The Hacker News
βœ”
151K subscribers
1.8K photos
9 videos
3 files
7.72K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
πŸ”₯ Researchers just broke Intel & AMD’s newest β€œsecure” enclaves β€” again.

A sub-$1K hardware rig can steal attestation keys from fully patched systems running SGX, TDX, and SEV-SNP with Ciphertext Hiding.

Even constant-time crypto and DDR5 encryption couldn’t stop it.

Learn how TEE-Fail cracks open AI and confidential VMs ↓ https://thehackernews.com/2025/10/new-teefail-side-channel-attack.html
😁11πŸ‘6🀯2
🚨 CISA confirmed ACTIVE exploitation of new flaws in Dassault SystΓ¨mes’ DELMIA Apriso and XWiki.

One lets any guest run code.
Another gives full admin access.
Hackers are already dropping crypto miners.

Agencies have until Nov 18 to patch ↓ https://thehackernews.com/2025/10/active-exploits-hit-dassault-and-xwiki.html
πŸ”₯4πŸ‘3
🚨 10 fake npm packages (~9.9K installs) hid a cross-platform info stealer.

It spawns a fake terminal, pulls a 24 MB payload from 195.133.79[.]43, and drains keyrings β€” not just browser creds.

Instant access to email, cloud, VPNs, and prod DBs.

Read details ↓ https://thehackernews.com/2025/10/10-npm-packages-caught-stealing.html
🀯10😁5πŸ‘1
🚨 Russian hackers breached Ukrainian networks β€” no malware needed.

They hijacked Windows tools (PowerShell, RDPClip, OpenSSH) to steal data and stay hidden for months.

Real fileless persistence β€” living in memory, invisible to AV.

Learn how they did it & how to detect it ↓ https://thehackernews.com/2025/10/russian-hackers-target-ukrainian.html
🀯18πŸ”₯8😁7πŸ‘1
πŸ”΄ The next big breach won’t start with a stolen password.

It’ll come from your own AI.

Agentic AIs are the new β€œconfused deputies” β€” doing what attackers tell them, with the access you gave them.

The scariest part? You trained the threat ↓ https://thehackernews.com/2025/10/preparing-for-digital-battlefield-of.html
🀯6😁5πŸ‘3πŸ”₯1
⚑ Your AI-driven compliance might already be non-compliant.

Regulators aren’t ready β€” but you can be.

Join the live session Nov 3 to uncover hidden risks and real fixes.

Register free β†’ https://thehackernews.com/2025/10/discover-practical-ai-tactics-for-grc.html
😁8
⚠️ AI browsers like ChatGPT Atlas and Perplexity Comet can be tricked into using fake data.

A new exploit β€” β€œAI-targeted cloaking” β€” lets attackers show one version of a page to humans and another to AI crawlers.

Same old SEO trick.
New weapon: misinformation at scale.

Read how it works ↓ https://thehackernews.com/2025/10/new-ai-targeted-cloaking-attack-tricks.html
😁14πŸ‘1
🚨 PHP servers are under attack.

Mirai, Mozi, and Gafgyt botnets are exploiting old CVEs to hijack WordPress and Craft CMS sites.

Some break-ins start from leftover PhpStorm debug sessions still running in production.

Check if yours is exposed ↓ https://thehackernews.com/2025/10/experts-reports-sharp-increase-in.html
πŸ‘9πŸ”₯2😁2πŸ‘1
🚨 PhantomRaven hit the npm registry β€” 126 malicious packages, 86K+ installs, stealing npm tokens, GitHub creds, and CI/CD secrets.

They hide malware in remote dynamic dependencies that show 0 deps, so scanners miss them.

Details β†’ https://thehackernews.com/2025/10/phantomraven-malware-found-in-126-npm.html
🀯10πŸ”₯3πŸ‘1
⚑ Cybercrime just got quieter, cheaper, and a lot more precise.

