This media is not supported in your browser
VIEW IN TELEGRAM
Forwarded from The Hacker News
β οΈ Hackers are exploiting a new 7-Zip flaw right now.
A simple ZIP file can break into Windows through a hidden link trick.
The bugβs been patched β but many still havenβt updated.
Details here (CVE-2025-11001) β https://thehackernews.com/2025/11/hackers-actively-exploiting-7-zip.html
A simple ZIP file can break into Windows through a hidden link trick.
The bugβs been patched β but many still havenβt updated.
Details here (CVE-2025-11001) β https://thehackernews.com/2025/11/hackers-actively-exploiting-7-zip.html
This media is not supported in your browser
VIEW IN TELEGRAM
Forwarded from The Hacker News
π¨ Hackers are running fake ads for popular apps β and they look 100% real.
Click one, and you install TamperedChef, a backdoor that lets attackers control your computer.
Experts say itβs still spreading.
Read here β https://thehackernews.com/2025/11/tamperedchef-malware-spreads-via-fake.html
Click one, and you install TamperedChef, a backdoor that lets attackers control your computer.
Experts say itβs still spreading.
Read here β https://thehackernews.com/2025/11/tamperedchef-malware-spreads-via-fake.html
This media is not supported in your browser
VIEW IN TELEGRAM
Forwarded from The Hacker News
β‘ Iranian hackers helped aim real missiles.
They broke into ship tracking systems and live cameras β then the ships got attacked days later.
Amazon says this marks a new kind of war: where hacking meets real-world strikes.
More on how it happened β https://thehackernews.com/2025/11/iran-linked-hackers-mapped-ship-ais.html
They broke into ship tracking systems and live cameras β then the ships got attacked days later.
Amazon says this marks a new kind of war: where hacking meets real-world strikes.
More on how it happened β https://thehackernews.com/2025/11/iran-linked-hackers-mapped-ship-ais.html
This media is not supported in your browser
VIEW IN TELEGRAM
Forwarded from The Hacker News
π New Android malware can read your private chats β even on Signal, WhatsApp, and Telegram.
It records your screen after messages are decrypted, stealing passwords and banking logins.
It even fakes system updates to hide what itβs doing.
Full story β https://thehackernews.com/2025/11/new-sturnus-android-trojan-quietly.html
It records your screen after messages are decrypted, stealing passwords and banking logins.
It even fakes system updates to hide what itβs doing.
Full story β https://thehackernews.com/2025/11/new-sturnus-android-trojan-quietly.html
This media is not supported in your browser
VIEW IN TELEGRAM
Forwarded from The Hacker News
This week's ThreatsDay looks at big cyber news from around the world:
πΉ Russian hackers got arrested
πΉ Chinese spies are using LinkedIn to find secrets
πΉ People caught washing dirty money with crypto
πΉ New hidden bugs found in phones, computers, and smart home gadgets
πΉ ... and many more.
π Zero-day attacks β’ Spying β’ Crypto crime β’ Bugs in everyday devices β’ Moving malware
Read all critical stories here β https://thehackernews.com/2025/11/threatsday-bulletin-0-days-linkedin.html
πΉ Russian hackers got arrested
πΉ Chinese spies are using LinkedIn to find secrets
πΉ People caught washing dirty money with crypto
πΉ New hidden bugs found in phones, computers, and smart home gadgets
πΉ ... and many more.
π Zero-day attacks β’ Spying β’ Crypto crime β’ Bugs in everyday devices β’ Moving malware
Read all critical stories here β https://thehackernews.com/2025/11/threatsday-bulletin-0-days-linkedin.html
This media is not supported in your browser
VIEW IN TELEGRAM
Forwarded from The Hacker News
JSGuLdr: Multi-Stage Loader Delivering PhantomStealer
#ANYRUN researchers identified #JSGuLdr, a multi-stage JavaScript-to-PowerShell loader used to deliver #PhantomStealer. A JScript file triggers PowerShell through an Explorer COM call, pulls the second stage from %APPDATA%\Registreri62, then uses Net.WebClient to fetch an encrypted payload from Google Drive into %APPDATA%\Autorise131[.]Tel. The payload is decoded in memory and loaded, with PhantomStealerinjected into msiexec.exe.
