The Hacker News
โœ”
151K subscribers
1.78K photos
9 videos
3 files
7.7K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: admin@thehackernews.com

๐ŸŒ Website: https://thehackernews.com
Download Telegram
๐Ÿšจ North Koreaโ€“linked BlueNoroff is running two active campaigns โ€” GhostCall & GhostHire โ€” into 2025.

GhostCall fakes Zoom/Teams meetings to drop malware via bogus SDK โ€œupdates.โ€

GhostHire targets Web3 devs on Telegram with booby-trapped GitHub tests.

Full report โ†“ https://thehackernews.com/2025/10/researchers-expose-ghostcall-and.html
๐Ÿ‘10๐Ÿ˜3๐Ÿคฏ3โšก2๐Ÿ”ฅ2
๐Ÿšจ New Android Trojan โ€˜Herodotusโ€™ is on the move.

Itโ€™s hitting phones in ๐Ÿ‡ฎ๐Ÿ‡น Italy & ๐Ÿ‡ง๐Ÿ‡ท Brazil โ€” stealing 2FA codes, logins, even lock PINs โ€” and typing like a human to slip past fraud detection.

๐Ÿ”— Read full report โ†’ https://thehackernews.com/2025/10/new-android-trojan-herodotus-outsmarts.html
๐Ÿ”ฅ12๐Ÿคฏ5๐Ÿ˜2๐Ÿ‘1๐Ÿ˜ฑ1
๐Ÿ”ฅ Researchers just broke Intel & AMDโ€™s newest โ€œsecureโ€ enclaves โ€” again.

A sub-$1K hardware rig can steal attestation keys from fully patched systems running SGX, TDX, and SEV-SNP with Ciphertext Hiding.

Even constant-time crypto and DDR5 encryption couldnโ€™t stop it.

Learn how TEE-Fail cracks open AI and confidential VMs โ†“ https://thehackernews.com/2025/10/new-teefail-side-channel-attack.html
๐Ÿ˜10๐Ÿ‘6๐Ÿคฏ2
๐Ÿšจ CISA confirmed ACTIVE exploitation of new flaws in Dassault Systรจmesโ€™ DELMIA Apriso and XWiki.

One lets any guest run code.
Another gives full admin access.
Hackers are already dropping crypto miners.

Agencies have until Nov 18 to patch โ†“ https://thehackernews.com/2025/10/active-exploits-hit-dassault-and-xwiki.html
๐Ÿ‘3๐Ÿ”ฅ2
๐Ÿšจ 10 fake npm packages (~9.9K installs) hid a cross-platform info stealer.

It spawns a fake terminal, pulls a 24 MB payload from 195.133.79[.]43, and drains keyrings โ€” not just browser creds.

Instant access to email, cloud, VPNs, and prod DBs.

Read details โ†“ https://thehackernews.com/2025/10/10-npm-packages-caught-stealing.html
๐Ÿ˜5๐Ÿคฏ4
๐Ÿšจ Russian hackers breached Ukrainian networks โ€” no malware needed.

They hijacked Windows tools (PowerShell, RDPClip, OpenSSH) to steal data and stay hidden for months.

Real fileless persistence โ€” living in memory, invisible to AV.

Learn how they did it & how to detect it โ†“ https://thehackernews.com/2025/10/russian-hackers-target-ukrainian.html
๐Ÿคฏ13๐Ÿ˜7๐Ÿ”ฅ5
๐Ÿ”ด The next big breach wonโ€™t start with a stolen password.

Itโ€™ll come from your own AI.

Agentic AIs are the new โ€œconfused deputiesโ€ โ€” doing what attackers tell them, with the access you gave them.

The scariest part? You trained the threat โ†“ https://thehackernews.com/2025/10/preparing-for-digital-battlefield-of.html
๐Ÿ‘3๐Ÿคฏ2๐Ÿ”ฅ1๐Ÿ˜1
โšก Your AI-driven compliance might already be non-compliant.

Regulators arenโ€™t ready โ€” but you can be.

Join the live session Nov 3 to uncover hidden risks and real fixes.

Register free โ†’ https://thehackernews.com/2025/10/discover-practical-ai-tactics-for-grc.html
โš ๏ธ AI browsers like ChatGPT Atlas and Perplexity Comet can be tricked into using fake data.

A new exploit โ€” โ€œAI-targeted cloakingโ€ โ€” lets attackers show one version of a page to humans and another to AI crawlers.

Same old SEO trick.
New weapon: misinformation at scale.

Read how it works โ†“ https://thehackernews.com/2025/10/new-ai-targeted-cloaking-attack-tricks.html
๐Ÿ˜2
๐Ÿšจ PHP servers are under attack.

Mirai, Mozi, and Gafgyt botnets are exploiting old CVEs to hijack WordPress and Craft CMS sites.

Some break-ins start from leftover PhpStorm debug sessions still running in production.

Check if yours is exposed โ†“ https://thehackernews.com/2025/10/experts-reports-sharp-increase-in.html