The Hacker News
โœ”
152K subscribers
1.88K photos
10 videos
3 files
7.79K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: [email protected]

๐ŸŒ Website: https://thehackernews.com
Download Telegram
๐Ÿšจ๐Ÿšจ New variant of XCSSET macOS malware spotted.

It can hijack crypto transactions by swapping wallet addresses, targets Firefox, and hides in shared Xcode projects with stronger persistence tricks.

Full details โ†’ https://thehackernews.com/2025/09/new-macos-xcsset-variant-targets.html
๐Ÿ‘13๐Ÿ”ฅ3
๐Ÿšจ Important: Hackers quietly exploited Fortra GoAnywhere MFT a full week before anyone knew.

CVE-2025-10035 (CVSS 10.0) gave them pre-auth RCE to slip in an โ€œadmin-goโ€ backdoor and drop payloads.

Patch now: 7.8.4 / 7.6.3.

Full story โ†’ https://thehackernews.com/2025/09/fortra-goanywhere-cvss-10-flaw.html
๐Ÿ‘7๐Ÿ”ฅ3
๐Ÿšจ West Sussex man arrested over ransomware attack that crippled baggage & check-in systems at major European airports, including Heathrow.

Collins Aerospace confirms โ€œHardBitโ€ ransomware caused hundreds of flight delays.

NCA probe ongoing โ†’ https://thehackernews.com/2025/09/threatsday-bulletin-rootkit-patch.html#basic-ransomware-big-chaos
๐Ÿ”ฅ18๐Ÿ˜6
โšก Blue Report 2025:

โ€ข Data exfiltration stopped just 3% of the time
โ€ข 54% of attacker moves left no logs
โ€ข Only 14% triggered alerts

Dashboards donโ€™t prove safetyโ€”BAS is the crash test that shows if your defenses really hold.

Read โ†’ https://thehackernews.com/2025/09/crash-tests-for-security-why-bas-is.html
๐Ÿ‘8๐Ÿ˜4๐Ÿ‘2
โš ๏ธ Two big cyber hits making waves:

๐Ÿ‡ท๐Ÿ‡บ COLDRIVER hackers are tricking people with fake CAPTCHAs to drop a stealthy PowerShell backdoor that steals files and hides its tracks.

๐Ÿ’ฅ At the same time, Bearlyfy ransomware is tearing through Russian companiesโ€”30+ victims so far, ransoms reaching โ‚ฌ80K.

Full story โ†’ https://thehackernews.com/2025/09/new-coldriver-malware-campaign-joins-bo.html
๐Ÿ‘14๐Ÿ˜6๐Ÿ‘3๐Ÿคฏ2๐Ÿ˜ฑ1
๐Ÿšจ Two fresh phishing campaigns, one big warning:

๐Ÿ‡บ๐Ÿ‡ฆ Hackers posing as Ukraineโ€™s National Police use SVG attachments to launch a chain that steals passwords & mines crypto.

๐Ÿ‡ป๐Ÿ‡ณ Another crew lures victims with fake copyright notices, ending in PureRAT backdoors for full remote control.

Full story โ†’ https://thehackernews.com/2025/09/researchers-expose-svg-and-purerat.html
โšก8๐Ÿ‘5๐Ÿ˜2
๐Ÿšจ CISA: Hackers exploited GeoServer CVE-2024-36401 RCE to breach a U.S. federal agency on July 11, 2024โ€”moving laterally across servers and deploying China Chopper web shells & LotL tools.

Full advisory โ†’ https://thehackernews.com/2025/09/threatsday-bulletin-rootkit-patch.html#geoserver-hole-exploited
๐Ÿ‘14๐Ÿค”4๐Ÿ”ฅ2๐Ÿ‘1
๐Ÿšจ China-linked cyber groups are upgrading their weapons:

โ€ข PlugX: hides in the Mobile Popup app, decrypts payloads in memory with XOR-RC4-RtlDecompressBuffer, packs a keylogger.

โ€ข Bookworm: slips shellcode in UUID strings to dodge detection.

Full story โ†’ https://thehackernews.com/2025/09/china-linked-plugx-and-bookworm-malware.html
๐Ÿ”ฅ23๐Ÿคฏ6๐Ÿค”2๐Ÿ˜ฑ2๐Ÿ‘1
๐Ÿšจ First real-world MCP server backdoor spotted!

A fake npm package postmark-mcp silently BCCโ€™d every email to an attackerโ€”over 1,600 downloads before removal.

โš ๏ธ One line of code. Thousands of stolen emails.

Read now โ†’ https://thehackernews.com/2025/09/first-malicious-mcp-server-found.html
๐Ÿ‘11๐Ÿ˜3๐Ÿ‘1๐Ÿ”ฅ1๐Ÿค”1
๐Ÿšจ Microsoft warns โ€” Hackers used LLM-generated code to hide malware in an SVG file disguised as a business dashboard, bypassing defenses with self-addressed emails + invisible scripts.

