
News Feed from The Hacker News
The Hacker News Most trusted, widely-read independent cybersecurity news source for everyone; supported by hackers and IT professionals — Send TIPs to admin@thehackernews.com
- ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universitiesby info@thehackernews.com (The Hacker News) on June 11, 2026 at 8:29 PM
The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to keep it private. The campaign hit universities hardest.Google's Mandiant attributes it to the group it tracks as UNC6240, and dates the activity between May 27 and June 9. Oracle did not publish its advisory until June 10, so the bug was a
- New Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secretsby info@thehackernews.com (The Hacker News) on June 11, 2026 at 5:46 PM
Two security teams have shown, in separate research published this week, that OpenClaw, the popular self-hosted AI agent, can be driven to run attacker-controlled code or hand over sensitive data through ordinary-looking inputs.Imperva buried instructions inside shared contacts, vCards, and location pins that the agent executed without the victim ever seeing them. Varonis built a test agent on
- New GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML Filesby info@thehackernews.com (The Hacker News) on June 11, 2026 at 5:43 PM
Security researcher Chaotic Eclipse (aka Nightmare-Eclipse and MSNightmare) has released a new Windows BitLocker bypass dubbed GreatXML, a day after they published an exploit for Microsoft Defender."This was an accidental discovery, it took a total of 4 hours to find this," the researcher said in a post on Blogger. "If you ever attempted to use Windows Defender Offline Scan, you're
- The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Wormby info@thehackernews.com (The Hacker News) on June 11, 2026 at 4:50 PM
A new analysis of The Gentlemen operation has revealed that the financially motivated threat group initially operated as an affiliate responsible for conducting double extortion attacks, while leveraging resources from various ransomware-as-a-service (RaaS) schemes like LockBit (aka Tenacious Mantis), Qilin (aka Pestilent Mantis), and Medusa (aka Venomous Mantis).According to a detailed report
- Cybersecurity Stars Awards 2026: Winners Announced Across 95 Categoriesby info@thehackernews.com (The Hacker News) on June 11, 2026 at 1:26 PM
Most good security work is invisible by design. Today is the exception.The 2026 Cybersecurity Stars Awards winners are announced across 95 subcategories in four main award categories.The reason is simple. Cybersecurity is full of work that deserves recognition and rarely gets it. Products that quietly close real gaps. Teams that stop incidents nobody reads about. Companies that raise the




