application. The flaw illustrates a systemic risk in AI agent sandboxing architectures where VM isolation boundaries are insufficiently enforced.

  9. 9
    0
    BleepingComputer general
    New RefluXFS Linux flaw lets attackers gain root privileges

    A nine-year-old race condition in the Linux kernel's XFS filesystem driver, tracked as CVE-2026-64600 and dubbed 'RefluXFS,' allows local attackers to overwrite protected files and escalate privileges to root. The vulnerability has existed since at least 2017, affecting a wide range of Linux distributions that use XFS as their default filesystem, including RHEL, CentOS, and Fedora variants. Local privilege escalation flaws in widely deployed Linux kernel filesystems present significant risk in shared hosting, container, and cloud environments.

  10. 10
    0
    The Hacker News general
    ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

    Zenity Labs disclosed 'AgentForger,' a critical vulnerability in OpenAI's ChatGPT Workspace Agents that allowed a single phishing link to silently create, authorize, and deploy an autonomous AI agent inside a victim organization's workspace, effectively inserting a persistent insider threat. OpenAI patched the vulnerability as of June 8, 2026. The attack required no user interaction beyond clicking the phishing link, and the rogue agent could operate with the victim's organizational permissions indefinitely.