# Archive
Browse past daily curated stories
Sunday, August 09, 2026
-
1The Hacker News generalNew CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
PortSwigger researcher Gareth Hayes demonstrated CSS-based attack chains affecting Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail that allow email content to escape message boundaries and interfere with the webmail UI. The techniques can capture passwords, steal session tokens, hijack trusted UI actions, and manipulate AI tools that parse email — making this a broad, high-impact finding for anyone operating or securing webmail infrastructure.
-
2The Hacker News generalMetabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
Metabase has disclosed a CVSS 10.0 zero-day vulnerability with no CVE assigned yet that allows unauthenticated remote attackers to inject arbitrary SQL into the application database, granting full admin access without credentials. Active exploitation in the wild has been confirmed, making immediate patching critical for any organization running Metabase for business intelligence or data visualization.
-
3The Hacker News generalProgress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
CISA added CVE-2026-8037 (CVSS 9.6), a command injection flaw in Progress Kemp LoadMaster, to its Known Exploited Vulnerabilities catalog after 792 reported exploit attempts. Organizations using LoadMaster for application delivery and load balancing should apply patches immediately under BOD 22-01 federal agency deadlines.
-
4The Hacker News generalN-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
N-able released a second hotfix for N-central RMM after threat actors evolved their attack techniques to achieve persistence on managed endpoints beyond what the first hotfix addressed. Because N-central is used by MSPs to manage client infrastructure at scale, ongoing active exploitation represents a supply-chain-level risk affecting downstream managed systems.
-
5The Hacker News generalNew NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables
Researcher Malcolm Stagg presented NatJack at Black Hat USA 2026, a novel attack class that manipulates NAT connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables. The techniques were demonstrated across multiple independently developed implementations including Windows, making this a systemic protocol-level concern rather than a single-vendor bug.
-
6The Hacker News generalMicrosoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
An active AitM phishing campaign is compromising Microsoft 365 accounts by using residential proxies to disguise malicious sign-ins as consumer traffic, then targeting personnel involved in payroll and financial workflows to harvest related emails. The use of residential proxies to evade IP-reputation defenses combined with financial-fraud intent makes this a high-priority detection challenge for enterprise defenders.
-
7The Hacker News generalNearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
Researchers at OpenSourceMalware identified nearly 800 malicious npm packages using typosquatting and AI-generated names to deliver a cross-platform RAT and infostealer targeting Windows, macOS, and Linux simultaneously. The scale of the campaign and its multi-OS payload coverage pose significant supply chain risk for developers who install packages without verification.
-
8The Hacker News generalTeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign
New analysis links threat actor TeamPCP to Redis-targeting attacks dating back to 2020, with overlapping domains, malware deployment paths, and backend infrastructure connecting early cryptomining campaigns to a later software supply chain operation. The longitudinal activity timeline suggests a well-resourced group that quietly expanded from opportunistic server compromise to targeted supply chain attacks.
-
9BleepingComputer generalNorth Carolina Ports confirms cyberattack disrupting operations
A cyberattack disrupted gate systems at all three North Carolina Ports Authority facilities — Port of Wilmington, Port of Morehead City, and Charlotte Inland Port — with the U.S. Coast Guard actively monitoring the incident. The attack on physical port gate systems demonstrates continued threat actor interest in critical transportation infrastructure and operational technology environments.
-
10The Hacker News generalMalware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
Security research disclosed at Black Hat USA 2026 shows that malware can abuse Windows Hello for Business cryptographic keys to maintain persistent access to Microsoft Entra ID, surviving credential resets that defenders typically rely on for eviction. This technique undermines a common incident response step and is relevant to any enterprise using Entra ID with passwordless authentication.