Forwarded from The Hacker News
🚨 A new Android spyware is spreading like a worm.
“ClayRat” infects phones, then messages every contact to spread further.
It hides as WhatsApp, YouTube, or Google Photos — even faking Play Store screens.
Full analysis ↓ https://thehackernews.com/2025/10/new-clayrat-spyware-targets-android.html
“ClayRat” infects phones, then messages every contact to spread further.
It hides as WhatsApp, YouTube, or Google Photos — even faking Play Store screens.
Full analysis ↓ https://thehackernews.com/2025/10/new-clayrat-spyware-targets-android.html
Forwarded from The Hacker News
A China-backed group just turned AI into a cyber weapon.
They’re using it to write phishing emails and build malware — across English, Chinese, and Japanese targets.
The result? A new backdoor called GOVERSHELL spreading via fake research invites.
Read how ↓ https://thehackernews.com/2025/10/from-healthkick-to-govershell-evolution.html
They’re using it to write phishing emails and build malware — across English, Chinese, and Japanese targets.
The result? A new backdoor called GOVERSHELL spreading via fake research invites.
Read how ↓ https://thehackernews.com/2025/10/from-healthkick-to-govershell-evolution.html
Forwarded from The Hacker News
🚨 Google confirms dozens of organizations breached via Oracle E-Business Suite zero-day (CVE-2025-61882).
Attackers exploited the flaw since July 2025, using multi-stage Java implants and extortion tactics.
🔹 Oracle issued an emergency patch Oct 4
🔹 Exploit code is now public — risk rising
🔗 Details: https://thehackernews.com/2025/10/cl0p-linked-hackers-breach-dozens-of.html
Attackers exploited the flaw since July 2025, using multi-stage Java implants and extortion tactics.
🔹 Oracle issued an emergency patch Oct 4
🔹 Exploit code is now public — risk rising
🔗 Details: https://thehackernews.com/2025/10/cl0p-linked-hackers-breach-dozens-of.html
Forwarded from The Hacker News
🚨 Active zero-day alert: Gladinet’s CentreStack & TrioFox are under live exploitation.
Hackers are chaining two CVEs to pull machine keys and trigger remote code execution — no patch yet.
Admins, disable the temp handler now ↓ https://thehackernews.com/2025/10/from-lfi-to-rce-active-exploitation.html
Hackers are chaining two CVEs to pull machine keys and trigger remote code execution — no patch yet.
Admins, disable the temp handler now ↓ https://thehackernews.com/2025/10/from-lfi-to-rce-active-exploitation.html
Forwarded from The Hacker News
🚨 Researchers uncovered 175 malicious npm packages used to host phishing redirects — downloaded 26,000+ times.
The campaign, dubbed Beamglea, abused npm + UNPKG to target 135 tech and energy firms worldwide.
No exploit. Just clever infrastructure abuse.
Read → https://thehackernews.com/2025/10/175-malicious-npm-packages-with-26000.html
The campaign, dubbed Beamglea, abused npm + UNPKG to target 135 tech and energy firms worldwide.
No exploit. Just clever infrastructure abuse.
Read → https://thehackernews.com/2025/10/175-malicious-npm-packages-with-26000.html
Forwarded from The Hacker News
⚠️ A zero-day in GoAnywhere MFT has been actively exploited since Sept 11.
Attackers bypassed cryptographic checks — no password, no auth. Microsoft says Storm-1175 used it to drop Medusa ransomware.
Full timeline + exploit details ↓ https://thehackernews.com/2025/10/from-detection-to-patch-fortra-reveals.html
Attackers bypassed cryptographic checks — no password, no auth. Microsoft says Storm-1175 used it to drop Medusa ransomware.
Full timeline + exploit details ↓ https://thehackernews.com/2025/10/from-detection-to-patch-fortra-reveals.html
Forwarded from The Hacker News
🔴 ALERT: Your next “HR alert” email might not be from HR.
Storm-2657 is phishing employees, taking over Workday accounts, and swapping bank details to steal salaries — no malware, just manipulation.
Inside Microsoft’s latest findings ↓ https://thehackernews.com/2025/10/microsoft-warns-of-payroll-pirates.html
Storm-2657 is phishing employees, taking over Workday accounts, and swapping bank details to steal salaries — no malware, just manipulation.
Inside Microsoft’s latest findings ↓ https://thehackernews.com/2025/10/microsoft-warns-of-payroll-pirates.html
Forwarded from The Hacker News
⚠️ New “Stealit” malware is using Node.js’ experimental SEA feature to slip full payloads into fake game & VPN installers — already spreading via Mediafire and Discord.
