Terminal

root@news:~/news$ ls -lah news/

The Hacker News Malvertising high Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

A malvertising operation dubbed SourTrade is making victims' browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fixed URL. Confiant, which detailed the campaign on July 23, 2026, said it has operated since late 2024 and impersonated TradingView, Solana, and Luno to target retail traders and

Cisco Talos Ransomware high Chaos ransomware hides RAT command-and-control inside Chrome and Edge traffic

Cisco Talos identified a Rust-based RAT that launches Chrome or Edge and controls it through the Chrome DevTools Protocol. Command-and-control traffic then leaves through legitimate browser processes using Cloudflare-hosted infrastructure, Google STUN and Twilio TURN over WebRTC.

Origin Energy Incident Response high Origin Energy confirms unauthorized access and disclosure of customer data

Origin Energy confirmed that customer records were accessed and disclosed without authorization. Potentially affected fields include names, addresses, dates of birth, phone numbers, account information and partial credit-card or bank-account digits.

Check Point CVE critical SmartConsole authentication bypass exploited against exposed management servers

Check Point confirmed in-the-wild exploitation of a SmartConsole login flaw that can let an unauthenticated remote attacker obtain an application token and authenticate with full administrative privileges. The exposed control plane can be used to modify security policies and management configuration.