The Hacker News
βœ”
151K subscribers
1.85K photos
10 videos
3 files
7.76K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
Security teams are overwhelmed β€” 960+ alerts a day, and 40% go unchecked.

The real danger? Some of those missed alerts are actual breaches.

AI-SOCs promise to handle every alert automatically β€” but not all AI delivers.

Here’s how to tell what’s real vs. hype ↓ https://thehackernews.com/2025/10/architectures-risks-and-adoption-how-to.html
πŸ”₯5πŸ€”1
Researchers uncovered "LinkPro," a Golang-based Linux rootkit that uses eBPF to hide processes and activate remotely via a secret β€œmagic packet.”

It spread through a malicious Docker image deployed on vulnerable Jenkins servers.

Full report ↓ https://thehackernews.com/2025/10/linkpro-linux-rootkit-uses-ebpf-to-hide.html
πŸ”₯9⚑4😱2
πŸ”΄ Hackers are hiding malware inside blockchain smart contracts.

They’re pushing stealers like Atomic & Lumma from hacked WordPress sites β€” updating payloads without ever touching them.

Google found 14,000+ infected pages.

Details here β†’ https://thehackernews.com/2025/10/hackers-abuse-blockchain-smart.html
πŸ”₯15
⚑ North Korean hackers just used the blockchain to hide malware β€” the first time ever seen.

Google says they used EtherHiding to plant code inside smart contracts, making it nearly impossible to remove and easy to update for just $1.37 in gas fees.

Full story ↓ https://thehackernews.com/2025/10/north-korean-hackers-use-etherhiding-to.html
πŸ”₯19😁3
Get an inside look at Georgetown's Cybersecurity Master's program. Register for the virtual sample class on October 29.

Attend here β†’ https://thn.news/georgetown-cyber-class
πŸ‘5πŸ”₯3
πŸ”’ Microsoft just revoked 200+ trusted certificates β€” used to sign ransomware disguised as Teams installers.

The fake setup files slipped past security checks for weeks.

Here’s how Vanilla Tempest pulled it off ↓ https://thehackernews.com/2025/10/microsoft-revokes-200-fraudulent.html
🀯17πŸ‘7😁5πŸ‘3πŸ€”3😱1
🚨 CVE-2025-9242 β€” Critical WatchGuard Fireware flaw (CVSS 9.3)

Unauthenticated attackers can exploit a 520-byte overflow in IKEv2 before cert checks, executing code on VPN firewalls β€” even spawning a Python shell over TCP.

Patch now ↓ https://thehackernews.com/2025/10/researchers-uncover-watchguard-vpn-bug.html
πŸ”₯11πŸ‘3
🚨 AI agents don’t make mistakes β€” they execute them.

One wrong logic chain can turn flawless automation into a flawless catastrophe.

The real risk? Most enterprises don’t even know which bots hold the keys.

Identity is the new firewall. Read the 2025-26 Horizons report ↓ https://thehackernews.com/2025/10/identity-security-your-first-and-last.html
😁18πŸ‘5
⚠️ A fake tech interview β†’ a real breach.

North Korean hackers merged β€œBeaverTail” + β€œOtterCookie” into a new advanced malwareβ€”keylogger, wallet stealer, and remote shell all in one.

Learn more ↓ https://thehackernews.com/2025/10/north-korean-hackers-combine-beavertail.html
🀯14πŸ”₯6😁6πŸ‘4πŸ€”1
πŸ“„ You open a tax doc.
πŸ’» Windows quietly loads malware.
πŸ›‘ Your AV dies.
πŸ’€ You’re owned.

That’s how Winos 4.0 and HoldingHands RAT are spreading right now β€” using Windows’ own Task Scheduler against it.

Details here ↓ https://thehackernews.com/2025/10/silver-fox-expands-winos-40-attacks-to.html
😱11😁6πŸ”₯3
Hackers just dropped a new .NET backdoor disguised as a tax notice.

Open the ZIP β†’ boom, your data’s gone.

It even runs through legit Windows tools so nothing looks off.

Full story β†’ https://thehackernews.com/2025/10/new-net-capi-backdoor-targets-russian.html
😁15🀯11πŸ”₯7πŸ‘5
πŸ’£ Europol just dismantled a SIM farm-for-hire platform that powered 49 million fake accounts used for global fraud.

It let anyone rent verified phone numbers from 80+ countries β€” to scam, extort, or launder money.

Details β†’ https://thehackernews.com/2025/10/europol-dismantles-sim-farm-network.html
πŸ”₯44🀯12πŸ‘8😁7⚑4πŸ‘3😱3πŸ€”2
πŸ•΅οΈ China says the NSA hacked its national time servers β€” the system that keeps everything in sync.

If that clock went down, it could’ve hit banks, power grids, even space launches.

The attack used foreign SMS exploits, forged certs, and 42 stealth tools.

Read β†’ https://thehackernews.com/2025/10/mss-claims-nsa-used-42-cyber-tools-in.html
πŸ”₯37😁14😱13πŸ€”8⚑3πŸ‘3πŸ‘2🀯1
🚨 131 Chrome extensions were caught turning WhatsApp Web into spam bots.

They look like β€œCRM tools,” but secretly send bulk messages.

Over 20,000 users already installed them.

Full details ↓ https://thehackernews.com/2025/10/131-chrome-extensions-caught-hijacking.html
😁14πŸ”₯4πŸ€”3
πŸ”΄ Silent breaches, blockchain malware, and new Android exploits β€” this week’s threat roundup proves attackers are getting bolder and smarter.

Catch the highlights:

⚑ F5 breach
⚑ EtherHiding malware
⚑ Cisco rootkits
⚑ Pixnapping 2FA theft

Read WEEKLY RECAP β†’ https://thehackernews.com/2025/10/weekly-recap-f5-breached-linux-rootkits.html
😁8πŸ‘1πŸ”₯1
🚨 A fake CAPTCHA just breached hospitals, universities, and city networks.

The scary part? Victims copied the attack code themselves β€” straight from their browser.

It’s called ClickFix, and it hijacks users through β€œfix this page” pop-ups β€” no downloads, no phishing email needed.

See how it slips past every control ↓ https://thehackernews.com/2025/10/analysing-clickfix-3-reasons-why.html
😁32😱10πŸ”₯5🀯3⚑2πŸ‘2
A Chinese-linked hacking group breached Europe’s telecom defenses β€” weaponizing antivirus software.

They planted a backdoor in legitimate Norton and Bkav installs.

Payload: SnappyBee, a new ShadowPad variant delivered via DLL side-loading.

Learn more ↓ https://thehackernews.com/2025/10/hackers-used-snappybee-malware-and.html
πŸ”₯10πŸ€”5πŸ‘3🀯3😱2
Russia’s COLDRIVER hackers rebuilt their malware tools in just 5 days.

Meet NOROBOT, YESROBOT, and MAYBEROBOT β€” hidden behind fake CAPTCHA checks and PowerShell tricks.

Google just exposed how they did it ↓ https://thehackernews.com/2025/10/google-identifies-three-new-russian.html
😁14πŸ”₯6⚑4🀯4
⚠️ 7 out of 10 threats faced by SOCs begin with phishing.

Phishkits dominate the threat landscape and become increasingly harder to detect.

Act now to set up strong defenses with fresh, actionable intel from 15K orgs ‡️ https://thn.news/threat-intel-tg
πŸ‘7πŸ‘2πŸ€”2