The Hacker News
βœ”
151K subscribers
1.84K photos
9 videos
3 files
7.75K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
⚠️ β€œPatch everything” is dead.

At the BAS Summit, CISOs said it straight β€” not every vuln matters, only the exploitable ones do.

Breach simulation shows where you bleed, not where scanners scream.

Proof beats panic. Read how BAS powers real defense β†’ https://thehackernews.com/2025/10/the-death-of-security-checkbox-bas-is.html
πŸ”₯5
πŸ”₯ A tool built for defenders is now arming attackers.

AdaptixC2 β€” an open-source C2 in Golang β€” was made for red teams.

Now, Russian ransomware gangs use it in fake Microsoft Teams help-desk scams.

Details ↓ https://thehackernews.com/2025/10/russian-ransomware-gangs-weaponize-open.html
🀯9πŸ€”4πŸ”₯3
πŸ’€ Google says it blocks over 10 billion scam calls and messages every month.

But scammers have adapted β€” they’ve gone social.

Now they send fake job offers in group chats, even adding fake β€œfriends” to make it look real.

The new scam tactic most experts overlooked ↓ https://thehackernews.com/2025/10/googles-built-in-ai-defenses-on-android.html
😁22πŸ€”13πŸ‘4πŸ”₯3
CISA added a new VMware zero-day to its KEV list.

CVE-2025-41244 (CVSS 7.8) lets local users on VMs with VMware Tools + Aria Operations gain root access.

Exploited since Oct 2024 by China-linked UNC5174.

Patch released last month ↓ https://thehackernews.com/2025/10/cisa-flags-vmware-zero-day-exploited-by.html
πŸ‘11πŸ‘2
Developers accidentally leaked VS Code tokens β€” letting attackers publish fake extensions.

Eclipse has revoked the tokens and added new safeguards after a campaign dubbed β€œGlassWorm.”

Read β†’ https://thehackernews.com/2025/10/eclipse-foundation-revokes-leaked-open.html
πŸ”₯9😁7πŸ‘1
A Mac app just bypassed macOS permission checks β€” silently turning on the mic and camera.

ThreatLocker’s new Device Access Control (DAC) for macOS, now in Beta, flags hidden risks like unencrypted drives, SMBv1, and weak sharing settings β€” before attackers can exploit them.

Learn more ↓ https://thehackernews.com/2025/10/a-new-security-layer-for-macos-takes.html
πŸ”₯11πŸ‘6
CISA and NSA just issued a warning:

Exchange servers are still getting hacked. Now a new WSUS flaw (CVE-2025-59287) lets attackers run code remotely.

Even patched systems aren’t fully safe.

If you manage Exchange or WSUS, read this ↓ https://thehackernews.com/2025/10/cisa-and-nsa-issue-urgent-guidance-to.html
⚑17😱4πŸ‘1
Most MSPs are walking straight into a trap.

Clients now expect enterprise-level cybersecurity β€” but many providers are still selling basic IT support.

The result? Lost clients, slower growth, and higher risk exposure.

Is your MSP ready to lead with security? ↓ https://thehackernews.com/2025/10/the-msp-cybersecurity-readiness-guide.html
πŸ‘8
⚠️ Chinese hackers are exploiting a critical 9.3 CVE (CVE-2025-61932) in Motex Lanscope Endpoint Manager.

It lets them run SYSTEM-level commands and plant a Gokcpdoor backdoor with new multiplexed C2 channels.

Active attacks confirmed ↓ https://thehackernews.com/2025/10/china-linked-tick-group-exploits.html
πŸ‘16😱4⚑1🀯1
🚨 China-backed hackers exploited an unpatched Windows shortcut bug to breach European diplomats.

UNC6384 used fake β€œEU Commission” and NATO meeting invites to plant PlugX malware (CVE-2025-9491) β€” still unpatched by Microsoft.

Full story ↓ https://thehackernews.com/2025/10/china-linked-hackers-exploit-windows.html
😱16😁6πŸ‘2🀯1
Nation-state hackers built Airstalk, a new malware abusing VMware Workspace ONE’s MDM API as a covert C2 channel.

