The Hacker News
โœ”
151K subscribers
1.85K photos
10 videos
3 files
7.77K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: [email protected]

๐ŸŒ Website: https://thehackernews.com
Download Telegram
๐Ÿšจ WARNING: Dutch cyber watchdog confirms: a Citrix zero-day (CVE-2025-6543) was exploited for months before disclosureโ€”hitting critical orgs, leaving hidden web shells, and erasing traces.

Patches are out. If you run NetScaler, act now.

Full story โ†’ https://thehackernews.com/2025/08/dutch-ncsc-confirms-active-exploitation.html
๐Ÿค”7๐Ÿ‘4๐Ÿ˜ฑ2๐Ÿ‘1๐Ÿ˜1
New research by Pentera builds on Wizโ€™s IngressNightmare and reveals critical injection vulnerabilities in the widely used ingress-nginx Kubernetes controller.

Penteraโ€™s team uncovered additional attack vectors that exploit common configuration oversights - going beyond the four originally disclosed CVEs. These newly discovered injection points can allow attackers to bypass security controls, execute arbitrary code, and pivot deeper into Kubernetes clusters.

๐Ÿ‘‰ Join experts live on August 20 at 11:00 AM ET for a technical deep dive into the full scope of these vulnerabilities and their real-world impact: https://thn.news/IngressNightmare-webinar

Read the full research report ๐Ÿ‘‰ https://thn.news/cyberattacks-explained
๐Ÿ‘7๐Ÿ‘2๐Ÿค”1
๐Ÿ‡ท๐Ÿ‡บ New Threat: Curly COMrades hacked govt & energy networks in Georgia & Moldova โ€” stealing credentials & hiding for months.

Their secret weapon? Hijacking Windowsโ€™ own components to run commands as SYSTEMโ€ฆ and no one notices.

Find details here โ†’ https://thehackernews.com/2025/08/new-curly-comrades-apt-using-ngen-com.html
๐Ÿคฏ11๐Ÿ˜2๐Ÿ”ฅ1๐Ÿ‘1
Identity attacks are evolving, but are your IR playbooks keeping up? Join Push Security's Josh Gideon on August 13th & 14th as he dives into the new challenges facing incident responders in the cloud. Don't miss out on a step-by-step walkthrough of how security teams are using browser telemetry to supercharge their security investigations.

Register here: https://thn.news/identity-attacks-webinar-tg
๐Ÿ‘7
๐Ÿšจ Your browser is now your biggest insider threat.

๐Ÿค– GenAI prompts
โš ๏ธ Risky extensions
๐Ÿ’ป Unmanaged devices

All leaking data in-session.

๐ŸฅŠ Enterprise Browser vs. Secure Extension โ€” 9 brutal rounds.

Who wins? โ†’ https://thehackernews.com/2025/08/the-ultimate-battle-enterprise-browsers.html
๐Ÿค”14๐Ÿ‘4๐Ÿ‘2
โš ๏ธ Two of the most dangerous hacker groups โ€” ShinyHunters & Scattered Spider โ€” are joining forces.

Theyโ€™ve hit Salesforce users worldwide, and signs show their next big target: banks & financial firms.

Hereโ€™s why this alliance is bad news โ†“ https://thehackernews.com/2025/08/cybercrime-groups-shinyhunters.html
๐Ÿ˜12๐Ÿคฏ7๐Ÿค”4๐Ÿ‘2๐Ÿ‘1
๐Ÿšจ 780+ malicious IPs just launched a coordinated brute-force attack on Fortinet SSL VPNs โ€” shifting mid-campaign to hit FortiManager.

Researchers warn this pattern often precedes a new CVE disclosure within weeks.

Read โ†’ https://thehackernews.com/2025/08/fortinet-ssl-vpns-hit-by-global-brute.html
๐Ÿ˜15๐Ÿค”6โšก4๐Ÿ”ฅ1
๐Ÿšจ Over a year after the XZ Utils backdoor was exposed, 35 infected Docker images are still live on Docker Hub โ€” some built on top of each other, quietly spreading the malware.

They can let attackers bypass SSH auth & run root commands.

Full story โ†’ https://thehackernews.com/2025/08/researchers-spot-xz-utils-backdoor-in.html
๐Ÿ˜ฑ11๐Ÿ˜9๐Ÿคฏ5๐Ÿ”ฅ2โšก1๐Ÿค”1
๐Ÿšจ New RANSOMWARE ALERT: โ€œCharonโ€ is hitting Middle East gov & aviation targetsโ€”using nation-state-level tactics to dodge defenses & lock files fast.

It mimics a China-linked APT, sideloads malicious DLLs, and even packs a driver to kill EDR (likely still in testing).

