PPHM HACKER NEWS
10.6K subscribers
3.32K photos
9 videos
1.53K links
PPHM Hacker News is a reliable news outlet that brings you the latest and most credential cyber news.

Contact us:
@pphmhackernews1

Website:
https://pphmnews.com/
Download Telegram
🔴 Engineer sentenced for locking over 3,000 devices on employer network

A former core infrastructure engineer at an industrial company headquartered in New Jersey was sentenced to 32 months in prison for locking thousands of devices on his employer's network in a ransomware-style attack.

57-year-old Daniel Rhyne from Kansas City, Missouri, pleaded guilty to his role in a failed extortion plot targeting the New Jersey company that employed him after being arrested in August 2024 and released after his initial appearance in federal court.

According to court documents, he remotely accessed the company's network without authorization using an administrator account between November 8 and November 25 and scheduled tasks on the domain controller that changed the password of the administrator account to "TheFr0zenCrew!", deleted 13 domain admin accounts, and changed the passwords for 301 domain user accounts to "TheFr0zenCrew!".
Undercover Blockchain Probe Maps Financial Pipeline Behind North Korean Cyber Heists

Blockchain investigator ZachXBT says he penetrated a Chinese organized-crime network suspected of processing cryptocurrency stolen in major cyberattacks attributed to North Korean hackers.

🔗 Read More
🔴 Initial Access: US Corporate Network

A threat actor is advertising Domain Admin access to an unnamed U.S. company reportedly generating more than $35M in revenue.
🔴 50 Petabytes of Logs to Be Scrubbed: OpenAI Searches for Signs of AI Leaks

The cost of AI misbehavior is now measured not only by the consequences, but also by the cost of investigation. OpenAI revealed that the review of its past activity covers approximately 50 petabytes of archived data and costs more than $500,000 per day. The company has already allocated enormous computing resources and plans to increase them as the investigation progresses.

The scale of the dataset explains the unusual expense. The study involved approximately 7,000 NVIDIA GB200 and GB300 accelerators, and the logs were examined month after month in reverse order. According to OpenAI, if the entire volume were imagined as a standard English text, it would take a person approximately 66 million years of continuous reading at a speed of 240 words per minute.
🔴 Social Engineering Detection Moves Into the Live Conversation

Companies are pouring time and dollars into security awareness training, but there is little empirical evidence to suggest it actually works against social engineering.

Social engineering remains a primary and successful attack vector. While system vulnerabilities can be patched, social engineering cannot. The most common pseudo ‘patch’ is user awareness training, but this has failed to block the vector. Human defenders should not and cannot be expected to detect trickery designed to manipulate their psychology. And the tricks are becoming better hidden and more sophisticated with the use of AI deep fakery.
🔴 Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution

Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.
🔴 AI and Privacy: What Happens to the Data We Entrust to Artificial Intelligence?

Artificial intelligence relies on the processing of data provided to it. When we use a chatbot, we send it questions, text, documents, images, or code. From the moment we press "Send," this information reaches the infrastructure that provides the service, where it is processed and, depending on the platform, account, and settings, may also be stored or used for further purposes.
🔥1
🔴 Threat Actor Claims Leak of Russian Ministry of Industry and Trade Military Data

A darkweb forum post alleges the theft and sale of sensitive data from the Russian Ministry of Industry and Trade. According to the listing, the actor claims to possess a 1.62 GB dataset comprising 1,502 files, which they describe as "original-source material" acquired through independent work rather than resold from other actors.

The post details that the alleged data dump includes highly sensitive defense-related information, such as:

- Arms and military-equipment licenses
- Suppliers for defence orders
- Mobilisation reservation of officers
- Defense-industry registers
- Service licenses for arms and military equipment
- Defence-order reports covering the period 2020–2026
🚨 October 7, 2023: The Day the Israel–Hamas War Began

On the morning of October 7, 2023, Hamas launched a large-scale attack on Israel. The attack involved thousands of rockets fired from the Gaza Strip, while armed militants crossed into southern Israel by land, sea, and air.

The attackers reached several Israeli cities, towns, kibbutzim, and the site of the Nova music festival. Around 1,200 people were killed, and 251 others were taken hostage and brought into Gaza.

The attack, described as the deadliest in Israel’s history, triggered a massive Israeli military response in Gaza and marked the beginning of a war with far-reaching humanitarian and regional consequences.
🔴 Atlassian Patches Critical Vulnerability Affecting 8 Products

Atlassian has rolled out patches for a critical-severity vulnerability that impacts all versions of eight of its products.

