๐จ WARNING: Dutch cyber watchdog confirms: a Citrix zero-day (CVE-2025-6543) was exploited for months before disclosureโhitting critical orgs, leaving hidden web shells, and erasing traces.
Patches are out. If you run NetScaler, act now.
Full story โ https://thehackernews.com/2025/08/dutch-ncsc-confirms-active-exploitation.html
Patches are out. If you run NetScaler, act now.
Full story โ https://thehackernews.com/2025/08/dutch-ncsc-confirms-active-exploitation.html
๐ค7๐4๐ฑ2๐1๐1
New research by Pentera builds on Wizโs IngressNightmare and reveals critical injection vulnerabilities in the widely used ingress-nginx Kubernetes controller.
Penteraโs team uncovered additional attack vectors that exploit common configuration oversights - going beyond the four originally disclosed CVEs. These newly discovered injection points can allow attackers to bypass security controls, execute arbitrary code, and pivot deeper into Kubernetes clusters.
๐ Join experts live on August 20 at 11:00 AM ET for a technical deep dive into the full scope of these vulnerabilities and their real-world impact: https://thn.news/IngressNightmare-webinar
Read the full research report ๐ https://thn.news/cyberattacks-explained
Penteraโs team uncovered additional attack vectors that exploit common configuration oversights - going beyond the four originally disclosed CVEs. These newly discovered injection points can allow attackers to bypass security controls, execute arbitrary code, and pivot deeper into Kubernetes clusters.
๐ Join experts live on August 20 at 11:00 AM ET for a technical deep dive into the full scope of these vulnerabilities and their real-world impact: https://thn.news/IngressNightmare-webinar
Read the full research report ๐ https://thn.news/cyberattacks-explained
๐7๐2๐ค1
๐ท๐บ New Threat: Curly COMrades hacked govt & energy networks in Georgia & Moldova โ stealing credentials & hiding for months.
Their secret weapon? Hijacking Windowsโ own components to run commands as SYSTEMโฆ and no one notices.
Find details here โ https://thehackernews.com/2025/08/new-curly-comrades-apt-using-ngen-com.html
Their secret weapon? Hijacking Windowsโ own components to run commands as SYSTEMโฆ and no one notices.
Find details here โ https://thehackernews.com/2025/08/new-curly-comrades-apt-using-ngen-com.html
๐คฏ11๐2๐ฅ1๐1
Identity attacks are evolving, but are your IR playbooks keeping up? Join Push Security's Josh Gideon on August 13th & 14th as he dives into the new challenges facing incident responders in the cloud. Don't miss out on a step-by-step walkthrough of how security teams are using browser telemetry to supercharge their security investigations.
Register here: https://thn.news/identity-attacks-webinar-tg
Register here: https://thn.news/identity-attacks-webinar-tg
๐7
๐จ Your browser is now your biggest insider threat.
๐ค GenAI prompts
โ ๏ธ Risky extensions
๐ป Unmanaged devices
All leaking data in-session.
๐ฅ Enterprise Browser vs. Secure Extension โ 9 brutal rounds.
Who wins? โ https://thehackernews.com/2025/08/the-ultimate-battle-enterprise-browsers.html
๐ค GenAI prompts
โ ๏ธ Risky extensions
๐ป Unmanaged devices
All leaking data in-session.
๐ฅ Enterprise Browser vs. Secure Extension โ 9 brutal rounds.
Who wins? โ https://thehackernews.com/2025/08/the-ultimate-battle-enterprise-browsers.html
๐ค14๐4๐2
โ ๏ธ Two of the most dangerous hacker groups โ ShinyHunters & Scattered Spider โ are joining forces.
Theyโve hit Salesforce users worldwide, and signs show their next big target: banks & financial firms.
Hereโs why this alliance is bad news โ https://thehackernews.com/2025/08/cybercrime-groups-shinyhunters.html
Theyโve hit Salesforce users worldwide, and signs show their next big target: banks & financial firms.
