Telegram C2, Browser-Built Malware, Fastjson RCE, GitLab RCE PoC, Certighost AD Exploit

THN Daily Updates
Newsletter
cover

AI Coding and Open Source Risk: What the Data Actually Shows About Remediation Debt

Join ActiveState to learn how to manage unvetted open-source code from AI tools. Get peer benchmarks, new survey data, and proven governance frameworks.

Download Now Sponsored
LATEST NEWS Jul 27, 2026

TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments

Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting government entities in the Middle East. The intrusions have resulted in the deployment of previou...

Read More
Twitter Facebook LinkedIn

GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption

GitHub has announced a new cooldown mechanism in Dependabot, allowing the tool to wait at least three days after a release is published before opening a pull request. "The cooldown configuration option in the dependabo...

Read More
Twitter Facebook LinkedIn

Stop Building Your Security Program From Scratch

Most teams don't have the time or resources to develop security best practices on their own. CIS SecureSuite® gives you the tools, guidance, and community you need all in one place. Learn more about CIS SecureSuite in an upcoming webinar. Save Your Spot.

Read More
Twitter Facebook LinkedIn

Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

A malvertising operation dubbed SourTrade is making victims' browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fix...

Read More
Twitter Facebook LinkedIn

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without aut...

Read More
Twitter Facebook LinkedIn

Claude Runs Across Six Surfaces in Your Company. Your Security Team Sees One.

Claude spans six enterprise surfaces, each with distinct identity, credential, and data risks that single-surface tools may miss.

Read More
Twitter Facebook LinkedIn

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six weeks earlier, on June 10. It runs commands as git on any self-managed 18.11.3 server that has ...

Read More
Twitter Facebook LinkedIn

Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine. They codenamed t...

Read More
Twitter Facebook LinkedIn
cover

AI Coding and Open Source Risk: What the Data Actually Shows About Remediation Debt

Join ActiveState to learn how to manage unvetted open-source code from AI tools. Get peer benchmarks, new survey data, and proven governance frameworks.

Download Now Sponsored

This email was sent to sikubaycom.s3cr3tz@blogger.com. You are receiving this newsletter because you opted-in to receive relevant communications from THN. To manage your email newsletter preferences, please click here.

Contact THN: info@thehackernews.com
Unsubscribe

THN | K.P BLock, Pitampura, Delhi