Trending in Cybersecurity
The Hacker News Most trusted, widely-read independent cybersecurity news source for everyone; supported by hackers and IT professionals — Send TIPs to admin@thehackernews.com
- LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Serversby info@thehackernews.com (The Hacker News) on June 15, 2026 at 4:39 pm
A default low-privilege account on a LiteLLM proxy can climb to full admin and run code on the server by chaining three vulnerabilities, researchers at Obsidian Security disclosed LiteLLM is a widely deployed open-source AI gateway that brokers calls to more than 100 model providers behind one OpenAI-compatible interface. A server takeover exposes every provider key it holds, the secrets that
- One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codesby info@thehackernews.com (The Hacker News) on June 15, 2026 at 3:09 pm
A single click on a trusted Microsoft link could have let an attacker pull emails, calendar details, and indexed files out of Microsoft 365 Copilot Enterprise Search. Researchers at Varonis Threat Labs chained three bugs into a one-click exfiltration path they call SearchLeak. Because the link pointed to a real microsoft.com domain, traditional anti-phishing and URL filtering tools were
- ⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and Moreby info@thehackernews.com (The Hacker News) on June 15, 2026 at 1:49 pm
Stuff broke again. Not in a movie way. An old tool was left exposed. An abandoned package was abused. A deprecated feature was still running in prod. This week is the same lesson in a new form: phishing kits are easier to rent, AI names are useful bait, old login paths still fail, and forgotten software keeps becoming someone else’s entry point. Scroll through the full Monday Cybersecurity
- The Onboarding Password Mistake That Creates Unnecessary Riskby info@thehackernews.com (The Hacker News) on June 15, 2026 at 11:30 am
Employee onboarding is a busy time for IT teams. New starters need devices, accounts, access permissions, and passwords, all delivered within a tight timeframe. That usually means sharing a temporary “first-day” password so employees can access systems for the first time. The issue is that these passwords don’t always stay temporary. They may be sent over email or SMS, reused across accounts,
- 152 Chrome Wallpaper Extensions with 105K Installs Linked to Adware and Fake Trafficby info@thehackernews.com (The Hacker News) on June 15, 2026 at 11:07 am
Cybersecurity researchers have discovered a network of 152 Google Chrome extensions that act as new tab live wallpaper add-ons to distribute a potentially unwanted program (PUP) family. The cluster spans 38 separate Chrome Web Store publisher accounts and three brand backends: tabplugins[.]com, yowgames[.]com, and chromewallpaper[.]com. They have been collectively installed 105,000 times. The
- Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sitesby info@thehackernews.com (The Hacker News) on June 15, 2026 at 9:59 am
An attacker tampered with trusted JavaScript files used by WordPress sites running PushEngage, OptinMonster, and TrustPulse, turning those files into a way to break into the sites. When a site administrator was logged in as the file loaded, the code created an admin account under the attacker’s control and installed a hidden plugin that opened a way back in. Ordinary visitors did not trigger it
- Sniper Dz Scams Target MENA Users via Fake Facebook Offers and Browser Alertsby info@thehackernews.com (The Hacker News) on June 15, 2026 at 6:30 am
Cybersecurity researchers have disclosed details of fraudulent activity targeting users across the Middle East and North Africa by employing various fraudulent Facebook accounts impersonating politicians, public figures, and trusted organizations. “These accounts promoted fake offers, including free mobile internet packages, financial compensation, and government subsidy programs,” Group-IB
- Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flawby info@thehackernews.com (The Hacker News) on June 15, 2026 at 6:17 am
Palo Alto Networks has revealed that it has observed “active exploitation” of a recently disclosed PAN-OS vulnerability by an unknown threat actor to obtain unauthorized access to GlobalProtect portals. The vulnerability in question is CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS software that could be exploited by bad
- Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authenticationby info@thehackernews.com (The Hacker News) on June 13, 2026 at 1:23 pm
Splunk has released security updates to address a critical security flaw in Splunk Enterprise that could be exploited to conduct unauthenticated file operations and even remote code execution. The vulnerability, tracked as CVE-2026-20253, is rated 9.8 on the CVSS scoring system. “In Splunk Enterprise versions below 10.2.4 and 10.0.7, an unauthenticated user could create or truncate arbitrary
- U.S. Orders Anthropic to Suspend Fable 5 and Mythos 5 Access for Foreign Nationalsby info@thehackernews.com (The Hacker News) on June 13, 2026 at 5:42 am
Anthropic said on Friday it will “abruptly disable” its most advanced artificial intelligence (AI) models, Claude Fable 5 and Mythos 5, for all users after the U.S. government ordered it to suspend access to the models for foreign nationals, whether inside or outside the U.S., citing national security concerns. The AI company said it received an order at 5:21 p.m. ET, instructing it to suspend
- Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkitby info@thehackernews.com (The Hacker News) on June 12, 2026 at 7:33 pm
Attackers took over more than 400 packages in the Arch User Repository (AUR) this week and rewrote their build scripts to install a credential stealer on any machine that built them. The malware is a Rust binary built to harvest developer secrets. When it lands with root, it can also load an eBPF rootkit to hide itself. The AUR is Arch Linux’s community package collection, and it is separate
- Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishingby info@thehackernews.com (The Hacker News) on June 12, 2026 at 6:59 pm
Google on Friday said it’s pursuing legal action against a Chinese cybercrime network, accusing it of using its Gemini artificial intelligence (AI) agent to send phishing text messages targeting Americans. The network is said to be behind the development and management of a phishing-as-a-service (PhaaS) software kit called Outsider, per the tech giant. “The operation weaponized Gemini to help