Execution chain: wscript.exe β‘οΈ explorer.exe (svchost.exe) β‘οΈ explorer.exe (COM) β‘οΈ powershell.exe β‘οΈ msiexec.exe
π See analysis session: https://app.any.run/tasks/7b295f6f-5f16-4a44-a02b-5d59fd4b1e8f?utm_source=tg_thehackernews&utm_medium=post&utm_campaign=techpost&utm_content=task&utm_term=201125
π Read full analysis: https://t.me/anyrun_app/698
#ANYRUN researchers identified #JSGuLdr, a multi-stage JavaScript-to-PowerShell loader used to deliver #PhantomStealer. A JScript file triggers PowerShell through an Explorer COM call, pulls the second stage from %APPDATA%\Registreri62, then uses Net.WebClient to fetch an encrypted payload from Google Drive into %APPDATA%\Autorise131[.]Tel. The payload is decoded in memory and loaded, with PhantomStealerinjected into msiexec.exe.
Execution chain: wscript.exe β‘οΈ explorer.exe (svchost.exe) β‘οΈ explorer.exe (COM) β‘οΈ powershell.exe β‘οΈ msiexec.exe
π See analysis session: https://app.any.run/tasks/7b295f6f-5f16-4a44-a02b-5d59fd4b1e8f?utm_source=tg_thehackernews&utm_medium=post&utm_campaign=techpost&utm_content=task&utm_term=201125
π Read full analysis: https://t.me/anyrun_app/698
This media is not supported in your browser
VIEW IN TELEGRAM
Forwarded from The Hacker News
WhatsApp accounts are being hijacked worldwide via fake WhatsApp Web pages that mimic the official interface exactly β including auto-detected language and country flag.
You scan QR or type code β they take your account β message your friends for money + steal everything.
Check the new CTM360 report β see exactly how the fake pages look and how to stay safe β https://thehackernews.com/2025/11/ctm360-exposes-global-whatsapp.html
You scan QR or type code β they take your account β message your friends for money + steal everything.
Check the new CTM360 report β see exactly how the fake pages look and how to stay safe β https://thehackernews.com/2025/11/ctm360-exposes-global-whatsapp.html
This media is not supported in your browser
VIEW IN TELEGRAM
Forwarded from The Hacker News
Hackers made a new botnet called Tsundere β itβs spreading through fake game downloads like Valorant and CS2.
It hides its servers on the Ethereum blockchain, making it almost impossible to shut down.
Researchers say itβs still active.
Read more β https://thehackernews.com/2025/11/tsundere-botnet-expands-using-game.html
It hides its servers on the Ethereum blockchain, making it almost impossible to shut down.
Researchers say itβs still active.
Read more β https://thehackernews.com/2025/11/tsundere-botnet-expands-using-game.html
This media is not supported in your browser
VIEW IN TELEGRAM
Forwarded from The Hacker News
π¨ Hackers are exploiting a 2-year-old authentication flaw (CVE-2023-48022) in the Ray AI framework to take over NVIDIA GPU clusters and run a self-spreading crypto-mining botnet called ShadowRay 2.0.
The bug remains unpatched by design, and over 230,000 Ray servers are exposed online.
Read about it here β https://thehackernews.com/2025/11/shadowray-20-exploits-unpatched-ray.html
The bug remains unpatched by design, and over 230,000 Ray servers are exposed online.
Read about it here β https://thehackernews.com/2025/11/shadowray-20-exploits-unpatched-ray.html
This media is not supported in your browser
VIEW IN TELEGRAM
Forwarded from vx-underground
Today Microsoft unveiled the new features coming to Windows 11 and what an "agentic OS" is.
Introducing: Copilot Actions
With Copilot actions, Microsoft Copilot AI can have access to your file system. Copilot Actions will carry out tasks for you.
https://www.pcgamer.com/software/windows/apparently-windows-11-becoming-agentic-ai-means-letting-the-bots-rummage-through-some-of-your-files/
Introducing: Copilot Actions
With Copilot actions, Microsoft Copilot AI can have access to your file system. Copilot Actions will carry out tasks for you.
https://www.pcgamer.com/software/windows/apparently-windows-11-becoming-agentic-ai-means-letting-the-bots-rummage-through-some-of-your-files/
PC Gamer
Apparently Windows 11 becoming 'agentic AI' means letting the bots rummage through some of your files
Thanks, I guess.
This media is not supported in your browser
VIEW IN TELEGRAM