The Hacker News
โœ”
151K subscribers
1.78K photos
9 videos
3 files
7.7K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: admin@thehackernews.com

๐ŸŒ Website: https://thehackernews.com
Download Telegram
CISOs planning 2026 budgets are rethinking priorities.

Data visibility & DSPM are moving from โ€œnice-to-haveโ€ to the foundation for risk reduction, faster audits & ROI.

Read: Why Data Visibility Belongs in Your 2026 Cybersecurity Budget ๐Ÿ‘‡ https://thn.news/security-priority-guide
๐Ÿ”ฅ10๐Ÿ‘2
๐Ÿ”ฅ The week in cyber: patches werenโ€™t fast enough, trust wasnโ€™t enough, and attackers werenโ€™t waiting.

โ†’ WSUS exploited
โ†’ LockBit 5.0 returns
โ†’ Telegram backdoor
โ†’ F5 breach deepens
โ†’ YouTube malware surge
โ†’ MuddyWater spying
โ†’ Lazarus fake jobs
โ†’ CoPhish OAuth attack
โ†’ Russia bug law
โ†’ UN cyber treaty

โšก Read the recap: https://thehackernews.com/2025/10/weekly-recap-wsus-exploited-lockbit-50.html
๐Ÿ”ฅ19๐Ÿค”3๐Ÿ‘1
๐Ÿšจ New exploit targets ChatGPT Atlas AI browser.

Researchers at LayerX found a CSRF flaw that lets attackers inject code into its persistent memory, surviving across browsers, sessions, and devices.

Once infected, even a normal chat can silently execute hidden commands.

Full report โ†“ https://thehackernews.com/2025/10/new-chatgpt-atlas-browser-exploit-lets.html
๐Ÿ˜19๐Ÿ”ฅ10๐Ÿ˜ฑ2
โš ๏ธ WARNING: X users with security keys (like YubiKeys) must re-enroll 2FA by Nov 10, 2025 โ€” or get locked out.

The update moves keys from twitter[.]com to x[.]com as Twitterโ€™s domain is retired.

Details โ†“ https://thehackernews.com/2025/10/x-warns-users-with-security-keys-to-re.html
๐Ÿ˜17๐Ÿค”5๐Ÿ‘3โšก1
โšก Security and speed shouldnโ€™t be enemies.

But when AI agents multiply faster than controls can keep up, most orgs fall into firefighting mode.

Join our live session to see how forward-thinking teams are:

โœ… Governing thousands of AI agents automatically
โœ… Embedding security guardrails that scale
โœ… Shipping AI features faster โ€” and safer

Live webinar: Learn how to scale AI securely, without compromise โ†’ https://thehacker.news/securing-ai-adoption
๐Ÿ˜6๐Ÿ‘2
โš ๏ธ SideWinder hackers strike again.

A European embassy in New Delhi was hit using fake Adobe Reader updates and signed apps to sneak in StealerBot malware โ€” stealing passwords, screenshots, and files.

Other targets: Sri Lanka, Pakistan, and Bangladesh.

Full report โ†“ https://thehackernews.com/2025/10/sidewinder-adopts-new-clickonce-based.html
๐Ÿ‘14๐Ÿ˜6๐Ÿ”ฅ4โšก3
โš ๏ธ ALERT: A Chrome zero-day (CVE-2025-2783) was exploited to deliver spyware built by Memento Labs โ€” the firm behind past government surveillance tools.

One click in Chromium = full sandbox escape.

Read this โ†’ https://thehackernews.com/2025/10/chrome-zero-day-exploited-to-deliver.html
๐Ÿ”ฅ18๐Ÿ‘4
Google Workspace isnโ€™t secure by default.

Many startups operate with open sharing, broad app access, and limited oversight.

The risk? It often looks completely normal.

See how lean teams are locking it down โ†’ https://thehackernews.com/2025/10/is-your-google-workspace-as-secure-as.html
๐Ÿ”ฅ13๐Ÿ‘3๐Ÿ‘1
AI-driven attacks move faster than humans can react.

The real risk? Teams flying blind.

ANYRUN flips the script โ€” predicting attacks before they strike. 99% unique IOCs. Zero lag. Full context.

Early detection turns panic into power โ†’ https://thehackernews.com/2025/10/why-early-threat-detection-is-must-for.html
๐Ÿ”ฅ7
๐Ÿšจ North Koreaโ€“linked BlueNoroff is running two active campaigns โ€” GhostCall & GhostHire โ€” into 2025.

GhostCall fakes Zoom/Teams meetings to drop malware via bogus SDK โ€œupdates.โ€

GhostHire targets Web3 devs on Telegram with booby-trapped GitHub tests.

