๐จ๐จ New variant of XCSSET macOS malware spotted.
It can hijack crypto transactions by swapping wallet addresses, targets Firefox, and hides in shared Xcode projects with stronger persistence tricks.
Full details โ https://thehackernews.com/2025/09/new-macos-xcsset-variant-targets.html
It can hijack crypto transactions by swapping wallet addresses, targets Firefox, and hides in shared Xcode projects with stronger persistence tricks.
Full details โ https://thehackernews.com/2025/09/new-macos-xcsset-variant-targets.html
๐13๐ฅ3
๐จ Important: Hackers quietly exploited Fortra GoAnywhere MFT a full week before anyone knew.
CVE-2025-10035 (CVSS 10.0) gave them pre-auth RCE to slip in an โadmin-goโ backdoor and drop payloads.
Patch now: 7.8.4 / 7.6.3.
Full story โ https://thehackernews.com/2025/09/fortra-goanywhere-cvss-10-flaw.html
CVE-2025-10035 (CVSS 10.0) gave them pre-auth RCE to slip in an โadmin-goโ backdoor and drop payloads.
Patch now: 7.8.4 / 7.6.3.
Full story โ https://thehackernews.com/2025/09/fortra-goanywhere-cvss-10-flaw.html
๐7๐ฅ3
๐จ West Sussex man arrested over ransomware attack that crippled baggage & check-in systems at major European airports, including Heathrow.
Collins Aerospace confirms โHardBitโ ransomware caused hundreds of flight delays.
NCA probe ongoing โ https://thehackernews.com/2025/09/threatsday-bulletin-rootkit-patch.html#basic-ransomware-big-chaos
Collins Aerospace confirms โHardBitโ ransomware caused hundreds of flight delays.
NCA probe ongoing โ https://thehackernews.com/2025/09/threatsday-bulletin-rootkit-patch.html#basic-ransomware-big-chaos
๐ฅ18๐6
โก Blue Report 2025:
โข Data exfiltration stopped just 3% of the time
โข 54% of attacker moves left no logs
โข Only 14% triggered alerts
Dashboards donโt prove safetyโBAS is the crash test that shows if your defenses really hold.
Read โ https://thehackernews.com/2025/09/crash-tests-for-security-why-bas-is.html
โข Data exfiltration stopped just 3% of the time
โข 54% of attacker moves left no logs
โข Only 14% triggered alerts
Dashboards donโt prove safetyโBAS is the crash test that shows if your defenses really hold.
Read โ https://thehackernews.com/2025/09/crash-tests-for-security-why-bas-is.html
๐8๐4๐2
โ ๏ธ Two big cyber hits making waves:
๐ท๐บ COLDRIVER hackers are tricking people with fake CAPTCHAs to drop a stealthy PowerShell backdoor that steals files and hides its tracks.
๐ฅ At the same time, Bearlyfy ransomware is tearing through Russian companiesโ30+ victims so far, ransoms reaching โฌ80K.
Full story โ https://thehackernews.com/2025/09/new-coldriver-malware-campaign-joins-bo.html
๐ท๐บ COLDRIVER hackers are tricking people with fake CAPTCHAs to drop a stealthy PowerShell backdoor that steals files and hides its tracks.
๐ฅ At the same time, Bearlyfy ransomware is tearing through Russian companiesโ30+ victims so far, ransoms reaching โฌ80K.
Full story โ https://thehackernews.com/2025/09/new-coldriver-malware-campaign-joins-bo.html
๐14๐6๐3๐คฏ2๐ฑ1
๐จ Two fresh phishing campaigns, one big warning:
๐บ๐ฆ Hackers posing as Ukraineโs National Police use SVG attachments to launch a chain that steals passwords & mines crypto.
๐ป๐ณ Another crew lures victims with fake copyright notices, ending in PureRAT backdoors for full remote control.
Full story โ https://thehackernews.com/2025/09/researchers-expose-svg-and-purerat.html
๐บ๐ฆ Hackers posing as Ukraineโs National Police use SVG attachments to launch a chain that steals passwords & mines crypto.
๐ป๐ณ Another crew lures victims with fake copyright notices, ending in PureRAT backdoors for full remote control.