The security defect, tracked as CVE-2026-21589 (CVSS score of 9.3), is described as an arbitrary file access issue.

It can be exploited without authentication to access specific files in the web application root directory.

“Exploitation requires prior knowledge of the target file’s exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be sensitive files present that increase your risk,” Atlassian notes in its advisory.
🚨 Documents reportedly obtained indicate that Saudi Arabia, in coordination with Turkey, transferred hundreds of extremist fighters from Syria to Saudi territory before deploying them to battlefronts in Yemen.
🔴 Android’s October 2026 Updates Patch 25 Vulnerabilities

Google this week announced the rollout of fresh Android security updates that resolve 25 vulnerabilities in the Framework and System components.

The fresh release arrives on devices as the 2026-10-01 security patch level and marks a change from the updates released over the past several years, which have been split into two parts.

Android’s October 2026 patches resolve seven flaws in Framework and 18 in System, including a total of seven critical-severity bugs (one in Framework and six in System).
🚨 Georgian State Security Service: A Georgian citizen has been arrested for allegedly possessing nuclear material illegally and attempting to sell uranium-238.

The suspect intended to sell the uranium to a foreign national for $700,000. Security officers launched an investigation after receiving information about the transaction and subsequently arrested the suspect.

Georgian authorities have not disclosed the foreign national’s nationality. The investigation remains ongoing.
🔴 CVE-2026-103435

Claude Code validated that a target file path resided within the project working directory at permission-check time, but re-resolved the path at write time without repeating that validation. This time-of-check to time-of-use (TOCTOU) gap allowed an attacker who could write to the workspace to atomically replace a project file with a symlink, causing Claude Code to follow the symlink and write its output to an arbitrary file outside the project sandbox. Exploitation required the ability to win a race condition against the write operation and write access to the shared workspace, enabling a lower-privileged attacker to redirect benign edits to sensitive files (e.g., shell configuration) in a higher-privileged session.

Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to the latest version.
🔴 GitHub is full of active passwords: 543,699 credentials found

Truffle Security researchers calculated that 543,699 unique and still-active credentials have been published in public repositories on GitHub. Some of these secrets have been accessible for years: the average lifetime of such leaks is 784 days, while the oldest secret (still active) dates back to 2009.

The experts' study is based on a dataset designed for training large language models. This dataset was collected through a GitHub crawl, which ended on August 7, 2025. To conduct the analysis, the company examined approximately 224 million repositories and over 58 billion files.
🔴 100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer

The Computer Emergency Response Team of Ukraine (CERT-UA) has identified more than 100 compromised websites that have been injected with malicious JavaScript to serve an information-stealing malware called LunexStealer (aka Psychedelic Stealer).

The activity, which was observed by the agency in September 2026, has been attributed to a threat cluster dubbed UAC-0277. It did not disclose who the victims of the campaign were or if any systems were successfully compromised as a result of these attacks.

"When visiting such a site, users were shown a forged Cloudflare verification page that, under the pretext of confirming the visitor is human, prompted them to execute a command," CERT-UA said in an advisory. "Executing the command caused a malicious MSI package to be downloaded and installed from a remote server (the ClickFix technique)."
🔴 ASOS Confirms Cyberattack, Data Breach

British online retailer ASOS has confirmed that hackers compromised a third-party communication platform after users received rogue notifications on their phones.

Over the past couple of days, numerous ASOS users in the UK complained about receiving a pop-up notification on their mobile apps, titled “ASOS hacked”.

“Dear ASOS DPO [data protection officer] and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it,” the notification read.
🔴 VirusTotal Enterprise API Key Offered for Sale for $350

The seller advertises limits of 5,000 requests per day, 300,000 per hour, and 1 billion per month, and offers to demonstrate that the key works before purchase.

Payment is accepted in BTC or LTC, with escrow also offered.
❤1
🔴 France Travail Employee Dataset With 62,848 Records Offered for Sale

An actor is selling an internal France Travail employee dataset containing 62,848 records.

This one is focused on staff rather than job seekers. The samples include employee names, work email addresses, phone numbers, job titles, departments, regions, internal identifiers, and links to profile photos hosted on France Travail's intranet.

The seller published a portion of the data as proof and is taking offers privately.