The Hacker News
โœ”
152K subscribers
1.88K photos
10 videos
3 files
7.79K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: [email protected]

๐ŸŒ Website: https://thehackernews.com
Download Telegram
๐Ÿšจ Microsoft just confirmed a critical GoAnywhere flaw (CVE-2025-10035) โ€” already exploited to deploy Medusa ransomware.

Attackers had a month-long head start โ€” silently breaching orgs while vendors stayed quiet.

Itโ€™s not just RCE โ€” itโ€™s persistence, lateral movement, and Cloudflare-tunneled C2.

Details โ†“ https://thehackernews.com/2025/10/microsoft-links-storm-1175-to.html
๐Ÿ˜11๐Ÿ”ฅ3๐Ÿ‘2
๐Ÿšจ Oracle EBS just joined CISAโ€™s Known Exploited list.

Cl0p (aka Graceful Spider) is using CVE-2025-61882 โ€” a 9.8 RCE โ€” to hit unpatched systems right now.

Attackers are chaining five bugs to hijack servers pre-auth.

Patch immediately. Read how the attack works โ†“ https://thehackernews.com/2025/10/oracle-ebs-under-fire-as-cl0p-exploits.html
๐Ÿ˜11๐Ÿ”ฅ1
๐ŸšจWARNING: CVE-2025-49844 (RediShell): Redis flaw rated 10.0 CVSS

A 13-year-old bug lets attackers escape Lua sandbox and run code on the host.

Even worse โ€” 60,000 Redis servers online have no auth.

Patch now or risk full system takeover: https://thehackernews.com/2025/10/13-year-redis-flaw-exposed-cvss-100.html
๐Ÿ”ฅ12
โšกALERT: XWorm 6.0 is back โ€” and itโ€™s evolved.

Now packing 35+ plug-ins for everything from webcam spying to ransomware ops.

Over 18,000 devices compromised โ€” and even threat actors got hit.

Learn more โ†“ https://thehackernews.com/2025/10/xworm-60-returns-with-35-plugins-and.html
๐Ÿ‘5๐Ÿ˜4๐Ÿ”ฅ1
Fragmented IAM is slowing teams down.

Learn why IAM silos happen and strategies to bridge the gaps in this Tines webinar.

Register now: https://thn.news/identity-sync
๐Ÿ‘5๐Ÿ”ฅ1
โš ๏ธ AI just overtook shadow IT.

New data shows generative AI is now the #1 vector for corporate data loss โ€” bigger than unmanaged SaaS or file sharing.

And the main culprit isnโ€™t uploads. Itโ€™s copy/paste โ†’ https://thehackernews.com/2025/10/new-research-ai-is-already-1-data.html
๐Ÿ˜9๐Ÿคฏ5
This media is not supported in your browser
VIEW IN TELEGRAM
๐Ÿ”ฅ Google just gave AI the power to patch your code โ€” automatically.

DeepMindโ€™s new AI agent, CodeMender, has already rewritten 4.5+ million lines of code across open-source projects & shipped 72 security fixes.

The next bug bounty? Might go to a bot โ†“ https://thehackernews.com/2025/10/googles-new-ai-doesnt-just-find.html
๐Ÿ”ฅ14๐Ÿ˜7๐Ÿ‘3๐Ÿ˜ฑ1
A fake job offer is stealing Facebook business accounts.

Hackers posing as recruiters are sending โ€œMarriott job descriptionsโ€ that secretly install Vampire Bot โ€” a Go-based malware that screenshots your system.

Itโ€™s still active. โ†“ https://thehackernews.com/2025/10/batshadow-group-uses-new-go-based.html
๐Ÿ˜18๐Ÿคฏ5โšก3๐Ÿ”ฅ2๐Ÿค”2
๐Ÿšจ OpenAI just disrupted 3 clusters abusing ChatGPT for malwareโ€”Russia, North Korea, China. Scammers even stripped em-dashes to dodge โ€œAI-writtenโ€ tells.

RAT/C2 snippets, Telegram exfil, macOS Finder ext.

The iteration pattern that fingerprints them โ†“ https://thehackernews.com/2025/10/openai-disrupts-russian-north-korean.html
๐Ÿ˜16๐Ÿ‘5๐Ÿ”ฅ5
๐Ÿšจ A single design flaw in Figmaโ€™s MCP server just opened a path to remote code execution.

Developers using AI-powered tools like Cursor were exposed for months.

The fix is out โ€” details here โ†“ https://thehackernews.com/2025/10/severe-figma-mcp-vulnerability-lets.html
๐Ÿ‘13๐Ÿ”ฅ3
๐Ÿ’ผ The board doesnโ€™t speak โ€˜cyber.โ€™

And thatโ€™s why even the smartest CISOs lose funding.