Read how → https://thehackernews.com/2025/10/stealit-malware-abuses-nodejs-single.html
Read how → https://thehackernews.com/2025/10/stealit-malware-abuses-nodejs-single.html
Forwarded from The Hacker News
🚨 Signal just threatened to leave the EU.
Why? The proposed “Chat Control” law would force apps to scan every private message before it’s sent.
The catch: even encrypted chats would be exposed. Experts call it “mass surveillance in disguise.”
The details you need to see ↓ https://thehackernews.com/2025/10/threatsday-bulletin-ms-teams-hack-mfa.html#opposition-to-e-u-chat-control
Why? The proposed “Chat Control” law would force apps to scan every private message before it’s sent.
The catch: even encrypted chats would be exposed. Experts call it “mass surveillance in disguise.”
The details you need to see ↓ https://thehackernews.com/2025/10/threatsday-bulletin-ms-teams-hack-mfa.html#opposition-to-e-u-chat-control
Forwarded from The Hacker News
🚨 Hackers just turned a DFIR tool into a ransomware weapon.
Storm-2603 hijacked Velociraptor to deploy LockBit, Warlock & Babuk—even creating fake domain admins and disabling defenses.
Details here ↓ https://thehackernews.com/2025/10/hackers-turn-velociraptor-dfir-tool.html
Storm-2603 hijacked Velociraptor to deploy LockBit, Warlock & Babuk—even creating fake domain admins and disabling defenses.
Details here ↓ https://thehackernews.com/2025/10/hackers-turn-velociraptor-dfir-tool.html
Forwarded from The Hacker News
⚠️ Over 100 SonicWall SSL VPN accounts breached — not brute-forced.
Attackers used legit creds and traced back to a single IP.
Even patched devices are falling to Akira ransomware campaigns.
Learn more → https://thehackernews.com/2025/10/experts-warn-of-widespread-sonicwall.html
Attackers used legit creds and traced back to a single IP.
Even patched devices are falling to Akira ransomware campaigns.
Learn more → https://thehackernews.com/2025/10/experts-warn-of-widespread-sonicwall.html
Forwarded from The Hacker News
⚡ Apple’s Siri recordings are under criminal investigation in France.
A whistleblower says they captured “intimate” conversations — enough to identify users.
Apple denies misuse, but prosecutors aren’t convinced.
Read ↓ https://thehackernews.com/2025/10/threatsday-bulletin-ms-teams-hack-mfa.html#france-opens-probe-into-apple-siri-voice-recordings
A whistleblower says they captured “intimate” conversations — enough to identify users.
Apple denies misuse, but prosecutors aren’t convinced.
Read ↓ https://thehackernews.com/2025/10/threatsday-bulletin-ms-teams-hack-mfa.html#france-opens-probe-into-apple-siri-voice-recordings
Forwarded from The Hacker News
🐭 A $35 gaming mouse just became a spy tool.
UC Irvine researchers turned its optical sensor into a microphone that steals conversations from air-gapped PCs.
It hides inside legit apps like games. Read the PoC → https://thehackernews.com/2025/10/threatsday-bulletin-ms-teams-hack-mfa.html#mic-e-mouse-attack-for-covert-data-exfiltration
UC Irvine researchers turned its optical sensor into a microphone that steals conversations from air-gapped PCs.
It hides inside legit apps like games. Read the PoC → https://thehackernews.com/2025/10/threatsday-bulletin-ms-teams-hack-mfa.html#mic-e-mouse-attack-for-covert-data-exfiltration
Forwarded from The Hacker News
⚠️ WARNING: Oracle just confirmed a new vulnerability (CVE-2025-61884) in E-Business Suite.
No login required. Full data access possible.
Even worse—similar flaws were just exploited by Cl0p-linked actors.
Read the latest news here → https://thehackernews.com/2025/10/new-oracle-e-business-suite-bug-could.html
No login required. Full data access possible.
Even worse—similar flaws were just exploited by Cl0p-linked actors.
Read the latest news here → https://thehackernews.com/2025/10/new-oracle-e-business-suite-bug-could.html
Forwarded from The Hacker News
🚨A new Rust-based backdoor called ChaosBot is hijacking corporate networks — and running its C2 over Discord.
It hides behind Microsoft Edge, abuses service accounts, and even checks for VMware to dodge analysis.
One slip → full network access ↓ https://thehackernews.com/2025/10/new-rust-based-malware-chaosbot-hijacks.html
It hides behind Microsoft Edge, abuses service accounts, and even checks for VMware to dodge analysis.
One slip → full network access ↓ https://thehackernews.com/2025/10/new-rust-based-malware-chaosbot-hijacks.html
Forwarded from The Hacker News
Hackers just turned GitHub into their command center.
