
Mohit Kumar
@unix_root
Founder — @TheHackersNews | Cyber Alchemist | Curious by Nature, Educator by Choice, Disciplined by Trading, Solution-Driven by Coding.
قد يعجبك
Researchers uncovered "LinkPro," a Golang-based Linux rootkit that uses eBPF to hide processes and activate remotely via a secret “magic packet.” It spread through a malicious Docker image deployed on vulnerable Jenkins servers. Full report ↓ thehackernews.com/2025/10/linkpr…
Get an inside look at Georgetown's Cybersecurity Risk Management program. Register for the virtual sample class on October 29. Attend here → thn.news/georgetown-cyb…

⚡ North Korean hackers just used the blockchain to hide malware — the first time ever seen. Google says they used EtherHiding to plant code inside smart contracts, making it nearly impossible to remove and easy to update for just $1.37 in gas fees. Full story ↓…

🚨 CISA just flagged a 10.0-severity flaw in Adobe Experience Manager. A single debug page can open the door to remote code execution — no login required. Attackers are already exploiting it, and many orgs still haven’t patched. Details ↓ thehackernews.com/2025/10/cisa-f…
🚨 Hackers just turned a Cisco zero-day (CVE-2025-20352) into a Linux rootkit dropper—hitting routers before the patch dropped. The backdoor’s universal password was “disco.” Learn more about the Operation Zero Disco ↓ thehackernews.com/2025/10/hacker…
🚨 China-linked “Jewelbug” hackers quietly lived inside a Russian IT provider for 5 months. They used Microsoft’s own debugger to slip past defenses — and exfiltrated data to Yandex Cloud. Full story ↓ thehackernews.com/2025/10/chines…
🔴 Microsoft just dropped fixes for 183 security flaws. 3 are already being exploited — including one buried in every Windows PC since XP. ...and at the same time, it is ending Windows 10 support (unless you pay). Details + patch info ↓ thehackernews.com/2025/10/two-ne…
⚠️ Heads-up! SAP just re-patched a critical CVSS 10.0 flaw (CVE-2025-42944) in NetWeaver AS Java — a deserialization bug that lets attackers execute commands without authentication. Apply. The. Fix. → thehackernews.com/2025/10/new-sa…
🍪 A cookie that spawns a shell 💀 A critical flaw (CVE-2025-2611, CVSS 9.3) in ICTBroadcast autodialer software is under active exploitation. Attackers inject commands via the BROADCAST session cookie for unauthenticated remote code execution. No patch yet — check your stack…

🚨 Billions lost. Operations frozen. Ransomware in 2025 is faster, smarter, and nearly unstoppable. LockBit, Lazarus, and FunkLocker are already inside corporate networks worldwide. Help your SOC detect threats early and respond with confidence ⬇️ thn.news/enterprise-thr…
🚨 A Chinese APT hid inside ArcGIS for over a year. They turned a legit Java extension into a web shell. 🔑 Added a hardcoded key → exclusive access 💾 Hid it in backups → survived restores That’s what “living off the land” really means ↓ thehackernews.com/2025/10/chines…
🚨 Attackers are turning Discord into a command center — using webhooks to steal API keys and config files right from npm, PyPI, and Ruby installs. ⚙️ North Korean actors even pushed 300+ fake packages with 50K+ downloads. Details here → thehackernews.com/2025/10/npm-py…
Hackers just turned GitHub into their command center. When police take down their servers, the malware just… reboots itself from GitHub. The twist? It hides configs inside images using steganography. This isn’t a glitch — it’s resilience by design. Read how it works →…

⚡ Latest Weekly Recap is out... 🚨 Oracle 0-Day exploited 🤖 Nation-state AI abuse on the rise 🎣 npm phishing spreading fast 💀 New ransomware cartel emerges …and more The threat landscape is moving fast — here’s what defenders need to know. 🔗 thehackernews.com/2025/10/weekly…
⚠️ WARNING: Oracle just confirmed a new vulnerability (CVE-2025-61884) in E-Business Suite. No login required. Full data access possible. Even worse—similar flaws were just exploited by Cl0p-linked actors. Read the latest news here → thehackernews.com/2025/10/new-or…
⚡ Apple’s Siri recordings are under criminal investigation in France. A whistleblower says they captured “intimate” conversations — enough to identify users. Apple denies misuse, but prosecutors aren’t convinced. Read ↓ thehackernews.com/2025/10/threat…

🐭 A $35 gaming mouse just became a spy tool. UC Irvine researchers turned its optical sensor into a microphone that steals conversations from air-gapped PCs. It hides inside legit apps like games. Read the PoC → thehackernews.com/2025/10/threat…

🚨 Active zero-day alert: Gladinet’s CentreStack & TrioFox are under live exploitation. Hackers are chaining two CVEs to pull machine keys and trigger remote code execution — no patch yet. Admins, disable the temp handler now ↓ thehackernews.com/2025/10/from-l…
🚨 Google confirms dozens of organizations breached via Oracle E-Business Suite zero-day (CVE-2025-61882). Attackers exploited the flaw since July 2025, using multi-stage Java implants and extortion tactics. 🔹 Oracle issued an emergency patch Oct 4 🔹 Exploit code is now…

A China-backed group just turned AI into a cyber weapon. They’re using it to write phishing emails and build malware — across English, Chinese, and Japanese targets. The result? A new backdoor called GOVERSHELL spreading via fake research invites. Read how ↓…

United States الاتجاهات
- 1. #KonamiWorldSeriesSweepstakes N/A
- 2. #2025MAMAVOTE 1.53M posts
- 3. Mitch McConnell 13.2K posts
- 4. Tyla 22.5K posts
- 5. Term 192K posts
- 6. #TrumpShutdownBadForUS 2,212 posts
- 7. Budapest 10.6K posts
- 8. No Kings 147K posts
- 9. Yung Miami 1,808 posts
- 10. Somalia 30.5K posts
- 11. Caresha 1,442 posts
- 12. Deport Harry Sisson 30K posts
- 13. Chanel 26.4K posts
- 14. Miguel Vick N/A
- 15. Spencer Dinwiddie N/A
- 16. ErgoChair X N/A
- 17. President Putin 23K posts
- 18. Carter Hart 1,647 posts
- 19. Brian Cashman N/A
- 20. #SpiritDay 2,161 posts
قد يعجبك
-
The Hacker News
@TheHackersNews -
Black Hat
@BlackHatEvents -
DEF CON
@defcon -
Pentester Academy
@SecurityTube -
Brute Logic
@BRuteLogic -
Security BSides
@SecurityBSides -
CySecurity News
@EHackerNews -
OWASP® Foundation
@owasp -
Eduard Kovacs
@EduardKovacs -
Pierluigi Paganini - Security Affairs
@securityaffairs -
packet storm
@packet_storm -
Hackread.com
@HackRead -
Core Impact
@_CoreImpact -
Panos Gkatziroulis 🦄
@netbiosX -
Bart
@bartblaze
Something went wrong.
Something went wrong.