The Hacker News
โœ”
151K subscribers
1.85K photos
10 videos
3 files
7.76K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: [email protected]

๐ŸŒ Website: https://thehackernews.com
Download Telegram
๐Ÿšจ An AI-generated npm package just stole crypto from devs.

"kodane/patch-manager" posed as a legit Node.js tool โ€” but hid a stealth wallet drainer that hit 1,500+ downloads before takedown.

Hereโ€™s what to know โ†“ https://thehackernews.com/2025/08/ai-generated-malicious-npm-package.html
๐Ÿ˜ฑ12โšก6๐Ÿ‘4๐Ÿ˜3
๐Ÿšจ Hackers are using fake Microsoft OAuth apps + the Tycoon phishing kit to hijack 365 accounts

Theyโ€™ve spoofed 50+ brands (Adobe, DocuSign, SharePoint), bypassing MFA with adversary-in-the-middle attacks.

3,000+ users hit across 900 orgs.

Details โ†’ https://thehackernews.com/2025/08/attackers-use-fake-oauth-apps-with.html
๐Ÿ‘13๐Ÿ˜4๐Ÿ‘3
๐Ÿšจ A single Slack message could hijack Cursorโ€”AI code editorโ€”with zero clicks.

CVE-2025-54135 let attackers run remote code just by posting in a public channel.

Cursor auto-executed it. No prompts. No approval.

Details here โ†’ https://thehackernews.com/2025/08/cursor-ai-code-editor-fixed-flaw.html
๐Ÿ‘18๐Ÿ˜5๐Ÿ”ฅ4๐Ÿค”1๐Ÿ˜ฑ1
๐Ÿšจ Akira ransomware is hitting SonicWall SSL VPNsโ€”some fully patched.

Researchers suspect a zero-day or credential abuse. Attacks surged in late July.

Org? Disable SSL VPN until further notice.

Full details โ†“ https://thehackernews.com/2025/08/akira-ransomware-exploits-sonicwall.html
๐Ÿ”ฅ18๐Ÿ˜3๐Ÿ‘2๐Ÿ‘1๐Ÿค”1
๐Ÿšจ China-linked threat group hacked Southeast Asia telecoms โ€” no data stolen, just full remote access to critical networks for 9 months.

They used stealth malware, tunneled through mobile operators, and wiped their tracks.

Hereโ€™s what we know โ†“ https://thehackernews.com/2025/08/cl-sta-0969-installs-covert-malware-in.html
๐Ÿ˜ฑ22๐Ÿ”ฅ11๐Ÿ‘4๐Ÿ˜4๐Ÿ‘1
๐Ÿšจ Over 11,000 Android phones hijacked by new PlayPraetor malware.

It fakes Google Play pages, abuses accessibility settings, and livestreams your screenโ€”all to steal banking and crypto credentials.

And it's spreading fast.

Hereโ€™s what you need to know โ†“ https://thehackernews.com/2025/08/playpraetor-android-trojan-infects.html
๐Ÿคฏ16๐Ÿ˜ฑ10๐Ÿ‘5๐Ÿ‘2
Youโ€™re not just using SaaS. Itโ€™s using you.

AI tools, browser plugins, and apps your team installs without asking are opening hidden doors to your data.

Most IT teams have no idea.

Hereโ€™s how to take back control โ†“ https://thehackernews.com/2025/08/the-wild-west-of-shadow-it.html
โšก7๐Ÿ˜7๐Ÿ‘5๐Ÿ˜ฑ4
โšก Weekly Recap โŸถ VPN 0โ€‘Day, Mac Stealer Backdoor, AI Malware Disguised as Dev Tools, and an APT Hiding in ISPs.

The scariest part? Most of it looked legit.

Catch up now โ†“ https://thehackernews.com/2025/08/weekly-recap-vpn-0-day-encryption.html
๐Ÿ˜7๐Ÿ˜ฑ3
๐Ÿšจ New wave of Python malware hits 4,000+ systems across 62 countries.

PXA Stealer is siphoning passwords, credit cards, and cookiesโ€”then selling them via Telegram-powered black markets.

Details here โ†’ https://thehackernews.com/2025/08/vietnamese-hackers-use-pxa-stealer-hit.html
๐Ÿ˜15๐Ÿ”ฅ3๐Ÿ‘3๐Ÿ‘2
๐Ÿ”ฅ Hackers can fully hijack NVIDIA's Triton AI servers โ€” no login needed.

A new exploit chain gives attackers remote code execution and access to sensitive AI models.

It all starts with a single malformed request.

