That copyright email in your inbox? It might not be legal trouble—it might be malware.
The “Noodlophile” attack hides in fake copyright notices, abuses Telegram, and slips past security tools.
If your brand lives on social media—you’re a target.
Here’s how it works ↓ https://thehackernews.com/2025/08/noodlophile-malware-campaign-expands.html
The “Noodlophile” attack hides in fake copyright notices, abuses Telegram, and slips past security tools.
If your brand lives on social media—you’re a target.
Here’s how it works ↓ https://thehackernews.com/2025/08/noodlophile-malware-campaign-expands.html
🤔13👍5👏1
⚡ Microsoft warns: PipeMagic isn’t malware—it’s a framework for stealth attacks. Storm-2460 is hitting IT, finance & real estate worldwide.
Details → https://thehackernews.com/2025/08/microsoft-windows-vulnerability.html
Details → https://thehackernews.com/2025/08/microsoft-windows-vulnerability.html
🤯11🤔5🔥4
⚡ PyPI just killed a major supply chain threat.
Over 1,800 email addresses tied to expired domains have been unverified—closing a loophole attackers used to hijack Python packages.
It’s a win, but not a cure-all.
👉 Full story ↓ https://thehackernews.com/2025/08/pypi-blocks-1800-expired-domain-emails.html
Over 1,800 email addresses tied to expired domains have been unverified—closing a loophole attackers used to hijack Python packages.
It’s a win, but not a cure-all.
👉 Full story ↓ https://thehackernews.com/2025/08/pypi-blocks-1800-expired-domain-emails.html
⚡11🤯6
Russia’s Secret Blizzard just did something scarier than phishing → They hacked the root of trust—bypassing MFA and silently stealing “secure” traffic.
When TLS itself is broken, FIDO and MFA collapse.
How to defend against state-level attacks ↓ https://thehackernews.com/expert-insights/2025/08/how-to-defend-against-root-of-trust.html
When TLS itself is broken, FIDO and MFA collapse.
How to defend against state-level attacks ↓ https://thehackernews.com/expert-insights/2025/08/how-to-defend-against-root-of-trust.html
🔥26👏4
The U.K. just dropped its demand that Apple build a backdoor into iCloud.
That order would’ve opened Americans’ encrypted data to governments—and hackers.
The plan’s dead. But the fight over encryption isn’t.
Here’s what happened → https://thehackernews.com/2025/08/uk-government-drops-apple-encryption.html
That order would’ve opened Americans’ encrypted data to governments—and hackers.
The plan’s dead. But the fight over encryption isn’t.
Here’s what happened → https://thehackernews.com/2025/08/uk-government-drops-apple-encryption.html
👏13⚡12👍8🔥6
🚨 Hackers are chaining two SAP flaws (CVSS 10.0 + 9.1) to bypass login and fully take over systems.
Ransomware crews + China-linked spies are already using it in the wild.
SAP patched in April/May—but attackers were exploiting since March.
Details here → https://thehackernews.com/2025/08/public-exploit-for-chained-sap-flaws.html
Ransomware crews + China-linked spies are already using it in the wild.
SAP patched in April/May—but attackers were exploiting since March.
Details here → https://thehackernews.com/2025/08/public-exploit-for-chained-sap-flaws.html
⚡12🤯1
🚨 60% of breaches in 2024 came from one source: people.
Not because employees are careless—because security is confusing, complex, and built for auditors, not humans. Until culture is fixed, tech alone won’t save you.
Here’s how to change that ↓ https://thehackernews.com/2025/08/why-your-security-culture-is-critical.html
Not because employees are careless—because security is confusing, complex, and built for auditors, not humans. Until culture is fixed, tech alone won’t save you.
Here’s how to change that ↓ https://thehackernews.com/2025/08/why-your-security-culture-is-critical.html
👏7👍4😱3🔥2
🚨 New RAT alert: Hackers are hitting trading firms with GodRAT—a backdoor hidden inside fake financial docs sent over Skype.
It steals files, passwords, and even drops more malware.
Built on 20-year-old Gh0st RAT code, but deadlier.
Full details → https://thehackernews.com/2025/08/new-godrat-trojan-targets-trading-firms.html
It steals files, passwords, and even drops more malware.
Built on 20-year-old Gh0st RAT code, but deadlier.
Full details → https://thehackernews.com/2025/08/new-godrat-trojan-targets-trading-firms.html
🤔12👍6⚡2
Hackers are breaking into Linux cloud servers using a 2-year-old bug in Apache ActiveMQ.
