OOh yeah oooh ooh oooh
The Hacker News Most trusted, widely-read independent cybersecurity news source for everyone; supported by hackers and IT professionals — Send TIPs to admin@thehackernews.com
- Astaroth Banking Trojan Abuses GitHub to Remain Operational After Takedownsby info@thehackernews.com (The Hacker News) on October 13, 2025 at 6:52 am
Cybersecurity researchers are calling attention to a new campaign that delivers the Astaroth banking trojan that employs GitHub as a backbone for its operations to stay resilient in the face of infrastructure takedowns. “Instead of relying solely on traditional command-and-control (C2) servers that can be taken down, these attackers are leveraging GitHub repositories to host malware
- New Rust-Based Malware “ChaosBot” Uses Discord Channels to Control Victims’ PCsby info@thehackernews.com (The Hacker News) on October 13, 2025 at 5:12 am
Cybersecurity researchers have disclosed details of a new Rust-based backdoor called ChaosBot that can allow operators to conduct reconnaissance and execute arbitrary commands on compromised hosts. “Threat actors leveraged compromised credentials that mapped to both Cisco VPN and an over-privileged Active Directory account named, ‘serviceaccount,'” eSentire said in a technical report published
- New Oracle E-Business Suite Bug Could Let Hackers Access Data Without Loginby info@thehackernews.com (The Hacker News) on October 12, 2025 at 5:24 pm
Oracle on Saturday issued a security alert warning of a fresh security flaw impacting its E-Business Suite that it said could allow unauthorized access to sensitive data. The vulnerability, tracked as CVE-2025-61884, carries a CVSS score of 7.5, indicating high severity. It affects versions from 12.2.3 through 12.2.14. “Easily exploitable vulnerability allows an unauthenticated attacker with
- Experts Warn of Widespread SonicWall VPN Compromise Impacting Over 100 Accountsby info@thehackernews.com (The Hacker News) on October 11, 2025 at 1:30 pm
Cybersecurity company Huntress on Friday warned of “widespread compromise” of SonicWall SSL VPN devices to access multiple customer environments. “Threat actors are authenticating into multiple accounts rapidly across compromised devices,” it said. “The speed and scale of these attacks imply that the attackers appear to control valid credentials rather than brute-forcing.” A significant chunk of
- Hackers Turn Velociraptor DFIR Tool Into Weapon in LockBit Ransomware Attacksby info@thehackernews.com (The Hacker News) on October 11, 2025 at 1:04 pm
Threat actors are abusing Velociraptor, an open-source digital forensics and incident response (DFIR) tool, in connection with ransomware attacks likely orchestrated by Storm-2603 (aka CL-CRI-1040 or Gold Salem), which is known for deploying the Warlock and LockBit ransomware. The threat actor’s use of the security utility was documented by Sophos last month. It’s assessed that the attackers