Breaking News – Cyber Threats (last 6h)
Generated: 2026-07-29 03:00 PDT
- Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
The Hacker News • 2026-07-29 01:58 • thehackernews.com
Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that has come under active exploitation in the wild.The vulnerability, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass in the SmartConsole login process that
https://thehackernews.com/2026/07/rapid7-releases-poc-for-exploited-check.html - OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach
The Hacker News • 2026-07-29 00:51 • thehackernews.com
OpenAI on Tuesday revealed the rogue artificial intelligence (AI) agent that escaped its sealed evaluation environment and broke into Hugging Face’s production environment also hacked multiple third-party accounts and services as part of the attack.The latest disclosure shows that the security incident, which stemmed from an internal security test, was more extensive in scope than previously
https://thehackernews.com/2026/07/openai-agent-used-exposed-credentials.html - New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands
The Hacker News • 2026-07-29 00:47 • thehackernews.com
Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gitea service account.Tracked as CVE-2026-60004 (CVSS score: 9.8), the flaw affects Gitea versions 1.17 and later before 1.27.1 and is fixed in 1.27.1. The
https://thehackernews.com/2026/07/new-gitea-rce-lets-repository-writers.html - Apple Patches Everything (July 2026), (Wed, Jul 29th)
SANS ISC Diary (full) • 2026-07-29 00:32 • isc.sans.eduI am a bit late with this summary, but this week Apple released updates to all its operating systems and Safari. The Safari update, as usual, targets macOS prior to macOS 26. macOS updates covered the two older versions (14 and 15), while other operating system patches only covered the current 26 versions.
- Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates
The Hacker News • 2026-07-29 00:07 • thehackernews.com
Source code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels. Hunt.io and independent researcher NetAskari traced matching control panels and certificates to 170 internet servers.They linked the framework to a fake “公安一网通办” Public Security service application targeting Android users in China. The kit supports payment-password
https://thehackernews.com/2026/07/flying-eagle-android-rat-traces-found.html - Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js
The Hacker News • 2026-07-28 21:20 • thehackernews.com
Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family.The list of affected packages is as follows –
@joyfill/layouts@0.1.2-2773.beta.0
@joyfill/components@4.0.0-rc24-2773-beta.4The two packages “contain an import-time JavaScript implant that resolves encrypted code
https://thehackernews.com/2026/07/two-compromised-joyfill-npm-packages.html
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.
