The Hacker News
βœ”
153K subscribers
1.99K photos
11 videos
3 files
7.91K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
Media is too big
VIEW IN TELEGRAM
πŸ€– We talk a lot about securing AI.

Almost no one talks about where it’s actually hiding.

NetworkChuck just dropped a video with Wiz, showing how they’re finding hidden AI risksβ€”β€œshadow AI”—before attackers do. It’s a smart look at where cloud security is headed next.

πŸš€See Wiz in Action β†’ https://thn.news/cloud-security-demo
😁13πŸ‘9πŸ”₯3🀯1
πŸ”₯ Hackers hit South Korea’s banks through one IT vendor β€” spreading Qilin ransomware to 28 firms and stealing 2 TB of data.

Evidence suggests Russian and North Korean groups worked together.

Full story ↓ https://thehackernews.com/2025/11/qilin-ransomware-turns-south-korean-msp.html
🀯21πŸ”₯9😱6😁3
⚠️ Eight β€œadvanced” tools failed at once.

A phishing attack slipped past all of them and reached exec inboxes. Only one thing stopped it β€” a strong SOC.

πŸ”— Learn why your β€œfirst line” is useless without the last ↓ https://thehackernews.com/2025/11/when-your-2m-security-detection-fails.html
πŸ‘12
⚠️ Hundreds of Maven packages just got caught running Shai-Hulud v2 β€” the same malware that hijacked npm.

It spread through automated rebuilds, infecting devs who never used npm.

Hiding in the Bun runtime, it steals GitHub + cloud creds and self-replicates like a worm β€” already leaking 11,000+ secrets across 4,600 repos.

Details here ↓ https://thehackernews.com/2025/11/shai-hulud-v2-campaign-spreads-from-npm.html
πŸ‘12πŸ”₯6
πŸ›‘ Gainsight just revealed more customers were affected than originally disclosed.

Salesforce revoked all Gainsight access tokens after the breach tied to ShinyHunters β€” and the same user-agent from prior Salesloft attacks popped up again.

The full scope remains unknown.

Read here β†’ https://thehackernews.com/2025/11/gainsight-expands-impacted-customer.html
😱6πŸ‘5
🚨 New ThreatsDay Bulletin is live!

πŸ€– AI malware that learns your habits
πŸ“ž Voice bots turned into attack tools
πŸ’Έ Crypto rings laundering billions
πŸ”Œ IoT gear under siege again
🌍 Smishing scams spreading worldwide

All that and 20+ more stories shaping the week in cybersecurity.

πŸ”— Read now: https://thehackernews.com/2025/11/threatsday-bulletin-ai-malware-voice.html
πŸ”₯9πŸ€”5
Microsoft will block all non-Microsoft scripts on Entra ID logins starting Oct 2026.

If your sign-in flow or browser extension injects any code, it may break β€” so test ASAP.

The new Content Security Policy only lets trusted Microsoft-hosted scripts.

Read more β†’ https://thehackernews.com/2025/11/microsoft-to-block-unauthorized-scripts.html
πŸ€”12πŸ‘9😁3
Hackers posing as Kyrgyzstan’s Justice Ministry are spreading 2013-era NetSupport RAT across Kyrgyzstan and Uzbekistan using fake PDFs and old Java tricksβ€”blocking outsiders to hide the attack.

Old tools. New victims. β†’ https://thehackernews.com/2025/11/bloody-wolf-expands-java-based.html
πŸ”₯19😁5πŸ‘4πŸ‘1
VPNs weren’t built for today’s hybrid networks. Hackers now exploit them as entry points to steal admin creds.

Remote Privileged Access Management (RPAM) closes that gap β€” no VPNs, no shared passwords, full session tracking.

Why it’s replacing PAM β†’ https://thehackernews.com/2025/11/why-organizations-are-turning-to-rpam.html
πŸ”₯14🀯6πŸ‘3😁1
🚨 North Korean hackers uploaded 197 malicious npm packages (31K+ downloads).

They drop a new OtterCookie variant that steals passwords, crypto data, and screenshots β€” all from a fake job interview setup.

Details here ↓ https://thehackernews.com/2025/11/north-korean-hackers-deploy-197-npm.html
πŸ‘8πŸ”₯6😱5πŸ‘3🀯1
⚠️ Researchers found old Python code that could expose projects to a supply chain attack.

Some PyPI packages β€” including Tornado and slapos.core β€” still call an expired domain that anyone could buy and use to run malicious code.

