
News Feed from The Hacker News
The Hacker News Most trusted, widely-read independent cybersecurity news source for everyone; supported by hackers and IT professionals — Send TIPs to admin@thehackernews.com
- BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Deliveryby info@thehackernews.com (The Hacker News) on July 24, 2026 at 3:12 PM
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malware."BlueNoroff has operationalised trust abuse by combining compromised industry contacts, social engineering, wallet
- Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controllerby info@thehackernews.com (The Hacker News) on July 24, 2026 at 2:15 PM
Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine.They codenamed the flaw Certighost. Because Domain Controller accounts carry directory replication rights, the resulting Kerberos credential can retrieve the krbtgt secret through DCSync.
- ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Linkby info@thehackernews.com (The Hacker News) on July 24, 2026 at 11:53 AM
Cybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial intelligence (AI) agent inside a victim's organization.The vulnerability has been codenamed AgentForger by Zenity Labs. The issue has since been addressed by OpenAI as of June 8,
- Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Serversby info@thehackernews.com (The Hacker News) on July 24, 2026 at 11:45 AM
A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers, and as root on the Linux machines in the same fleet.XBOW's testing got the same result on workers across different hosts and network ranges, so the problem sat in Bing's image tier, not on one bad machine. Microsoft issued two critical CVEs, CVE-2026-32194 and
- Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Doby info@thehackernews.com (The Hacker News) on July 24, 2026 at 11:30 AM
AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we've collectively discovered is that enforcing least privilege for AI agents is harder than we ever imagined. This is why there are so many approaches, from prompt filtering to identity-layer access controls. Where we've collectively landed is that understanding the intent of




