The Hacker News
โœ”
152K subscribers
1.88K photos
10 videos
3 files
7.79K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: [email protected]

๐ŸŒ Website: https://thehackernews.com
Download Telegram
๐ŸŽƒ This Halloween, face your password nightmares.

Think your passwords are safe? Most IT teams didโ€”until the breach.

Join โ€œTales from the Password Graveyardโ€ โ€” real stories, real lessons, and how to stop the next one.

Live webinar โ€” donโ€™t miss it โ†’ https://thehackernews.com/2025/10/step-into-password-graveyard-if-you.html
๐Ÿ˜13๐Ÿ”ฅ1
AI is now writing the next wave of cyberattacks.

The irony? Most defenders still canโ€™t use it effectively.
The attackers are fasterโ€”and smarter.

Hereโ€™s how to fight back โ†“ https://thehackernews.com/2025/09/automation-is-redefining-pentest.html
๐Ÿ”ฅ5
China-linked hackers just turned a trusted open-source tool into a weapon.

They used log poisoning to slip a web shell onto servers โ€” and dropped Gh0st RAT without custom malware.

100+ servers hit, Gh0st RAT deployed, and the control panel? Written in Russian.

Find details here โ†’ https://thehackernews.com/2025/10/chinese-hackers-weaponize-open-source.html
๐Ÿ˜12๐Ÿค”5๐Ÿ”ฅ1๐Ÿคฏ1
๐Ÿšจ New Threat ALERT! Hackers are exploiting WordPress themes with fake Cloudflare checks, redirecting users to malware via porsasystem[.]com.

Meanwhile, new ClickFix phishing kits use cache smuggling to deliver โ€œinvisibleโ€ payloadsโ€”no downloads needed.

How to spot & kill it โ†“ https://thehackernews.com/2025/10/hackers-exploit-wordpress-themes-to.html
๐Ÿ˜13๐Ÿ”ฅ6๐Ÿ‘1
๐Ÿšจ Hackers are hijacking WordPress sites right now.

A critical flaw (CVE-2025-5947) in the Service Finder theme lets anyone log in as an admin โ€” no password needed.

13,800+ exploit attempts. Still rising.
Most sites havenโ€™t patched.

Details here โ†’ https://thehackernews.com/2025/10/critical-exploit-lets-hackers-bypass.html
๐Ÿ˜11๐Ÿ‘2๐Ÿ‘2
Preemptive Defense is the next frontier of identity security.

It can block AI-driven attacks before a user even authenticates โ€” no login required.

Hereโ€™s how it works (and why Gartnerโ€™s calling it the new IAM essential).

Learn more โ†“ https://thehackernews.com/expert-insights/2025/10/identity-and-ai-threats-developing.html
๐Ÿ‘8๐Ÿ”ฅ2
Russian hackers are now using AI to write malware.

Ukraineโ€™s cybersecurity agency says over 3,000 cyberattacks hit in early 2025 โ€” many powered by AI-generated phishing and data-stealing code.

One strain, WRECKSTEEL, was built with AI tools to target state networks.

Full report โ†’ https://thehackernews.com/2025/10/from-phishing-to-malware-ai-becomes.html
๐Ÿ˜23๐Ÿ‘3๐Ÿคฏ3
โšก Latest ThreatsDay Bulletin Out Now!

Hackers exploit MS Teams + MFA to breach orgs โ€” plus a $2B crypto heist, .LNK malware with PowerShell implants, Autodesk zero-days, and IoT hub exploits.

๐Ÿ”— Your quick intel brief โ†’ https://thehackernews.com/2025/10/threatsday-bulletin-ms-teams-hack-mfa.html
๐Ÿ‘8๐Ÿ”ฅ1
๐Ÿšจ One stolen token can bypass MFA.

Last year, a single unrotated API key let attackers compromise Cloudflareโ€™s internal systems โ€” even after a full credential reset.

OAuth & API tokens are the new backdoors hiding in plain sight.

How to spot them before attackers do โ†“ https://thehackernews.com/2025/10/saas-breaches-start-with-tokens-what.html
๐Ÿ‘11
๐ŸŸฅ SonicWall breach ALERT!

Hackers accessed cloud-stored firewall backups โ€” about 5% of customers affected.

The files hold encrypted credentials and configs that could help attackers target devices.

Check your MySonicWall portal for impacted devices โ†’ https://thehackernews.com/2025/10/hackers-access-sonicwall-cloud-firewall.html
๐Ÿ˜ฑ11๐Ÿ”ฅ1
๐Ÿšจ A new Android spyware is spreading like a worm.

