The Hacker News
โœ”
151K subscribers
1.84K photos
10 videos
3 files
7.76K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: [email protected]

๐ŸŒ Website: https://thehackernews.com
Download Telegram
๐Ÿšจ New Adobe Commerce flaw (CVE-2025-54236, CVSS 9.1) under active attack.

Over 250 exploit attempts in 24 hoursโ€”mostly on unpatched Magento sites.

PoC is public. Patch now.

Details โ†’ https://thehackernews.com/2025/10/over-250-magento-stores-hit-overnight.html
๐Ÿ”ฅ5
๐ŸŽ Hackers found a new jackpot โ€” cloud gift cards.

A group called Jingle Thief broke into retail cloud systems and quietly issued fake gift cards for months, hiding inside Microsoft 365 accounts.

Full story โ†“ https://thehackernews.com/2025/10/jingle-thief-hackers-exploit-cloud.html
๐Ÿ˜24๐Ÿคฏ4๐Ÿ˜ฑ1
In this 20-minute session, learn how to harden your images, secure dependencies, and lock down your CI/CD pipeline against real-world supply chain attacks.

๐Ÿ“… Tuesday, Oct 28 | 8 AM PST | 11 AM EST

๐ŸŽฅ Register Now โ†“ https://thn.news/secure-stack-webinar
๐Ÿ”ฅ7
๐Ÿšจ Static secrets are fading fast.

Teams using managed identities cut 95% of credential hassleโ€”yet hidden API keys still lurk in legacy systems.

The fix? Run NHI discovery to find every key, then migrate 70โ€“80% to managed identities.

Your roadmap โ†“ https://thehackernews.com/2025/10/why-organizations-are-abandoning-static.html
๐Ÿ‘7
From crypto fines to malware & data leaks โ€” the weekโ€™s biggest cyber hits:

๐Ÿ‡จ๐Ÿ‡ฆ Cryptomus fined $176M
๐Ÿ›ฐ๏ธ Starlink scam crackdown
๐Ÿค– AI vuln in Oat++ MCP
๐Ÿ“ง Tykit phishing campaign

.... 15+ more important news stories.

Read the latest #ThreatsDay Bulletin ๐Ÿ‘‡ https://thehackernews.com/2025/10/threatsday-bulletin-176m-crypto-fine.html
โšก9๐Ÿ”ฅ2
๐Ÿ“ข WEBINAR ALERT!

You canโ€™t secure what you canโ€™t see. AI agents are spreading fast โ€” unseen, unmanaged & risky.

Join this free #cybersecurity session to learn how leading security teams are regaining control & speed.

๐Ÿ—“๏ธ 27 Oct, 2025

๐Ÿ”— Watch This โ†“ https://thehackernews.com/2025/10/secure-ai-at-scale-and-speed-learn.html
๐Ÿ”ฅ8
North Korean hackers are posing as recruitersโ€”again.

This time, theyโ€™re stealing drone tech from Europeโ€™s defense firms.

The trap? A fake job PDF hiding a remote access tool.

Itโ€™s been activeโ€”undetectedโ€”since March.

Read โ†’ https://thehackernews.com/2025/10/north-korean-hackers-lure-defense.html
๐Ÿค”13๐Ÿ˜ฑ6๐Ÿ‘2
๐Ÿšจ GlassWorm hits VS Code extensions โ€” 14 infected builds, ~35K installs since Oct 17 2025.

It steals dev creds, drains crypto wallets, turns machines into bots โ€” and auto-updates itself.

Read โ†“ https://thehackernews.com/2025/10/self-spreading-glassworm-infects-vs.html
๐Ÿ˜14๐Ÿ‘2๐Ÿ”ฅ2
๐Ÿšจ Hackers turned YouTube into a malware factory. Over 3,000 fake โ€œtutorialsโ€ hide stealers like Lumma and Rhadamanthys.

They hijack real channels โ€” likes, comments, and all โ€” to look legit.

Even that โ€œPhotoshop crackโ€ or โ€œRoblox cheatโ€ video could infect you.

Read here โ†“ https://thehackernews.com/2025/10/3000-youtube-videos-exposed-as-malware.html
๐Ÿคฏ16๐Ÿ˜15โšก6๐Ÿ”ฅ3
Your SOC passed every test.
But your people? Failed the real one.

Modern AEV tools prove your defenses work โ€”
until humans enter the equation.

The next frontier of validation isnโ€™t technical.
Itโ€™s behavioral โ†“ https://thehackernews.com/expert-insights/2025/10/beyond-tools-why-testing-human.html
๐Ÿ‘10๐Ÿ”ฅ1
๐Ÿšจ A bug in the FIA driver portal exposed Formula 1 driversโ€™ personal data โ€” including passports and licenses.

Anyone could become an โ€œadminโ€ with a single API request.

