Most MSPs are walking straight into a trap.
Clients now expect enterprise-level cybersecurity β but many providers are still selling basic IT support.
The result? Lost clients, slower growth, and higher risk exposure.
Is your MSP ready to lead with security? β https://thehackernews.com/2025/10/the-msp-cybersecurity-readiness-guide.html
Clients now expect enterprise-level cybersecurity β but many providers are still selling basic IT support.
The result? Lost clients, slower growth, and higher risk exposure.
Is your MSP ready to lead with security? β https://thehackernews.com/2025/10/the-msp-cybersecurity-readiness-guide.html
π8
β οΈ Chinese hackers are exploiting a critical 9.3 CVE (CVE-2025-61932) in Motex Lanscope Endpoint Manager.
It lets them run SYSTEM-level commands and plant a Gokcpdoor backdoor with new multiplexed C2 channels.
Active attacks confirmed β https://thehackernews.com/2025/10/china-linked-tick-group-exploits.html
It lets them run SYSTEM-level commands and plant a Gokcpdoor backdoor with new multiplexed C2 channels.
Active attacks confirmed β https://thehackernews.com/2025/10/china-linked-tick-group-exploits.html
π16π±4β‘1π€―1
π¨ China-backed hackers exploited an unpatched Windows shortcut bug to breach European diplomats.
UNC6384 used fake βEU Commissionβ and NATO meeting invites to plant PlugX malware (CVE-2025-9491) β still unpatched by Microsoft.
Full story β https://thehackernews.com/2025/10/china-linked-hackers-exploit-windows.html
UNC6384 used fake βEU Commissionβ and NATO meeting invites to plant PlugX malware (CVE-2025-9491) β still unpatched by Microsoft.
Full story β https://thehackernews.com/2025/10/china-linked-hackers-exploit-windows.html
π±15π6π2π€―1
Nation-state hackers built Airstalk, a new malware abusing VMware Workspace ONEβs MDM API as a covert C2 channel.
Signed with a stolen cert, itβs exfiltrating browser data from BPO networks.
Full analysis β https://thehackernews.com/2025/10/nation-state-hackers-deploy-new.html
Signed with a stolen cert, itβs exfiltrating browser data from BPO networks.
Full analysis β https://thehackernews.com/2025/10/nation-state-hackers-deploy-new.html
π14π3π€―2
π₯ OpenAI just launched an AI #cybersecurity researcher.
It finds bugs, proves theyβre real, and patches them β all by itself.
Powered by GPT-5, itβs already discovered 10 vulnerabilities.
The age of autonomous bug hunters starts now β https://thehackernews.com/2025/10/openai-unveils-aardvark-gpt-5-agent.html
It finds bugs, proves theyβre real, and patches them β all by itself.
Powered by GPT-5, itβs already discovered 10 vulnerabilities.
The age of autonomous bug hunters starts now β https://thehackernews.com/2025/10/openai-unveils-aardvark-gpt-5-agent.html
β‘27π±15π₯10π9π5π€3π1
π Chrome is going fully HTTPS by default starting April 2026.
Google will make βAlways Use Secure Connectionsβ the default settingβfirst for Enhanced Safe Browsing users, then for everyone by October 2026.
No more HTTP by default. Safer web, less room for attacks.
Full details β https://thehackernews.com/2025/10/threatsday-bulletin-dns-poisoning-flaw.html#chrome-takes-final-step-toward-full-https-web
#ThreatsDay
Google will make βAlways Use Secure Connectionsβ the default settingβfirst for Enhanced Safe Browsing users, then for everyone by October 2026.
No more HTTP by default. Safer web, less room for attacks.
Full details β https://thehackernews.com/2025/10/threatsday-bulletin-dns-poisoning-flaw.html#chrome-takes-final-step-toward-full-https-web
#ThreatsDay
π₯35π9β‘5π€3π2π€―1
π¨ 400+ Cisco routers hacked across Australia!
A new implant called BADCANDY is exploiting CVE-2023-20198 β even after patches.
Rebooting wonβt help. Hackers just come back.
