The Hacker News
βœ”
152K subscribers
1.87K photos
10 videos
3 files
7.79K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
🚨 Hackers are hijacking WordPress sites right now.

A critical flaw (CVE-2025-5947) in the Service Finder theme lets anyone log in as an admin β€” no password needed.

13,800+ exploit attempts. Still rising.
Most sites haven’t patched.

Details here β†’ https://thehackernews.com/2025/10/critical-exploit-lets-hackers-bypass.html
😁11πŸ‘2πŸ‘2
Preemptive Defense is the next frontier of identity security.

It can block AI-driven attacks before a user even authenticates β€” no login required.

Here’s how it works (and why Gartner’s calling it the new IAM essential).

Learn more ↓ https://thehackernews.com/expert-insights/2025/10/identity-and-ai-threats-developing.html
πŸ‘8πŸ”₯2
Russian hackers are now using AI to write malware.

Ukraine’s cybersecurity agency says over 3,000 cyberattacks hit in early 2025 β€” many powered by AI-generated phishing and data-stealing code.

One strain, WRECKSTEEL, was built with AI tools to target state networks.

Full report β†’ https://thehackernews.com/2025/10/from-phishing-to-malware-ai-becomes.html
😁23πŸ‘3🀯3
⚑ Latest ThreatsDay Bulletin Out Now!

Hackers exploit MS Teams + MFA to breach orgs β€” plus a $2B crypto heist, .LNK malware with PowerShell implants, Autodesk zero-days, and IoT hub exploits.

πŸ”— Your quick intel brief β†’ https://thehackernews.com/2025/10/threatsday-bulletin-ms-teams-hack-mfa.html
πŸ‘8πŸ”₯1
🚨 One stolen token can bypass MFA.

Last year, a single unrotated API key let attackers compromise Cloudflare’s internal systems β€” even after a full credential reset.

OAuth & API tokens are the new backdoors hiding in plain sight.

How to spot them before attackers do ↓ https://thehackernews.com/2025/10/saas-breaches-start-with-tokens-what.html
πŸ‘11
πŸŸ₯ SonicWall breach ALERT!

Hackers accessed cloud-stored firewall backups β€” about 5% of customers affected.

The files hold encrypted credentials and configs that could help attackers target devices.

Check your MySonicWall portal for impacted devices β†’ https://thehackernews.com/2025/10/hackers-access-sonicwall-cloud-firewall.html
😱11πŸ”₯1
🚨 A new Android spyware is spreading like a worm.

β€œClayRat” infects phones, then messages every contact to spread further.

It hides as WhatsApp, YouTube, or Google Photos β€” even faking Play Store screens.

Full analysis ↓ https://thehackernews.com/2025/10/new-clayrat-spyware-targets-android.html
πŸ”₯21🀯9😁3
A China-backed group just turned AI into a cyber weapon.

They’re using it to write phishing emails and build malware β€” across English, Chinese, and Japanese targets.

The result? A new backdoor called GOVERSHELL spreading via fake research invites.

Read how ↓ https://thehackernews.com/2025/10/from-healthkick-to-govershell-evolution.html
πŸ”₯11πŸ‘6πŸ€”1
🚨 Google confirms dozens of organizations breached via Oracle E-Business Suite zero-day (CVE-2025-61882).

Attackers exploited the flaw since July 2025, using multi-stage Java implants and extortion tactics.

πŸ”Ή Oracle issued an emergency patch Oct 4
πŸ”Ή Exploit code is now public β€” risk rising

πŸ”— Details: https://thehackernews.com/2025/10/cl0p-linked-hackers-breach-dozens-of.html
πŸ‘7πŸ‘4😁3🀯2πŸ€”1
🚨 Active zero-day alert: Gladinet’s CentreStack & TrioFox are under live exploitation.

Hackers are chaining two CVEs to pull machine keys and trigger remote code execution β€” no patch yet.

Admins, disable the temp handler now ↓ https://thehackernews.com/2025/10/from-lfi-to-rce-active-exploitation.html
πŸ”₯7πŸ‘1
🚨 Researchers uncovered 175 malicious npm packages used to host phishing redirects β€” downloaded 26,000+ times.

