The Hacker News
βœ”
152K subscribers
1.95K photos
11 videos
3 files
7.87K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
🚨 New ThreatsDay Bulletin is live!

πŸ€– AI malware that learns your habits
πŸ“ž Voice bots turned into attack tools
πŸ’Έ Crypto rings laundering billions
πŸ”Œ IoT gear under siege again
🌍 Smishing scams spreading worldwide

All that and 20+ more stories shaping the week in cybersecurity.

πŸ”— Read now: https://thehackernews.com/2025/11/threatsday-bulletin-ai-malware-voice.html
πŸ”₯9πŸ€”5
Microsoft will block all non-Microsoft scripts on Entra ID logins starting Oct 2026.

If your sign-in flow or browser extension injects any code, it may break β€” so test ASAP.

The new Content Security Policy only lets trusted Microsoft-hosted scripts.

Read more β†’ https://thehackernews.com/2025/11/microsoft-to-block-unauthorized-scripts.html
πŸ€”12πŸ‘9😁3
Hackers posing as Kyrgyzstan’s Justice Ministry are spreading 2013-era NetSupport RAT across Kyrgyzstan and Uzbekistan using fake PDFs and old Java tricksβ€”blocking outsiders to hide the attack.

Old tools. New victims. β†’ https://thehackernews.com/2025/11/bloody-wolf-expands-java-based.html
πŸ”₯19πŸ‘4😁4πŸ‘1
VPNs weren’t built for today’s hybrid networks. Hackers now exploit them as entry points to steal admin creds.

Remote Privileged Access Management (RPAM) closes that gap β€” no VPNs, no shared passwords, full session tracking.

Why it’s replacing PAM β†’ https://thehackernews.com/2025/11/why-organizations-are-turning-to-rpam.html
πŸ”₯14🀯5πŸ‘3😁1
🚨 North Korean hackers uploaded 197 malicious npm packages (31K+ downloads).

They drop a new OtterCookie variant that steals passwords, crypto data, and screenshots β€” all from a fake job interview setup.

Details here ↓ https://thehackernews.com/2025/11/north-korean-hackers-deploy-197-npm.html
πŸ‘8πŸ”₯6😱4πŸ‘3🀯1
⚠️ Researchers found old Python code that could expose projects to a supply chain attack.

Some PyPI packages β€” including Tornado and slapos.core β€” still call an expired domain that anyone could buy and use to run malicious code.

Details ↓ https://thehackernews.com/2025/11/legacy-python-bootstrap-scripts-create.html
πŸ”₯11😱6
🚨 CISA added a real-world exploited flaw in OpenPLC ScadaBR to its Known Exploited Vulnerabilities list.

Hackers used the bug (CVE-2021-26829) to deface a fake water plant system in under 26 hours β€” disabling logs and alarms.

Read β†’ https://thehackernews.com/2025/11/cisa-adds-actively-exploited-xss-bug.html
πŸ‘18πŸ”₯9⚑5
🚨 Tomiris is back β€” and harder to spot.

Kaspersky reports the group is using Telegram & Discord as C2 servers to hide attacks on government networks in Russia & Central Asia.

Its new malware β€” written in Python, Rust, Go, PowerShell & C#.

Full details ↓ https://thehackernews.com/2025/12/tomiris-shifts-to-public-service.html
😁13πŸ‘5
🚨 New Android malware Albiriox is being sold as a service.

It can remotely control phones, stream screens from banking apps, and fake updates to steal logins.

It even bypasses Android’s screen protections.

Read about it here β†’ https://thehackernews.com/2025/12/new-albiriox-maas-malware-targets-400.html

Spread via fake Google Play links, it’s already targeting users in Austria.
😱12🀯5⚑3πŸ‘3πŸ”₯2
🚨 Webinar Alert: Resilient Patching β€” Guardrails for Community Repos

You trust your patching tools. Attackers trust that too. A single unsafe package on Chocolatey or Winget can flip your defenses against you.

Learn how top teams patch fast, safe, and under control.

πŸ‘‰ Register & get the full playbook β†’ https://thehacker.news/resilient-patching
πŸ‘5
🚨 The browser just became your riskiest employee.

New AI browsers like ChatGPT Atlas can act on your behalf β€” booking, buying, sending data. One hidden command can turn them against you.

Join this expert webinar to learn how to spot and stop these new AI browser threats ↓ https://thehackernews.com/2025/12/webinar-agentic-trojan-horse-why-new-ai.html
πŸ”₯5⚑1πŸ‘1
⚑ New Cyber Recap is live.

πŸ› npm worm returns
πŸ“§ M365 email + token raids
πŸ“± spyware on chat apps
🧱 Firefox RCE + hot CVEs
πŸ’Έ Cryptomixer takedown

If you ship code, manage access, or touch cloud… this one’s worth 3 minutes.

Read: https://thehackernews.com/2025/12/weekly-recap-hot-cves-npm-worm-returns.html
πŸ”₯5🀯2
🐼 ShadyPanda quietly turned trusted Chrome and Edge extensions into spyware.

Over 4.3 million installs in 7 years β€” some were even once verified by Google.

After silent updates in mid-2024, they began sending users’ browsing data and cookies to remote servers.

πŸ”— Read here β†’ https://thehackernews.com/2025/12/shadypanda-turns-popular-browser.html
😱8πŸ”₯1
πŸ“’ URGENT: India just made a cybersecurity app mandatory on all new phones.

The app β€” Sanchar Saathi β€” can’t be deleted or disabled.

It helps report fraud, trace lost devices, and block illegal calls.

Full story ↓ https://thehackernews.com/2025/12/india-orders-phone-makers-to-pre.html

Phone makers have 90 days to preload it, and must also update phones already in the supply chain.
πŸ€”23😁8πŸ”₯3πŸ‘1🀯1😱1