News
Entertainment
Science & Technology
Sport
Business & Money
Life
Culture & Art
Hobbies
4 | Follower
The Hacker News
13.09.2025
Samsung patched CVE-2025-21043 on Sep 2025 after zero-day Android exploits enabled code execution.
CISA added CVE-2025-5086 to KEV after active Apriso exploitation; agencies must patch by Oct 2, 2025.
Apple warned French users of spyware on Sept 3, 2025, marking its fourth alert this year.
Runtime visibility dominates 2025 CNAPP strategies, cutting false positives and enabling faster AI-driven threat response.
HybridPetya ransomware exploits CVE-2024-7344 to bypass UEFI Secure Boot, encrypts NTFS MFT, and demands $1,000 Bitcoin ransom.
12.09.2025
Akira ransomware exploits SonicWall CVE-2024-40766 with 9.3 CVSS flaw, driving 40 attacks in July 2025.
Google Pixel 10 integrates C2PA Content Credentials with offline cryptographic security, boosting media transparency and trust.
Boards face SEC and NIS2 accountability, yet weak oversight drives urgent CISO risk reporting training.
Fake Meta browser extensions in Feb–Mar 2025 steal Facebook session cookies, enabling account hijacks and business ad frau
Sen. Wyden urges FTC probe after Ascension breach exposed 5.6M records via Microsoft’s insecure RC4 defaults.
Cursor ships with Workspace Trust disabled by default, exposing users to silent code execution risks
11.09.2025
Microsoft patched 80 flaws in Sept 2025, including CVE-2025-55234 SMB bug and CVSS 10 Azure risk.
EggStreme malware targets Philippines military with fileless multi-stage attacks, enabling persistent espionage and data theft.
Apple’s iPhone 17 debuts Memory Integrity Enforcement, blocking buffer overflows and spyware exploits with minimal performance impact.
Automation cuts vCISO workloads by 68% in 2025, saving 10+ hours per task and boosting scalability.
China-linked APT41 campaigns stole U.S. trade data via phishing emails on Sept 7, 2025
CHILLYHELL macOS malware, notarized since 2021, exposed May 2025 with flexible persistence and C2 evasion tactics.
AsyncRAT exploits ConnectWise ScreenConnect via fileless loader, stealing credentials and crypto data, maintaining persistence through fake “Skype Upd
10.09.2025
MostereRAT phishing campaign targets Japanese users with advanced evasion tactics, disabling defenses and stealing data.
Akamai found TOR-based Docker API cryptojacking in Aug 2025, hinting at botnet plans and data theft.
RatOn malware, first seen July 5, 2025, evolves into ATS trojan targeting crypto wallets and Czech banking.
SAP patches critical NetWeaver and S/4HANA flaws (CVSS 8.1–10.0), preventing code execution, file upload, and data loss.
Axios abuse surged 241% June–August 2025, powering phishing campaigns with 70% success via Microsoft Direct Send.
Adobe Commerce CVE-2025-54236 allows account takeover; hotfix and WAF deployed to block attacks.
88% of boards see cybersecurity as business risk; continuous validation proves ROI and prevents $5M losses.
Shadow AI Agents multiply unchecked across enterprises today, leaking data and impersonating users, outpacing governance.
Salty2FA phishing kit active since June 2025 bypasses 2FA in US and EU campaigns, fueling enterprise breaches.
09.09.2025
20 npm packages with 2B weekly downloads compromised after maintainer phishing led to crypto-stealing malware.
From Drift chaos to zero-days on the loose — this week’s cyber recap has it all. ⚡ Stay sharp, stay patched.
45 domains linked to Salt Typhoon date back to May 2020, revealing ongoing China-backed cyber espionage.
North Korean hiring fraud surged 220% in 2023, using AI deepfakes to infiltrate companies and steal data.
GPUGate malware uses Google Ads and fake GitHub commits to steal data from IT firms since Dec 2024, bypassing sandboxes and GPU-lacking systems.
GitHub compromise led to Drift data breach, impacting 22 companies and prompting Salesloft app suspension.
07.09.2025
Noisy Bear hit KazMunaiGas in May 2025 via phishing emails, using Aeza Group hosting.
06.09.2025
CastleRAT and CastleLoader, active since March 2025, spread malware via phishing and GitHub repos, enabling data theft.
CVE-2025-42957 in SAP S/4HANA exploited with CVSS 9.9 severity, enabling full system compromise.
CVE-2025-53690, a critical Sitecore flaw (CVSS 9.0), exploited since Dec 2024, enables RCE and data theft.
Four npm packages uploaded since Sep 2023 impersonate Flashbots, stealing Ethereum keys and seeds via Telegram
05.09.2025
GhostRedirector compromised 65 Windows servers since Aug 2024 using Rungan and Gamshen malware, driving SEO fraud.
Automated pentest delivery replaces static reports, cutting weeks off remediation and reducing MTTR through real-time workflows.