The campaign, dubbed Beamglea, abused npm + UNPKG to target 135 tech and energy firms worldwide.

No exploit. Just clever infrastructure abuse.

Read β†’ https://thehackernews.com/2025/10/175-malicious-npm-packages-with-26000.html
🀯10πŸ€”7
⚠️ A zero-day in GoAnywhere MFT has been actively exploited since Sept 11.

Attackers bypassed cryptographic checks β€” no password, no auth. Microsoft says Storm-1175 used it to drop Medusa ransomware.

Full timeline + exploit details ↓ https://thehackernews.com/2025/10/from-detection-to-patch-fortra-reveals.html
πŸ‘11
πŸ”΄ ALERT: Your next β€œHR alert” email might not be from HR.

Storm-2657 is phishing employees, taking over Workday accounts, and swapping bank details to steal salaries β€” no malware, just manipulation.

Inside Microsoft’s latest findings ↓ https://thehackernews.com/2025/10/microsoft-warns-of-payroll-pirates.html
😁13πŸ”₯4
⚠️ New β€œStealit” malware is using Node.js’ experimental SEA feature to slip full payloads into fake game & VPN installers β€” already spreading via Mediafire and Discord.

Read how β†’ https://thehackernews.com/2025/10/stealit-malware-abuses-nodejs-single.html
😁20
🚨 Signal just threatened to leave the EU.

Why? The proposed β€œChat Control” law would force apps to scan every private message before it’s sent.

The catch: even encrypted chats would be exposed. Experts call it β€œmass surveillance in disguise.”

The details you need to see ↓ https://thehackernews.com/2025/10/threatsday-bulletin-ms-teams-hack-mfa.html#opposition-to-e-u-chat-control
πŸ‘56🀯21πŸ”₯9😁9⚑4πŸ€”1
🚨 Hackers just turned a DFIR tool into a ransomware weapon.

Storm-2603 hijacked Velociraptor to deploy LockBit, Warlock & Babukβ€”even creating fake domain admins and disabling defenses.

Details here ↓ https://thehackernews.com/2025/10/hackers-turn-velociraptor-dfir-tool.html
😁16😱5πŸ”₯4
⚠️ Over 100 SonicWall SSL VPN accounts breached β€” not brute-forced.

Attackers used legit creds and traced back to a single IP.

Even patched devices are falling to Akira ransomware campaigns.

Learn more β†’ https://thehackernews.com/2025/10/experts-warn-of-widespread-sonicwall.html
πŸ”₯10😁4🀯4πŸ‘1
⚑ Apple’s Siri recordings are under criminal investigation in France.

A whistleblower says they captured β€œintimate” conversations β€” enough to identify users.

Apple denies misuse, but prosecutors aren’t convinced.

Read ↓ https://thehackernews.com/2025/10/threatsday-bulletin-ms-teams-hack-mfa.html#france-opens-probe-into-apple-siri-voice-recordings
πŸ”₯27😁10😱3
🐭 A $35 gaming mouse just became a spy tool.

UC Irvine researchers turned its optical sensor into a microphone that steals conversations from air-gapped PCs.

It hides inside legit apps like games. Read the PoC β†’ https://thehackernews.com/2025/10/threatsday-bulletin-ms-teams-hack-mfa.html#mic-e-mouse-attack-for-covert-data-exfiltration
😱46πŸ€”11πŸ‘5πŸ‘5
⚠️ WARNING: Oracle just confirmed a new vulnerability (CVE-2025-61884) in E-Business Suite.

No login required. Full data access possible.

Even worseβ€”similar flaws were just exploited by Cl0p-linked actors.

Read the latest news here β†’ https://thehackernews.com/2025/10/new-oracle-e-business-suite-bug-could.html
⚑11πŸ‘8πŸ‘3
🚨A new Rust-based backdoor called ChaosBot is hijacking corporate networks β€” and running its C2 over Discord.

It hides behind Microsoft Edge, abuses service accounts, and even checks for VMware to dodge analysis.

One slip β†’ full network access ↓ https://thehackernews.com/2025/10/new-rust-based-malware-chaosbot-hijacks.html
😁14πŸ‘6πŸ”₯4⚑2πŸ€”1