
Mohit Kumar
@unix_root
Founder — @TheHackersNews | Cyber Alchemist | Curious by Nature, Educator by Choice, Disciplined by Trading, Solution-Driven by Coding.
Potrebbero piacerti
🚨 New Adobe Commerce flaw (CVE-2025-54236, CVSS 9.1) under active attack. Over 250 exploit attempts in 24 hours—mostly on unpatched Magento sites. PoC is public. Patch now. Details → thehackernews.com/2025/10/over-2…
thehackernews.com
Over 250 Magento Stores Hit Overnight as Hackers Exploit New Adobe Commerce Flaw
Sansec reports 250+ attacks exploiting Adobe Commerce flaw CVE-2025-54236; 62% of stores remain unpatched.
Which Industries Are Most at Risk for DDoS Attacks? While DDoS attacks can hit any organization, some industries face far higher risk—and potentially greater impact when they do. The latest DDoS Resiliency Score (DRS) report ranks the industries most frequently targeted and…

⚠️ Your AppSec blind spots are costing you. The gap between code and cloud runtime drives 90% of delayed fixes—and missed accountability. Map vulnerabilities, misconfigs, and secrets across your pipeline to regain control. Cut the noise. Reduce risk. Start now ↓…

Meta just rolled out new anti-scam tools for WhatsApp & Messenger. ⚠️ Screen-share warnings 🤖 AI scam detection 🚨 Instant alerts ... but one setting quietly breaks 🔐 encryption. Learn more ↓ thehackernews.com/2025/10/meta-r…
🔥 Your Cisco, ASUS, QNAP, or Synology router might secretly be part of a botnet. A new threat called PolarEdge is hiding inside routers, turning them into undetectable spies using a secret TLS server and a hidden config file. Exploit chain, IOCs & decryption trick ↓…

CISA just added 5 active CVEs to the KEV list. The big one? Oracle EBS — under live attack from a new SSRF flaw (CVE-2025-61884). Remote access, no auth. Real-world hits confirmed. Deadline to patch: Nov 10. Details → thehackernews.com/2025/10/five-n…
thehackernews.com
Five New Exploited Bugs Land in CISA's Catalog — Oracle and Microsoft Among Targets
CISA adds five exploited vulnerabilities, including Oracle, Microsoft, Kentico, and Apple flaws, requiring fixes by Nov 10, 2025.
🔴 Silent breaches, blockchain malware, and new Android exploits — this week’s threat roundup proves attackers are getting bolder and smarter. Catch the highlights: ⚡ F5 breach ⚡ EtherHiding malware ⚡ Cisco rootkits ⚡ Pixnapping 2FA theft Read WEEKLY RECAP →…

🚨 131 Chrome extensions were caught turning WhatsApp Web into spam bots. They look like “CRM tools,” but secretly send bulk messages. Over 20,000 users already installed them. Full details ↓ thehackernews.com/2025/10/131-ch…
thehackernews.com
131 Chrome Extensions Caught Hijacking WhatsApp Web for Massive Spam Campaign
Researchers uncover 131 Chrome extensions automating WhatsApp spam, impacting 20,905 users in Brazil.
🚨 A fake CAPTCHA just breached hospitals, universities, and city networks. The scary part? Victims copied the attack code themselves — straight from their browser. It’s called ClickFix, and it hijacks users through “fix this page” pop-ups — no downloads, no phishing email…

🕵️ China says the NSA hacked its national time servers — the system that keeps everything in sync. If that clock went down, it could’ve hit banks, power grids, even space launches. The attack used foreign SMS exploits, forged certs, and 42 stealth tools. Read →…

