๐จ Important: Hackers quietly exploited Fortra GoAnywhere MFT a full week before anyone knew.
CVE-2025-10035 (CVSS 10.0) gave them pre-auth RCE to slip in an โadmin-goโ backdoor and drop payloads.
Patch now: 7.8.4 / 7.6.3.
Full story โ https://thehackernews.com/2025/09/fortra-goanywhere-cvss-10-flaw.html
CVE-2025-10035 (CVSS 10.0) gave them pre-auth RCE to slip in an โadmin-goโ backdoor and drop payloads.
Patch now: 7.8.4 / 7.6.3.
Full story โ https://thehackernews.com/2025/09/fortra-goanywhere-cvss-10-flaw.html
๐7๐ฅ3
๐จ West Sussex man arrested over ransomware attack that crippled baggage & check-in systems at major European airports, including Heathrow.
Collins Aerospace confirms โHardBitโ ransomware caused hundreds of flight delays.
NCA probe ongoing โ https://thehackernews.com/2025/09/threatsday-bulletin-rootkit-patch.html#basic-ransomware-big-chaos
Collins Aerospace confirms โHardBitโ ransomware caused hundreds of flight delays.
NCA probe ongoing โ https://thehackernews.com/2025/09/threatsday-bulletin-rootkit-patch.html#basic-ransomware-big-chaos
๐ฅ18๐6
โก Blue Report 2025:
โข Data exfiltration stopped just 3% of the time
โข 54% of attacker moves left no logs
โข Only 14% triggered alerts
Dashboards donโt prove safetyโBAS is the crash test that shows if your defenses really hold.
Read โ https://thehackernews.com/2025/09/crash-tests-for-security-why-bas-is.html
โข Data exfiltration stopped just 3% of the time
โข 54% of attacker moves left no logs
โข Only 14% triggered alerts
Dashboards donโt prove safetyโBAS is the crash test that shows if your defenses really hold.
Read โ https://thehackernews.com/2025/09/crash-tests-for-security-why-bas-is.html
๐8๐4๐2
โ ๏ธ Two big cyber hits making waves:
๐ท๐บ COLDRIVER hackers are tricking people with fake CAPTCHAs to drop a stealthy PowerShell backdoor that steals files and hides its tracks.
๐ฅ At the same time, Bearlyfy ransomware is tearing through Russian companiesโ30+ victims so far, ransoms reaching โฌ80K.
Full story โ https://thehackernews.com/2025/09/new-coldriver-malware-campaign-joins-bo.html
๐ท๐บ COLDRIVER hackers are tricking people with fake CAPTCHAs to drop a stealthy PowerShell backdoor that steals files and hides its tracks.
๐ฅ At the same time, Bearlyfy ransomware is tearing through Russian companiesโ30+ victims so far, ransoms reaching โฌ80K.
Full story โ https://thehackernews.com/2025/09/new-coldriver-malware-campaign-joins-bo.html
๐14๐6๐3๐คฏ2๐ฑ1
๐จ Two fresh phishing campaigns, one big warning:
๐บ๐ฆ Hackers posing as Ukraineโs National Police use SVG attachments to launch a chain that steals passwords & mines crypto.
๐ป๐ณ Another crew lures victims with fake copyright notices, ending in PureRAT backdoors for full remote control.
Full story โ https://thehackernews.com/2025/09/researchers-expose-svg-and-purerat.html
๐บ๐ฆ Hackers posing as Ukraineโs National Police use SVG attachments to launch a chain that steals passwords & mines crypto.
๐ป๐ณ Another crew lures victims with fake copyright notices, ending in PureRAT backdoors for full remote control.
Full story โ https://thehackernews.com/2025/09/researchers-expose-svg-and-purerat.html
โก8๐5๐2
๐จ CISA: Hackers exploited GeoServer CVE-2024-36401 RCE to breach a U.S. federal agency on July 11, 2024โmoving laterally across servers and deploying China Chopper web shells & LotL tools.
Full advisory โ https://thehackernews.com/2025/09/threatsday-bulletin-rootkit-patch.html#geoserver-hole-exploited
Full advisory โ https://thehackernews.com/2025/09/threatsday-bulletin-rootkit-patch.html#geoserver-hole-exploited
๐14๐ค4๐ฅ2๐1
๐จ China-linked cyber groups are upgrading their weapons:
โข PlugX: hides in the Mobile Popup app, decrypts payloads in memory with XOR-RC4-RtlDecompressBuffer, packs a keylogger.
