The Hacker News
Kanalga Telegramโda oโtish
โญ Official THN Telegram Channel โ A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. ๐จ Contact: admin@thehackernews.com ๐ Website: https://thehackernews.com
Ko'proq ko'rsatish2025 yil raqamlarda

153 666
Obunachilar
+4924 soatlar
+3847 kunlar
+1 47630 kunlar
Postlar arxiv
Photo unavailableShow in Telegram
๐ฅ OpenAI just launched an AI #cybersecurity researcher.
It finds bugs, proves theyโre real, and patches them โ all by itself.
Powered by GPT-5, itโs already discovered 10 vulnerabilities.
The age of autonomous bug hunters starts now โ https://thehackernews.com/2025/10/openai-unveils-aardvark-gpt-5-agent.html
โก 27๐ฑ 15๐ฅ 10๐ 9๐ 5๐ค 4๐ 1
Photo unavailableShow in Telegram
Nation-state hackers built Airstalk, a new malware abusing VMware Workspace ONEโs MDM API as a covert C2 channel.
Signed with a stolen cert, itโs exfiltrating browser data from BPO networks.
Full analysis โ https://thehackernews.com/2025/10/nation-state-hackers-deploy-new.html
๐ 14๐ 3๐คฏ 3
Photo unavailableShow in Telegram
๐จ China-backed hackers exploited an unpatched Windows shortcut bug to breach European diplomats.
UNC6384 used fake โEU Commissionโ and NATO meeting invites to plant PlugX malware (CVE-2025-9491) โ still unpatched by Microsoft.
Full story โ https://thehackernews.com/2025/10/china-linked-hackers-exploit-windows.html
๐ฑ 16๐ 7๐ 2๐คฏ 1
Photo unavailableShow in Telegram
โ ๏ธ Chinese hackers are exploiting a critical 9.3 CVE (CVE-2025-61932) in Motex Lanscope Endpoint Manager.
It lets them run SYSTEM-level commands and plant a Gokcpdoor backdoor with new multiplexed C2 channels.
Active attacks confirmed โ https://thehackernews.com/2025/10/china-linked-tick-group-exploits.html
๐ 16๐ฑ 4โก 1๐คฏ 1
Photo unavailableShow in Telegram
Most MSPs are walking straight into a trap.
Clients now expect enterprise-level cybersecurity โ but many providers are still selling basic IT support.
The result? Lost clients, slower growth, and higher risk exposure.
Is your MSP ready to lead with security? โ https://thehackernews.com/2025/10/the-msp-cybersecurity-readiness-guide.html
๐ 9
Photo unavailableShow in Telegram
CISA and NSA just issued a warning:
Exchange servers are still getting hacked. Now a new WSUS flaw (CVE-2025-59287) lets attackers run code remotely.
Even patched systems arenโt fully safe.
If you manage Exchange or WSUS, read this โ https://thehackernews.com/2025/10/cisa-and-nsa-issue-urgent-guidance-to.html
โก 17๐ฑ 4๐ 1๐ 1
Photo unavailableShow in Telegram
A Mac app just bypassed macOS permission checks โ silently turning on the mic and camera.
ThreatLockerโs new Device Access Control (DAC) for macOS, now in Beta, flags hidden risks like unencrypted drives, SMBv1, and weak sharing settings โ before attackers can exploit them.
Learn more โ https://thehackernews.com/2025/10/a-new-security-layer-for-macos-takes.html
๐ฅ 11๐ 6
Photo unavailableShow in Telegram
Developers accidentally leaked VS Code tokens โ letting attackers publish fake extensions.
Eclipse has revoked the tokens and added new safeguards after a campaign dubbed โGlassWorm.โ
Read โ https://thehackernews.com/2025/10/eclipse-foundation-revokes-leaked-open.html
๐ฅ 9๐ 7๐ 1
Photo unavailableShow in Telegram
CISA added a new VMware zero-day to its KEV list.
CVE-2025-41244 (CVSS 7.8) lets local users on VMs with VMware Tools + Aria Operations gain root access.
Exploited since Oct 2024 by China-linked UNC5174.
Patch released last month โ https://thehackernews.com/2025/10/cisa-flags-vmware-zero-day-exploited-by.html
๐ 11๐ 2
Photo unavailableShow in Telegram
๐ Google says it blocks over 10 billion scam calls and messages every month.
But scammers have adapted โ theyโve gone social.
Now they send fake job offers in group chats, even adding fake โfriendsโ to make it look real.
