The Hacker News
โœ”
152K subscribers
1.88K photos
10 videos
3 files
7.79K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: [email protected]

๐ŸŒ Website: https://thehackernews.com
Download Telegram
๐Ÿšจ Important: Hackers quietly exploited Fortra GoAnywhere MFT a full week before anyone knew.

CVE-2025-10035 (CVSS 10.0) gave them pre-auth RCE to slip in an โ€œadmin-goโ€ backdoor and drop payloads.

Patch now: 7.8.4 / 7.6.3.

Full story โ†’ https://thehackernews.com/2025/09/fortra-goanywhere-cvss-10-flaw.html
๐Ÿ‘7๐Ÿ”ฅ3
๐Ÿšจ West Sussex man arrested over ransomware attack that crippled baggage & check-in systems at major European airports, including Heathrow.

Collins Aerospace confirms โ€œHardBitโ€ ransomware caused hundreds of flight delays.

NCA probe ongoing โ†’ https://thehackernews.com/2025/09/threatsday-bulletin-rootkit-patch.html#basic-ransomware-big-chaos
๐Ÿ”ฅ18๐Ÿ˜6
โšก Blue Report 2025:

โ€ข Data exfiltration stopped just 3% of the time
โ€ข 54% of attacker moves left no logs
โ€ข Only 14% triggered alerts

Dashboards donโ€™t prove safetyโ€”BAS is the crash test that shows if your defenses really hold.

Read โ†’ https://thehackernews.com/2025/09/crash-tests-for-security-why-bas-is.html
๐Ÿ‘8๐Ÿ˜4๐Ÿ‘2
โš ๏ธ Two big cyber hits making waves:

๐Ÿ‡ท๐Ÿ‡บ COLDRIVER hackers are tricking people with fake CAPTCHAs to drop a stealthy PowerShell backdoor that steals files and hides its tracks.

๐Ÿ’ฅ At the same time, Bearlyfy ransomware is tearing through Russian companiesโ€”30+ victims so far, ransoms reaching โ‚ฌ80K.

Full story โ†’ https://thehackernews.com/2025/09/new-coldriver-malware-campaign-joins-bo.html
๐Ÿ‘14๐Ÿ˜6๐Ÿ‘3๐Ÿคฏ2๐Ÿ˜ฑ1
๐Ÿšจ Two fresh phishing campaigns, one big warning:

๐Ÿ‡บ๐Ÿ‡ฆ Hackers posing as Ukraineโ€™s National Police use SVG attachments to launch a chain that steals passwords & mines crypto.

๐Ÿ‡ป๐Ÿ‡ณ Another crew lures victims with fake copyright notices, ending in PureRAT backdoors for full remote control.

Full story โ†’ https://thehackernews.com/2025/09/researchers-expose-svg-and-purerat.html
โšก8๐Ÿ‘5๐Ÿ˜2
๐Ÿšจ CISA: Hackers exploited GeoServer CVE-2024-36401 RCE to breach a U.S. federal agency on July 11, 2024โ€”moving laterally across servers and deploying China Chopper web shells & LotL tools.

Full advisory โ†’ https://thehackernews.com/2025/09/threatsday-bulletin-rootkit-patch.html#geoserver-hole-exploited
๐Ÿ‘14๐Ÿค”4๐Ÿ”ฅ2๐Ÿ‘1
๐Ÿšจ China-linked cyber groups are upgrading their weapons:

โ€ข PlugX: hides in the Mobile Popup app, decrypts payloads in memory with XOR-RC4-RtlDecompressBuffer, packs a keylogger.

โ€ข Bookworm: slips shellcode in UUID strings to dodge detection.

Full story โ†’ https://thehackernews.com/2025/09/china-linked-plugx-and-bookworm-malware.html
๐Ÿ”ฅ23๐Ÿคฏ6๐Ÿค”2๐Ÿ˜ฑ2๐Ÿ‘1
๐Ÿšจ First real-world MCP server backdoor spotted!

A fake npm package postmark-mcp silently BCCโ€™d every email to an attackerโ€”over 1,600 downloads before removal.

โš ๏ธ One line of code. Thousands of stolen emails.

Read now โ†’ https://thehackernews.com/2025/09/first-malicious-mcp-server-found.html
๐Ÿ‘11๐Ÿ˜3๐Ÿ‘1๐Ÿ”ฅ1๐Ÿค”1
๐Ÿšจ Microsoft warns โ€” Hackers used LLM-generated code to hide malware in an SVG file disguised as a business dashboard, bypassing defenses with self-addressed emails + invisible scripts.

Details โ†’ https://thehackernews.com/2025/09/microsoft-flags-ai-driven-phishing-llm.html
๐Ÿ˜19๐Ÿคฏ5๐Ÿ‘1๐Ÿ”ฅ1
๐Ÿ•ต๏ธโ€โ™€๏ธ Missed the action? Hackers didnโ€™t restโ€”neither should you.

See the key security stories you might have missed.