Read โ†’ https://thehackernews.com/2025/08/charon-ransomware-hits-middle-east.html
โšก10๐Ÿ‘2๐Ÿ”ฅ1๐Ÿค”1
โšก Microsoft patched 111 flaws โ€” including a zero-day in Windows Kerberos that could let attackers seize entire Active Directory domains.

Some bugs score 10/10 severity. Others hit Azure OpenAI, Microsoft 365 Copilot, & Edge.

Read: https://thehackernews.com/2025/08/microsoft-august-2025-patch-tuesday.html
๐Ÿ‘17โšก5๐Ÿ‘3๐Ÿ”ฅ1๐Ÿ˜1
Your Salesforce scans arenโ€™t telling you everything.

Automated tools show whatโ€™s already there.

Only human-led penetration testing shows what could happen โ€” uncovering hidden attack paths your scanners miss.

Hereโ€™s why most teams remain exposed โ†’ https://thehackernews.com/expert-insights/2025/08/the-second-layer-of-salesforce-security.html
๐Ÿ”ฅ6๐Ÿค”2
๐Ÿ›‘ Hackers are now using AI to deepfake your CFOโ€™s voice, create perfect fake identities, and break into systems at machine speed.

The frontline isnโ€™t your ๐Ÿ›ก๏ธ firewall anymore. Itโ€™s your login screen.

โšก Join this free WEBINAR to see how to protect your business before itโ€™s too late โ†’ https://thehackernews.com/2025/08/webinar-what-next-wave-of-ai.html
๐Ÿ‘7๐Ÿ˜6
๐Ÿšจ Active Exploit Alert โ†’ A critical FortiSIEM flaw (CVSS 9.8) lets attackers run code without logging in โ€” and hackers are already using it.

No clear signs if youโ€™ve been hit. Update now or risk silent compromise.

Full details โ†’ https://thehackernews.com/2025/08/fortinet-warns-about-fortisiem.html
๐Ÿ‘13โšก4๐Ÿ˜2
Advance your skills in strategic security design with Georgetownโ€™s Online Certificate in Cybersecurity Strategy.

Learn more โ†’ https://thn.news/cybersecurity-strategy-gt-ig
โšก5
๐Ÿšจ Critical flaws just hit Zoom & Xerox.

One lets attackers hijack Windows Zoom clients (CVSS 9.6).

Another in Xerox FreeFlow Core (CVSS 9.8) could give full remote controlโ€”easy to exploit.

PATCH NOW / Details โ†’ https://thehackernews.com/2025/08/zoom-and-xerox-release-critical.html
๐Ÿคฏ10๐Ÿ˜4โšก2
๐Ÿค– AI is taking over the SOC grind.

Gartner just named AI SOC agents the next big thingโ€”slashing false positives, spotting gaps, and investigating threats in minutes.

But when it comes to the toughest calls? Humans still decide.

โšก Read how itโ€™s changing security โ†’ https://thehackernews.com/2025/08/ai-soc-101-key-capabilities-security.html
๐Ÿ‘8๐Ÿ”ฅ3
New Malware Alert: A stealthy threat called PS1Bot is hiding in online adsโ€”stealing passwords, crypto wallets, and screenshotsโ€”while leaving almost no trace.

Itโ€™s already active worldwide.

Hereโ€™s how it works (and how to spot it) โ†’ https://thehackernews.com/2025/08/new-ps1bot-malware-campaign-uses.html
๐Ÿ”ฅ13๐Ÿ‘4โšก1
๐Ÿšจ CISA warns: Hackers are actively exploiting 2 new flaws in N-ableโ€™s N-central โ€” the RMM tool used by countless MSPs to control client systems.

Both bugs allow command execution if exploited. Patch by Aug 20 or risk takeover.

Full story โ†’ https://thehackernews.com/2025/08/cisa-adds-two-n-able-n-central-flaws-to.html
๐Ÿ”ฅ9๐Ÿค”1
Google now requires crypto app developers in the US, UK, EU & 12 more regions to get official licenses before hitting Play Store.

Non-compliance? Apps pulled.

Learn more about this crackdown โ†’ https://thehackernews.com/2025/08/google-requires-crypto-app-licenses-in.html
๐Ÿ”ฅ20๐Ÿค”4โšก3๐Ÿ‘2๐Ÿ˜ฑ2๐Ÿ‘1
๐Ÿ›‘ Your bank card. Your calls. Your phone โ€” all in a cybercriminals' hands.

๐Ÿ’ณ PhantomCard โ€“ NFC trojan that clones your bank card & spends like itโ€™s theirs.
๐Ÿ“ž SpyBanker โ€“ Steals banking data & hijacks calls in India.
โš™๏ธ KernelSU exploits โ€“ Full control of rooted Android devices.

How they work & how to stop them โ†’ https://thehackernews.com/2025/08/new-android-malware-wave-hits-banking.html
๐Ÿ”ฅ22