Category: TheHackerNews

Pixnapping Android Flaw
14
Oct
2025

New Pixnapping Android Flaw Lets Rogue Apps Steal 2FA Codes Without Permissions

Oct 14, 2025Ravie LakshmananVulnerability / Mobile Security Android devices from Google and Samsung have been found vulnerable to a side-channel…

Single 8-Byte Write Shatters AMD's SEV-SNP Confidential Computing
14
Oct
2025

Single 8-Byte Write Shatters AMD’s SEV-SNP Confidential Computing

Oct 14, 2025Ravie LakshmananVulnerability / Hardware Security Chipmaker AMD has released fixes to address a security flaw dubbed RMPocalypse that…

How Threat Hunting Builds Readiness
14
Oct
2025

How Threat Hunting Builds Readiness

Every October brings a familiar rhythm – pumpkin-spice everything in stores and cafés, alongside a wave of reminders, webinars, and…

MonsterV2 Malware
14
Oct
2025

Researchers Expose TA585’s MonsterV2 Malware Capabilities and Attack Chain

Oct 14, 2025Ravie LakshmananMalware / Social Engineering Cybersecurity researchers have shed light on a previously undocumented threat actor called TA585…

npm, PyPI, and RubyGems Packages Found Sending Developer Data to Discord Channels
14
Oct
2025

npm, PyPI, and RubyGems Packages Found Sending Developer Data to Discord Channels

Oct 14, 2025Ravie LakshmananMalware / Typosquatting Cybersecurity researchers have identified several malicious packages across npm, Python, and Ruby ecosystems that…

Why Unmonitored JavaScript Is Your Biggest Holiday Security Risk
13
Oct
2025

Why Unmonitored JavaScript Is Your Biggest Holiday Security Risk

Think your WAF has you covered? Think again. This holiday season, unmonitored JavaScript is a critical oversight allowing attackers to…

Microsoft Locks Down IE Mode After Hackers Turned Legacy Feature Into Backdoor
13
Oct
2025

Microsoft Locks Down IE Mode After Hackers Turned Legacy Feature Into Backdoor

Oct 13, 2025Ravie LakshmananBrowser Security / Windows Security Microsoft said it has revamped the Internet Explorer (IE) mode in its…

Researchers Warn RondoDox Botnet is Weaponizing Over 50 Flaws Across 30+ Vendors
13
Oct
2025

Researchers Warn RondoDox Botnet is Weaponizing Over 50 Flaws Across 30+ Vendors

Malware campaigns distributing the RondoDox botnet have expanded their targeting focus to exploit more than 50 vulnerabilities across over 30…

Astaroth Banking Trojan
13
Oct
2025

Astaroth Banking Trojan Abuses GitHub to Remain Operational After Takedowns

Oct 13, 2025Ravie LakshmananMalware / Financial Security Cybersecurity researchers are calling attention to a new campaign that delivers the Astaroth…

Rust-Based Malware "ChaosBot"
13
Oct
2025

New Rust-Based Malware “ChaosBot” Uses Discord Channels to Control Victims’ PCs

Oct 13, 2025Ravie LakshmananRansomware / Windows Security Cybersecurity researchers have disclosed details of a new Rust-based backdoor called ChaosBot that…

New Oracle E-Business Suite Bug Could Let Hackers Access Data Without Login
12
Oct
2025

New Oracle E-Business Suite Bug Could Let Hackers Access Data Without Login

Oct 12, 2025Ravie LakshmananVulnerability / Threat Intelligence Oracle on Saturday issued a security alert warning of a fresh security flaw…

Experts Warn of Widespread SonicWall VPN Compromise Impacting Over 100 Accounts
11
Oct
2025

Experts Warn of Widespread SonicWall VPN Compromise Impacting Over 100 Accounts

Oct 11, 2025Ravie LakshmananCloud Security / Network Security Cybersecurity company Huntress on Friday warned of “widespread compromise” of SonicWall SSL…