The twist? After sneaking in, they patch the flaw themselves—locking out rivals and hiding from defenders.
Full story here → https://thehackernews.com/2025/08/apache-activemq-flaw-exploited-to.html
The twist? After sneaking in, they patch the flaw themselves—locking out rivals and hiding from defenders.
Full story here → https://thehackernews.com/2025/08/apache-activemq-flaw-exploited-to.html
😁30🤔10🤯10🔥4😱4👏1
🚨 A 22-year-old from Oregon built a DDoS-for-hire botnet so massive it launched 370,000+ attacks across 80 countries.
Powered by 95,000 hacked devices, “RapperBot” could blast traffic at 6 Tbps—enough to cripple major platforms.
The FBI just shut it down.
Full story → https://thehackernews.com/2025/08/doj-charges-22-year-old-for-running.html
Powered by 95,000 hacked devices, “RapperBot” could blast traffic at 6 Tbps—enough to cripple major platforms.
The FBI just shut it down.
Full story → https://thehackernews.com/2025/08/doj-charges-22-year-old-for-running.html
🤯32🔥11👏11😁6⚡2🤔2
🚨 Nearly half of AI-generated code snippets contain exploitable bugs.
Worse? Developers trust them blindly—introducing SQL injections, hardcoded secrets, and overly permissive cloud configs at scale.
AI isn’t just coding faster—it’s coding insecurely.
Full story ↓ https://thehackernews.com/expert-insights/2025/08/ais-hidden-security-debt.html
Worse? Developers trust them blindly—introducing SQL injections, hardcoded secrets, and overly permissive cloud configs at scale.
AI isn’t just coding faster—it’s coding insecurely.
Full story ↓ https://thehackernews.com/expert-insights/2025/08/ais-hidden-security-debt.html
😁22🤯7⚡3👍2🤔2
North Korean hackers ran a months-long cyber-espionage op against diplomats—hiding malware traffic in GitHub & Dropbox.
Their activity froze during Chinese national holidays.
Details → https://thehackernews.com/2025/08/north-korea-uses-github-in-diplomat.html
Their activity froze during Chinese national holidays.
Details → https://thehackernews.com/2025/08/north-korea-uses-github-in-diplomat.html
😁19🔥5
Ransomware. Outages. Human error.
The threats are multiplying—and downtime is no longer an option.
The survival playbook? A rock-solid BIA: the map that makes your BCDR strategy actually work.
Here’s why IT leaders can’t afford to skip it ↓ https://thehackernews.com/2025/08/turning-bia-insights-into-resilient-recovery.html
The threats are multiplying—and downtime is no longer an option.
The survival playbook? A rock-solid BIA: the map that makes your BCDR strategy actually work.
Here’s why IT leaders can’t afford to skip it ↓ https://thehackernews.com/2025/08/turning-bia-insights-into-resilient-recovery.html
🔥6👍4
451 Research Reveals: Why AI & SaaS Security Can’t Be Managed Separately.
Security leaders: AI is reshaping your SaaS environment faster than old tools can keep up. Hear from Justin Lam, Principal Analyst at 451 Research, in a live session breaking down the new realities:
🔸 Hidden risks from shadow AI and third-party SaaS
🔸 Real-world attack scenarios and trends, including ShinyHunters
🔸 How unified SaaS & AI security platforms close the gaps
Save your seat for actionable insights, practical frameworks, and a live Q&A with one of the industry’s top minds—so your team is ready for what’s next.
Save My Spot → https://thn.news/ai-saas-attack-surface
Security leaders: AI is reshaping your SaaS environment faster than old tools can keep up. Hear from Justin Lam, Principal Analyst at 451 Research, in a live session breaking down the new realities:
🔸 Hidden risks from shadow AI and third-party SaaS
🔸 Real-world attack scenarios and trends, including ShinyHunters
🔸 How unified SaaS & AI security platforms close the gaps
Save your seat for actionable insights, practical frameworks, and a live Q&A with one of the industry’s top minds—so your team is ready for what’s next.
Save My Spot → https://thn.news/ai-saas-attack-surface
👍5🤯1
🔥 WEBINAR ALERT!
Shadow AI agents are already running inside your business—often unseen, unlogged, and unmanaged.
Once hacked, they don’t think. They just execute—24/7.
Most security programs aren’t built for this.