โข Bookworm: slips shellcode in UUID strings to dodge detection.
Full story โ https://thehackernews.com/2025/09/china-linked-plugx-and-bookworm-malware.html
โข PlugX: hides in the Mobile Popup app, decrypts payloads in memory with XOR-RC4-RtlDecompressBuffer, packs a keylogger.
โข Bookworm: slips shellcode in UUID strings to dodge detection.
Full story โ https://thehackernews.com/2025/09/china-linked-plugx-and-bookworm-malware.html
๐ฅ23๐คฏ6๐ค2๐ฑ2๐1
๐จ First real-world MCP server backdoor spotted!
A fake npm package postmark-mcp silently BCCโd every email to an attackerโover 1,600 downloads before removal.
โ ๏ธ One line of code. Thousands of stolen emails.
Read now โ https://thehackernews.com/2025/09/first-malicious-mcp-server-found.html
A fake npm package postmark-mcp silently BCCโd every email to an attackerโover 1,600 downloads before removal.
โ ๏ธ One line of code. Thousands of stolen emails.
Read now โ https://thehackernews.com/2025/09/first-malicious-mcp-server-found.html
๐11๐3๐1๐ฅ1๐ค1
๐จ Microsoft warns โ Hackers used LLM-generated code to hide malware in an SVG file disguised as a business dashboard, bypassing defenses with self-addressed emails + invisible scripts.
Details โ https://thehackernews.com/2025/09/microsoft-flags-ai-driven-phishing-llm.html
Details โ https://thehackernews.com/2025/09/microsoft-flags-ai-driven-phishing-llm.html
๐19๐คฏ5๐1๐ฅ1
๐ต๏ธโโ๏ธ Missed the action? Hackers didnโt restโneither should you.
See the key security stories you might have missed.
Check full recap โ https://thehackernews.com/2025/09/weekly-recap-cisco-0-day-record-ddos.html
See the key security stories you might have missed.
Check full recap โ https://thehackernews.com/2025/09/weekly-recap-cisco-0-day-record-ddos.html
๐11๐1
๐จ SOCs are drowning: 40% of security alerts go uninvestigated, and 61% of the ones ignored later turn out to be critical.
Teams face 3,000+ daily alerts and 70-minute investigationsโfar slower than the 48 minutes attackers need to compromise.
Read โ https://thehackernews.com/2025/09/the-state-of-ai-in-soc-2025-insights.html
Teams face 3,000+ daily alerts and 70-minute investigationsโfar slower than the 48 minutes attackers need to compromise.
Read โ https://thehackernews.com/2025/09/the-state-of-ai-in-soc-2025-insights.html
๐ฅ16๐1
๐จ EvilAI is live and global: Malware hidden inside โlegitโ AI & productivity apps is quietly invading manufacturing, healthcare, gov & tech across ๐ฎ๐ณ ๐บ๐ธ ๐ซ๐ท ๐ง๐ท and more.
๐ต๏ธโโ๏ธ Uses real code-signing certs, AES-encrypted C2, even NeutralinoJS tricks to slip past detection.
Read โ https://thehackernews.com/2025/09/evilai-malware-masquerades-as-ai-tools.html
๐ต๏ธโโ๏ธ Uses real code-signing certs, AES-encrypted C2, even NeutralinoJS tricks to slip past detection.
Read โ https://thehackernews.com/2025/09/evilai-malware-masquerades-as-ai-tools.html
๐17๐6โก1๐1๐ฅ1
๐จ Linux/Unix alert: CISA just flagged a critical Sudo flaw (CVE-2025-32463, CVSS 9.3) now exploited in the wild.
Attackers can hijack sudoโs --chroot option to run arbitrary commands as rootโeven if not in sudoers.
Details โ https://thehackernews.com/2025/09/cisa-sounds-alarm-on-critical-sudo-flaw.html
Attackers can hijack sudoโs --chroot option to run arbitrary commands as rootโeven if not in sudoers.
