The Hacker News
βœ”
152K subscribers
1.87K photos
10 videos
3 files
7.79K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
🚨 Threat Alert: A new group, TA585, is running end-to-end phishing campaigns delivering MonsterV2 malware.

No middlemen. Just pure, in-house cybercrime ops.

Phishing β†’ fake CAPTCHAs β†’ PowerShell payloads β†’ MonsterV2.

Learn how their stack works β†’ https://thehackernews.com/2025/10/researchers-expose-ta585s-monsterv2.html
😁15πŸ”₯1😱1
🚨 Attackers are turning Discord into a command center β€” using webhooks to steal API keys and config files right from npm, PyPI, and Ruby installs.

βš™οΈ North Korean actors even pushed 300+ fake packages with 50K+ downloads.

Details here β†’ https://thehackernews.com/2025/10/npm-pypi-and-rubygems-packages-found.html
😁15πŸ‘2
⚑ New Android exploit β€œPixnapping” steals 2FA codes via GPU side-channels.

β€” No special permissions
β€” Works across apps (Maps, Authenticator, etc.)
β€” Full 2FA capture in ~30s

Read the full story ↓ https://thehackernews.com/2025/10/new-pixnapping-android-flaw-lets-rogue.html
😱21😁5πŸ‘3πŸ€”2⚑1
🧩 AMD’s β€œsecure” virtualization can be broken with a single memory write.

A new flaw, RMPocalypse (CVE-2025-0033), lets attackers corrupt the Reverse Map Table and steal data from virtual machines β€” all through one 8-byte overwrite.

Read the details ↓ https://thehackernews.com/2025/10/rmpocalypse-single-8-byte-write.html
😁11πŸ€”7⚑1
πŸ€– AI lets attackers map your environment before sending a payload.

No exploits needed β€” your JS, APIs, and error logs are enough. Harmless data is now reconnaissance fuel.

See how it changes defense strategy ↓ https://thehackernews.com/2025/10/what-ai-reveals-about-web-applications.html
😁7😱5
🚨Billions lost. Operations frozen. Ransomware in 2025 is faster, smarter, and nearly unstoppable.

LockBit, Lazarus, and FunkLocker are already inside corporate networks worldwide.

Help your SOC detect threats early and respond with confidence ⬇️ https://thn.news/enterprise-defense
😁9πŸ”₯7πŸ‘2
⚠️ Security training β‰  security.

Training teaches people to see risk β€” threat hunting proves whether it still exists. Real security starts before the first alert.

πŸ” Don’t just educate. Learn how to validate ↓ https://thehackernews.com/2025/10/moving-beyond-awareness-how-threat.html
πŸ‘9πŸ”₯2
🚨 A Chinese APT hid inside ArcGIS for over a year.

They turned a legit Java extension into a web shell.

πŸ”‘ Added a hardcoded key β†’ exclusive access
πŸ’Ύ Hid it in backups β†’ survived restores

That’s what β€œliving off the land” really means ↓ https://thehackernews.com/2025/10/chinese-hackers-exploit-arcgis-server.html
πŸ”₯22🀯8😁1
⚠️ Heads-up! SAP just re-patched a critical CVSS 10.0 flaw (CVE-2025-42944) in NetWeaver AS Java β€” a deserialization bug that lets attackers execute commands without authentication.

Apply. The. Fix. β†’ https://thehackernews.com/2025/10/new-sap-netweaver-bug-lets-attackers.html
πŸ”₯13🀯2
πŸͺ A cookie that spawns a shell πŸ’€

A critical flaw (CVE-2025-2611, CVSS 9.3) in ICTBroadcast autodialer software is under active exploitation.

Attackers inject commands via the BROADCAST session cookie for unauthenticated remote code execution.

No patch yet β€” check your stack β†’ https://thehackernews.com/2025/10/hackers-target-ictbroadcast-servers-via.html

~200 servers are exposed.
😁15πŸ”₯8πŸ‘1
πŸ”₯ Agentic AI isn’t just automatingβ€”it’s thinking and acting.

Zscaler’s CEO says it’s a bigger shift than cloud or IoT.

The upside? Faster support and instant threat response.
The risk? Rogue AIs scanning your network right now.

Learn why Zero Trust isn’t optional anymore β†’ https://thehackernews.com/videos/2025/10/exploring-agentic-ai-innovation-meets.html
πŸ‘11πŸ€”2
βš™οΈ If you run industrial gear β€” check your Red Lion RTUs.

Two CVEs (both 10/10) let anyone pop root via one open port. Water, energy, transport β€” all at risk.

Patch ASAP. Details here β†’ https://thehackernews.com/2025/10/two-cvss-100-bugs-in-red-lion-rtus.html
😁11πŸ‘2
πŸ”΄ Microsoft just dropped fixes for 183 security flaws.

3 are already being exploited β€” including one buried in every Windows PC since XP.

...and at the same time, it is ending Windows 10 support (unless you pay).

Details + patch info ↓ https://thehackernews.com/2025/10/two-new-windows-zero-days-exploited-in.html
πŸ‘19πŸ”₯8😱6😁2
πŸ”₯ New free playbook from Pillar Security : a hands-on framework for red-teaming agentic AI systems.

Covers the AI Kill Chain, context engineering, and the CFS model for crafting and testing realistic attack simulations.

πŸ”— No sign-up required: https://thn.news/agentic-defend
πŸ”₯16πŸ‘6
🚨 Over 100 VS Code extensions leaked access tokens β€” letting attackers push malicious updates to 150,000+ installs.

A single exposed key could’ve weaponized the software supply chain.

Full story ↓ https://thehackernews.com/2025/10/over-100-vs-code-extensions-exposed.html
😁13😱7πŸ”₯3
πŸ‘€ F5 just confirmed a nation-state breach that went undetected for months.

Hackers stole BIG-IP source code and data on undisclosed vulnerabilities.

Full story ↓ https://thehackernews.com/2025/10/f5-breach-exposes-big-ip-source-code.html
😱19😁10πŸ”₯3πŸ€”3πŸ‘2πŸ‘1