Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests
2026-09-01T13:24:00Z•05ee9cbfcad4d882ff2c2ceac940be6fa85984754b08d517c8b4aa7caf1c429d
CVE-2023-49105CVE-2026-0768CVE-2026-65643CVE-2026-66066CVE-2026-74232CVE-2026-74233CVE-2026-76581CVE-2026-76639CVE-2026-76640AI securityChina-linked threat actorsClickFixLinuxNode.js malwareNorth KoreaWordPressactive exploitationbackdoorscloud securitycredential theftcritical vulnerabilitiescross-platform RATcryptocurrency theftinsider threatmacOSnetwork espionagephishingprompt injectionransomwareremote code executionrouter implantssocial engineeringsupply-chain compromiseunauthenticated access
What happened
The feed highlights active exploitation of critical vulnerabilities, credential theft, ransomware and backdoor campaigns, phishing and ClickFix social engineering, supply-chain and firmware implants, espionage activity, and emerging AI-agent abuse. The highest-risk items include unauthenticated remote code execution in Langflow, Ruby on Rails, WordPress, PaperCut, ServiceNow, routers, cPanel, and robotics platforms; exploitation of ownCloud and Cosmos EVM flaws; and state-aligned campaigns targeting network infrastructure and organizations.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 05ee9cbfcad4d882ff2c2ceac940be6fa85984754b08d517c8b4aa7caf1c429d
- Enrichment time
- 2026-09-01T13:24:00Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.