Join our next webinar to learn how to stop them before attackers strike ↓ https://thehackernews.com/2025/08/webinar-discover-and-control-shadow-ai.html
Shadow AI agents are already running inside your business—often unseen, unlogged, and unmanaged.
Once hacked, they don’t think. They just execute—24/7.
Most security programs aren’t built for this.
Join our next webinar to learn how to stop them before attackers strike ↓ https://thehackernews.com/2025/08/webinar-discover-and-control-shadow-ai.html
🔥7⚡1😁1🤯1
🛑 PromptFix ALERT! Researchers show AI browsers like Comet can be tricked by hidden prompts inside fake CAPTCHAs.
Moreover, AI browsers may unknowingly:
• Auto-click phishing links
• Autofill credit cards and addresses
• Trigger malware downloads
🔗 Full details here → https://thehackernews.com/2025/08/experts-find-ai-browsers-can-be-tricked.html
Moreover, AI browsers may unknowingly:
• Auto-click phishing links
• Autofill credit cards and addresses
• Trigger malware downloads
🔗 Full details here → https://thehackernews.com/2025/08/experts-find-ai-browsers-can-be-tricked.html
😁13⚡1👍1🤔1
🇷🇺 Russia’s Static Tundra hackers (linked to the FSB) are exploiting a 7-year-old critical Cisco flaw to breach telecom, education & manufacturing networks worldwide.
They’re stealing configs, planting implants like SYNful Knock, and hijacking traffic for espionage.
Details → https://thehackernews.com/2025/08/fbi-warns-russian-fsb-linked-hackers.html
They’re stealing configs, planting implants like SYNful Knock, and hijacking traffic for espionage.
Details → https://thehackernews.com/2025/08/fbi-warns-russian-fsb-linked-hackers.html
🔥13⚡7😱2😁1
⚠️ A single click on a fake site can hijack your password manager.
Researchers found 11 popular extensions (1Password, LastPass, iCloud & more) vulnerable—putting logins, 2FA codes, and credit cards at risk.
6 vendors still haven’t patched.
Protect your PASSWORDS ↓ https://thehackernews.com/2025/08/dom-based-extension-clickjacking.html
Researchers found 11 popular extensions (1Password, LastPass, iCloud & more) vulnerable—putting logins, 2FA codes, and credit cards at risk.
6 vendors still haven’t patched.
Protect your PASSWORDS ↓ https://thehackernews.com/2025/08/dom-based-extension-clickjacking.html
🤯33🔥5🤔5😁3😱2👏1
🚨 Apple just patched a zero-day already under attack.
Hackers were exploiting a malicious image bug (CVE-2025-43300) in iPhones, iPads & Macs.
Apple says it was used in extremely sophisticated targeted attacks.
Update now. Details ↓ https://thehackernews.com/2025/08/apple-patches-cve-2025-43300-zero-day.html
Hackers were exploiting a malicious image bug (CVE-2025-43300) in iPhones, iPads & Macs.
Apple says it was used in extremely sophisticated targeted attacks.
Update now. Details ↓ https://thehackernews.com/2025/08/apple-patches-cve-2025-43300-zero-day.html
👍13😱7🤔1
🚫 That “CEO” on your Zoom call? Might be an AI fake.
Deepfake scams have already stolen $25M+ in single hits—voices, faces, even biometrics can be forged.
The line between real and fake is gone.
How to spot it before it’s too late ↓ https://thehackernews.com/expert-insights/2025/08/defending-against-adversarial-ai-and.html
Deepfake scams have already stolen $25M+ in single hits—voices, faces, even biometrics can be forged.
The line between real and fake is gone.
How to spot it before it’s too late ↓ https://thehackernews.com/expert-insights/2025/08/defending-against-adversarial-ai-and.html
🤯12🤔3👍1👏1😁1
A 20-year-old hacker just got 10 YEARS in prison.
Noah Urban, part of the Scattered Spider crew, stole millions through SIM swaps & crypto heists—and now owes $13M in restitution.
But the gang isn’t gone. They’ve merged with other groups to get even stronger.
Full story → https://thehackernews.com/2025/08/scattered-spider-hacker-gets-10-years.html
Noah Urban, part of the Scattered Spider crew, stole millions through SIM swaps & crypto heists—and now owes $13M in restitution.
But the gang isn’t gone. They’ve merged with other groups to get even stronger.
Full story → https://thehackernews.com/2025/08/scattered-spider-hacker-gets-10-years.html
🤯23🔥8👏3😱3