๐ฅ ALERT: Toptal's GitHub was HACKED โ attackers pushed 10 malicious npm packages.
They stole GitHub tokens, wiped systems silently, and racked up 5,000+ downloads before detection.
Hereโs what devs need to know โ https://thehackernews.com/2025/07/hackers-breach-toptal-github-publish-10.html
They stole GitHub tokens, wiped systems silently, and racked up 5,000+ downloads before detection.
Hereโs what devs need to know โ https://thehackernews.com/2025/07/hackers-breach-toptal-github-publish-10.html
๐ฑ21๐9๐คฏ8โก5๐1
๐จ CISA just confirmed active exploitation of a critical PaperCut bug (CVE-2023-2533) โ attackers can hijack admin sessions to run code remotely.
Itโs being used by ransomware gangs right now.
Patch before August 18 or risk breach.
Full details โ https://thehackernews.com/2025/07/cisa-adds-papercut-ngmf-csrf.html
Itโs being used by ransomware gangs right now.
Patch before August 18 or risk breach.
Full details โ https://thehackernews.com/2025/07/cisa-adds-papercut-ngmf-csrf.html
๐7
๐จ 100,000+ sites hacked in 2024โs biggest JavaScript injection attack.
Even React wasnโt safe โ a trusted library was turned into a malware delivery system.
Hereโs how modern JS threats are breaking your app โ https://thehackernews.com/2025/07/why-react-didnt-kill-xss-new-javascript.html
Even React wasnโt safe โ a trusted library was turned into a malware delivery system.
Hereโs how modern JS threats are breaking your app โ https://thehackernews.com/2025/07/why-react-didnt-kill-xss-new-javascript.html
๐8๐ค1
๐จ A wave of mobile malware is sweeping Asiaโtargeting Android & iOS with fake apps, phishing, and spyware.
๐ธ 250+ fake dating & social apps (SarangTrap) stealing photos, contacts, SMS
๐ธ Banking trojans like RedHook hijack devices in Vietnam
๐ธ Fake Telegram & finance apps hit users in India, Korea, Bangladesh
๐ธ Criminals now rent malware kits or buy access to infected phones
Cybercrime is now a business. Stay alert โ https://thehackernews.com/2025/07/cybercriminals-use-fake-apps-to-steal.html
๐ธ 250+ fake dating & social apps (SarangTrap) stealing photos, contacts, SMS
๐ธ Banking trojans like RedHook hijack devices in Vietnam
๐ธ Fake Telegram & finance apps hit users in India, Korea, Bangladesh
๐ธ Criminals now rent malware kits or buy access to infected phones
Cybercrime is now a business. Stay alert โ https://thehackernews.com/2025/07/cybercriminals-use-fake-apps-to-steal.html
๐13๐ฑ7๐1
Chaos is backโand it's wearing a new mask.
A rebrand of BlackSuit (linked to Royal & Conti), the new Chaos #ransomware gang is hitting U.S. victims hard with $300K ransoms, voice phishing, RMM abuse & stealthy multi-threaded encryption.
Details here โ https://thehackernews.com/2025/07/chaos-raas-emerges-after-blacksuit.html
A rebrand of BlackSuit (linked to Royal & Conti), the new Chaos #ransomware gang is hitting U.S. victims hard with $300K ransoms, voice phishing, RMM abuse & stealthy multi-threaded encryption.
Details here โ https://thehackernews.com/2025/07/chaos-raas-emerges-after-blacksuit.html
๐ค9
HACKasan 2025 is ON โ and this year, itโs better than ever!
For the 4th year running, Pentera is hosting THE most epic Black Hat & DEF CON after-party, exclusively for cybersecurity pros on Thursday, August 7th!
๐ง Live DJ + drummer combo
๐ธ Open bar
๐ Legendary Hakkasan light show
๐ฅ Cyber crowd only
๐ Register Today! Free of charge: https://thn.news/pentera-blackhat-party-2025
For the 4th year running, Pentera is hosting THE most epic Black Hat & DEF CON after-party, exclusively for cybersecurity pros on Thursday, August 7th!
๐ง Live DJ + drummer combo
๐ธ Open bar
๐ Legendary Hakkasan light show
๐ฅ Cyber crowd only
๐ Register Today! Free of charge: https://thn.news/pentera-blackhat-party-2025
๐ฅ9โก5๐2
๐จ PyPI users are being phished โ and the fake login pages look real.