When police take down their servers, the malware just… reboots itself from GitHub.
The twist? It hides configs inside images using steganography. This isn’t a glitch — it’s resilience by design.
Read how it works → https://thehackernews.com/2025/10/astaroth-banking-trojan-abuses-github.html
When police take down their servers, the malware just… reboots itself from GitHub.
The twist? It hides configs inside images using steganography. This isn’t a glitch — it’s resilience by design.
Read how it works → https://thehackernews.com/2025/10/astaroth-banking-trojan-abuses-github.html
Forwarded from The Hacker News
⚠️ Microsoft just locked down Internet Explorer mode in Edge after real-world zero-day attacks.
Hackers abused the old IE engine (Chakra) to hijack devices — bypassing modern browser defenses.
Full story ↓ https://thehackernews.com/2025/10/microsoft-locks-down-ie-mode-after.html
Hackers abused the old IE engine (Chakra) to hijack devices — bypassing modern browser defenses.
Full story ↓ https://thehackernews.com/2025/10/microsoft-locks-down-ie-mode-after.html
Forwarded from The Hacker News
🟥 RondoDox Botnet just went nuclear.
It’s now exploiting 56 vulnerabilities across 30+ vendors — from routers to web servers.
The irony? 18 of those flaws don’t even have CVEs yet.
Learn more → https://thehackernews.com/2025/10/researchers-warn-rondodox-botnet-is.html
It’s now exploiting 56 vulnerabilities across 30+ vendors — from routers to web servers.
The irony? 18 of those flaws don’t even have CVEs yet.
Learn more → https://thehackernews.com/2025/10/researchers-warn-rondodox-botnet-is.html
Forwarded from The Hacker News
Your WAF can’t see this.
Attackers are skimming payment data right now through unmonitored JavaScript—while your dashboards stay clean.
The worst part? It’s happening in your customers’ browsers.
See what every retailer must fix before Black Friday ↓ https://thehackernews.com/2025/10/why-unmonitored-javascript-is-your.html
Attackers are skimming payment data right now through unmonitored JavaScript—while your dashboards stay clean.
The worst part? It’s happening in your customers’ browsers.
See what every retailer must fix before Black Friday ↓ https://thehackernews.com/2025/10/why-unmonitored-javascript-is-your.html
Forwarded from The Hacker News
⚡ Latest Weekly Recap is out...
🚨 Oracle 0-Day exploited
🤖 Nation-state AI abuse on the rise
🎣 npm phishing spreading fast
💀 New ransomware cartel emerges
…and more
The threat landscape is moving fast — here’s what defenders need to know.
🔗 https://thehackernews.com/2025/10/weekly-recap-whatsapp-worm-critical.html
🚨 Oracle 0-Day exploited
🤖 Nation-state AI abuse on the rise
🎣 npm phishing spreading fast
💀 New ransomware cartel emerges
…and more
The threat landscape is moving fast — here’s what defenders need to know.
🔗 https://thehackernews.com/2025/10/weekly-recap-whatsapp-worm-critical.html
Forwarded from #TBOT: Take Back Our Tech
Media is too big
VIEW IN TELEGRAM
⚡️Installing Apps Without Google Play Store is Easier Than You Think
In my recent chat with Mike Adams on Brighteon, we dove into a game-changer for installing apps away from Google play store. The Aurora Store makes it easy to get the apps you need without hunting down APKs, and it even shows you "nutrition facts" for each app—like which trackers are hidden inside. Think of it like reading a food label, but for your phone.
You might be surprised how many apps come bundled with trackers like Facebook, Google, and more. With Aurora Store, you can see exactly who's tracking your apps and keep control in your hands.
🪧 Watch the full interview here
📲 Learn more about the Above Phone
—
🫶 @takebackourtech
📩 WEBSITE & NEWSLETTER | 🎥 VIDEOS| XMPP | SUBSTACK
In my recent chat with Mike Adams on Brighteon, we dove into a game-changer for installing apps away from Google play store. The Aurora Store makes it easy to get the apps you need without hunting down APKs, and it even shows you "nutrition facts" for each app—like which trackers are hidden inside. Think of it like reading a food label, but for your phone.
You might be surprised how many apps come bundled with trackers like Facebook, Google, and more. With Aurora Store, you can see exactly who's tracking your apps and keep control in your hands.
🪧 Watch the full interview here
📲 Learn more about the Above Phone
—
🫶 @takebackourtech
📩 WEBSITE & NEWSLETTER | 🎥 VIDEOS| XMPP | SUBSTACK