The Hacker News
Open in Telegram
โญ Official THN Telegram Channel โ A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. ๐จ Contact: admin@thehackernews.com ๐ Website: https://thehackernews.com
Show more2025 year in numbers

153 682
Subscribers
+4924 hours
+3847 days
+1 47630 days
Posts Archive
Photo unavailableShow in Telegram
๐จ 10 fake npm packages (~9.9K installs) hid a cross-platform info stealer.
It spawns a fake terminal, pulls a 24 MB payload from 195.133.79[.]43, and drains keyrings โ not just browser creds.
Instant access to email, cloud, VPNs, and prod DBs.
Read details โ https://thehackernews.com/2025/10/10-npm-packages-caught-stealing.html
๐คฏ 11๐ 5๐ 2
Photo unavailableShow in Telegram
๐จ CISA confirmed ACTIVE exploitation of new flaws in Dassault Systรจmesโ DELMIA Apriso and XWiki.
One lets any guest run code.
Another gives full admin access.
Hackers are already dropping crypto miners.
Agencies have until Nov 18 to patch โ https://thehackernews.com/2025/10/active-exploits-hit-dassault-and-xwiki.html
๐ 5๐ฅ 4
Photo unavailableShow in Telegram
๐ฅ Researchers just broke Intel & AMDโs newest โsecureโ enclaves โ again.
A sub-$1K hardware rig can steal attestation keys from fully patched systems running SGX, TDX, and SEV-SNP with Ciphertext Hiding.
Even constant-time crypto and DDR5 encryption couldnโt stop it.
Learn how TEE-Fail cracks open AI and confidential VMs โ https://thehackernews.com/2025/10/new-teefail-side-channel-attack.html
๐ 11๐ 6๐คฏ 3
Photo unavailableShow in Telegram
๐จ New Android Trojan โHerodotusโ is on the move.
Itโs hitting phones in ๐ฎ๐น Italy & ๐ง๐ท Brazil โ stealing 2FA codes, logins, even lock PINs โ and typing like a human to slip past fraud detection.
๐ Read full report โ https://thehackernews.com/2025/10/new-android-trojan-herodotus-outsmarts.html
๐ฅ 15๐คฏ 5๐ 4๐ 2๐ 1๐ฑ 1
Photo unavailableShow in Telegram
๐จ North Koreaโlinked BlueNoroff is running two active campaigns โ GhostCall & GhostHire โ into 2025.
GhostCall fakes Zoom/Teams meetings to drop malware via bogus SDK โupdates.โ
GhostHire targets Web3 devs on Telegram with booby-trapped GitHub tests.
Full report โ https://thehackernews.com/2025/10/researchers-expose-ghostcall-and.html
๐ 12๐ 3๐คฏ 3โก 2๐ฅ 2
Photo unavailableShow in Telegram
AI-driven attacks move faster than humans can react.
The real risk? Teams flying blind.
ANYRUN flips the script โ predicting attacks before they strike. 99% unique IOCs. Zero lag. Full context.
Early detection turns panic into power โ https://thehackernews.com/2025/10/why-early-threat-detection-is-must-for.html
๐ฅ 10
Photo unavailableShow in Telegram
AI-driven attacks move faster than humans can react.
The real risk? Teams flying blind.
ANYRUN flips the script โ predicting attacks before they strike. 99% unique IOCs. Zero lag. Full context.
Early detection turns panic into power โ https://thehackernews.com/2025/10/why-early-threat-detection-is-must-for.html
Photo unavailableShow in Telegram
Google Workspace isnโt secure by default.
Many startups operate with open sharing, broad app access, and limited oversight.
The risk? It often looks completely normal.
See how lean teams are locking it down โ https://thehackernews.com/2025/10/is-your-google-workspace-as-secure-as.html
๐ฅ 14๐ 3๐คฏ 2๐ 1
Photo unavailableShow in Telegram
โ ๏ธ ALERT: A Chrome zero-day (CVE-2025-2783) was exploited to deliver spyware built by Memento Labs โ the firm behind past government surveillance tools.
One click in Chromium = full sandbox escape.
Read this โ https://thehackernews.com/2025/10/chrome-zero-day-exploited-to-deliver.html
๐ฅ 19๐ 4๐ 1
Photo unavailableShow in Telegram
โ ๏ธ SideWinder hackers strike again.
A European embassy in New Delhi was hit using fake Adobe Reader updates and signed apps to sneak in StealerBot malware โ stealing passwords, screenshots, and files.
Other targets: Sri Lanka, Pakistan, and Bangladesh.
Full report โ https://thehackernews.com/2025/10/sidewinder-adopts-new-clickonce-based.html
๐ 15๐ 6๐ฅ 5โก 3
Photo unavailableShow in Telegram
โก Security and speed shouldnโt be enemies.
But when AI agents multiply faster than controls can keep up, most orgs fall into firefighting mode.
Join our live session to see how forward-thinking teams are:
โ
Governing thousands of AI agents automatically
โ
Embedding security guardrails that scale
โ
Shipping AI features faster โ and safer
Live webinar: Learn how to scale AI securely, without compromise โ https://thehacker.news/securing-ai-adoption
๐ 9๐ 3
Photo unavailableShow in Telegram
โ ๏ธ WARNING: X users with security keys (like YubiKeys) must re-enroll 2FA by Nov 10, 2025 โ or get locked out.
The update moves keys from twitter[.]com to x[.]com as Twitterโs domain is retired.
Details โ https://thehackernews.com/2025/10/x-warns-users-with-security-keys-to-re.html
๐ 19๐ค 5๐ 3โก 1
