The Hacker News
151K subscribers
1.85K photos
10 videos
3 files
7.76K links
Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

📨 Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
🔐 "How much AI is too much in customer experiences?"

Users are starting to push back.

Join our new 📺 WEBINAR featuring an expert from @Okta as she reveals new research on how to balance innovation with trust—straight from the 2025 CIAM Trends Report.

👉 Watch the webinar now → https://thehacker.news/ai-customer-identity
👍12🤔2
🚨 Hackers are poisoning your Python packages, hijacking logins & weaponizing AI.

The next wave of cyberattacks is already here—and most defenses won’t stop it.

3 New urgent cybersecurity webinars show how to lock down your code, identity & AI stack → https://www.linkedin.com/pulse/secure-your-ai-supply-chain-stack-3-new-cybersecurity-webinars-d9zwc/
14🔥5👏1🤔1
🚨 SOCs are losing the AI race — and it’s not because of their tools.

They’re feeding cutting-edge AI systems junk data: incomplete logs, siloed alerts, zero context.

Meanwhile, attackers are training like elite athletes.

Here’s why defenders are falling behind ↓ https://thehackernews.com/2025/08/you-are-what-you-eat-why-your-ai.html
🔥17
🚨 An AI-generated npm package just stole crypto from devs.

"kodane/patch-manager" posed as a legit Node.js tool — but hid a stealth wallet drainer that hit 1,500+ downloads before takedown.

Here’s what to know ↓ https://thehackernews.com/2025/08/ai-generated-malicious-npm-package.html
😱126👍4😁3
🚨 Hackers are using fake Microsoft OAuth apps + the Tycoon phishing kit to hijack 365 accounts

They’ve spoofed 50+ brands (Adobe, DocuSign, SharePoint), bypassing MFA with adversary-in-the-middle attacks.

3,000+ users hit across 900 orgs.

Details → https://thehackernews.com/2025/08/attackers-use-fake-oauth-apps-with.html
👍13😁4👏3
🚨 A single Slack message could hijack Cursor—AI code editor—with zero clicks.

CVE-2025-54135 let attackers run remote code just by posting in a public channel.

Cursor auto-executed it. No prompts. No approval.

Details here → https://thehackernews.com/2025/08/cursor-ai-code-editor-fixed-flaw.html
👏18😁5🔥4🤔1😱1
🚨 Akira ransomware is hitting SonicWall SSL VPNs—some fully patched.

Researchers suspect a zero-day or credential abuse. Attacks surged in late July.

Org? Disable SSL VPN until further notice.

Full details ↓ https://thehackernews.com/2025/08/akira-ransomware-exploits-sonicwall.html
🔥18😁3👍2👏1🤔1
🚨 China-linked threat group hacked Southeast Asia telecoms — no data stolen, just full remote access to critical networks for 9 months.

They used stealth malware, tunneled through mobile operators, and wiped their tracks.

Here’s what we know ↓ https://thehackernews.com/2025/08/cl-sta-0969-installs-covert-malware-in.html
😱22🔥11👏4😁4👍1
🚨 Over 11,000 Android phones hijacked by new PlayPraetor malware.

It fakes Google Play pages, abuses accessibility settings, and livestreams your screen—all to steal banking and crypto credentials.

And it's spreading fast.

Here’s what you need to know ↓ https://thehackernews.com/2025/08/playpraetor-android-trojan-infects.html
🤯16😱10👍5👏2
You’re not just using SaaS. It’s using you.

AI tools, browser plugins, and apps your team installs without asking are opening hidden doors to your data.

Most IT teams have no idea.

Here’s how to take back control ↓ https://thehackernews.com/2025/08/the-wild-west-of-shadow-it.html
7😁7👍5😱4
Weekly Recap ⟶ VPN 0‑Day, Mac Stealer Backdoor, AI Malware Disguised as Dev Tools, and an APT Hiding in ISPs.

The scariest part? Most of it looked legit.

Catch up now ↓ https://thehackernews.com/2025/08/weekly-recap-vpn-0-day-encryption.html
😁7😱3
🚨 New wave of Python malware hits 4,000+ systems across 62 countries.

PXA Stealer is siphoning passwords, credit cards, and cookies—then selling them via Telegram-powered black markets.

Details here → https://thehackernews.com/2025/08/vietnamese-hackers-use-pxa-stealer-hit.html
😁15🔥3👏3👍2
🔥 Hackers can fully hijack NVIDIA's Triton AI servers — no login needed.

A new exploit chain gives attackers remote code execution and access to sensitive AI models.

It all starts with a single malformed request.

Full details → https://thehackernews.com/2025/08/nvidia-triton-bugs-let-unauthenticated.html
😁27🔥6👍5😱41👏1
🚨 A suspected zero-day in SonicWall Gen 7 firewalls is under active attack.

Akira ransomware is exploiting SSL VPNs to breach networks—even with MFA.

20+ confirmed attacks. Domain controllers hit within hours.

Urgent steps + full report → https://thehackernews.com/2025/08/sonicwall-investigating-potential-ssl.html
👏14🔥2
🚨 DDoS attacks surged 358% in Q1 2025. But it’s not just volume—it’s AI-powered, precision-targeted, and actively evading defenses.

The old playbook is obsolete. Most orgs only test 1% of their attack surface.

The rest? Fully exposed.

Details here → https://thehackernews.com/expert-insights/2025/08/the-new-face-of-ddos-is-impacted-by-ai.html
👍11😱1
🚨 15,000+ fake TikTok Shop sites are stealing logins & crypto.

A massive scam uses AI-generated videos, Meta ads & trojan apps to hijack your device.

It mimics influencers—and it's global.

Here’s what you need to know ↓ https://thehackernews.com/2025/08/15000-fake-tiktok-shop-domains-deliver.html
😁9👍7👏1
🚨 A phishing attack hidden behind a QR code + CAPTCHA was fully exposed in under 60 seconds—no analyst touch needed.

How? A live, automated sandbox detonated the payload, bypassed defenses, and surfaced IOCs instantly.

Your SOC is missing this.

Details here → https://thehackernews.com/2025/08/how-top-cisos-save-their-socs-from.html
😁14👏1
🚨 A high-severity flaw in Cursor AI (CVE-2025-54136) let attackers hijack trusted MCP configs—triggering remote code execution every time you opened the project.

No re-prompt. No warning. Just silent compromise by modifying a config file you already trusted.

Learn more → https://thehackernews.com/2025/08/cursor-ai-code-editor-vulnerability.html
👏16😁6👍2
🔑 53% of orgs trust their SaaS vendors. But 70% of SaaS incidents come from misconfigs & bad permissions—your responsibility.

Worse? They leave no logs. No alerts. Just exposure.

Here’s why posture > detection: https://thehackernews.com/2025/08/misconfigurations-are-not.html
🤔71
🚨 Google just fixed 3 Android bugs hackers were already using.

One lets them hijack your phone through the graphics chip — no clicks needed.

Spyware vendors may be behind it.

PATCH your phones now → https://thehackernews.com/2025/08/google-fixes-3-android-vulnerabilities.html
😁23🤯9🔥5🤔1
🚨 CAPTCHAgeddon is here. A fake CAPTCHA scam called ClickFix hijacks devices with a single paste—no download, no file, just clipboard commands.

It's smarter than ClearFake—and spreading fast.

Here’s how it works ↓ https://thehackernews.com/2025/08/clickfix-malware-campaign-exploits.html
😱8🔥3👍2🤔2😁1