Hackers spoofed PyPI emails & built replica sites that steal credentials, then forward victims to the legit site to cover their tracks.
Full details โ https://thehackernews.com/2025/07/pypi-warns-of-ongoing-phishing-campaign.html
Hackers spoofed PyPI emails & built replica sites that steal credentials, then forward victims to the legit site to cover their tracks.
Full details โ https://thehackernews.com/2025/07/pypi-warns-of-ongoing-phishing-campaign.html
๐ฅ7๐3๐ฑ2
๐จ AI-powered vibe coding platform Base44 had a critical flaw: anyone with a public app_id could bypass SSO and access private appsโno auth required.
Wix patched it fast, but it exposes serious risks in AI dev platforms.
Full story โ https://thehackernews.com/2025/07/wiz-uncovers-critical-access-bypass.html
Wix patched it fast, but it exposes serious risks in AI dev platforms.
Full story โ https://thehackernews.com/2025/07/wiz-uncovers-critical-access-bypass.html
๐13๐คฏ7โก3
๐จ The browser is now the front line of cyber attacks.
Phishing, infostealers & token hijacking are bypassing MFA, targeting SaaS logins, and owning orgs โ all in the browser.
Identity is the prize. And most teams arenโt watching.
Hereโs why it matters โ https://thehackernews.com/2025/07/how-browser-became-main-cyber.html
Phishing, infostealers & token hijacking are bypassing MFA, targeting SaaS logins, and owning orgs โ all in the browser.
Identity is the prize. And most teams arenโt watching.
Hereโs why it matters โ https://thehackernews.com/2025/07/how-browser-became-main-cyber.html
๐คฏ14๐ฅ4๐1
โก Scattered Spider hacker group just went quietโbut donโt exhale yet.
After UK arrests, Mandiant says the groupโs intrusions have stopped.
But copycats are already using their same ruthless tactics.
Nowโs the moment to harden your defenses.
Read - https://thehackernews.com/2025/07/scattered-spider-hacker-arrests-halt.html
After UK arrests, Mandiant says the groupโs intrusions have stopped.
But copycats are already using their same ruthless tactics.
Nowโs the moment to harden your defenses.
Read - https://thehackernews.com/2025/07/scattered-spider-hacker-arrests-halt.html
๐11๐3
A critical SAP flaw just gave hackers remote access to a U.S. chemicals company.
They deployed Auto-Colorโstealthy Linux malware that hides itself when it canโt reach its C2 server.
Details you need to know โ https://thehackernews.com/2025/07/hackers-exploit-sap-vulnerability-to.html
They deployed Auto-Colorโstealthy Linux malware that hides itself when it canโt reach its C2 server.
Details you need to know โ https://thehackernews.com/2025/07/hackers-exploit-sap-vulnerability-to.html
๐ฅ17๐2
๐จ Most ransomware attacks donโt hack inโthey log in.
EDR alone canโt stop attackers using legit credentials.
The fix? Pair it with Endpoint Privilege Management (EPM) to shut down stealthy privilege abuse before it starts.
Hereโs why both are critical โ https://thehackernews.com/expert-insights/2025/07/edr-detects-epm-prevents-why-using-both.html
EDR alone canโt stop attackers using legit credentials.
The fix? Pair it with Endpoint Privilege Management (EPM) to shut down stealthy privilege abuse before it starts.
Hereโs why both are critical โ https://thehackernews.com/expert-insights/2025/07/edr-detects-epm-prevents-why-using-both.html
๐13๐ค3
๐จ Google just fired a double shot at cyber threats:
โ DBSC is now in open beta โ it locks session cookies to your device, stopping attackers from hijacking logins.
โ Project Zero goes public with unpatched bug reports to pressure faster fixes.
Big moves to end cookie theft & shrink patch gaps.
Details here โ https://thehackernews.com/2025/07/google-launches-dbsc-open-beta-in.html
โ DBSC is now in open beta โ it locks session cookies to your device, stopping attackers from hijacking logins.
โ Project Zero goes public with unpatched bug reports to pressure faster fixes.
Big moves to end cookie theft & shrink patch gaps.