The new scam tactic most experts overlooked โ https://thehackernews.com/2025/10/googles-built-in-ai-defenses-on-android.html
๐ 22๐ค 14๐ 4๐ฅ 3
Photo unavailableShow in Telegram
๐ฅ A tool built for defenders is now arming attackers.
AdaptixC2 โ an open-source C2 in Golang โ was made for red teams.
Now, Russian ransomware gangs use it in fake Microsoft Teams help-desk scams.
Details โ https://thehackernews.com/2025/10/russian-ransomware-gangs-weaponize-open.html
๐คฏ 9๐ค 4๐ฅ 3
Photo unavailableShow in Telegram
โ ๏ธ โPatch everythingโ is dead.
At the BAS Summit, CISOs said it straight โ not every vuln matters, only the exploitable ones do.
Breach simulation shows where you bleed, not where scanners scream.
Proof beats panic. Read how BAS powers real defense โ https://thehackernews.com/2025/10/the-death-of-security-checkbox-bas-is.html
๐ฅ 5
Photo unavailableShow in Telegram
๐จ A single line of JavaScript can crash any Chromium browser.
Researcher Jose Pino calls it Brash โ it abuses how document.title handles rapid updates.
24 million title changes per second = instant crash.
Still unpatched. Details โ https://thehackernews.com/2025/10/new-brash-exploit-crashes-chromium.html
๐ฅ 11๐ 7๐คฏ 7
Photo unavailableShow in Telegram
โก Cybercrime just got quieter, cheaper, and a lot more precise.
๐ฅ DNS flaws exploited
๐ฅ Rust binaries hiding payloads
๐ฅ Supply-chain heists rising
๐ฅ New RATs everywhere
Your weekly ThreatsDay recap has it all โ https://thehackernews.com/2025/10/threatsday-bulletin-dns-poisoning-flaw.html
๐ 11๐ 4โก 2๐ 2๐ฅ 1
Photo unavailableShow in Telegram
๐จ PhantomRaven hit the npm registry โ 126 malicious packages, 86K+ installs, stealing npm tokens, GitHub creds, and CI/CD secrets.
They hide malware in remote dynamic dependencies that show 0 deps, so scanners miss them.
Details โ https://thehackernews.com/2025/10/phantomraven-malware-found-in-126-npm.html
๐คฏ 11๐ฅ 3๐ 1
Photo unavailableShow in Telegram
๐จ PHP servers are under attack.
Mirai, Mozi, and Gafgyt botnets are exploiting old CVEs to hijack WordPress and Craft CMS sites.
Some break-ins start from leftover PhpStorm debug sessions still running in production.
Check if yours is exposed โ https://thehackernews.com/2025/10/experts-reports-sharp-increase-in.html
๐ 11๐ฅ 2๐ 2๐ 1
Photo unavailableShow in Telegram
โ ๏ธ AI browsers like ChatGPT Atlas and Perplexity Comet can be tricked into using fake data.
A new exploit โ โAI-targeted cloakingโ โ lets attackers show one version of a page to humans and another to AI crawlers.
Same old SEO trick.
New weapon: misinformation at scale.
Read how it works โ https://thehackernews.com/2025/10/new-ai-targeted-cloaking-attack-tricks.html
๐ 15๐ 1
Photo unavailableShow in Telegram
โก Your AI-driven compliance might already be non-compliant.
Regulators arenโt ready โ but you can be.
Join the live session Nov 3 to uncover hidden risks and real fixes.
Register free โ https://thehackernews.com/2025/10/discover-practical-ai-tactics-for-grc.html
๐ 8
Photo unavailableShow in Telegram
๐ด The next big breach wonโt start with a stolen password.
Itโll come from your own AI.
Agentic AIs are the new โconfused deputiesโ โ doing what attackers tell them, with the access you gave them.
The scariest part? You trained the threat โ https://thehackernews.com/2025/10/preparing-for-digital-battlefield-of.html
๐คฏ 7๐ 5๐ 3๐ฅ 1
Photo unavailableShow in Telegram
๐จ Russian hackers breached Ukrainian networks โ no malware needed.
They hijacked Windows tools (PowerShell, RDPClip, OpenSSH) to steal data and stay hidden for months.
Real fileless persistence โ living in memory, invisible to AV.
Learn how they did it & how to detect it โ https://thehackernews.com/2025/10/russian-hackers-target-ukrainian.html
๐คฏ 18๐ฅ 8๐ 8๐ 1