💣 Europol just dismantled a SIM farm-for-hire platform that powered 49 million fake accounts used for global fraud. It let anyone rent verified phone numbers from 80+ countries — to scam, extort, or launder money. Details → thehackernews.com/2025/10/europo…
⚠️ Update: Contagious Interview now uses OtterCandy — a Node.js RAT + info-stealer tied to North Korean actors. Hides in npm/supply-chain lures, uses socket[.]io C2 to steal browser passwords & crypto wallets. v2 adds Suiet/Trust/Rabby harvesting + Windows registry wipes. Read…
![TheHackersNews's tweet image. ⚠️ Update: Contagious Interview now uses OtterCandy — a Node.js RAT + info-stealer tied to North Korean actors.
Hides in npm/supply-chain lures, uses socket[.]io C2 to steal browser passwords & crypto wallets. v2 adds Suiet/Trust/Rabby harvesting + Windows registry wipes.
Read…](https://pbs.twimg.com/media/G3mlM7ZWkAAqnkb.png)
📄 You open a tax doc. 💻 Windows quietly loads malware. 🛑 Your AV dies. 💀 You’re owned. That’s how Winos 4.0 and HoldingHands RAT are spreading right now — using Windows’ own Task Scheduler against it. Details here ↓ thehackernews.com/2025/10/silver…
🚨 CVE-2025-9242 — Critical WatchGuard Fireware flaw (CVSS 9.3) Unauthenticated attackers can exploit a 520-byte overflow in IKEv2 before cert checks, executing code on VPN firewalls — even spawning a Python shell over TCP. Patch now ↓ thehackernews.com/2025/10/resear…
Researchers uncovered "LinkPro," a Golang-based Linux rootkit that uses eBPF to hide processes and activate remotely via a secret “magic packet.” It spread through a malicious Docker image deployed on vulnerable Jenkins servers. Full report ↓ thehackernews.com/2025/10/linkpr…
thehackernews.com
LinkPro Linux Rootkit Uses eBPF to Hide and Activates via Magic TCP Packets
Synacktiv uncovered LinkPro, a Golang rootkit using eBPF hide/knock modules activated by TCP window 54321.
Get an inside look at Georgetown's Cybersecurity Risk Management program. Register for the virtual sample class on October 29. Attend here → thn.news/georgetown-cyb…

⚡ North Korean hackers just used the blockchain to hide malware — the first time ever seen. Google says they used EtherHiding to plant code inside smart contracts, making it nearly impossible to remove and easy to update for just $1.37 in gas fees. Full story ↓…

🚨 CISA just flagged a 10.0-severity flaw in Adobe Experience Manager. A single debug page can open the door to remote code execution — no login required. Attackers are already exploiting it, and many orgs still haven’t patched. Details ↓ thehackernews.com/2025/10/cisa-f…
🚨 Hackers just turned a Cisco zero-day (CVE-2025-20352) into a Linux rootkit dropper—hitting routers before the patch dropped. The backdoor’s universal password was “disco.” Learn more about the Operation Zero Disco ↓ thehackernews.com/2025/10/hacker…
thehackernews.com
Hackers Deploy Linux Rootkits via Cisco SNMP Flaw in 'Zero Disco' Attacks
Operation Zero Disco exploits Cisco IOS flaw CVE-2025-20352 to deploy persistent Linux rootkits
🚨 China-linked “Jewelbug” hackers quietly lived inside a Russian IT provider for 5 months. They used Microsoft’s own debugger to slip past defenses — and exfiltrated data to Yandex Cloud. Full story ↓ thehackernews.com/2025/10/chines…
United States Tendenze
- 1. Chauncey Billups 34.4K posts
- 2. Chauncey Billups 34.4K posts
- 3. Mafia 78.3K posts
- 4. Gilbert Arenas 2,788 posts
- 5. Damon Jones 5,636 posts
- 6. 5sos 26.2K posts
- 7. #7_years_with_ATEEZ 36.5K posts
- 8. Toronto Rangers 1,052 posts
- 9. Kirby Air Riders 4,707 posts
- 10. Kash Patel 26.8K posts
- 11. #에이티즈_7주년_항해는_계속된다 28.3K posts
- 12. #A_TO_Z 28K posts
- 13. Feds 20.4K posts
- 14. The FBI 116K posts
- 15. Adam Silver 3,369 posts
- 16. The NBA 159K posts
- 17. Sakurai 8,392 posts
- 18. Gambling 79.4K posts
- 19. Malik Beasley 5,108 posts
- 20. Poker 22.5K posts
Potrebbero piacerti
-
The Hacker News
@TheHackersNews -
Black Hat
@BlackHatEvents -
DEF CON
@defcon -
Pentester Academy
@SecurityTube -
Brute Logic
@BRuteLogic -
Security BSides
@SecurityBSides -
CySecurity News
@EHackerNews -
OWASP® Foundation
@owasp -
Eduard Kovacs
@EduardKovacs -
Pierluigi Paganini - Security Affairs
@securityaffairs -
packet storm
@packet_storm -
Hackread.com
@HackRead -
Core Impact
@_CoreImpact -
Panos Gkatziroulis 🦄
@netbiosX -
Bart
@bartblaze
Something went wrong.
Something went wrong.