
News Feed from The Hacker News
The Hacker News Most trusted, widely-read independent cybersecurity news source for everyone; supported by hackers and IT professionals — Send TIPs to admin@thehackernews.com
- Public Exploits Released for Four Linux Kernel Flaws That Enable Local Rootby info@thehackernews.com (The Hacker News) on September 18, 2026 at 6:02 PM
A security researcher has released working exploit code for four Linux kernel flaws that each let a local user gain root, the highest level of access on a machine.Kernel maintainers have fixed all four over the past few weeks, so a system running an up-to-date kernel is not affected. But the exploit code is now public, and any machine still running an older kernel should be updated.The flaws
- New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Executionby info@thehackernews.com (The Hacker News) on September 18, 2026 at 4:56 PM
WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in administrator, to install a theme from the official WordPress.org directory without anyone clicking Install.The security firm pwn.ai, whose researchers reported the flaw, calls the attack chain Click2Shell. On its own the flaw only
- Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2by info@thehackernews.com (The Hacker News) on September 18, 2026 at 3:24 PM
The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan.The attacks, per Zscaler ThreatLabz, involve the use of previously undocumented tools called RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The activity has been codenamed Operation
- Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalationby info@thehackernews.com (The Hacker News) on September 18, 2026 at 12:47 PM
Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required.The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0."Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network,"
- An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.by info@thehackernews.com (The Hacker News) on September 18, 2026 at 11:01 AM
In July 2025, someone registered a domain that used to belong to a content delivery network. The CDN had been wound down years earlier, and the domain it served assets from was allowed to expire. What it had not lost were its callers. Thousands of websites, code repositories, and documentation pages still carry hard-coded references to hostnames beneath it. The new owner holds