Details here โ https://thehackernews.com/2025/07/google-launches-dbsc-open-beta-in.html
๐ฅ16๐5๐3๐ค1
๐จ Apple just patched a zero-day used in the wild โ tied to a Chrome exploit.
The bug let attackers break out of the browser sandbox using a malicious web page.
iPhones, Macs, iPads, and more were at risk. Update now.
Details here โ https://thehackernews.com/2025/07/apple-patches-safari-vulnerability-also.html
The bug let attackers break out of the browser sandbox using a malicious web page.
iPhones, Macs, iPads, and more were at risk. Update now.
Details here โ https://thehackernews.com/2025/07/apple-patches-safari-vulnerability-also.html
๐ฅ9๐5๐2
๐จ Critical flaws in Dahua smart cameras let attackers take full remote controlโno login needed.
Used in homes, stores, and casinos, these bugs allow root access, persistent malware, and no easy fix.
Exposed devices are still at risk.
Full details โ https://thehackernews.com/2025/07/critical-dahua-camera-flaws-enable.html
Used in homes, stores, and casinos, these bugs allow root access, persistent malware, and no easy fix.
Exposed devices are still at risk.
Full details โ https://thehackernews.com/2025/07/critical-dahua-camera-flaws-enable.html
๐16๐5๐ค1
๐จ Your AI agent might already be vulnerable.
Pillar Security just launched a full-lifecycle AI defense platformโbuilt by ex-offensive and defensive cyber opsโto catch threats before code is even written.
From threat modeling to runtime guardrails, this flips AI security on its head.
Full story โ https://thehackernews.com/2025/07/product-walkthrough-look-inside-pillars.html
Pillar Security just launched a full-lifecycle AI defense platformโbuilt by ex-offensive and defensive cyber opsโto catch threats before code is even written.
From threat modeling to runtime guardrails, this flips AI security on its head.
Full story โ https://thehackernews.com/2025/07/product-walkthrough-look-inside-pillars.html
๐8๐2๐ค1
Custom containers, zero headaches.
ActiveState builds and scans your stack from OS to appโSBOM, low-to-no CVEs, ready for your CI/CD. Own your security. Stop inheriting risk.
Customize Your Container โ https://thn.news/activestate-container-security
#DevSecOps #OpenSourceSecurity
ActiveState builds and scans your stack from OS to appโSBOM, low-to-no CVEs, ready for your CI/CD. Own your security. Stop inheriting risk.
Customize Your Container โ https://thn.news/activestate-container-security
#DevSecOps #OpenSourceSecurity
๐6
๐ฅ A free decryptor just landed for FunkSec ransomware โ 172 victims hit across tech, gov, and education can now get their files back.
Built with AI. Written in Rust. Broken by rookies.
Get the tool + full story โ https://thehackernews.com/2025/07/funksec-ransomware-decryptor-released.html
Built with AI. Written in Rust. Broken by rookies.
Get the tool + full story โ https://thehackernews.com/2025/07/funksec-ransomware-decryptor-released.html
๐11๐คฏ7๐1
๐จ Thousands tricked by fake crypto apps via Facebook ads.
They install a stealthy new malwareโJSCEALโthat hijacks wallets, steals passwords in real-time, and evades most detection tools.
Worse? It's still active.
Hereโs how it works (and how to avoid it) โ https://thehackernews.com/2025/07/hackers-use-facebook-ads-to-spread.html
They install a stealthy new malwareโJSCEALโthat hijacks wallets, steals passwords in real-time, and evades most detection tools.
Worse? It's still active.
Hereโs how it works (and how to avoid it) โ https://thehackernews.com/2025/07/hackers-use-facebook-ads-to-spread.html
๐15๐ฅ3๐3
๐จ 120,000+ attacks in the wild.
Hackers are exploiting a critical bug (CVSS 9.8) in a popular WordPress theme to hijack sitesโno login needed.
Theyโre planting PHP backdoors and rogue admin accounts.
Details here โ https://thehackernews.com/2025/07/hackers-exploit-critical-wordpress.html
Hackers are exploiting a critical bug (CVSS 9.8) in a popular WordPress theme to hijack sitesโno login needed.
Theyโre planting PHP backdoors and rogue admin accounts.
Details here โ https://thehackernews.com/2025/07/hackers-exploit-critical-wordpress.html
๐12๐คฏ6๐ฅ3๐3