Watch for fake cisco_sys_manager accounts β https://thehackernews.com/2025/11/asd-warns-of-ongoing-badcandy-attacks.html
A new implant called BADCANDY is exploiting CVE-2023-20198 β even after patches.
Rebooting wonβt help. Hackers just come back.
Watch for fake cisco_sys_manager accounts β https://thehackernews.com/2025/11/asd-warns-of-ongoing-badcandy-attacks.html
π₯25π3π€―3π2
β οΈ North Koreaβs Kimsuky just dropped a new backdoor β HttpTroy β hidden in a fake VPN invoice.
It shows a decoy PDF, sets a fake βAhnlabUpdateβ task, and rebuilds code on the fly to dodge detection.
Details β https://thehackernews.com/2025/11/new-httptroy-backdoor-poses-as-vpn.html
It shows a decoy PDF, sets a fake βAhnlabUpdateβ task, and rebuilds code on the fly to dodge detection.
Details β https://thehackernews.com/2025/11/new-httptroy-backdoor-poses-as-vpn.html
π₯9π€4π€―3π2
π΅οΈ Two Android trojans are silently draining accounts.
πΉ One pretends to be a government ID app.
πΉ The other hides as a food delivery tracker.
They even mute your phone β so you never hear it happen.
Learn more about BankBot-YNRK & DeliveryRAT β https://thehackernews.com/2025/11/researchers-uncover-bankbot-ynrk-and.html
πΉ One pretends to be a government ID app.
πΉ The other hides as a food delivery tracker.
They even mute your phone β so you never hear it happen.
Learn more about BankBot-YNRK & DeliveryRAT β https://thehackernews.com/2025/11/researchers-uncover-bankbot-ynrk-and.html
π11π€1π€―1
Last week: hacked security tools, broken chip protections, smart AI malware, and dev tools used to attack us.
Hackers are moving faster than we can stop them.
See all the top threats: https://thehackernews.com/2025/11/weekly-recap-lazarus-hits-web3-intelamd.html
Hackers are moving faster than we can stop them.
See all the top threats: https://thehackernews.com/2025/11/weekly-recap-lazarus-hits-web3-intelamd.html
π11π₯3π2π1
π¨ Hackers are now hijacking trucking/logistics firms β not just for data, but for the cargo itself.
Theyβre loading up legit remote-management tools like ScreenConnect & LogMeIn, hijacking load-boards and booking real shipments of food/beverage.
Read how β https://thehackernews.com/2025/11/cybercriminals-exploit-remote.html
Theyβre loading up legit remote-management tools like ScreenConnect & LogMeIn, hijacking load-boards and booking real shipments of food/beverage.
Read how β https://thehackernews.com/2025/11/cybercriminals-exploit-remote.html
π14π₯8π3
π§ SOC teams built to stop breaches... are built to miss them.
Detection tools catch signals, not connections β and attackers live in the gaps.
The future isnβt faster alerts. Itβs smarter context.
π Donβt miss how theyβre doing it β https://thehackernews.com/2025/11/the-evolution-of-soc-operations-how.html
Detection tools catch signals, not connections β and attackers live in the gaps.
The future isnβt faster alerts. Itβs smarter context.
π Donβt miss how theyβre doing it β https://thehackernews.com/2025/11/the-evolution-of-soc-operations-how.html
π₯17π€2
π¨ Microsoft just found a new backdoor called SesameOp β and itβs using the OpenAI Assistants API to talk to its attackers.
Instead of sketchy servers, it hides inside legit AI traffic. It lived undetected for months.
Commands were sent through the βdescriptionβ field.
Read how it works β https://thehackernews.com/2025/11/microsoft-detects-sesameop-backdoor.html
Instead of sketchy servers, it hides inside legit AI traffic. It lived undetected for months.
Commands were sent through the βdescriptionβ field.
Read how it works β https://thehackernews.com/2025/11/microsoft-detects-sesameop-backdoor.html
π22π±6π3π₯3
π₯ Ransomware negotiators turned attackers.
They were supposed to stop hackers β but instead used BlackCat ransomware to hit 5 U.S. companies.
They demanded up to $10M. One company actually paid.