Check full recap โ†’ https://thehackernews.com/2025/09/weekly-recap-cisco-0-day-record-ddos.html
๐Ÿ‘11๐Ÿ‘1
๐Ÿšจ SOCs are drowning: 40% of security alerts go uninvestigated, and 61% of the ones ignored later turn out to be critical.

Teams face 3,000+ daily alerts and 70-minute investigationsโ€”far slower than the 48 minutes attackers need to compromise.

Read โ†’ https://thehackernews.com/2025/09/the-state-of-ai-in-soc-2025-insights.html
๐Ÿ”ฅ16๐Ÿ‘1
๐Ÿšจ EvilAI is live and global: Malware hidden inside โ€œlegitโ€ AI & productivity apps is quietly invading manufacturing, healthcare, gov & tech across ๐Ÿ‡ฎ๐Ÿ‡ณ ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿ‡ซ๐Ÿ‡ท ๐Ÿ‡ง๐Ÿ‡ท and more.

๐Ÿ•ต๏ธโ€โ™‚๏ธ Uses real code-signing certs, AES-encrypted C2, even NeutralinoJS tricks to slip past detection.

Read โ†’ https://thehackernews.com/2025/09/evilai-malware-masquerades-as-ai-tools.html
๐Ÿ‘17๐Ÿ˜6โšก1๐Ÿ‘1๐Ÿ”ฅ1
๐Ÿšจ Linux/Unix alert: CISA just flagged a critical Sudo flaw (CVE-2025-32463, CVSS 9.3) now exploited in the wild.

Attackers can hijack sudoโ€™s --chroot option to run arbitrary commands as rootโ€”even if not in sudoers.

Details โ†’ https://thehackernews.com/2025/09/cisa-sounds-alarm-on-critical-sudo-flaw.html
๐Ÿ‘16๐Ÿคฏ12๐Ÿ‘2๐Ÿ˜ฑ2
๐Ÿšจ U.K. police just seized ยฃ5.5B ($7.4B) in cryptoโ€”the largest Bitcoin confiscation in history.

A Chinese fraudster duped 128,000 victims, laundered funds into 61,000 BTC, and tried to hide in London with fake IDs.

The twist? She was caught buying property.

Full story โ†’ https://thehackernews.com/2025/09/uk-police-just-seized-55-billion-in.html
๐Ÿคฏ16๐Ÿ‘5๐Ÿ”ฅ4๐Ÿ˜4
๐Ÿšจ Shadow AI is exploding inside enterprises. Employees are adopting LLM-powered apps without oversightโ€”creating blind spots, supply chain risks, and data leaks.

Wing Security says traditional defenses canโ€™t keep up. The fix? Real-time discovery + AI supply chain governance.

Read โ†’ https://thehackernews.com/2025/09/evolving-enterprise-defense-to-secure.html
๐Ÿ”ฅ7๐Ÿ‘1
๐Ÿšจ A new Android banking trojan is here: Datzbro.

It doesnโ€™t just steal loginsโ€”it recreates your screen in real time for full device takeover.

Victims? Seniors lured via fake โ€œactive tripโ€ groups on Facebook.

Details โ†’ https://thehackernews.com/2025/09/new-android-trojan-datzbro-tricking.html
๐Ÿ˜ฑ12๐Ÿ”ฅ6๐Ÿ‘1๐Ÿคฏ1
๐Ÿ”ฅ [New] VMware zero-day (CVE-2025-41244) exploited in the wild!

UNC5174 popped root by abusing a regex bug in get_version() โ€” drop /tmp/httpd, open a socket, and youโ€™re root.

Already active since Oct โ€™24.

Details โ†’ https://thehackernews.com/2025/09/urgent-china-linked-hackers-exploit-new.html
๐Ÿ”ฅ25๐Ÿ‘1
๐Ÿ›  AI wonโ€™t fix your workflowsโ€”it might break them.

Learn how top teams actually blend humans + LLMs without over-engineering.

Secure, auditable, scalable.

๐Ÿ“… Join the webinar โ†’ https://thehacker.news/ai-automating-cybersecurity
๐Ÿ˜5
๐Ÿšจ Microsoft just made Sentinel an agentic SIEM.

Now GA: Sentinel data lake + preview of Graph & MCP server.

AI agents can retro-hunt, trace attack paths & plug into VS Code. From reactive to predictive defense.

Details โ†’ https://thehackernews.com/2025/09/microsoft-expands-sentinel-into-agentic.html
๐Ÿคฏ9
๐Ÿšจ Googleโ€™s Gemini AI had a โ€œTrifectaโ€ of flaws that let attackers steal user data + hijack cloud assets.

The wildest part? Hackers could smuggle prompts inside HTTP headers to make Gemini expose IAM misconfigs & query Cloud APIs on their behalf.

Read โ†’ https://thehackernews.com/2025/09/researchers-disclose-google-gemini-ai.html
๐Ÿ‘13๐Ÿ‘2