The Hacker News
βœ”
151K subscribers
1.78K photos
9 videos
3 files
7.69K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
πŸ“’ WEBINAR ALERT!

You can’t secure what you can’t see. AI agents are spreading fast β€” unseen, unmanaged & risky.

Join this free #cybersecurity session to learn how leading security teams are regaining control & speed.

πŸ—“οΈ 27 Oct, 2025

πŸ”— Watch This ↓ https://thehackernews.com/2025/10/secure-ai-at-scale-and-speed-learn.html
πŸ”₯8
North Korean hackers are posing as recruitersβ€”again.

This time, they’re stealing drone tech from Europe’s defense firms.

The trap? A fake job PDF hiding a remote access tool.

It’s been activeβ€”undetectedβ€”since March.

Read β†’ https://thehackernews.com/2025/10/north-korean-hackers-lure-defense.html
πŸ€”13😱6πŸ‘2
🚨 GlassWorm hits VS Code extensions β€” 14 infected builds, ~35K installs since Oct 17 2025.

It steals dev creds, drains crypto wallets, turns machines into bots β€” and auto-updates itself.

Read ↓ https://thehackernews.com/2025/10/self-spreading-glassworm-infects-vs.html
😁14πŸ‘2πŸ”₯2
🚨 Hackers turned YouTube into a malware factory. Over 3,000 fake β€œtutorials” hide stealers like Lumma and Rhadamanthys.

They hijack real channels β€” likes, comments, and all β€” to look legit.

Even that β€œPhotoshop crack” or β€œRoblox cheat” video could infect you.

Read here ↓ https://thehackernews.com/2025/10/3000-youtube-videos-exposed-as-malware.html
😁15🀯12⚑6πŸ”₯3
Your SOC passed every test.
But your people? Failed the real one.

Modern AEV tools prove your defenses work β€”
until humans enter the equation.

The next frontier of validation isn’t technical.
It’s behavioral ↓ https://thehackernews.com/expert-insights/2025/10/beyond-tools-why-testing-human.html
πŸ‘9πŸ”₯1
🚨 A bug in the FIA driver portal exposed Formula 1 drivers’ personal data β€” including passports and licenses.

Anyone could become an β€œadmin” with a single API request.

The flaw is now fixed β€” but it was open for days ↓ https://thehackernews.com/2025/10/threatsday-bulletin-176m-crypto-fine.html#admin-bug-exposes-formula-1-driver-data
🀯19πŸ”₯6😱3
India’s BOSS Linux systems are under silent attack.

A Pakistan-linked group just dropped a new Golang RAT β€” DeskRAT β€” hidden inside fake government PDFs.

It sticks around with 4 persistence tricks and steals files through WebSockets.

Read ↓ https://thehackernews.com/2025/10/apt36-targets-indian-government-with.html
😁19πŸ€”6πŸ”₯5πŸ‘2🀯2
Microsoft just patched a critical WSUS flaw (CVE-2025-59287) β€” and attackers are already using it.

One crafted request = full SYSTEM control.

The twist? It comes from BinaryFormatter β€” the same tool Microsoft killed off last year.

Patch now ↓ https://thehackernews.com/2025/10/microsoft-issues-emergency-patch-for.html
😁18πŸ‘6πŸ”₯2
🚨 194,000 fake sites. $1B stolen.

The Smishing Triad is posing as USPS, banks, and toll services β€” all hosted on U.S. clouds to stay invisible.

Next target: brokerage accounts.

Full report ↓ https://thehackernews.com/2025/10/smishing-triad-linked-to-194000.html
πŸ‘16😱4πŸ”₯1
⚑ OpenAI’s new ChatGPT Atlas browser can be hijacked by a fake URL.

A prompt injection disguised as a normal link tricks the omnibox into running hidden commands.

One click, and your AI agent takes orders from attackers.

Read here ↓ https://thehackernews.com/2025/10/chatgpt-atlas-browser-can-be-tricked-by.html
😱25😁14⚑4πŸ”₯4
Qilin ransomware just got smarter.