Details โ https://thehackernews.com/2025/09/cisa-sounds-alarm-on-critical-sudo-flaw.html
๐16๐คฏ12๐2๐ฑ2
๐จ U.K. police just seized ยฃ5.5B ($7.4B) in cryptoโthe largest Bitcoin confiscation in history.
A Chinese fraudster duped 128,000 victims, laundered funds into 61,000 BTC, and tried to hide in London with fake IDs.
The twist? She was caught buying property.
Full story โ https://thehackernews.com/2025/09/uk-police-just-seized-55-billion-in.html
A Chinese fraudster duped 128,000 victims, laundered funds into 61,000 BTC, and tried to hide in London with fake IDs.
The twist? She was caught buying property.
Full story โ https://thehackernews.com/2025/09/uk-police-just-seized-55-billion-in.html
๐คฏ16๐5๐ฅ4๐4
๐จ Shadow AI is exploding inside enterprises. Employees are adopting LLM-powered apps without oversightโcreating blind spots, supply chain risks, and data leaks.
Wing Security says traditional defenses canโt keep up. The fix? Real-time discovery + AI supply chain governance.
Read โ https://thehackernews.com/2025/09/evolving-enterprise-defense-to-secure.html
Wing Security says traditional defenses canโt keep up. The fix? Real-time discovery + AI supply chain governance.
Read โ https://thehackernews.com/2025/09/evolving-enterprise-defense-to-secure.html
๐ฅ7๐1
๐จ A new Android banking trojan is here: Datzbro.
It doesnโt just steal loginsโit recreates your screen in real time for full device takeover.
Victims? Seniors lured via fake โactive tripโ groups on Facebook.
Details โ https://thehackernews.com/2025/09/new-android-trojan-datzbro-tricking.html
It doesnโt just steal loginsโit recreates your screen in real time for full device takeover.
Victims? Seniors lured via fake โactive tripโ groups on Facebook.
Details โ https://thehackernews.com/2025/09/new-android-trojan-datzbro-tricking.html
๐ฑ12๐ฅ6๐1๐คฏ1
๐ฅ [New] VMware zero-day (CVE-2025-41244) exploited in the wild!
UNC5174 popped root by abusing a regex bug in get_version() โ drop /tmp/httpd, open a socket, and youโre root.
Already active since Oct โ24.
Details โ https://thehackernews.com/2025/09/urgent-china-linked-hackers-exploit-new.html
UNC5174 popped root by abusing a regex bug in get_version() โ drop /tmp/httpd, open a socket, and youโre root.
Already active since Oct โ24.
Details โ https://thehackernews.com/2025/09/urgent-china-linked-hackers-exploit-new.html
๐ฅ25๐1
๐ AI wonโt fix your workflowsโit might break them.
Learn how top teams actually blend humans + LLMs without over-engineering.
Secure, auditable, scalable.
๐ Join the webinar โ https://thehacker.news/ai-automating-cybersecurity
Learn how top teams actually blend humans + LLMs without over-engineering.
Secure, auditable, scalable.
๐ Join the webinar โ https://thehacker.news/ai-automating-cybersecurity
๐5
๐จ Microsoft just made Sentinel an agentic SIEM.
Now GA: Sentinel data lake + preview of Graph & MCP server.
AI agents can retro-hunt, trace attack paths & plug into VS Code. From reactive to predictive defense.
Details โ https://thehackernews.com/2025/09/microsoft-expands-sentinel-into-agentic.html
Now GA: Sentinel data lake + preview of Graph & MCP server.
AI agents can retro-hunt, trace attack paths & plug into VS Code. From reactive to predictive defense.
Details โ https://thehackernews.com/2025/09/microsoft-expands-sentinel-into-agentic.html
๐คฏ9
๐จ Googleโs Gemini AI had a โTrifectaโ of flaws that let attackers steal user data + hijack cloud assets.
The wildest part? Hackers could smuggle prompts inside HTTP headers to make Gemini expose IAM misconfigs & query Cloud APIs on their behalf.
Read โ https://thehackernews.com/2025/09/researchers-disclose-google-gemini-ai.html
The wildest part? Hackers could smuggle prompts inside HTTP headers to make Gemini expose IAM misconfigs & query Cloud APIs on their behalf.
Read โ https://thehackernews.com/2025/09/researchers-disclose-google-gemini-ai.html
๐13๐2