The Hacker News
βœ”
151K subscribers
1.77K photos
9 videos
3 files
7.68K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
🚨 194,000 fake sites. $1B stolen.

The Smishing Triad is posing as USPS, banks, and toll services β€” all hosted on U.S. clouds to stay invisible.

Next target: brokerage accounts.

Full report ↓ https://thehackernews.com/2025/10/smishing-triad-linked-to-194000.html
πŸ‘15😱4πŸ”₯1
⚑ OpenAI’s new ChatGPT Atlas browser can be hijacked by a fake URL.

A prompt injection disguised as a normal link tricks the omnibox into running hidden commands.

One click, and your AI agent takes orders from attackers.

Read here ↓ https://thehackernews.com/2025/10/chatgpt-atlas-browser-can-be-tricked-by.html
😱21😁13⚑4πŸ”₯4
Qilin ransomware just got smarter.

It’s hitting Windows and Linux together, wiping Veeam backups, and using a vulnerable driver to shut down security tools β€” all in one strike.

Over 100 victims in June alone.

Full story ↓ https://thehackernews.com/2025/10/qilin-ransomware-combines-linux-payload.html
πŸ”₯15😱5🀯2πŸ‘1
CISOs planning 2026 budgets are rethinking priorities.

Data visibility & DSPM are moving from β€œnice-to-have” to the foundation for risk reduction, faster audits & ROI.

Read: Why Data Visibility Belongs in Your 2026 Cybersecurity Budget πŸ‘‡ https://thn.news/security-priority-guide
πŸ”₯9πŸ‘2
πŸ”₯ The week in cyber: patches weren’t fast enough, trust wasn’t enough, and attackers weren’t waiting.

β†’ WSUS exploited
β†’ LockBit 5.0 returns
β†’ Telegram backdoor
β†’ F5 breach deepens
β†’ YouTube malware surge
β†’ MuddyWater spying
β†’ Lazarus fake jobs
β†’ CoPhish OAuth attack
β†’ Russia bug law
β†’ UN cyber treaty

⚑ Read the recap: https://thehackernews.com/2025/10/weekly-recap-wsus-exploited-lockbit-50.html
πŸ”₯10πŸ€”3
🚨 New exploit targets ChatGPT Atlas AI browser.

Researchers at LayerX found a CSRF flaw that lets attackers inject code into its persistent memory, surviving across browsers, sessions, and devices.

Once infected, even a normal chat can silently execute hidden commands.

Full report ↓ https://thehackernews.com/2025/10/new-chatgpt-atlas-browser-exploit-lets.html
😁13πŸ”₯8😱1
⚠️ WARNING: X users with security keys (like YubiKeys) must re-enroll 2FA by Nov 10, 2025 β€” or get locked out.

The update moves keys from twitter[.]com to x[.]com as Twitter’s domain is retired.

Details ↓ https://thehackernews.com/2025/10/x-warns-users-with-security-keys-to-re.html
😁11πŸ€”4
⚑ Security and speed shouldn’t be enemies.

But when AI agents multiply faster than controls can keep up, most orgs fall into firefighting mode.

Join our live session to see how forward-thinking teams are:

βœ… Governing thousands of AI agents automatically
βœ… Embedding security guardrails that scale
βœ… Shipping AI features faster β€” and safer

Live webinar: Learn how to scale AI securely, without compromise β†’ https://thehacker.news/securing-ai-adoption