Breaking News – Cyber Threats (last 6h)
Generated: 2026-07-24 03:00 PDT
- NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats
The Hacker News • 2026-07-24 00:41 • thehackernews.com
Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and says its AI pentest agents found them in a six-hour review of the forum software’s source code.Every version before 4.14.0 is affected. NodeBB has fixed them all, and administrators should be on 4.14.2.
The simplest one takes a settings change. A
https://thehackernews.com/2026/07/nodebb-patches-eight-ai-found-flaws.html - Clop ransomware targets Windchill, FlexPLM in data theft attacks
BleepingComputer • 2026-07-24 00:36 • www.bleepingcomputer.com
The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. […]
https://www.bleepingcomputer.com/news/security/clop-ransomware-targets-windchill-flexplm-in-data-theft-attacks/ - Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say
The Hacker News • 2026-07-23 23:58 • thehackernews.com
Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0.All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and the bundled RedisBloom module. Redis says the underlying memory flaws may lead to remote code execution.
Redis 6.2.23, 7.2.15, and 7.4.10
https://thehackernews.com/2026/07/kimi-k3-agents-found-redis-zero-days.html - Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
The Hacker News • 2026-07-23 23:50 • thehackernews.com
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that’s dressed up as a Notepad++ plugin to compromise Windows systems.The activity has been attributed by the agency to a threat cluster it tracks as UAC-0099, a Russia-aligned group that has previously observed weaponizing security flaws in WinRAR software to
https://thehackernews.com/2026/07/fake-notepad-plugin-delivers.html
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.
