The Hacker News
โœ”
152K subscribers
1.87K photos
10 videos
3 files
7.79K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: [email protected]

๐ŸŒ Website: https://thehackernews.com
Download Telegram
๐Ÿšจ China-backed hackers exploited an unpatched Windows shortcut bug to breach European diplomats.

UNC6384 used fake โ€œEU Commissionโ€ and NATO meeting invites to plant PlugX malware (CVE-2025-9491) โ€” still unpatched by Microsoft.

Full story โ†“ https://thehackernews.com/2025/10/china-linked-hackers-exploit-windows.html
๐Ÿ˜ฑ16๐Ÿ˜7๐Ÿ‘2๐Ÿคฏ1
Nation-state hackers built Airstalk, a new malware abusing VMware Workspace ONEโ€™s MDM API as a covert C2 channel.

Signed with a stolen cert, itโ€™s exfiltrating browser data from BPO networks.

Full analysis โ†“ https://thehackernews.com/2025/10/nation-state-hackers-deploy-new.html
๐Ÿ‘14๐Ÿ‘3๐Ÿคฏ3
๐Ÿ”ฅ OpenAI just launched an AI #cybersecurity researcher.

It finds bugs, proves theyโ€™re real, and patches them โ€” all by itself.

Powered by GPT-5, itโ€™s already discovered 10 vulnerabilities.

The age of autonomous bug hunters starts now โ†’ https://thehackernews.com/2025/10/openai-unveils-aardvark-gpt-5-agent.html
โšก27๐Ÿ˜ฑ15๐Ÿ”ฅ10๐Ÿ˜9๐Ÿ‘5๐Ÿค”4๐Ÿ‘1
๐Ÿ”’ Chrome is going fully HTTPS by default starting April 2026.

Google will make โ€œAlways Use Secure Connectionsโ€ the default settingโ€”first for Enhanced Safe Browsing users, then for everyone by October 2026.

No more HTTP by default. Safer web, less room for attacks.

Full details โ†“ https://thehackernews.com/2025/10/threatsday-bulletin-dns-poisoning-flaw.html#chrome-takes-final-step-toward-full-https-web
#ThreatsDay
๐Ÿ”ฅ35๐Ÿ˜9โšก5๐Ÿค”5๐Ÿ‘2๐Ÿคฏ1
๐Ÿšจ 400+ Cisco routers hacked across Australia!

A new implant called BADCANDY is exploiting CVE-2023-20198 โ€” even after patches.

Rebooting wonโ€™t help. Hackers just come back.

Watch for fake cisco_sys_manager accounts โ†“ https://thehackernews.com/2025/11/asd-warns-of-ongoing-badcandy-attacks.html
๐Ÿ”ฅ25๐Ÿ˜3๐Ÿคฏ3๐Ÿ‘2
โš ๏ธ North Koreaโ€™s Kimsuky just dropped a new backdoor โ€” HttpTroy โ€” hidden in a fake VPN invoice.

It shows a decoy PDF, sets a fake โ€œAhnlabUpdateโ€ task, and rebuilds code on the fly to dodge detection.

Details โ†“ https://thehackernews.com/2025/11/new-httptroy-backdoor-poses-as-vpn.html
๐Ÿ”ฅ10๐Ÿค”6๐Ÿคฏ4๐Ÿ‘2
๐Ÿ•ต๏ธ Two Android trojans are silently draining accounts.

๐Ÿ”น One pretends to be a government ID app.
๐Ÿ”น The other hides as a food delivery tracker.

They even mute your phone โ€” so you never hear it happen.

Learn more about BankBot-YNRK & DeliveryRAT โ†“ https://thehackernews.com/2025/11/researchers-uncover-bankbot-ynrk-and.html
๐Ÿ˜12๐Ÿ‘1๐Ÿค”1๐Ÿคฏ1
Last week: hacked security tools, broken chip protections, smart AI malware, and dev tools used to attack us.

Hackers are moving faster than we can stop them.

See all the top threats: https://thehackernews.com/2025/11/weekly-recap-lazarus-hits-web3-intelamd.html
๐Ÿ‘11๐Ÿ”ฅ3๐Ÿ‘2๐Ÿ˜1
๐Ÿšจ Hackers are now hijacking trucking/logistics firms โ€” not just for data, but for the cargo itself.

Theyโ€™re loading up legit remote-management tools like ScreenConnect & LogMeIn, hijacking load-boards and booking real shipments of food/beverage.

Read how โ†’ https://thehackernews.com/2025/11/cybercriminals-exploit-remote.html
๐Ÿ‘14๐Ÿ”ฅ9๐Ÿ˜3
๐Ÿง  SOC teams built to stop breaches... are built to miss them.

Detection tools catch signals, not connections โ€” and attackers live in the gaps.

The future isnโ€™t faster alerts. Itโ€™s smarter context.