Details โ†’ https://thehackernews.com/2025/09/microsoft-flags-ai-driven-phishing-llm.html
๐Ÿ˜19๐Ÿคฏ5๐Ÿ‘1๐Ÿ”ฅ1
๐Ÿ•ต๏ธโ€โ™€๏ธ Missed the action? Hackers didnโ€™t restโ€”neither should you.

See the key security stories you might have missed.

Check full recap โ†’ https://thehackernews.com/2025/09/weekly-recap-cisco-0-day-record-ddos.html
๐Ÿ‘11๐Ÿ‘1
๐Ÿšจ SOCs are drowning: 40% of security alerts go uninvestigated, and 61% of the ones ignored later turn out to be critical.

Teams face 3,000+ daily alerts and 70-minute investigationsโ€”far slower than the 48 minutes attackers need to compromise.

Read โ†’ https://thehackernews.com/2025/09/the-state-of-ai-in-soc-2025-insights.html
๐Ÿ”ฅ16๐Ÿ‘1
๐Ÿšจ EvilAI is live and global: Malware hidden inside โ€œlegitโ€ AI & productivity apps is quietly invading manufacturing, healthcare, gov & tech across ๐Ÿ‡ฎ๐Ÿ‡ณ ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿ‡ซ๐Ÿ‡ท ๐Ÿ‡ง๐Ÿ‡ท and more.

๐Ÿ•ต๏ธโ€โ™‚๏ธ Uses real code-signing certs, AES-encrypted C2, even NeutralinoJS tricks to slip past detection.

Read โ†’ https://thehackernews.com/2025/09/evilai-malware-masquerades-as-ai-tools.html
๐Ÿ‘17๐Ÿ˜6โšก1๐Ÿ‘1๐Ÿ”ฅ1
๐Ÿšจ Linux/Unix alert: CISA just flagged a critical Sudo flaw (CVE-2025-32463, CVSS 9.3) now exploited in the wild.

Attackers can hijack sudoโ€™s --chroot option to run arbitrary commands as rootโ€”even if not in sudoers.

Details โ†’ https://thehackernews.com/2025/09/cisa-sounds-alarm-on-critical-sudo-flaw.html
๐Ÿ‘16๐Ÿคฏ12๐Ÿ‘2๐Ÿ˜ฑ2
๐Ÿšจ U.K. police just seized ยฃ5.5B ($7.4B) in cryptoโ€”the largest Bitcoin confiscation in history.

A Chinese fraudster duped 128,000 victims, laundered funds into 61,000 BTC, and tried to hide in London with fake IDs.

The twist? She was caught buying property.

Full story โ†’ https://thehackernews.com/2025/09/uk-police-just-seized-55-billion-in.html
๐Ÿคฏ16๐Ÿ‘5๐Ÿ”ฅ4๐Ÿ˜4
๐Ÿšจ Shadow AI is exploding inside enterprises. Employees are adopting LLM-powered apps without oversightโ€”creating blind spots, supply chain risks, and data leaks.

Wing Security says traditional defenses canโ€™t keep up. The fix? Real-time discovery + AI supply chain governance.

Read โ†’ https://thehackernews.com/2025/09/evolving-enterprise-defense-to-secure.html
๐Ÿ”ฅ7๐Ÿ‘1
๐Ÿšจ A new Android banking trojan is here: Datzbro.

It doesnโ€™t just steal loginsโ€”it recreates your screen in real time for full device takeover.

Victims? Seniors lured via fake โ€œactive tripโ€ groups on Facebook.

Details โ†’ https://thehackernews.com/2025/09/new-android-trojan-datzbro-tricking.html
๐Ÿ˜ฑ12๐Ÿ”ฅ6๐Ÿ‘1๐Ÿคฏ1
๐Ÿ”ฅ [New] VMware zero-day (CVE-2025-41244) exploited in the wild!

UNC5174 popped root by abusing a regex bug in get_version() โ€” drop /tmp/httpd, open a socket, and youโ€™re root.

Already active since Oct โ€™24.

Details โ†’ https://thehackernews.com/2025/09/urgent-china-linked-hackers-exploit-new.html
๐Ÿ”ฅ25๐Ÿ‘1
๐Ÿ›  AI wonโ€™t fix your workflowsโ€”it might break them.

Learn how top teams actually blend humans + LLMs without over-engineering.

Secure, auditable, scalable.

๐Ÿ“… Join the webinar โ†’ https://thehacker.news/ai-automating-cybersecurity
๐Ÿ˜5
๐Ÿšจ Microsoft just made Sentinel an agentic SIEM.

Now GA: Sentinel data lake + preview of Graph & MCP server.

AI agents can retro-hunt, trace attack paths & plug into VS Code. From reactive to predictive defense.

Details โ†’ https://thehackernews.com/2025/09/microsoft-expands-sentinel-into-agentic.html
๐Ÿคฏ9