Signed with a stolen cert, it’s exfiltrating browser data from BPO networks.

Full analysis ↓ https://thehackernews.com/2025/10/nation-state-hackers-deploy-new.html
πŸ‘14πŸ‘3🀯3
πŸ”₯ OpenAI just launched an AI #cybersecurity researcher.

It finds bugs, proves they’re real, and patches them β€” all by itself.

Powered by GPT-5, it’s already discovered 10 vulnerabilities.

The age of autonomous bug hunters starts now β†’ https://thehackernews.com/2025/10/openai-unveils-aardvark-gpt-5-agent.html
⚑27😱15πŸ”₯10😁9πŸ‘5πŸ€”3πŸ‘1
πŸ”’ Chrome is going fully HTTPS by default starting April 2026.

Google will make β€œAlways Use Secure Connections” the default settingβ€”first for Enhanced Safe Browsing users, then for everyone by October 2026.

No more HTTP by default. Safer web, less room for attacks.

Full details ↓ https://thehackernews.com/2025/10/threatsday-bulletin-dns-poisoning-flaw.html#chrome-takes-final-step-toward-full-https-web
#ThreatsDay
πŸ”₯35😁9⚑5πŸ€”4πŸ‘2🀯1
🚨 400+ Cisco routers hacked across Australia!

A new implant called BADCANDY is exploiting CVE-2023-20198 β€” even after patches.

Rebooting won’t help. Hackers just come back.

Watch for fake cisco_sys_manager accounts ↓ https://thehackernews.com/2025/11/asd-warns-of-ongoing-badcandy-attacks.html
πŸ”₯25😁3🀯3πŸ‘2
⚠️ North Korea’s Kimsuky just dropped a new backdoor β€” HttpTroy β€” hidden in a fake VPN invoice.

It shows a decoy PDF, sets a fake β€œAhnlabUpdate” task, and rebuilds code on the fly to dodge detection.

Details ↓ https://thehackernews.com/2025/11/new-httptroy-backdoor-poses-as-vpn.html
πŸ”₯9πŸ€”4🀯3πŸ‘2
πŸ•΅οΈ Two Android trojans are silently draining accounts.

πŸ”Ή One pretends to be a government ID app.
πŸ”Ή The other hides as a food delivery tracker.

They even mute your phone β€” so you never hear it happen.

Learn more about BankBot-YNRK & DeliveryRAT ↓ https://thehackernews.com/2025/11/researchers-uncover-bankbot-ynrk-and.html
😁11πŸ€”1🀯1
Last week: hacked security tools, broken chip protections, smart AI malware, and dev tools used to attack us.

Hackers are moving faster than we can stop them.

See all the top threats: https://thehackernews.com/2025/11/weekly-recap-lazarus-hits-web3-intelamd.html
πŸ‘11πŸ”₯3πŸ‘2😁1
🚨 Hackers are now hijacking trucking/logistics firms β€” not just for data, but for the cargo itself.

They’re loading up legit remote-management tools like ScreenConnect & LogMeIn, hijacking load-boards and booking real shipments of food/beverage.

Read how β†’ https://thehackernews.com/2025/11/cybercriminals-exploit-remote.html
πŸ‘14πŸ”₯8😁3
🧠 SOC teams built to stop breaches... are built to miss them.

Detection tools catch signals, not connections β€” and attackers live in the gaps.

The future isn’t faster alerts. It’s smarter context.

πŸ” Don’t miss how they’re doing it ↓ https://thehackernews.com/2025/11/the-evolution-of-soc-operations-how.html
πŸ”₯17πŸ€”2
🚨 Microsoft just found a new backdoor called SesameOp β€” and it’s using the OpenAI Assistants API to talk to its attackers.

Instead of sketchy servers, it hides inside legit AI traffic. It lived undetected for months.

Commands were sent through the β€œdescription” field.

Read how it works ↓ https://thehackernews.com/2025/11/microsoft-detects-sesameop-backdoor.html
😁22😱6πŸ”₯4πŸ‘3