Full story โ https://thehackernews.com/2025/09/researchers-expose-svg-and-purerat.html
โก8๐5๐2
๐จ CISA: Hackers exploited GeoServer CVE-2024-36401 RCE to breach a U.S. federal agency on July 11, 2024โmoving laterally across servers and deploying China Chopper web shells & LotL tools.
Full advisory โ https://thehackernews.com/2025/09/threatsday-bulletin-rootkit-patch.html#geoserver-hole-exploited
Full advisory โ https://thehackernews.com/2025/09/threatsday-bulletin-rootkit-patch.html#geoserver-hole-exploited
๐14๐ค4๐ฅ2๐1
๐จ China-linked cyber groups are upgrading their weapons:
โข PlugX: hides in the Mobile Popup app, decrypts payloads in memory with XOR-RC4-RtlDecompressBuffer, packs a keylogger.
โข Bookworm: slips shellcode in UUID strings to dodge detection.
Full story โ https://thehackernews.com/2025/09/china-linked-plugx-and-bookworm-malware.html
โข PlugX: hides in the Mobile Popup app, decrypts payloads in memory with XOR-RC4-RtlDecompressBuffer, packs a keylogger.
โข Bookworm: slips shellcode in UUID strings to dodge detection.
Full story โ https://thehackernews.com/2025/09/china-linked-plugx-and-bookworm-malware.html
๐ฅ23๐คฏ6๐ค2๐ฑ2๐1
๐จ First real-world MCP server backdoor spotted!
A fake npm package postmark-mcp silently BCCโd every email to an attackerโover 1,600 downloads before removal.
โ ๏ธ One line of code. Thousands of stolen emails.
Read now โ https://thehackernews.com/2025/09/first-malicious-mcp-server-found.html
A fake npm package postmark-mcp silently BCCโd every email to an attackerโover 1,600 downloads before removal.
โ ๏ธ One line of code. Thousands of stolen emails.
Read now โ https://thehackernews.com/2025/09/first-malicious-mcp-server-found.html
๐11๐3๐1๐ฅ1๐ค1
๐จ Microsoft warns โ Hackers used LLM-generated code to hide malware in an SVG file disguised as a business dashboard, bypassing defenses with self-addressed emails + invisible scripts.
Details โ https://thehackernews.com/2025/09/microsoft-flags-ai-driven-phishing-llm.html
Details โ https://thehackernews.com/2025/09/microsoft-flags-ai-driven-phishing-llm.html
๐19๐คฏ5๐1๐ฅ1
๐ต๏ธโโ๏ธ Missed the action? Hackers didnโt restโneither should you.
See the key security stories you might have missed.
Check full recap โ https://thehackernews.com/2025/09/weekly-recap-cisco-0-day-record-ddos.html
See the key security stories you might have missed.
Check full recap โ https://thehackernews.com/2025/09/weekly-recap-cisco-0-day-record-ddos.html
๐11๐1
๐จ SOCs are drowning: 40% of security alerts go uninvestigated, and 61% of the ones ignored later turn out to be critical.
Teams face 3,000+ daily alerts and 70-minute investigationsโfar slower than the 48 minutes attackers need to compromise.
Read โ https://thehackernews.com/2025/09/the-state-of-ai-in-soc-2025-insights.html
Teams face 3,000+ daily alerts and 70-minute investigationsโfar slower than the 48 minutes attackers need to compromise.
Read โ https://thehackernews.com/2025/09/the-state-of-ai-in-soc-2025-insights.html
๐ฅ16๐1
๐จ EvilAI is live and global: Malware hidden inside โlegitโ AI & productivity apps is quietly invading manufacturing, healthcare, gov & tech across ๐ฎ๐ณ ๐บ๐ธ ๐ซ๐ท ๐ง๐ท and more.
๐ต๏ธโโ๏ธ Uses real code-signing certs, AES-encrypted C2, even NeutralinoJS tricks to slip past detection.
Read โ https://thehackernews.com/2025/09/evilai-malware-masquerades-as-ai-tools.html
๐ต๏ธโโ๏ธ Uses real code-signing certs, AES-encrypted C2, even NeutralinoJS tricks to slip past detection.