Hereโs why this alliance is bad news โ https://thehackernews.com/2025/08/cybercrime-groups-shinyhunters.html
๐12๐คฏ7๐ค4๐2๐1
๐จ 780+ malicious IPs just launched a coordinated brute-force attack on Fortinet SSL VPNs โ shifting mid-campaign to hit FortiManager.
Researchers warn this pattern often precedes a new CVE disclosure within weeks.
Read โ https://thehackernews.com/2025/08/fortinet-ssl-vpns-hit-by-global-brute.html
Researchers warn this pattern often precedes a new CVE disclosure within weeks.
Read โ https://thehackernews.com/2025/08/fortinet-ssl-vpns-hit-by-global-brute.html
๐15๐ค6โก4๐ฅ1
๐จ Over a year after the XZ Utils backdoor was exposed, 35 infected Docker images are still live on Docker Hub โ some built on top of each other, quietly spreading the malware.
They can let attackers bypass SSH auth & run root commands.
Full story โ https://thehackernews.com/2025/08/researchers-spot-xz-utils-backdoor-in.html
They can let attackers bypass SSH auth & run root commands.
Full story โ https://thehackernews.com/2025/08/researchers-spot-xz-utils-backdoor-in.html
๐ฑ11๐9๐คฏ5๐ฅ2โก1๐ค1
๐จ New RANSOMWARE ALERT: โCharonโ is hitting Middle East gov & aviation targetsโusing nation-state-level tactics to dodge defenses & lock files fast.
It mimics a China-linked APT, sideloads malicious DLLs, and even packs a driver to kill EDR (likely still in testing).
Read โ https://thehackernews.com/2025/08/charon-ransomware-hits-middle-east.html
It mimics a China-linked APT, sideloads malicious DLLs, and even packs a driver to kill EDR (likely still in testing).
Read โ https://thehackernews.com/2025/08/charon-ransomware-hits-middle-east.html
โก10๐2๐ฅ1๐ค1
โก Microsoft patched 111 flaws โ including a zero-day in Windows Kerberos that could let attackers seize entire Active Directory domains.
Some bugs score 10/10 severity. Others hit Azure OpenAI, Microsoft 365 Copilot, & Edge.
Read: https://thehackernews.com/2025/08/microsoft-august-2025-patch-tuesday.html
Some bugs score 10/10 severity. Others hit Azure OpenAI, Microsoft 365 Copilot, & Edge.
Read: https://thehackernews.com/2025/08/microsoft-august-2025-patch-tuesday.html
๐17โก5๐3๐ฅ1๐1
Your Salesforce scans arenโt telling you everything.
Automated tools show whatโs already there.
Only human-led penetration testing shows what could happen โ uncovering hidden attack paths your scanners miss.
Hereโs why most teams remain exposed โ https://thehackernews.com/expert-insights/2025/08/the-second-layer-of-salesforce-security.html
Automated tools show whatโs already there.
Only human-led penetration testing shows what could happen โ uncovering hidden attack paths your scanners miss.
Hereโs why most teams remain exposed โ https://thehackernews.com/expert-insights/2025/08/the-second-layer-of-salesforce-security.html
๐ฅ6๐ค2
๐ Hackers are now using AI to deepfake your CFOโs voice, create perfect fake identities, and break into systems at machine speed.
The frontline isnโt your ๐ก๏ธ firewall anymore. Itโs your login screen.
โก Join this free WEBINAR to see how to protect your business before itโs too late โ https://thehackernews.com/2025/08/webinar-what-next-wave-of-ai.html
The frontline isnโt your ๐ก๏ธ firewall anymore. Itโs your login screen.
โก Join this free WEBINAR to see how to protect your business before itโs too late โ https://thehackernews.com/2025/08/webinar-what-next-wave-of-ai.html
๐7๐6
๐จ Active Exploit Alert โ A critical FortiSIEM flaw (CVSS 9.8) lets attackers run code without logging in โ and hackers are already using it.
No clear signs if youโve been hit. Update now or risk silent compromise.
Full details โ https://thehackernews.com/2025/08/fortinet-warns-about-fortisiem.html
No clear signs if youโve been hit. Update now or risk silent compromise.