It’s hitting Windows and Linux together, wiping Veeam backups, and using a vulnerable driver to shut down security tools β€” all in one strike.

Over 100 victims in June alone.

Full story ↓ https://thehackernews.com/2025/10/qilin-ransomware-combines-linux-payload.html
πŸ”₯16😱6🀯3πŸ‘1
CISOs planning 2026 budgets are rethinking priorities.

Data visibility & DSPM are moving from β€œnice-to-have” to the foundation for risk reduction, faster audits & ROI.

Read: Why Data Visibility Belongs in Your 2026 Cybersecurity Budget πŸ‘‡ https://thn.news/security-priority-guide
πŸ”₯10πŸ‘2
πŸ”₯ The week in cyber: patches weren’t fast enough, trust wasn’t enough, and attackers weren’t waiting.

β†’ WSUS exploited
β†’ LockBit 5.0 returns
β†’ Telegram backdoor
β†’ F5 breach deepens
β†’ YouTube malware surge
β†’ MuddyWater spying
β†’ Lazarus fake jobs
β†’ CoPhish OAuth attack
β†’ Russia bug law
β†’ UN cyber treaty

⚑ Read the recap: https://thehackernews.com/2025/10/weekly-recap-wsus-exploited-lockbit-50.html
πŸ”₯18πŸ€”3πŸ‘1
🚨 New exploit targets ChatGPT Atlas AI browser.

Researchers at LayerX found a CSRF flaw that lets attackers inject code into its persistent memory, surviving across browsers, sessions, and devices.

Once infected, even a normal chat can silently execute hidden commands.

Full report ↓ https://thehackernews.com/2025/10/new-chatgpt-atlas-browser-exploit-lets.html
😁19πŸ”₯10😱1
⚠️ WARNING: X users with security keys (like YubiKeys) must re-enroll 2FA by Nov 10, 2025 β€” or get locked out.

The update moves keys from twitter[.]com to x[.]com as Twitter’s domain is retired.

Details ↓ https://thehackernews.com/2025/10/x-warns-users-with-security-keys-to-re.html
😁16πŸ€”5πŸ‘2⚑1
⚑ Security and speed shouldn’t be enemies.

But when AI agents multiply faster than controls can keep up, most orgs fall into firefighting mode.

Join our live session to see how forward-thinking teams are:

βœ… Governing thousands of AI agents automatically
βœ… Embedding security guardrails that scale
βœ… Shipping AI features faster β€” and safer

Live webinar: Learn how to scale AI securely, without compromise β†’ https://thehacker.news/securing-ai-adoption
😁6πŸ‘2
⚠️ SideWinder hackers strike again.

A European embassy in New Delhi was hit using fake Adobe Reader updates and signed apps to sneak in StealerBot malware β€” stealing passwords, screenshots, and files.

Other targets: Sri Lanka, Pakistan, and Bangladesh.

Full report ↓ https://thehackernews.com/2025/10/sidewinder-adopts-new-clickonce-based.html
πŸ‘13😁6πŸ”₯4⚑3
⚠️ ALERT: A Chrome zero-day (CVE-2025-2783) was exploited to deliver spyware built by Memento Labs β€” the firm behind past government surveillance tools.

One click in Chromium = full sandbox escape.

Read this β†’ https://thehackernews.com/2025/10/chrome-zero-day-exploited-to-deliver.html
πŸ”₯17πŸ‘3
Google Workspace isn’t secure by default.

Many startups operate with open sharing, broad app access, and limited oversight.

The risk? It often looks completely normal.

See how lean teams are locking it down β†’ https://thehackernews.com/2025/10/is-your-google-workspace-as-secure-as.html
πŸ”₯11πŸ‘3
AI-driven attacks move faster than humans can react.

The real risk? Teams flying blind.

ANYRUN flips the script β€” predicting attacks before they strike. 99% unique IOCs. Zero lag. Full context.

Early detection turns panic into power β†’ https://thehackernews.com/2025/10/why-early-threat-detection-is-must-for.html
πŸ”₯5