๐Ÿ” Donโ€™t miss how theyโ€™re doing it โ†“ https://thehackernews.com/2025/11/the-evolution-of-soc-operations-how.html
๐Ÿ”ฅ18๐Ÿค”2
๐Ÿšจ Microsoft just found a new backdoor called SesameOp โ€” and itโ€™s using the OpenAI Assistants API to talk to its attackers.

Instead of sketchy servers, it hides inside legit AI traffic. It lived undetected for months.

Commands were sent through the โ€œdescriptionโ€ field.

Read how it works โ†“ https://thehackernews.com/2025/11/microsoft-detects-sesameop-backdoor.html
๐Ÿ˜23๐Ÿ˜ฑ6๐Ÿ”ฅ4๐Ÿ‘3
๐Ÿ”ฅ Ransomware negotiators turned attackers.

They were supposed to stop hackers โ€” but instead used BlackCat ransomware to hit 5 U.S. companies.

They demanded up to $10M. One company actually paid.

Full story โ†“ https://thehackernews.com/2025/11/us-prosecutors-indict-cybersecurity.html
๐Ÿ”ฅ9๐Ÿคฏ4๐Ÿ‘2๐Ÿ˜2
โšก Googleโ€™s AI just found 5 serious bugs in Appleโ€™s Safari โ€” before hackers did.

One flaw could crash your browser instantly, another could break memory protection.

Appleโ€™s patched them all. Update now.

Full story โ†’ https://thehackernews.com/2025/11/googles-ai-big-sleep-finds-5-new.html
๐Ÿ˜ฑ18๐Ÿ˜6๐Ÿคฏ4
๐Ÿ’ก Your AI-SOC works best when it keeps learning.

Without regular analyst feedback, false alerts rise and real threats slip by.

The real upgrade isnโ€™t a new model โ€” itโ€™s a continuous feedback loop.

Read how it works โ†“ https://thehackernews.com/expert-insights/2025/11/continuous-feedback-loops-why-training.html
โšก8
๐Ÿšจ A new cyber-espionage campaign, Operation SkyCloak, is targeting defense networks in Russia and Belarus.

Attackers use fake military documents to install a hidden SSH backdoor that talks through Tor โ€” disguised as a legit GitHub app.

Details here โ†“ https://thehackernews.com/2025/11/operation-skycloak-deploys-tor-enabled.html
๐Ÿ˜ฑ8๐Ÿ‘6๐Ÿคฏ2๐Ÿ”ฅ1
๐Ÿšจ Researchers just found 4 serious flaws in Microsoft Teams that let attackers fake messages and impersonate coworkers โ€” no โ€œEditedโ€ label, no warning.

If your team uses Teams, read this now โ†“ https://thehackernews.com/2025/11/microsoft-teams-bugs-let-attackers.html
๐Ÿ”ฅ8๐Ÿ˜ฑ8๐Ÿ˜4๐Ÿ‘1
๐Ÿšจ A critical CVSS 9.8 flaw in "react-native-community/cli" let anyone run OS commands on your dev machineโ€”no login needed.

Itโ€™s patched now, but millions of React Native devs were exposed for months.

Check your version and lock down that dev server. โ†’ https://thehackernews.com/2025/11/critical-react-native-cli-flaw-exposed.html
๐Ÿ”ฅ11๐Ÿ˜4
๐Ÿ•’ When ransomware hits, every second counts.

DOGE Big Balls spreads fast โ€” encrypting files and leaving ransom notes everywhere.

Wazuh detects it early, isolates the threat, and stops the damage. Hereโ€™s how their detection rules and live response work โ†“ https://thehackernews.com/2025/11/ransomware-defense-using-wazuh-open.html
๐Ÿ”ฅ10
๐Ÿšจ A โ‚ฌ600M crypto scam just got taken down.

9 suspects across 5 countries ran fake โ€œinvestmentโ€ sites that looked 100% real. They even laundered the money on-chain โ€” hiding millions in plain view.

Read here โ†“ https://thehackernews.com/2025/11/europol-and-eurojust-dismantle-600.html
๐Ÿ‘14
๐Ÿ› ๏ธ You patch daily.
๐Ÿ•ต๏ธ You scan weekly.
โšกBut your attack surface changes every hour.

Static defenses canโ€™t keep up.

Join The Hacker News x Bitdefender webinar to see how Dynamic Attack Surface Reduction (DASR) keeps you ahead โž  https://thehacker.news/attack-surface-reduction
๐Ÿ”ฅ6
๐Ÿ”ฅ Three of the internetโ€™s most notorious hacker crews โ€” Scattered Spider, LAPSUS$, and ShinyHunters โ€” just merged into one cartel: Scattered LAPSUS$ Hunters.

Theyโ€™ve rebuilt their Telegram network 16 times in 80 days and now run extortion-as-a-service for affiliates.

Details here โ†“ https://thehackernews.com/2025/11/a-cybercrime-merger-like-no-other.html
๐Ÿ‘12๐Ÿ˜8๐Ÿ”ฅ5