A new course is teaching security leaders how to turn threat data into boardroom decisions โ€” before compliance fines or missed budgets hit.

โšก Learn more โ†’ https://thehackernews.com/expert-insights/2025/10/cracking-boardroom-code-helping-cisos.html
๐Ÿ˜9๐Ÿ‘4
๐Ÿ’ฃ Three of the worldโ€™s most dangerous ransomware gangs just joined forces.

LockBit, DragonForce, and Qilin are pooling tools, infrastructure, and targets โ€” a move that could supercharge attacks on critical sectors.

Full story โ†’ https://thehackernews.com/2025/10/lockbit-qilin-and-dragonforce-join.html
๐Ÿคฏ17๐Ÿ‘3๐Ÿ˜3๐Ÿ”ฅ2๐Ÿ‘1
๐ŸŽƒ This Halloween, face your password nightmares.

Think your passwords are safe? Most IT teams didโ€”until the breach.

Join โ€œTales from the Password Graveyardโ€ โ€” real stories, real lessons, and how to stop the next one.

Live webinar โ€” donโ€™t miss it โ†’ https://thehackernews.com/2025/10/step-into-password-graveyard-if-you.html
๐Ÿ˜13๐Ÿ”ฅ1
AI is now writing the next wave of cyberattacks.

The irony? Most defenders still canโ€™t use it effectively.
The attackers are fasterโ€”and smarter.

Hereโ€™s how to fight back โ†“ https://thehackernews.com/2025/09/automation-is-redefining-pentest.html
๐Ÿ”ฅ5
China-linked hackers just turned a trusted open-source tool into a weapon.

They used log poisoning to slip a web shell onto servers โ€” and dropped Gh0st RAT without custom malware.

100+ servers hit, Gh0st RAT deployed, and the control panel? Written in Russian.

Find details here โ†’ https://thehackernews.com/2025/10/chinese-hackers-weaponize-open-source.html
๐Ÿ˜12๐Ÿค”5๐Ÿ”ฅ1๐Ÿคฏ1
๐Ÿšจ New Threat ALERT! Hackers are exploiting WordPress themes with fake Cloudflare checks, redirecting users to malware via porsasystem[.]com.

Meanwhile, new ClickFix phishing kits use cache smuggling to deliver โ€œinvisibleโ€ payloadsโ€”no downloads needed.

How to spot & kill it โ†“ https://thehackernews.com/2025/10/hackers-exploit-wordpress-themes-to.html
๐Ÿ˜13๐Ÿ”ฅ6๐Ÿ‘1
๐Ÿšจ Hackers are hijacking WordPress sites right now.

A critical flaw (CVE-2025-5947) in the Service Finder theme lets anyone log in as an admin โ€” no password needed.

13,800+ exploit attempts. Still rising.
Most sites havenโ€™t patched.

Details here โ†’ https://thehackernews.com/2025/10/critical-exploit-lets-hackers-bypass.html
๐Ÿ˜11๐Ÿ‘2๐Ÿ‘2
Preemptive Defense is the next frontier of identity security.

It can block AI-driven attacks before a user even authenticates โ€” no login required.

Hereโ€™s how it works (and why Gartnerโ€™s calling it the new IAM essential).

Learn more โ†“ https://thehackernews.com/expert-insights/2025/10/identity-and-ai-threats-developing.html
๐Ÿ‘8๐Ÿ”ฅ2
Russian hackers are now using AI to write malware.

Ukraineโ€™s cybersecurity agency says over 3,000 cyberattacks hit in early 2025 โ€” many powered by AI-generated phishing and data-stealing code.

One strain, WRECKSTEEL, was built with AI tools to target state networks.

Full report โ†’ https://thehackernews.com/2025/10/from-phishing-to-malware-ai-becomes.html
๐Ÿ˜23๐Ÿ‘3๐Ÿคฏ3
โšก Latest ThreatsDay Bulletin Out Now!

Hackers exploit MS Teams + MFA to breach orgs โ€” plus a $2B crypto heist, .LNK malware with PowerShell implants, Autodesk zero-days, and IoT hub exploits.

๐Ÿ”— Your quick intel brief โ†’ https://thehackernews.com/2025/10/threatsday-bulletin-ms-teams-hack-mfa.html
๐Ÿ‘8๐Ÿ”ฅ1
๐Ÿšจ One stolen token can bypass MFA.

Last year, a single unrotated API key let attackers compromise Cloudflareโ€™s internal systems โ€” even after a full credential reset.

OAuth & API tokens are the new backdoors hiding in plain sight.

How to spot them before attackers do โ†“ https://thehackernews.com/2025/10/saas-breaches-start-with-tokens-what.html
๐Ÿ‘11