π¨ AI tools are now running inside your browser β reading data, following hidden prompts, and moving info across tabs.
IT canβt see it. Security canβt stop it.
Seraphic Securityβs Suresh Batchu calls this the next big blind spot: Shadow AI in the enterprise browser.
π Read β https://thehackernews.com/expert-insights/2025/12/shadow-ai-in-browser-next-enterprise.html
IT canβt see it. Security canβt stop it.
Seraphic Securityβs Suresh Batchu calls this the next big blind spot: Shadow AI in the enterprise browser.
π Read β https://thehackernews.com/expert-insights/2025/12/shadow-ai-in-browser-next-enterprise.html
π€―13π6π€3π2
π¨ A fake Microsoft Teams installer is spreading malware in China.
Hackers called "Silver Fox" made it look like a Russian attack to hide their tracks.
It installs ValleyRAT, giving full remote access to victims.
π Read: https://thehackernews.com/2025/12/silver-fox-uses-fake-microsoft-teams.html
Hackers called "Silver Fox" made it look like a Russian attack to hide their tracks.
It installs ValleyRAT, giving full remote access to victims.
π Read: https://thehackernews.com/2025/12/silver-fox-uses-fake-microsoft-teams.html
π14π₯12
β οΈ Hackers are exploiting a command injection bug in Array Networks AG Series gateways β active since August 2025.
It lets attackers run any command on systems using βDesktopDirectβ remote access.
π Details β https://thehackernews.com/2025/12/jpcert-confirms-active-command.html
It lets attackers run any command on systems using βDesktopDirectβ remote access.
π Details β https://thehackernews.com/2025/12/jpcert-confirms-active-command.html
π₯9π4π3
π¨ CISA just warned about a new Chinese state-backed hack tool called BRICKSTORM β a backdoor found in VMware and Windows systems used by U.S. government and tech networks.
It can reinstall itself if removed, hide in normal traffic, and give hackers full remote control.
πRead β https://thehackernews.com/2025/12/cisa-reports-prc-hackers-using.html
It can reinstall itself if removed, hide in normal traffic, and give hackers full remote control.
πRead β https://thehackernews.com/2025/12/cisa-reports-prc-hackers-using.html
π€―20π₯6π3π2
π¨ A lawyer in Pakistan was hacked with Predator β the first known spyware attack on a civil society member.
It started with a link on WhatsApp, but new leaks show Predator can also spread through ads β no click needed.
It can read chats, record audio, take photos β and Intellexa may still access customer systems remotely.
π Read β https://thehackernews.com/2025/12/intellexa-leaks-reveal-zero-days-and.html
It started with a link on WhatsApp, but new leaks show Predator can also spread through ads β no click needed.
It can read chats, record audio, take photos β and Intellexa may still access customer systems remotely.
π Read β https://thehackernews.com/2025/12/intellexa-leaks-reveal-zero-days-and.html
π9π±5π₯2π1
β οΈ Within HOURS of disclosure, two China-linked hacking groups weaponized a critical React flaw (CVE-2025-55182).
Theyβre already scanning the web for unpatched apps.
Update to React 19.0.1+ now.
π Read β https://thehackernews.com/2025/12/chinese-hackers-have-started-exploiting.html
Theyβre already scanning the web for unpatched apps.
Update to React 19.0.1+ now.
π Read β https://thehackernews.com/2025/12/chinese-hackers-have-started-exploiting.html
π€―7π₯4
π¨ Critical Apache Tika flaw (CVE-2025-66516) just dropped β CVSS 10.0.
A single fake PDF can trigger an XXE attack, letting hackers read server files or run code.
π Read β https://thehackernews.com/2025/12/critical-xxe-bug-cve-2025-66516-cvss.html
Update to v3.2.2 now.
A single fake PDF can trigger an XXE attack, letting hackers read server files or run code.
π Read β https://thehackernews.com/2025/12/critical-xxe-bug-cve-2025-66516-cvss.html
Update to v3.2.2 now.
π₯13π€5π±1
π§© 57% of SMBs say cybersecurity is a top priority β yet they still turn down MSPs.
β‘ The issue isnβt interest. Itβs confusion.
β‘ Theyβre tired of jargon, fear, and hard selling.
βGetting to Yesβ helps MSPs explain security in plain business terms β and win trust.