Full details โ https://thehackernews.com/2025/08/fortinet-warns-about-fortisiem.html
๐13โก4๐2
Advance your skills in strategic security design with Georgetownโs Online Certificate in Cybersecurity Strategy.
Learn more โ https://thn.news/cybersecurity-strategy-gt-ig
Learn more โ https://thn.news/cybersecurity-strategy-gt-ig
โก5
๐จ Critical flaws just hit Zoom & Xerox.
One lets attackers hijack Windows Zoom clients (CVSS 9.6).
Another in Xerox FreeFlow Core (CVSS 9.8) could give full remote controlโeasy to exploit.
PATCH NOW / Details โ https://thehackernews.com/2025/08/zoom-and-xerox-release-critical.html
One lets attackers hijack Windows Zoom clients (CVSS 9.6).
Another in Xerox FreeFlow Core (CVSS 9.8) could give full remote controlโeasy to exploit.
PATCH NOW / Details โ https://thehackernews.com/2025/08/zoom-and-xerox-release-critical.html
๐คฏ10๐4โก2
๐ค AI is taking over the SOC grind.
Gartner just named AI SOC agents the next big thingโslashing false positives, spotting gaps, and investigating threats in minutes.
But when it comes to the toughest calls? Humans still decide.
โก Read how itโs changing security โ https://thehackernews.com/2025/08/ai-soc-101-key-capabilities-security.html
Gartner just named AI SOC agents the next big thingโslashing false positives, spotting gaps, and investigating threats in minutes.
But when it comes to the toughest calls? Humans still decide.
โก Read how itโs changing security โ https://thehackernews.com/2025/08/ai-soc-101-key-capabilities-security.html
๐8๐ฅ3
New Malware Alert: A stealthy threat called PS1Bot is hiding in online adsโstealing passwords, crypto wallets, and screenshotsโwhile leaving almost no trace.
Itโs already active worldwide.
Hereโs how it works (and how to spot it) โ https://thehackernews.com/2025/08/new-ps1bot-malware-campaign-uses.html
Itโs already active worldwide.
Hereโs how it works (and how to spot it) โ https://thehackernews.com/2025/08/new-ps1bot-malware-campaign-uses.html
๐ฅ13๐4โก1
๐จ CISA warns: Hackers are actively exploiting 2 new flaws in N-ableโs N-central โ the RMM tool used by countless MSPs to control client systems.
Both bugs allow command execution if exploited. Patch by Aug 20 or risk takeover.
Full story โ https://thehackernews.com/2025/08/cisa-adds-two-n-able-n-central-flaws-to.html
Both bugs allow command execution if exploited. Patch by Aug 20 or risk takeover.
Full story โ https://thehackernews.com/2025/08/cisa-adds-two-n-able-n-central-flaws-to.html
๐ฅ9๐ค1
Google now requires crypto app developers in the US, UK, EU & 12 more regions to get official licenses before hitting Play Store.
Non-compliance? Apps pulled.
Learn more about this crackdown โ https://thehackernews.com/2025/08/google-requires-crypto-app-licenses-in.html
Non-compliance? Apps pulled.
Learn more about this crackdown โ https://thehackernews.com/2025/08/google-requires-crypto-app-licenses-in.html
๐ฅ20๐ค4โก3๐2๐ฑ2๐1
๐ Your bank card. Your calls. Your phone โ all in a cybercriminals' hands.
๐ณ PhantomCard โ NFC trojan that clones your bank card & spends like itโs theirs.
๐ SpyBanker โ Steals banking data & hijacks calls in India.
โ๏ธ KernelSU exploits โ Full control of rooted Android devices.
How they work & how to stop them โ https://thehackernews.com/2025/08/new-android-malware-wave-hits-banking.html
๐ณ PhantomCard โ NFC trojan that clones your bank card & spends like itโs theirs.
๐ SpyBanker โ Steals banking data & hijacks calls in India.
โ๏ธ KernelSU exploits โ Full control of rooted Android devices.
How they work & how to stop them โ https://thehackernews.com/2025/08/new-android-malware-wave-hits-banking.html
๐ฅ22