Category: TheHackerNews

npm, PyPI, and RubyGems Packages Found Sending Developer Data to Discord Channels
14
Oct
2025

npm, PyPI, and RubyGems Packages Found Sending Developer Data to Discord Channels

Oct 14, 2025Ravie LakshmananMalware / Typosquatting Cybersecurity researchers have identified several malicious packages across npm, Python, and Ruby ecosystems that…

Why Unmonitored JavaScript Is Your Biggest Holiday Security Risk
13
Oct
2025

Why Unmonitored JavaScript Is Your Biggest Holiday Security Risk

Think your WAF has you covered? Think again. This holiday season, unmonitored JavaScript is a critical oversight allowing attackers to…

Microsoft Locks Down IE Mode After Hackers Turned Legacy Feature Into Backdoor
13
Oct
2025

Microsoft Locks Down IE Mode After Hackers Turned Legacy Feature Into Backdoor

Oct 13, 2025Ravie LakshmananBrowser Security / Windows Security Microsoft said it has revamped the Internet Explorer (IE) mode in its…

Researchers Warn RondoDox Botnet is Weaponizing Over 50 Flaws Across 30+ Vendors
13
Oct
2025

Researchers Warn RondoDox Botnet is Weaponizing Over 50 Flaws Across 30+ Vendors

Malware campaigns distributing the RondoDox botnet have expanded their targeting focus to exploit more than 50 vulnerabilities across over 30…

Astaroth Banking Trojan
13
Oct
2025

Astaroth Banking Trojan Abuses GitHub to Remain Operational After Takedowns

Oct 13, 2025Ravie LakshmananMalware / Financial Security Cybersecurity researchers are calling attention to a new campaign that delivers the Astaroth…

Rust-Based Malware "ChaosBot"
13
Oct
2025

New Rust-Based Malware “ChaosBot” Uses Discord Channels to Control Victims’ PCs

Oct 13, 2025Ravie LakshmananRansomware / Windows Security Cybersecurity researchers have disclosed details of a new Rust-based backdoor called ChaosBot that…

New Oracle E-Business Suite Bug Could Let Hackers Access Data Without Login
12
Oct
2025

New Oracle E-Business Suite Bug Could Let Hackers Access Data Without Login

Oct 12, 2025Ravie LakshmananVulnerability / Threat Intelligence Oracle on Saturday issued a security alert warning of a fresh security flaw…

Experts Warn of Widespread SonicWall VPN Compromise Impacting Over 100 Accounts
11
Oct
2025

Experts Warn of Widespread SonicWall VPN Compromise Impacting Over 100 Accounts

Oct 11, 2025Ravie LakshmananCloud Security / Network Security Cybersecurity company Huntress on Friday warned of “widespread compromise” of SonicWall SSL…

Hackers Turn Velociraptor DFIR Tool
11
Oct
2025

Hackers Turn Velociraptor DFIR Tool Into Weapon in LockBit Ransomware Attacks

Oct 11, 2025Ravie LakshmananNetwork Security / Vulnerability Threat actors are abusing Velociraptor, an open-source digital forensics and incident response (DFIR)…

Payroll Pirates
10
Oct
2025

Microsoft Warns of ‘Payroll Pirates’ Hijacking HR SaaS Accounts to Steal Employee Salaries

Oct 10, 2025Ravie LakshmananSaaS Security / Threat Intelligence A threat actor known as Storm-2657 has been observed hijacking employee accounts…

Stealit Malware Abuses Node.js Single Executable Feature
10
Oct
2025

Stealit Malware Abuses Node.js Single Executable Feature via Game and VPN Installers

Oct 10, 2025Ravie LakshmananRansomware / Data Theft Cybersecurity researchers have disclosed details of an active malware campaign called Stealit that…

175 Malicious npm Packages with 26,000 Downloads Used in Credential Phishing Campaign
10
Oct
2025

175 Malicious npm Packages with 26,000 Downloads Used in Credential Phishing Campaign

Oct 10, 2025Ravie LakshmananCybercrime / Malware Cybersecurity researchers have flagged a new set of 175 malicious packages on the npm…