π See how itβs done β https://thehackernews.com/2025/12/getting-to-yes-anti-sales-guide-for-msps.html
β‘ The issue isnβt interest. Itβs confusion.
β‘ Theyβre tired of jargon, fear, and hard selling.
βGetting to Yesβ helps MSPs explain security in plain business terms β and win trust.
π See how itβs done β https://thehackernews.com/2025/12/getting-to-yes-anti-sales-guide-for-msps.html
π4
π¨ WARNING: A new attack can trick Perplexityβs Comet browser into deleting your Google Drive.
Just one normal-looking email with hidden cleanup instructions can make the AI agent erase real files β no exploit, no warning.
π Details here β https://thehackernews.com/2025/12/zero-click-agentic-browser-attack-can.html
Just one normal-looking email with hidden cleanup instructions can make the AI agent erase real files β no exploit, no warning.
π Details here β https://thehackernews.com/2025/12/zero-click-agentic-browser-attack-can.html
π€―23π14π₯8
CISA added the new 10.0-rated React RCE flaw (CVE-2025-55182) to its exploited list.
π Exploited within hours by Chinese hackers.
π₯ Affects Next.js, React Router, Vite, Waku & more.
π° Some attacks dropped crypto-miners & stole AWS creds.
π Read: https://thehackernews.com/2025/12/critical-react2shell-flaw-added-to-cisa.html
π Exploited within hours by Chinese hackers.
π₯ Affects Next.js, React Router, Vite, Waku & more.
π° Some attacks dropped crypto-miners & stole AWS creds.
π Read: https://thehackernews.com/2025/12/critical-react2shell-flaw-added-to-cisa.html
π₯18π11π4π4π€―2
π Over 30 security flaws found in AI-powered coding tools like Copilot, Cursor, and Zed β letting hackers steal data or run malicious code without you doing a thing.
Researchers are calling it βIDEsaster.β
π Details here β https://thehackernews.com/2025/12/researchers-uncover-30-flaws-in-ai.html
Researchers are calling it βIDEsaster.β
π Details here β https://thehackernews.com/2025/12/researchers-uncover-30-flaws-in-ai.html
π32π15π€―12π₯1
β οΈ Iranβs MuddyWater hackers are using a new backdoor called "UDPGangster" that hides in fake βelection seminarβ Word files.
It only runs after checking if your computer is real β not a sandbox β then steals data over UDP to dodge detection.
π Read β https://thehackernews.com/2025/12/muddywater-deploys-udpgangster-backdoor.html
It only runs after checking if your computer is real β not a sandbox β then steals data over UDP to dodge detection.
π Read β https://thehackernews.com/2025/12/muddywater-deploys-udpgangster-backdoor.html
π17π₯10π€―8β‘4π4π€2
β οΈ Hackers are exploiting a bug in the Sneeit Framework plugin (CVE-2025-6389) to run code on servers and create admin accounts on WordPress sites.
β οΈ Separately, a flaw in ICTBroadcast (CVE-2025-2611) lets attackers use the BROADCAST cookie for unauthenticated remote shell access on exposed hosts.
π Read β https://thehackernews.com/2025/12/sneeit-wordpress-rce-exploited-in-wild.html
β οΈ Separately, a flaw in ICTBroadcast (CVE-2025-2611) lets attackers use the BROADCAST cookie for unauthenticated remote shell access on exposed hosts.
π Read β https://thehackernews.com/2025/12/sneeit-wordpress-rce-exploited-in-wild.html
π€10π3π±2
β οΈ Three new Android threats just dropped:
β’ FvncBot β fake βmBankβ app that logs keys, streams screens, and steals banking data.
β’ SeedSnatcher β spreads via Telegram to steal crypto seed phrases and 2FA codes.
β’ ClayRat β upgraded spyware faking YouTube & taxi apps for full device control.
All abuse Androidβs accessibility features.
π Read here β https://thehackernews.com/2025/12/android-malware-fvncbot-seedsnatcher.html
β’ FvncBot β fake βmBankβ app that logs keys, streams screens, and steals banking data.
β’ SeedSnatcher β spreads via Telegram to steal crypto seed phrases and 2FA codes.
β’ ClayRat β upgraded spyware faking YouTube & taxi apps for full device control.
All abuse Androidβs accessibility features.
π Read here β https://thehackernews.com/2025/12/android-malware-fvncbot-seedsnatcher.html
π₯12π4π€―4π3π2
β οΈ Holiday shopping means hacker season.