πŸ’₯ DNS flaws exploited
πŸ’₯ Rust binaries hiding payloads
πŸ’₯ Supply-chain heists rising
πŸ’₯ New RATs everywhere

Your weekly ThreatsDay recap has it all β†’ https://thehackernews.com/2025/10/threatsday-bulletin-dns-poisoning-flaw.html
πŸ‘10πŸ‘4😁2⚑1πŸ”₯1
🚨 A single line of JavaScript can crash any Chromium browser.

Researcher Jose Pino calls it Brash β€” it abuses how document.title handles rapid updates.

24 million title changes per second = instant crash.

Still unpatched. Details ↓ https://thehackernews.com/2025/10/new-brash-exploit-crashes-chromium.html
πŸ”₯8😁7🀯7
⚠️ β€œPatch everything” is dead.

At the BAS Summit, CISOs said it straight β€” not every vuln matters, only the exploitable ones do.

Breach simulation shows where you bleed, not where scanners scream.

Proof beats panic. Read how BAS powers real defense β†’ https://thehackernews.com/2025/10/the-death-of-security-checkbox-bas-is.html
πŸ”₯3
πŸ”₯ A tool built for defenders is now arming attackers.

AdaptixC2 β€” an open-source C2 in Golang β€” was made for red teams.

Now, Russian ransomware gangs use it in fake Microsoft Teams help-desk scams.

Details ↓ https://thehackernews.com/2025/10/russian-ransomware-gangs-weaponize-open.html
🀯7πŸ€”4πŸ”₯2
πŸ’€ Google says it blocks over 10 billion scam calls and messages every month.

But scammers have adapted β€” they’ve gone social.

Now they send fake job offers in group chats, even adding fake β€œfriends” to make it look real.

The new scam tactic most experts overlooked ↓ https://thehackernews.com/2025/10/googles-built-in-ai-defenses-on-android.html
😁20πŸ€”11πŸ‘4πŸ”₯2
CISA added a new VMware zero-day to its KEV list.

CVE-2025-41244 (CVSS 7.8) lets local users on VMs with VMware Tools + Aria Operations gain root access.

Exploited since Oct 2024 by China-linked UNC5174.

Patch released last month ↓ https://thehackernews.com/2025/10/cisa-flags-vmware-zero-day-exploited-by.html
πŸ‘9πŸ‘2
Developers accidentally leaked VS Code tokens β€” letting attackers publish fake extensions.

Eclipse has revoked the tokens and added new safeguards after a campaign dubbed β€œGlassWorm.”

Read β†’ https://thehackernews.com/2025/10/eclipse-foundation-revokes-leaked-open.html
πŸ”₯7😁5πŸ‘1
A Mac app just bypassed macOS permission checks β€” silently turning on the mic and camera.

ThreatLocker’s new Device Access Control (DAC) for macOS, now in Beta, flags hidden risks like unencrypted drives, SMBv1, and weak sharing settings β€” before attackers can exploit them.

Learn more ↓ https://thehackernews.com/2025/10/a-new-security-layer-for-macos-takes.html
πŸ”₯10πŸ‘6
CISA and NSA just issued a warning:

Exchange servers are still getting hacked. Now a new WSUS flaw (CVE-2025-59287) lets attackers run code remotely.

Even patched systems aren’t fully safe.

If you manage Exchange or WSUS, read this ↓ https://thehackernews.com/2025/10/cisa-and-nsa-issue-urgent-guidance-to.html
⚑14😱3πŸ‘1
Most MSPs are walking straight into a trap.

Clients now expect enterprise-level cybersecurity β€” but many providers are still selling basic IT support.

The result? Lost clients, slower growth, and higher risk exposure.

Is your MSP ready to lead with security? ↓ https://thehackernews.com/2025/10/the-msp-cybersecurity-readiness-guide.html
πŸ‘7
⚠️ Chinese hackers are exploiting a critical 9.3 CVE (CVE-2025-61932) in Motex Lanscope Endpoint Manager.

It lets them run SYSTEM-level commands and plant a Gokcpdoor backdoor with new multiplexed C2 channels.

Active attacks confirmed ↓ https://thehackernews.com/2025/10/china-linked-tick-group-exploits.html
πŸ‘15😱4⚑1