
Mohit Kumar
@unix_root
Founder — @TheHackersNews | Cyber Alchemist | Curious by Nature, Educator by Choice, Disciplined by Trading, Solution-Driven by Coding.
Może Ci się spodobać
⚠️ Your AppSec blind spots are costing you. The gap between code and cloud runtime drives 90% of delayed fixes—and missed accountability. Map vulnerabilities, misconfigs, and secrets across your pipeline to regain control. Cut the noise. Reduce risk. Start now ↓…

Meta just rolled out new anti-scam tools for WhatsApp & Messenger. ⚠️ Screen-share warnings 🤖 AI scam detection 🚨 Instant alerts ... but one setting quietly breaks 🔐 encryption. Learn more ↓ thehackernews.com/2025/10/meta-r…
🔥 Your Cisco, ASUS, QNAP, or Synology router might secretly be part of a botnet. A new threat called PolarEdge is hiding inside routers, turning them into undetectable spies using a secret TLS server and a hidden config file. Exploit chain, IOCs & decryption trick ↓…

CISA just added 5 active CVEs to the KEV list. The big one? Oracle EBS — under live attack from a new SSRF flaw (CVE-2025-61884). Remote access, no auth. Real-world hits confirmed. Deadline to patch: Nov 10. Details → thehackernews.com/2025/10/five-n…
🔴 Silent breaches, blockchain malware, and new Android exploits — this week’s threat roundup proves attackers are getting bolder and smarter. Catch the highlights: ⚡ F5 breach ⚡ EtherHiding malware ⚡ Cisco rootkits ⚡ Pixnapping 2FA theft Read WEEKLY RECAP →…

🚨 131 Chrome extensions were caught turning WhatsApp Web into spam bots. They look like “CRM tools,” but secretly send bulk messages. Over 20,000 users already installed them. Full details ↓ thehackernews.com/2025/10/131-ch…
🚨 A fake CAPTCHA just breached hospitals, universities, and city networks. The scary part? Victims copied the attack code themselves — straight from their browser. It’s called ClickFix, and it hijacks users through “fix this page” pop-ups — no downloads, no phishing email…

🕵️ China says the NSA hacked its national time servers — the system that keeps everything in sync. If that clock went down, it could’ve hit banks, power grids, even space launches. The attack used foreign SMS exploits, forged certs, and 42 stealth tools. Read →…

💣 Europol just dismantled a SIM farm-for-hire platform that powered 49 million fake accounts used for global fraud. It let anyone rent verified phone numbers from 80+ countries — to scam, extort, or launder money. Details → thehackernews.com/2025/10/europo…
⚠️ Update: Contagious Interview now uses OtterCandy — a Node.js RAT + info-stealer tied to North Korean actors. Hides in npm/supply-chain lures, uses socket[.]io C2 to steal browser passwords & crypto wallets. v2 adds Suiet/Trust/Rabby harvesting + Windows registry wipes. Read…
![TheHackersNews's tweet image. ⚠️ Update: Contagious Interview now uses OtterCandy — a Node.js RAT + info-stealer tied to North Korean actors.
Hides in npm/supply-chain lures, uses socket[.]io C2 to steal browser passwords & crypto wallets. v2 adds Suiet/Trust/Rabby harvesting + Windows registry wipes.
Read…](https://pbs.twimg.com/media/G3mlM7ZWkAAqnkb.png)
📄 You open a tax doc. 💻 Windows quietly loads malware. 🛑 Your AV dies. 💀 You’re owned. That’s how Winos 4.0 and HoldingHands RAT are spreading right now — using Windows’ own Task Scheduler against it. Details here ↓ thehackernews.com/2025/10/silver…
🚨 CVE-2025-9242 — Critical WatchGuard Fireware flaw (CVSS 9.3) Unauthenticated attackers can exploit a 520-byte overflow in IKEv2 before cert checks, executing code on VPN firewalls — even spawning a Python shell over TCP. Patch now ↓ thehackernews.com/2025/10/resear…
Researchers uncovered "LinkPro," a Golang-based Linux rootkit that uses eBPF to hide processes and activate remotely via a secret “magic packet.” It spread through a malicious Docker image deployed on vulnerable Jenkins servers. Full report ↓ thehackernews.com/2025/10/linkpr…
Get an inside look at Georgetown's Cybersecurity Risk Management program. Register for the virtual sample class on October 29. Attend here → thn.news/georgetown-cyb…

⚡ North Korean hackers just used the blockchain to hide malware — the first time ever seen. Google says they used EtherHiding to plant code inside smart contracts, making it nearly impossible to remove and easy to update for just $1.37 in gas fees. Full story ↓…

🚨 CISA just flagged a 10.0-severity flaw in Adobe Experience Manager. A single debug page can open the door to remote code execution — no login required. Attackers are already exploiting it, and many orgs still haven’t patched. Details ↓ thehackernews.com/2025/10/cisa-f…
🚨 Hackers just turned a Cisco zero-day (CVE-2025-20352) into a Linux rootkit dropper—hitting routers before the patch dropped. The backdoor’s universal password was “disco.” Learn more about the Operation Zero Disco ↓ thehackernews.com/2025/10/hacker…
🚨 China-linked “Jewelbug” hackers quietly lived inside a Russian IT provider for 5 months. They used Microsoft’s own debugger to slip past defenses — and exfiltrated data to Yandex Cloud. Full story ↓ thehackernews.com/2025/10/chines…
🔴 Microsoft just dropped fixes for 183 security flaws. 3 are already being exploited — including one buried in every Windows PC since XP. ...and at the same time, it is ending Windows 10 support (unless you pay). Details + patch info ↓ thehackernews.com/2025/10/two-ne…
⚠️ Heads-up! SAP just re-patched a critical CVSS 10.0 flaw (CVE-2025-42944) in NetWeaver AS Java — a deserialization bug that lets attackers execute commands without authentication. Apply. The. Fix. → thehackernews.com/2025/10/new-sa…
United States Trendy
- 1. Russ 30K posts
- 2. Arsenal 335K posts
- 3. Lakers 40.6K posts
- 4. Martinelli 37.4K posts
- 5. White House 124K posts
- 6. NASA 73.4K posts
- 7. Crosby 9,149 posts
- 8. Sean Payton 2,619 posts
- 9. Warriors 57K posts
- 10. Atlas 61.8K posts
- 11. Platner 11.8K posts
- 12. Atletico 125K posts
- 13. Simeone 25.8K posts
- 14. John Brennan 31K posts
- 15. Woody Johnson 2,722 posts
- 16. #COYG 7,291 posts
- 17. Gyokeres 48.9K posts
- 18. $BYND 151K posts
- 19. Knicks 10.8K posts
- 20. Napoli 33.6K posts
Może Ci się spodobać
-
The Hacker News
@TheHackersNews -
Black Hat
@BlackHatEvents -
DEF CON
@defcon -
Pentester Academy
@SecurityTube -
Brute Logic
@BRuteLogic -
Security BSides
@SecurityBSides -
CySecurity News
@EHackerNews -
OWASP® Foundation
@owasp -
Eduard Kovacs
@EduardKovacs -
Pierluigi Paganini - Security Affairs
@securityaffairs -
packet storm
@packet_storm -
Hackread.com
@HackRead -
Core Impact
@_CoreImpact -
Panos Gkatziroulis 🦄
@netbiosX -
Bart
@bartblaze
Something went wrong.
Something went wrong.