Details ↓ https://thehackernews.com/2025/11/legacy-python-bootstrap-scripts-create.html
πŸ”₯11😱7
🚨 CISA added a real-world exploited flaw in OpenPLC ScadaBR to its Known Exploited Vulnerabilities list.

Hackers used the bug (CVE-2021-26829) to deface a fake water plant system in under 26 hours β€” disabling logs and alarms.

Read β†’ https://thehackernews.com/2025/11/cisa-adds-actively-exploited-xss-bug.html
πŸ‘18πŸ”₯9⚑5
🚨 Tomiris is back β€” and harder to spot.

Kaspersky reports the group is using Telegram & Discord as C2 servers to hide attacks on government networks in Russia & Central Asia.

Its new malware β€” written in Python, Rust, Go, PowerShell & C#.

Full details ↓ https://thehackernews.com/2025/12/tomiris-shifts-to-public-service.html
😁15πŸ‘5
🚨 New Android malware Albiriox is being sold as a service.

It can remotely control phones, stream screens from banking apps, and fake updates to steal logins.

It even bypasses Android’s screen protections.

Read about it here β†’ https://thehackernews.com/2025/12/new-albiriox-maas-malware-targets-400.html

Spread via fake Google Play links, it’s already targeting users in Austria.
😱12πŸ”₯5🀯5⚑4πŸ‘3
🚨 Webinar Alert: Resilient Patching β€” Guardrails for Community Repos

You trust your patching tools. Attackers trust that too. A single unsafe package on Chocolatey or Winget can flip your defenses against you.

Learn how top teams patch fast, safe, and under control.

πŸ‘‰ Register & get the full playbook β†’ https://thehacker.news/resilient-patching
πŸ‘6
🚨 The browser just became your riskiest employee.

New AI browsers like ChatGPT Atlas can act on your behalf β€” booking, buying, sending data. One hidden command can turn them against you.

Join this expert webinar to learn how to spot and stop these new AI browser threats ↓ https://thehackernews.com/2025/12/webinar-agentic-trojan-horse-why-new-ai.html
πŸ”₯7⚑2πŸ‘2
⚑ New Cyber Recap is live.

πŸ› npm worm returns
πŸ“§ M365 email + token raids
πŸ“± spyware on chat apps
🧱 Firefox RCE + hot CVEs
πŸ’Έ Cryptomixer takedown

If you ship code, manage access, or touch cloud… this one’s worth 3 minutes.

Read: https://thehackernews.com/2025/12/weekly-recap-hot-cves-npm-worm-returns.html
πŸ”₯7🀯3
🐼 ShadyPanda quietly turned trusted Chrome and Edge extensions into spyware.

Over 4.3 million installs in 7 years β€” some were even once verified by Google.

After silent updates in mid-2024, they began sending users’ browsing data and cookies to remote servers.

πŸ”— Read here β†’ https://thehackernews.com/2025/12/shadypanda-turns-popular-browser.html
😱12πŸ”₯4πŸ‘1
πŸ“’ URGENT: India just made a cybersecurity app mandatory on all new phones.

The app β€” Sanchar Saathi β€” can’t be deleted or disabled.

It helps report fraud, trace lost devices, and block illegal calls.

Full story ↓ https://thehackernews.com/2025/12/india-orders-phone-makers-to-pre.html

Phone makers have 90 days to preload it, and must also update phones already in the supply chain.
πŸ€”52😁22πŸ”₯9😱6⚑2🀯2πŸ‘1
⚠️ Google just fixed 107 security flaws in Android β€” including two that hackers already used in real attacks.

The exploited bugs (CVE-2025-48633 & CVE-2025-48572) affect the Android Framework and could expose data or give attackers higher access.

Read: https://thehackernews.com/2025/12/google-patches-107-android-flaws.html

πŸ“± Update your device as soon as the December patch is available.
πŸ‘13πŸ‘9🀯5
🚨 Iranian hackers are attacking Israeli networks with a new tool called MuddyViper.

The group MuddyWater used fake emails and VPN bugs to break into systems in tech, transport, and utilities.

MuddyViper can steal passwords, browser data, and control infected computers β€” while pretending to be the Snake game.

Read more β†’ https://thehackernews.com/2025/12/iran-linked-hackers-hits-israeli.html
πŸ”₯36πŸ‘18😁7πŸ‘6πŸ€”4