# Archive

Browse past daily curated stories

Aug 09 Aug 08 Aug 07 Aug 06 Aug 05 Aug 04 Aug 03 Aug 02 Aug 01 Jul 31 Jul 30 Jul 29 Jul 28 Jul 27 Jul 26 Jul 25 Jul 24 Jul 23 Jul 22 Jul 21 Jul 19 Jul 18 Jul 17 Jul 16 Jul 15 Jul 14 Jul 12 Jul 11 Jul 10 Jul 09

Sunday, August 09, 2026

  1. 1
    0
    The Hacker News general
    New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

    PortSwigger researcher Gareth Hayes demonstrated CSS-based attack chains affecting Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail that allow email content to escape message boundaries and interfere with the webmail UI. The techniques can capture passwords, steal session tokens, hijack trusted UI actions, and manipulate AI tools that parse email — making this a broad, high-impact finding for anyone operating or securing webmail infrastructure.

  2. 2
    0
    The Hacker News general
    Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

    Metabase has disclosed a CVSS 10.0 zero-day vulnerability with no CVE assigned yet that allows unauthenticated remote attackers to inject arbitrary SQL into the application database, granting full admin access without credentials. Active exploitation in the wild has been confirmed, making immediate patching critical for any organization running Metabase for business intelligence or data visualization.

  3. 3
    0
    The Hacker News general
    Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

    CISA added CVE-2026-8037 (CVSS 9.6), a command injection flaw in Progress Kemp LoadMaster, to its Known Exploited Vulnerabilities catalog after 792 reported exploit attempts. Organizations using LoadMaster for application delivery and load balancing should apply patches immediately under BOD 22-01 federal agency deadlines.

  4. 4
    0
    The Hacker News general
    N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist

    N-able released a second hotfix for N-central RMM after threat actors evolved their attack techniques to achieve persistence on managed endpoints beyond what the first hotfix addressed. Because N-central is used by MSPs to manage client infrastructure at scale, ongoing active exploitation represents a supply-chain-level risk affecting downstream managed systems.

  5. 5
    0
    The Hacker News general
    New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables

    Researcher Malcolm Stagg presented NatJack at Black Hat USA 2026, a novel attack class that manipulates NAT connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables. The techniques were demonstrated across multiple independently developed implementations including Windows, making this a systemic protocol-level concern rather than a single-vendor bug.

  6. 6
    0
    The Hacker News general
    Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

    An active AitM phishing campaign is compromising Microsoft 365 accounts by using residential proxies to disguise malicious sign-ins as consumer traffic, then targeting personnel involved in payroll and financial workflows to harvest related emails. The use of residential proxies to evade IP-reputation defenses combined with financial-fraud intent makes this a high-priority detection challenge for enterprise defenders.

  7. 7
    0
    The Hacker News general
    Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

    Researchers at OpenSourceMalware identified nearly 800 malicious npm packages using typosquatting and AI-generated names to deliver a cross-platform RAT and infostealer targeting Windows, macOS, and Linux simultaneously. The scale of the campaign and its multi-OS payload coverage pose significant supply chain risk for developers who install packages without verification.

  8. 8
    0
    The Hacker News general
    TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

    New analysis links threat actor TeamPCP to Redis-targeting attacks dating back to 2020, with overlapping domains, malware deployment paths, and backend infrastructure connecting early cryptomining campaigns to a later software supply chain operation. The longitudinal activity timeline suggests a well-resourced group that quietly expanded from opportunistic server compromise to targeted supply chain attacks.

  9. 9
    0
    BleepingComputer general
    North Carolina Ports confirms cyberattack disrupting operations

    A cyberattack disrupted gate systems at all three North Carolina Ports Authority facilities — Port of Wilmington, Port of Morehead City, and Charlotte Inland Port — with the U.S. Coast Guard actively monitoring the incident. The attack on physical port gate systems demonstrates continued threat actor interest in critical transportation infrastructure and operational technology environments.

  10. 10
    0
    The Hacker News general
    Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

    Security research disclosed at Black Hat USA 2026 shows that malware can abuse Windows Hello for Business cryptographic keys to maintain persistent access to Microsoft Entra ID, surviving credential resets that defenders typically rely on for eviction. This technique undermines a common incident response step and is relevant to any enterprise using Entra ID with passwordless authentication.