The flaw is now fixed โ€” but it was open for days โ†“ https://thehackernews.com/2025/10/threatsday-bulletin-176m-crypto-fine.html#admin-bug-exposes-formula-1-driver-data
๐Ÿคฏ21๐Ÿ”ฅ6๐Ÿ˜ฑ3
Indiaโ€™s BOSS Linux systems are under silent attack.

A Pakistan-linked group just dropped a new Golang RAT โ€” DeskRAT โ€” hidden inside fake government PDFs.

It sticks around with 4 persistence tricks and steals files through WebSockets.

Read โ†“ https://thehackernews.com/2025/10/apt36-targets-indian-government-with.html
๐Ÿ˜19๐Ÿ”ฅ6๐Ÿค”6๐Ÿ‘2๐Ÿคฏ2
Microsoft just patched a critical WSUS flaw (CVE-2025-59287) โ€” and attackers are already using it.

One crafted request = full SYSTEM control.

The twist? It comes from BinaryFormatter โ€” the same tool Microsoft killed off last year.

Patch now โ†“ https://thehackernews.com/2025/10/microsoft-issues-emergency-patch-for.html
๐Ÿ˜18๐Ÿ‘7๐Ÿ”ฅ3
๐Ÿšจ 194,000 fake sites. $1B stolen.

The Smishing Triad is posing as USPS, banks, and toll services โ€” all hosted on U.S. clouds to stay invisible.

Next target: brokerage accounts.

Full report โ†“ https://thehackernews.com/2025/10/smishing-triad-linked-to-194000.html
๐Ÿ‘16๐Ÿ˜ฑ5๐Ÿ”ฅ1
โšก OpenAIโ€™s new ChatGPT Atlas browser can be hijacked by a fake URL.

A prompt injection disguised as a normal link tricks the omnibox into running hidden commands.

One click, and your AI agent takes orders from attackers.

Read here โ†“ https://thehackernews.com/2025/10/chatgpt-atlas-browser-can-be-tricked-by.html
๐Ÿ˜ฑ30๐Ÿ˜16๐Ÿ”ฅ5โšก4
Qilin ransomware just got smarter.

Itโ€™s hitting Windows and Linux together, wiping Veeam backups, and using a vulnerable driver to shut down security tools โ€” all in one strike.

Over 100 victims in June alone.

Full story โ†“ https://thehackernews.com/2025/10/qilin-ransomware-combines-linux-payload.html
๐Ÿ”ฅ16๐Ÿ˜ฑ6๐Ÿคฏ4๐Ÿ‘1
CISOs planning 2026 budgets are rethinking priorities.

Data visibility & DSPM are moving from โ€œnice-to-haveโ€ to the foundation for risk reduction, faster audits & ROI.

Read: Why Data Visibility Belongs in Your 2026 Cybersecurity Budget ๐Ÿ‘‡ https://thn.news/security-priority-guide
๐Ÿ”ฅ10๐Ÿ‘2
๐Ÿ”ฅ The week in cyber: patches werenโ€™t fast enough, trust wasnโ€™t enough, and attackers werenโ€™t waiting.

โ†’ WSUS exploited
โ†’ LockBit 5.0 returns
โ†’ Telegram backdoor
โ†’ F5 breach deepens
โ†’ YouTube malware surge
โ†’ MuddyWater spying
โ†’ Lazarus fake jobs
โ†’ CoPhish OAuth attack
โ†’ Russia bug law
โ†’ UN cyber treaty

โšก Read the recap: https://thehackernews.com/2025/10/weekly-recap-wsus-exploited-lockbit-50.html
๐Ÿ”ฅ19๐Ÿค”4๐Ÿ‘2๐Ÿ˜1
๐Ÿšจ New exploit targets ChatGPT Atlas AI browser.

Researchers at LayerX found a CSRF flaw that lets attackers inject code into its persistent memory, surviving across browsers, sessions, and devices.

Once infected, even a normal chat can silently execute hidden commands.

Full report โ†“ https://thehackernews.com/2025/10/new-chatgpt-atlas-browser-exploit-lets.html
๐Ÿ˜22๐Ÿ”ฅ11๐Ÿ˜ฑ2
โš ๏ธ WARNING: X users with security keys (like YubiKeys) must re-enroll 2FA by Nov 10, 2025 โ€” or get locked out.

The update moves keys from twitter[.]com to x[.]com as Twitterโ€™s domain is retired.

Details โ†“ https://thehackernews.com/2025/10/x-warns-users-with-security-keys-to-re.html
๐Ÿ˜19๐Ÿค”5๐Ÿ‘3โšก1
โšก Security and speed shouldnโ€™t be enemies.

But when AI agents multiply faster than controls can keep up, most orgs fall into firefighting mode.

Join our live session to see how forward-thinking teams are:

โœ… Governing thousands of AI agents automatically
โœ… Embedding security guardrails that scale
โœ… Shipping AI features faster โ€” and safer

Live webinar: Learn how to scale AI securely, without compromise โ†’ https://thehacker.news/securing-ai-adoption
๐Ÿ˜9๐Ÿ‘3