Bots hit hardest around Black Friday & Christmas.
Reused passwords = easy targets.
Block breached logins + secure vendor accounts now.
π Read β https://thehackernews.com/2025/12/how-can-retailers-cyber-prepare-for.html
Bots hit hardest around Black Friday & Christmas.
Reused passwords = easy targets.
Block breached logins + secure vendor accounts now.
π Read β https://thehackernews.com/2025/12/how-can-retailers-cyber-prepare-for.html
β‘11
Catch the the latest CybersecurityRecap for:
π₯ USB drives spreading crypto miners.
π° Fake investment sites busted.
π CastleRAT creeping through networks.
βοΈ Portugal shields ethical hackers.
πΈ Ransomware payouts falling fast.
π Get the full stories, latest tools, and expert webinars in the latest recap: https://thehackernews.com/2025/12/weekly-recap-usb-malware-react2shell.html
π₯ USB drives spreading crypto miners.
π° Fake investment sites busted.
π CastleRAT creeping through networks.
βοΈ Portugal shields ethical hackers.
πΈ Ransomware payouts falling fast.
π Get the full stories, latest tools, and expert webinars in the latest recap: https://thehackernews.com/2025/12/weekly-recap-usb-malware-react2shell.html
β‘6π4π₯1π1
β οΈ Hackers are hiding malware in normal websites.
A new attack called JS#SMUGGLER plants code that quietly runs PowerShell through mshta.exe to install NetSupport RAT β giving attackers full control of your computer.
It even checks your device type to avoid being caught.
π Read β https://thehackernews.com/2025/12/experts-confirm-jssmuggler-uses.html
A new attack called JS#SMUGGLER plants code that quietly runs PowerShell through mshta.exe to install NetSupport RAT β giving attackers full control of your computer.
It even checks your device type to avoid being caught.
π Read β https://thehackernews.com/2025/12/experts-confirm-jssmuggler-uses.html
π€16π€―10π5π₯2π2
β οΈ Researchers found malicious packages in VS Code, Go, npm, and Rust stealing developer data.
They mimicked themes, AI tools, and libraries to grab screenshots, Wi-Fi passwords, and browser cookies.
π Find details here β https://thehackernews.com/2025/12/researchers-find-malicious-vs-code-go.html
They mimicked themes, AI tools, and libraries to grab screenshots, Wi-Fi passwords, and browser cookies.
π Find details here β https://thehackernews.com/2025/12/researchers-find-malicious-vs-code-go.html
π€―16π5π€4π2π₯1
π¨ Hackers are uploading fake resumes on Indeed and JazzHR to breach Canadian companies.
80% of attacks in this campaign hit Canada.
The βPDFsβ actually launch QWCrypt ransomware through a tool called RedLoader.
π Read: https://thehackernews.com/2025/12/stac6565-targets-canada-in-80-of.html
80% of attacks in this campaign hit Canada.
The βPDFsβ actually launch QWCrypt ransomware through a tool called RedLoader.
π Read: https://thehackernews.com/2025/12/stac6565-targets-canada-in-80-of.html
π±12π6π5
π₯ You can win $20K for breaking Googleβs new Chrome security feature.
Google just added the βUser Alignment Critic,β a safeguard that uses a second model to double-check Chromeβs AI agent and block prompt attacks or data leaks.
π Read: https://thehackernews.com/2025/12/google-adds-layered-defenses-to-chrome.html
Google just added the βUser Alignment Critic,β a safeguard that uses a second model to double-check Chromeβs AI agent and block prompt attacks or data leaks.
π Read: https://thehackernews.com/2025/12/google-adds-layered-defenses-to-chrome.html
π19π₯7π€7
π‘ Most Zero Trust tools still donβt talk to each other β so access decisions lag behind real risks.
A MongoDB engineer built a workflow using Tines that lets Kolide send real-time device alerts to Okta through the Shared Signals Framework.
Finally, Zero Trust that actually works in sync.
π Read: https://thehackernews.com/2025/12/how-to-streamline-zero-trust-using.html
A MongoDB engineer built a workflow using Tines that lets Kolide send real-time device alerts to Okta through the Shared Signals Framework.
Finally, Zero Trust that actually works in sync.
π Read: https://thehackernews.com/2025/12/how-to-streamline-zero-trust-using.html
π14