Apple Private Relay IP Leak, Model-Less AI Tool Attacks, $5.7M Lost to CryptoJS Flaw, and More

THN Daily Updates
Newsletter
cover

Zero Trust Security: A Hands-on Guide ($101.95 Value) FREE for a Limited Time

Principles, applications, and methodologies to help organizations transition from traditional security models to a Zero Trust approach

Download Now Sponsored
LATEST NEWS Aug 6, 2026

CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps

Coinspect has identified CryptoJS.lib.WordArray.random() as the weak random number generator behind the Ill Bloom wallet drains. Introduced in the JavaScript cryptography library 12 years ago, the function supplied wea...

Read More
Twitter Facebook LinkedIn

Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses

Cybersecurity researchers have disclosed a security issue with Apple's iCloud Private Relay tool that can expose a user's real IP address. Introduced with iOS 15, iCloud Private Relay employs a dual-hop architecture to...

Read More
Twitter Facebook LinkedIn

Pivotal Moment: Capitalize on Mythos Hype to Fix Your Exposure and Vulnerability Management

Get the Gartner report: redesign exposure management around time, scale, and decision velocity.

Read More
Twitter Facebook LinkedIn

AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory

A new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and no zero-day exploit. It abuses a standard feature built into almost every major AI assistant: p...

Read More
Twitter Facebook LinkedIn

Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access

Attackers broke into an organization's Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit without writing an executable to disk. They fed Java sou...

Read More
Twitter Facebook LinkedIn

AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model

Security flaws in agent infrastructure from Amazon Web Services (AWS), Google, and Vercel let untrusted or forged instructions reach an agent's tools with no check that a model turn had authorized them. In several of t...

Read More
Twitter Facebook LinkedIn

Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells

Cybersecurity researchers have disclosed details of a "factory-shipped backdoor" implanted in at least 20 Chinese router models from Zbtlink. According to a new report from VulnCheck, the implant appears in all 21 fi...

Read More
Twitter Facebook LinkedIn

Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt

Cybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) models on underground cybercrime forums and messaging platforms. One such serv...

Read More
Twitter Facebook LinkedIn
cover

Zero Trust Security: A Hands-on Guide ($101.95 Value) FREE for a Limited Time

Principles, applications, and methodologies to help organizations transition from traditional security models to a Zero Trust approach

Download Now Sponsored

This email was sent to sikubaycom.s3cr3tz@blogger.com. You are receiving this newsletter because you opted-in to receive relevant communications from THN. To manage your email newsletter preferences, please click here.

Contact THN: info@thehackernews.com
Unsubscribe

THN | K.P BLock, Pitampura, Delhi