โ€œClayRatโ€ infects phones, then messages every contact to spread further.

It hides as WhatsApp, YouTube, or Google Photos โ€” even faking Play Store screens.

Full analysis โ†“ https://thehackernews.com/2025/10/new-clayrat-spyware-targets-android.html
๐Ÿ”ฅ21๐Ÿคฏ9๐Ÿ˜3
A China-backed group just turned AI into a cyber weapon.

Theyโ€™re using it to write phishing emails and build malware โ€” across English, Chinese, and Japanese targets.

The result? A new backdoor called GOVERSHELL spreading via fake research invites.

Read how โ†“ https://thehackernews.com/2025/10/from-healthkick-to-govershell-evolution.html
๐Ÿ”ฅ11๐Ÿ‘6๐Ÿค”1
๐Ÿšจ Google confirms dozens of organizations breached via Oracle E-Business Suite zero-day (CVE-2025-61882).

Attackers exploited the flaw since July 2025, using multi-stage Java implants and extortion tactics.

๐Ÿ”น Oracle issued an emergency patch Oct 4
๐Ÿ”น Exploit code is now public โ€” risk rising

๐Ÿ”— Details: https://thehackernews.com/2025/10/cl0p-linked-hackers-breach-dozens-of.html
๐Ÿ‘7๐Ÿ‘4๐Ÿ˜3๐Ÿคฏ2๐Ÿค”1
๐Ÿšจ Active zero-day alert: Gladinetโ€™s CentreStack & TrioFox are under live exploitation.

Hackers are chaining two CVEs to pull machine keys and trigger remote code execution โ€” no patch yet.

Admins, disable the temp handler now โ†“ https://thehackernews.com/2025/10/from-lfi-to-rce-active-exploitation.html
๐Ÿ”ฅ7๐Ÿ‘1
๐Ÿšจ Researchers uncovered 175 malicious npm packages used to host phishing redirects โ€” downloaded 26,000+ times.

The campaign, dubbed Beamglea, abused npm + UNPKG to target 135 tech and energy firms worldwide.

No exploit. Just clever infrastructure abuse.

Read โ†’ https://thehackernews.com/2025/10/175-malicious-npm-packages-with-26000.html
๐Ÿคฏ10๐Ÿค”7
โš ๏ธ A zero-day in GoAnywhere MFT has been actively exploited since Sept 11.

Attackers bypassed cryptographic checks โ€” no password, no auth. Microsoft says Storm-1175 used it to drop Medusa ransomware.

Full timeline + exploit details โ†“ https://thehackernews.com/2025/10/from-detection-to-patch-fortra-reveals.html
๐Ÿ‘11
๐Ÿ”ด ALERT: Your next โ€œHR alertโ€ email might not be from HR.

Storm-2657 is phishing employees, taking over Workday accounts, and swapping bank details to steal salaries โ€” no malware, just manipulation.

Inside Microsoftโ€™s latest findings โ†“ https://thehackernews.com/2025/10/microsoft-warns-of-payroll-pirates.html
๐Ÿ˜13๐Ÿ”ฅ4
โš ๏ธ New โ€œStealitโ€ malware is using Node.jsโ€™ experimental SEA feature to slip full payloads into fake game & VPN installers โ€” already spreading via Mediafire and Discord.

Read how โ†’ https://thehackernews.com/2025/10/stealit-malware-abuses-nodejs-single.html
๐Ÿ˜20
๐Ÿšจ Signal just threatened to leave the EU.

Why? The proposed โ€œChat Controlโ€ law would force apps to scan every private message before itโ€™s sent.

The catch: even encrypted chats would be exposed. Experts call it โ€œmass surveillance in disguise.โ€

The details you need to see โ†“ https://thehackernews.com/2025/10/threatsday-bulletin-ms-teams-hack-mfa.html#opposition-to-e-u-chat-control
๐Ÿ‘56๐Ÿคฏ21๐Ÿ”ฅ9๐Ÿ˜9โšก4๐Ÿค”1
๐Ÿšจ Hackers just turned a DFIR tool into a ransomware weapon.

Storm-2603 hijacked Velociraptor to deploy LockBit, Warlock & Babukโ€”even creating fake domain admins and disabling defenses.

Details here โ†“ https://thehackernews.com/2025/10/hackers-turn-velociraptor-dfir-tool.html
๐Ÿ˜16๐Ÿ˜ฑ5๐Ÿ”ฅ4