Full report โ†“ https://thehackernews.com/2025/10/researchers-expose-ghostcall-and.html
๐Ÿ‘10๐Ÿ˜3๐Ÿคฏ3โšก2๐Ÿ”ฅ2
๐Ÿšจ New Android Trojan โ€˜Herodotusโ€™ is on the move.

Itโ€™s hitting phones in ๐Ÿ‡ฎ๐Ÿ‡น Italy & ๐Ÿ‡ง๐Ÿ‡ท Brazil โ€” stealing 2FA codes, logins, even lock PINs โ€” and typing like a human to slip past fraud detection.

๐Ÿ”— Read full report โ†’ https://thehackernews.com/2025/10/new-android-trojan-herodotus-outsmarts.html
๐Ÿ”ฅ12๐Ÿคฏ5๐Ÿ˜2๐Ÿ‘1๐Ÿ˜ฑ1
๐Ÿ”ฅ Researchers just broke Intel & AMDโ€™s newest โ€œsecureโ€ enclaves โ€” again.

A sub-$1K hardware rig can steal attestation keys from fully patched systems running SGX, TDX, and SEV-SNP with Ciphertext Hiding.

Even constant-time crypto and DDR5 encryption couldnโ€™t stop it.

Learn how TEE-Fail cracks open AI and confidential VMs โ†“ https://thehackernews.com/2025/10/new-teefail-side-channel-attack.html
๐Ÿ˜10๐Ÿ‘6๐Ÿคฏ2
๐Ÿšจ CISA confirmed ACTIVE exploitation of new flaws in Dassault Systรจmesโ€™ DELMIA Apriso and XWiki.

One lets any guest run code.
Another gives full admin access.
Hackers are already dropping crypto miners.

Agencies have until Nov 18 to patch โ†“ https://thehackernews.com/2025/10/active-exploits-hit-dassault-and-xwiki.html
๐Ÿ‘3๐Ÿ”ฅ3
๐Ÿšจ 10 fake npm packages (~9.9K installs) hid a cross-platform info stealer.

It spawns a fake terminal, pulls a 24 MB payload from 195.133.79[.]43, and drains keyrings โ€” not just browser creds.

Instant access to email, cloud, VPNs, and prod DBs.

Read details โ†“ https://thehackernews.com/2025/10/10-npm-packages-caught-stealing.html
๐Ÿ˜5๐Ÿคฏ5
๐Ÿšจ Russian hackers breached Ukrainian networks โ€” no malware needed.

They hijacked Windows tools (PowerShell, RDPClip, OpenSSH) to steal data and stay hidden for months.

Real fileless persistence โ€” living in memory, invisible to AV.

Learn how they did it & how to detect it โ†“ https://thehackernews.com/2025/10/russian-hackers-target-ukrainian.html
๐Ÿคฏ14๐Ÿ”ฅ7๐Ÿ˜7
๐Ÿ”ด The next big breach wonโ€™t start with a stolen password.

Itโ€™ll come from your own AI.

Agentic AIs are the new โ€œconfused deputiesโ€ โ€” doing what attackers tell them, with the access you gave them.

The scariest part? You trained the threat โ†“ https://thehackernews.com/2025/10/preparing-for-digital-battlefield-of.html
๐Ÿ‘3๐Ÿ˜2๐Ÿคฏ2๐Ÿ”ฅ1
โšก Your AI-driven compliance might already be non-compliant.

Regulators arenโ€™t ready โ€” but you can be.

Join the live session Nov 3 to uncover hidden risks and real fixes.

Register free โ†’ https://thehackernews.com/2025/10/discover-practical-ai-tactics-for-grc.html
๐Ÿ˜1
โš ๏ธ AI browsers like ChatGPT Atlas and Perplexity Comet can be tricked into using fake data.

A new exploit โ€” โ€œAI-targeted cloakingโ€ โ€” lets attackers show one version of a page to humans and another to AI crawlers.

Same old SEO trick.
New weapon: misinformation at scale.

Read how it works โ†“ https://thehackernews.com/2025/10/new-ai-targeted-cloaking-attack-tricks.html
๐Ÿ˜6
๐Ÿšจ PHP servers are under attack.

Mirai, Mozi, and Gafgyt botnets are exploiting old CVEs to hijack WordPress and Craft CMS sites.

Some break-ins start from leftover PhpStorm debug sessions still running in production.

Check if yours is exposed โ†“ https://thehackernews.com/2025/10/experts-reports-sharp-increase-in.html
๐Ÿ‘4