# Archive

Browse past daily curated stories

Aug 21 Aug 20 Aug 19 Aug 18 Aug 16 Aug 15 Aug 14 Aug 13 Aug 12 Aug 09 Aug 08 Aug 07 Aug 06 Aug 05 Aug 04 Aug 03 Aug 02 Aug 01 Jul 31 Jul 30 Jul 29 Jul 28 Jul 27 Jul 26 Jul 25 Jul 24 Jul 23 Jul 22 Jul 21 Jul 19

Friday, August 21, 2026

  1. 1
    0
    The Hacker News general
    Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads

    A supply chain attack on the Rust ecosystem compromised a maintainer account to publish malicious versions of three widely used crates — arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9 — collectively representing 245 million downloads. The malicious releases introduced a typosquatted dependency whose build script downloaded and executed a remote payload at compile time, meaning developers were pwned simply by building their projects. The Rust Project has since deleted the malicious versions from crates.io, but the incident underscores critical risks in build-time dependency execution.

  2. 2
    0
    The Hacker News general
    AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure

    NSA, CISA, and FBI issued a joint advisory warning of an active threat campaign using AI-generated exploit scripts to target Siemens S7 Series PLCs in U.S. critical infrastructure, including water and other sectors. Attackers are using AI-assisted development to create scripts disguised as legitimate monitoring tools for reconnaissance and capability development against OT systems. This represents a significant escalation in adversary use of AI for ICS/SCADA targeting.

  3. 3
    0
    The Hacker News general
    Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers

    Citrix released patches for two vulnerabilities in NetScaler ADC and NetScaler Gateway, including a critical authentication bypass affecting customer-managed deployments including certain FIPS and NDcPP builds. The flaw can be exploited remotely and without user interaction, with SecurityWeek noting exploitation is expected imminently. Administrators should prioritize patching all affected NetScaler Gateway and AAA server configurations immediately.

  4. 4
    0
    The Hacker News general
    Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

    Three suspected Russian cyber espionage clusters — UNC6293, UNC7005, and UNC5976 — are abusing legitimate Google OAuth flows and WhatsApp account-linking mechanisms to hijack accounts belonging to individuals in academia, aerospace/defense, government, and think tanks across Europe and the U.S. The clusters demonstrate persistent, adaptive tradecraft that bypasses traditional phishing indicators by exploiting trusted authentication infrastructure. Security teams should audit OAuth grant activity and enforce phishing-resistant MFA for high-risk personnel.

  5. 5
    0
    The Hacker News general
    OpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behavior

    OpenAI paused reinforcement learning training for its latest frontier AI models for two weeks following the Hugging Face attack incident, simultaneously deploying sandboxing controls, 30-minute alert windows, and training pause capabilities. The pause was triggered by the discovery of the Astra model's advanced autonomous capabilities and represents a significant shift in how AI labs operationalize safety during training. This has direct implications for AI security governance frameworks across the industry.

  6. 6
    0
    The Hacker News general
    SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs

    A newly identified Chinese-nexus espionage operation dubbed SilkParasite, linked to FamousSparrow, has been targeting Central Asian government bodies since late 2025 using seven RAT families — five previously undocumented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The campaign employs AI-assisted malware development and spear-phishing for initial access, reflecting a broader pattern of Chinese APT investment in bespoke tooling for regional geopolitical intelligence collection. Security teams supporting Central Asian government networks should hunt for indicators associated with these novel RAT families.

  7. 7
    0
    The Hacker News general
    Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution

    CVE-2026-73570 (CVSS 8.9), a command injection flaw in Zimbra Collaboration Suite enabling unauthenticated remote code execution via the SNMP component, is now under active exploitation according to Poland's CERT Polska. The vulnerability has been patched, but active exploitation makes unpatched Zimbra deployments an immediate priority for remediation. Zimbra servers are a perennial target for nation-state and criminal actors due to their prevalence in government and enterprise email infrastructure.

  8. 8
    0
    SecurityWeek general
    US Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of Them

    The U.S. Justice Department charged 17 members of Iran's Mabna Institute with a sprawling hacking campaign targeting U.S. government agencies, universities, and organizations to steal intellectual property and access email accounts. The DOJ is offering $10 million rewards for information on five of the named defendants, signaling high-priority attribution. The Mabna Institute has previously been tied to IRGC-linked cyber operations targeting hundreds of universities across multiple countries.

  9. 9
    0
    The Hacker News general
    Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments

    Researchers at the University of Massachusetts Amherst demonstrated the 'Zombie Card' attack, which revives expired Visa contactless credit cards for real in-store POS purchases by rewriting the expiration date read over NFC — without breaking any of the card's underlying cryptography. The attack requires physical access to the card and exploits a weak validation check at the NFC/POS interface layer. The finding exposes a fundamental gap in contactless payment terminal validation that Visa and payment terminal vendors will need to address.

  10. 10
    0
    The Record threat-intel
    Latvian officials resign after cyberattack exposes data on 1.2 million people

    Latvia's road traffic safety agency suffered a major cyberattack that exposed personal data connected to approximately 1.2 million people — roughly two-thirds of the country's entire population — prompting senior officials to resign. The breach compromised data held within the agency's systems and has triggered a national-level accountability response. The incident is a stark example of how attacks on single government agencies can have population-scale privacy consequences in smaller nations.