Full story β https://thehackernews.com/2025/11/us-prosecutors-indict-cybersecurity.html
They were supposed to stop hackers β but instead used BlackCat ransomware to hit 5 U.S. companies.
They demanded up to $10M. One company actually paid.
Full story β https://thehackernews.com/2025/11/us-prosecutors-indict-cybersecurity.html
π₯8π€―4π2π2
β‘ Googleβs AI just found 5 serious bugs in Appleβs Safari β before hackers did.
One flaw could crash your browser instantly, another could break memory protection.
Appleβs patched them all. Update now.
Full story β https://thehackernews.com/2025/11/googles-ai-big-sleep-finds-5-new.html
One flaw could crash your browser instantly, another could break memory protection.
Appleβs patched them all. Update now.
Full story β https://thehackernews.com/2025/11/googles-ai-big-sleep-finds-5-new.html
π±18π4π€―4
π‘ Your AI-SOC works best when it keeps learning.
Without regular analyst feedback, false alerts rise and real threats slip by.
The real upgrade isnβt a new model β itβs a continuous feedback loop.
Read how it works β https://thehackernews.com/expert-insights/2025/11/continuous-feedback-loops-why-training.html
Without regular analyst feedback, false alerts rise and real threats slip by.
The real upgrade isnβt a new model β itβs a continuous feedback loop.
Read how it works β https://thehackernews.com/expert-insights/2025/11/continuous-feedback-loops-why-training.html
β‘7
π¨ A new cyber-espionage campaign, Operation SkyCloak, is targeting defense networks in Russia and Belarus.
Attackers use fake military documents to install a hidden SSH backdoor that talks through Tor β disguised as a legit GitHub app.
Details here β https://thehackernews.com/2025/11/operation-skycloak-deploys-tor-enabled.html
Attackers use fake military documents to install a hidden SSH backdoor that talks through Tor β disguised as a legit GitHub app.
Details here β https://thehackernews.com/2025/11/operation-skycloak-deploys-tor-enabled.html
π±8π4π€―2π₯1
π¨ Researchers just found 4 serious flaws in Microsoft Teams that let attackers fake messages and impersonate coworkers β no βEditedβ label, no warning.
If your team uses Teams, read this now β https://thehackernews.com/2025/11/microsoft-teams-bugs-let-attackers.html
If your team uses Teams, read this now β https://thehackernews.com/2025/11/microsoft-teams-bugs-let-attackers.html
π±8π₯7π3π1
π¨ A critical CVSS 9.8 flaw in "react-native-community/cli" let anyone run OS commands on your dev machineβno login needed.
Itβs patched now, but millions of React Native devs were exposed for months.
Check your version and lock down that dev server. β https://thehackernews.com/2025/11/critical-react-native-cli-flaw-exposed.html
Itβs patched now, but millions of React Native devs were exposed for months.
Check your version and lock down that dev server. β https://thehackernews.com/2025/11/critical-react-native-cli-flaw-exposed.html
π₯9π3
π When ransomware hits, every second counts.
DOGE Big Balls spreads fast β encrypting files and leaving ransom notes everywhere.
Wazuh detects it early, isolates the threat, and stops the damage. Hereβs how their detection rules and live response work β https://thehackernews.com/2025/11/ransomware-defense-using-wazuh-open.html
DOGE Big Balls spreads fast β encrypting files and leaving ransom notes everywhere.
Wazuh detects it early, isolates the threat, and stops the damage. Hereβs how their detection rules and live response work β https://thehackernews.com/2025/11/ransomware-defense-using-wazuh-open.html
π₯9
π¨ A β¬600M crypto scam just got taken down.
9 suspects across 5 countries ran fake βinvestmentβ sites that looked 100% real. They even laundered the money on-chain β hiding millions in plain view.
Read here β https://thehackernews.com/2025/11/europol-and-eurojust-dismantle-600.html
9 suspects across 5 countries ran fake βinvestmentβ sites that looked 100% real. They even laundered the money on-chain β hiding millions in plain view.
Read here β https://thehackernews.com/2025/11/europol-and-eurojust-dismantle-600.html
π13