Claude AI Goes Rogue, OVSwrap Linux Exploit, Massive npm Worm Outbreak, Critical Gitea Flaw, and More

THN Daily Updates
Newsletter
cover

Blockchain, Crypto and DeFi: Bridging Finance and Technology ($45.00 Value) FREE for a Limited Time

Unlock the future of finance with Blockchain, Crypto, and DeFi

Download Now Sponsored
LATEST NEWS Aug 5, 2026

New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch

A memory corruption flaw in the Linux kernel's Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured distributions, and a public exploit ships with pre-built records for ro...

Read More
Twitter Facebook LinkedIn

Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk

Kali365 is turning a legitimate Microsoft login into a gateway to corporate data. The phishing kit targets US organizations with attacker-controlled device codes that victims approve on Microsoft's real authentication ...

Read More
Twitter Facebook LinkedIn

Your Org Deployed the AI. Who's Actually Securing It?

Training to protect LLMs, agents, and pipelines against real attacks. GAIPS cert prep at SANS Raleigh.

Read More
Twitter Facebook LinkedIn

Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup

An unauthenticated attacker can read any file the service account can access on Gitea, the self-hosted Git platform, in versions 1.22.1 through 1.27.0. No login, no repository write access. A public repository and craft...

Read More
Twitter Facebook LinkedIn

Leaked n8n API Tokens Exposed Live Instances to Credential Theft

GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive data and downstream credentials without explo...

Read More
Twitter Facebook LinkedIn

Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself

An agent running Anthropic's Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project during a cyber evaluation by the UK's AI Security Institute. When a bystander publicly ...

Read More
Twitter Facebook LinkedIn

CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The list ...

Read More
Twitter Facebook LinkedIn

Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks

A credential-stealing npm worm that first appeared in keyv@6.0.0 spread beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations on August 4, 2026. SafeDep verified 353 poisoned ...

Read More
Twitter Facebook LinkedIn
cover

Blockchain, Crypto and DeFi: Bridging Finance and Technology ($45.00 Value) FREE for a Limited Time

Unlock the future of finance with Blockchain, Crypto, and DeFi

Download Now Sponsored

This email was sent to sikubaycom.s3cr3tz@blogger.com. You are receiving this newsletter because you opted-in to receive relevant communications from THN. To manage your email newsletter preferences, please click here.

Contact THN: info@thehackernews.com
Unsubscribe

THN | K.P BLock, Pitampura, Delhi