Category: TheHackerNews

Malicious npm Packages Impersonate Flashbots, Steal Ethereum Wallet Keys
06
Sep
2025

Malicious npm Packages Impersonate Flashbots, Steal Ethereum Wallet Keys

Sep 06, 2025Ravie LakshmananSoftware Security / Cryptocurrency A new set of four malicious packages have been discovered in the npm…

Critical Sitecore Vulnerability Under Active Exploitation
05
Sep
2025

CISA Orders Immediate Patch of Critical Sitecore Vulnerability Under Active Exploitation

Federal Civilian Executive Branch (FCEB) agencies are being advised to update their Sitecore instances by September 25, 2025, following the…

TAG-150 Develops CastleRAT in Python and C, Expanding CastleLoader Malware Operations
05
Sep
2025

TAG-150 Develops CastleRAT in Python and C, Expanding CastleLoader Malware Operations

The threat actor behind the malware-as-a-service (MaaS) framework and loader called CastleLoader has also developed a remote access trojan known…

SAP S/4HANA Critical Vulnerability CVE-2025-42957 Exploited in the Wild
05
Sep
2025

SAP S/4HANA Critical Vulnerability CVE-2025-42957 Exploited in the Wild

Sep 05, 2025Ravie LakshmananVulnerability / Enterprise Security A critical security vulnerability impacting SAP S/4HANA, an Enterprise Resource Planning (ERP) software,…

Automation Is Redefining Pentest Delivery
05
Sep
2025

Automation Is Redefining Pentest Delivery

Sep 05, 2025The Hacker NewsPentesting / Security Operations Pentesting remains one of the most effective ways to identify real-world security…

VirusTotal Finds 44 Undetected SVG Files Used to Deploy Base64-Encoded Phishing Pages
05
Sep
2025

VirusTotal Finds 44 Undetected SVG Files Used to Deploy Base64-Encoded Phishing Pages

Sep 05, 2025Ravie LakshmananMalware / Cryptocurrency Cybersecurity researchers have flagged a new malware campaign that has leveraged Scalable Vector Graphics…

GhostRedirector Hacks 65 Windows Servers Using Rungan Backdoor and Gamshen IIS Module
04
Sep
2025

GhostRedirector Hacks 65 Windows Servers Using Rungan Backdoor and Gamshen IIS Module

Cybersecurity researchers have lifted the lid on a previously undocumented threat cluster dubbed GhostRedirector that has managed to compromise at…

Russian APT28 Deploys "NotDoor" Outlook Backdoor Against Companies in NATO Countries
04
Sep
2025

Russian APT28 Deploys “NotDoor” Outlook Backdoor Against Companies in NATO Countries

Sep 04, 2025Ravie LakshmananCybersecurity / Malware The Russian state-sponsored hacking group tracked as APT28 has been attributed to a new…

CISA Flags TP-Link Router Flaws CVE-2023-50224 and CVE-2025-9377 as Actively Exploited
04
Sep
2025

CISA Flags TP-Link Router Flaws CVE-2023-50224 and CVE-2025-9377 as Actively Exploited

Sep 04, 2025Ravie LakshmananVulnerability / Network Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added two security…

Google Fined $379 Million by French Regulator for Cookie Consent Violations
04
Sep
2025

Google Fined $379 Million by French Regulator for Cookie Consent Violations

Sep 04, 2025Ravie LakshmananGDPR / Data Privacy The French data protection authority has fined Google and Chinese e-commerce giant Shein…

Grok AI to Bypass Ad Protections
04
Sep
2025

Cybercriminals Exploit X’s Grok AI to Bypass Ad Protections and Spread Malware to Millions

Sep 04, 2025Ravie LakshmananArtificial Intelligence / Malware Cybersecurity researchers have flagged a new technique that cybercriminals have adopted to bypass…

Malicious npm Packages Exploit Ethereum Smart Contracts to Target Crypto Developers
04
Sep
2025

Malicious npm Packages Exploit Ethereum Smart Contracts to Target Crypto Developers

Sep 03, 2025Ravie LakshmananMalware / Social Engineering Cybersecurity researchers have discovered two new malicious packages on the npm registry that…