Read โ https://thehackernews.com/2025/09/evilai-malware-masquerades-as-ai-tools.html
๐17๐6โก1๐1๐ฅ1
๐จ Linux/Unix alert: CISA just flagged a critical Sudo flaw (CVE-2025-32463, CVSS 9.3) now exploited in the wild.
Attackers can hijack sudoโs --chroot option to run arbitrary commands as rootโeven if not in sudoers.
Details โ https://thehackernews.com/2025/09/cisa-sounds-alarm-on-critical-sudo-flaw.html
Attackers can hijack sudoโs --chroot option to run arbitrary commands as rootโeven if not in sudoers.
Details โ https://thehackernews.com/2025/09/cisa-sounds-alarm-on-critical-sudo-flaw.html
๐16๐คฏ12๐2๐ฑ2
๐จ U.K. police just seized ยฃ5.5B ($7.4B) in cryptoโthe largest Bitcoin confiscation in history.
A Chinese fraudster duped 128,000 victims, laundered funds into 61,000 BTC, and tried to hide in London with fake IDs.
The twist? She was caught buying property.
Full story โ https://thehackernews.com/2025/09/uk-police-just-seized-55-billion-in.html
A Chinese fraudster duped 128,000 victims, laundered funds into 61,000 BTC, and tried to hide in London with fake IDs.
The twist? She was caught buying property.
Full story โ https://thehackernews.com/2025/09/uk-police-just-seized-55-billion-in.html
๐คฏ16๐5๐ฅ4๐4
๐จ Shadow AI is exploding inside enterprises. Employees are adopting LLM-powered apps without oversightโcreating blind spots, supply chain risks, and data leaks.
Wing Security says traditional defenses canโt keep up. The fix? Real-time discovery + AI supply chain governance.
Read โ https://thehackernews.com/2025/09/evolving-enterprise-defense-to-secure.html
Wing Security says traditional defenses canโt keep up. The fix? Real-time discovery + AI supply chain governance.
Read โ https://thehackernews.com/2025/09/evolving-enterprise-defense-to-secure.html
๐ฅ7๐1
๐จ A new Android banking trojan is here: Datzbro.
It doesnโt just steal loginsโit recreates your screen in real time for full device takeover.
Victims? Seniors lured via fake โactive tripโ groups on Facebook.
Details โ https://thehackernews.com/2025/09/new-android-trojan-datzbro-tricking.html
It doesnโt just steal loginsโit recreates your screen in real time for full device takeover.
Victims? Seniors lured via fake โactive tripโ groups on Facebook.
Details โ https://thehackernews.com/2025/09/new-android-trojan-datzbro-tricking.html
๐ฑ12๐ฅ6๐1๐คฏ1
๐ฅ [New] VMware zero-day (CVE-2025-41244) exploited in the wild!
UNC5174 popped root by abusing a regex bug in get_version() โ drop /tmp/httpd, open a socket, and youโre root.
Already active since Oct โ24.
Details โ https://thehackernews.com/2025/09/urgent-china-linked-hackers-exploit-new.html
UNC5174 popped root by abusing a regex bug in get_version() โ drop /tmp/httpd, open a socket, and youโre root.
Already active since Oct โ24.
Details โ https://thehackernews.com/2025/09/urgent-china-linked-hackers-exploit-new.html
๐ฅ25๐1
๐ AI wonโt fix your workflowsโit might break them.
Learn how top teams actually blend humans + LLMs without over-engineering.
Secure, auditable, scalable.
๐ Join the webinar โ https://thehacker.news/ai-automating-cybersecurity
Learn how top teams actually blend humans + LLMs without over-engineering.
Secure, auditable, scalable.
๐ Join the webinar โ https://thehacker.news/ai-automating-cybersecurity
๐5
๐จ Microsoft just made Sentinel an agentic SIEM.
Now GA: Sentinel data lake + preview of Graph & MCP server.
AI agents can retro-hunt, trace attack paths & plug into VS Code. From reactive to predictive defense.
Details โ https://thehackernews.com/2025/09/microsoft-expands-sentinel-into-agentic.html
Now GA: Sentinel data lake + preview of Graph & MCP server.
AI agents can retro-hunt, trace attack paths & plug into VS Code. From reactive to predictive defense.
Details โ https://thehackernews.com/2025/09/microsoft-expands-sentinel-into-agentic.html
๐คฏ9