Full details โ†’ https://thehackernews.com/2025/08/nvidia-triton-bugs-let-unauthenticated.html
๐Ÿ˜27๐Ÿ”ฅ6๐Ÿ‘5๐Ÿ˜ฑ4โšก1๐Ÿ‘1
๐Ÿšจ A suspected zero-day in SonicWall Gen 7 firewalls is under active attack.

Akira ransomware is exploiting SSL VPNs to breach networksโ€”even with MFA.

20+ confirmed attacks. Domain controllers hit within hours.

Urgent steps + full report โ†’ https://thehackernews.com/2025/08/sonicwall-investigating-potential-ssl.html
๐Ÿ‘14๐Ÿ”ฅ2
๐Ÿšจ DDoS attacks surged 358% in Q1 2025. But itโ€™s not just volumeโ€”itโ€™s AI-powered, precision-targeted, and actively evading defenses.

The old playbook is obsolete. Most orgs only test 1% of their attack surface.

The rest? Fully exposed.

Details here โ†’ https://thehackernews.com/expert-insights/2025/08/the-new-face-of-ddos-is-impacted-by-ai.html
๐Ÿ‘11๐Ÿ˜ฑ1
๐Ÿšจ 15,000+ fake TikTok Shop sites are stealing logins & crypto.

A massive scam uses AI-generated videos, Meta ads & trojan apps to hijack your device.

It mimics influencersโ€”and it's global.

Hereโ€™s what you need to know โ†“ https://thehackernews.com/2025/08/15000-fake-tiktok-shop-domains-deliver.html
๐Ÿ˜9๐Ÿ‘7๐Ÿ‘1
๐Ÿšจ A phishing attack hidden behind a QR code + CAPTCHA was fully exposed in under 60 secondsโ€”no analyst touch needed.

How? A live, automated sandbox detonated the payload, bypassed defenses, and surfaced IOCs instantly.

Your SOC is missing this.

Details here โ†’ https://thehackernews.com/2025/08/how-top-cisos-save-their-socs-from.html
๐Ÿ˜14๐Ÿ‘1
๐Ÿšจ A high-severity flaw in Cursor AI (CVE-2025-54136) let attackers hijack trusted MCP configsโ€”triggering remote code execution every time you opened the project.

No re-prompt. No warning. Just silent compromise by modifying a config file you already trusted.

Learn more โ†’ https://thehackernews.com/2025/08/cursor-ai-code-editor-vulnerability.html
๐Ÿ‘16๐Ÿ˜6๐Ÿ‘2
๐Ÿ”‘ 53% of orgs trust their SaaS vendors. But 70% of SaaS incidents come from misconfigs & bad permissionsโ€”your responsibility.

Worse? They leave no logs. No alerts. Just exposure.

Hereโ€™s why posture > detection: https://thehackernews.com/2025/08/misconfigurations-are-not.html
๐Ÿค”7โšก1
๐Ÿšจ Google just fixed 3 Android bugs hackers were already using.

One lets them hijack your phone through the graphics chip โ€” no clicks needed.

Spyware vendors may be behind it.

PATCH your phones now โ†’ https://thehackernews.com/2025/08/google-fixes-3-android-vulnerabilities.html
๐Ÿ˜23๐Ÿคฏ9๐Ÿ”ฅ5๐Ÿค”1
๐Ÿšจ CAPTCHAgeddon is here. A fake CAPTCHA scam called ClickFix hijacks devices with a single pasteโ€”no download, no file, just clipboard commands.

It's smarter than ClearFakeโ€”and spreading fast.

Hereโ€™s how it works โ†“ https://thehackernews.com/2025/08/clickfix-malware-campaign-exploits.html
๐Ÿ˜ฑ8๐Ÿ”ฅ3๐Ÿ‘2๐Ÿค”2๐Ÿ˜1
๐Ÿ‘€ Still pip installing and praying?

Supply chain attacks are everywhere in Python:
โ†’ YOLO package hacked
โ†’ Critical vulns in base images
โ†’ Malicious packages live on PyPI

๐Ÿ”ฅ Join the free webinar to secure your Python stack โ†’ https://thehacker.news/safeguarding-python-supply-chain
๐Ÿ‘10๐Ÿ”ฅ5๐Ÿ˜ฑ2๐Ÿ˜1
๐Ÿ”’ UPDATE: Akira ransomware now uses legit Windows drivers (rwdrv.sys, hlpdrv.sys) in a BYOVD attack to disable Defender and gain kernel accessโ€”even in hardened environments.

Tied to SonicWall SSL VPN zero-dayโ€”still under active investigation.

Read โ†’ https://thehackernews.com/2025/08/sonicwall-investigating-potential-ssl.html
๐Ÿ”ฅ21๐Ÿ˜3๐Ÿ˜ฑ2๐Ÿ‘1