๐ Chrome is going fully HTTPS by default starting April 2026.
Google will make โAlways Use Secure Connectionsโ the default settingโfirst for Enhanced Safe Browsing users, then for everyone by October 2026.
No more HTTP by default. Safer web, less room for attacks.
Full details โ https://thehackernews.com/2025/10/threatsday-bulletin-dns-poisoning-flaw.html#chrome-takes-final-step-toward-full-https-web
#ThreatsDay
Google will make โAlways Use Secure Connectionsโ the default settingโfirst for Enhanced Safe Browsing users, then for everyone by October 2026.
No more HTTP by default. Safer web, less room for attacks.
Full details โ https://thehackernews.com/2025/10/threatsday-bulletin-dns-poisoning-flaw.html#chrome-takes-final-step-toward-full-https-web
#ThreatsDay
๐ฅ35๐9โก5๐ค4๐2๐คฏ1
๐จ 400+ Cisco routers hacked across Australia!
A new implant called BADCANDY is exploiting CVE-2023-20198 โ even after patches.
Rebooting wonโt help. Hackers just come back.
Watch for fake cisco_sys_manager accounts โ https://thehackernews.com/2025/11/asd-warns-of-ongoing-badcandy-attacks.html
A new implant called BADCANDY is exploiting CVE-2023-20198 โ even after patches.
Rebooting wonโt help. Hackers just come back.
Watch for fake cisco_sys_manager accounts โ https://thehackernews.com/2025/11/asd-warns-of-ongoing-badcandy-attacks.html
๐ฅ25๐3๐คฏ3๐2
โ ๏ธ North Koreaโs Kimsuky just dropped a new backdoor โ HttpTroy โ hidden in a fake VPN invoice.
It shows a decoy PDF, sets a fake โAhnlabUpdateโ task, and rebuilds code on the fly to dodge detection.
Details โ https://thehackernews.com/2025/11/new-httptroy-backdoor-poses-as-vpn.html
It shows a decoy PDF, sets a fake โAhnlabUpdateโ task, and rebuilds code on the fly to dodge detection.
Details โ https://thehackernews.com/2025/11/new-httptroy-backdoor-poses-as-vpn.html
๐ฅ9๐ค4๐คฏ3๐2
๐ต๏ธ Two Android trojans are silently draining accounts.
๐น One pretends to be a government ID app.
๐น The other hides as a food delivery tracker.
They even mute your phone โ so you never hear it happen.
Learn more about BankBot-YNRK & DeliveryRAT โ https://thehackernews.com/2025/11/researchers-uncover-bankbot-ynrk-and.html
๐น One pretends to be a government ID app.
๐น The other hides as a food delivery tracker.
They even mute your phone โ so you never hear it happen.
Learn more about BankBot-YNRK & DeliveryRAT โ https://thehackernews.com/2025/11/researchers-uncover-bankbot-ynrk-and.html
๐11๐ค1๐คฏ1
Last week: hacked security tools, broken chip protections, smart AI malware, and dev tools used to attack us.
Hackers are moving faster than we can stop them.
See all the top threats: https://thehackernews.com/2025/11/weekly-recap-lazarus-hits-web3-intelamd.html
Hackers are moving faster than we can stop them.
See all the top threats: https://thehackernews.com/2025/11/weekly-recap-lazarus-hits-web3-intelamd.html
๐11๐ฅ3๐2๐1
๐จ Hackers are now hijacking trucking/logistics firms โ not just for data, but for the cargo itself.
Theyโre loading up legit remote-management tools like ScreenConnect & LogMeIn, hijacking load-boards and booking real shipments of food/beverage.
Read how โ https://thehackernews.com/2025/11/cybercriminals-exploit-remote.html
Theyโre loading up legit remote-management tools like ScreenConnect & LogMeIn, hijacking load-boards and booking real shipments of food/beverage.
Read how โ https://thehackernews.com/2025/11/cybercriminals-exploit-remote.html
๐14๐ฅ8๐3
๐ง SOC teams built to stop breaches... are built to miss them.
Detection tools catch signals, not connections โ and attackers live in the gaps.
The future isnโt faster alerts. Itโs smarter context.
๐ Donโt miss how theyโre doing it โ https://thehackernews.com/2025/11/the-evolution-of-soc-operations-how.html
Detection tools catch signals, not connections โ and attackers live in the gaps.
The future isnโt faster alerts. Itโs smarter context.
๐ Donโt miss how theyโre doing it โ https://thehackernews.com/2025/11/the-evolution-of-soc-operations-how.html
๐ฅ17๐ค2
๐จ Microsoft just found a new backdoor called SesameOp โ and itโs using the OpenAI Assistants API to talk to its attackers.
Instead of sketchy servers, it hides inside legit AI traffic. It lived undetected for months.
Commands were sent through the โdescriptionโ field.
Read how it works โ https://thehackernews.com/2025/11/microsoft-detects-sesameop-backdoor.html
Instead of sketchy servers, it hides inside legit AI traffic. It lived undetected for months.
Commands were sent through the โdescriptionโ field.
Read how it works โ https://thehackernews.com/2025/11/microsoft-detects-sesameop-backdoor.html
๐22๐ฑ6๐ฅ4๐3
๐ฅ Ransomware negotiators turned attackers.
They were supposed to stop hackers โ but instead used BlackCat ransomware to hit 5 U.S. companies.
They demanded up to $10M. One company actually paid.
Full story โ https://thehackernews.com/2025/11/us-prosecutors-indict-cybersecurity.html
They were supposed to stop hackers โ but instead used BlackCat ransomware to hit 5 U.S. companies.
They demanded up to $10M. One company actually paid.
Full story โ https://thehackernews.com/2025/11/us-prosecutors-indict-cybersecurity.html
๐ฅ8๐คฏ4๐2๐2
โก Googleโs AI just found 5 serious bugs in Appleโs Safari โ before hackers did.
One flaw could crash your browser instantly, another could break memory protection.
Appleโs patched them all. Update now.
Full story โ https://thehackernews.com/2025/11/googles-ai-big-sleep-finds-5-new.html
One flaw could crash your browser instantly, another could break memory protection.
Appleโs patched them all. Update now.
Full story โ https://thehackernews.com/2025/11/googles-ai-big-sleep-finds-5-new.html
๐ฑ18๐5๐คฏ4
๐ก Your AI-SOC works best when it keeps learning.
Without regular analyst feedback, false alerts rise and real threats slip by.
The real upgrade isnโt a new model โ itโs a continuous feedback loop.
Read how it works โ https://thehackernews.com/expert-insights/2025/11/continuous-feedback-loops-why-training.html
Without regular analyst feedback, false alerts rise and real threats slip by.
The real upgrade isnโt a new model โ itโs a continuous feedback loop.
Read how it works โ https://thehackernews.com/expert-insights/2025/11/continuous-feedback-loops-why-training.html
โก7
๐จ A new cyber-espionage campaign, Operation SkyCloak, is targeting defense networks in Russia and Belarus.
Attackers use fake military documents to install a hidden SSH backdoor that talks through Tor โ disguised as a legit GitHub app.
Details here โ https://thehackernews.com/2025/11/operation-skycloak-deploys-tor-enabled.html
Attackers use fake military documents to install a hidden SSH backdoor that talks through Tor โ disguised as a legit GitHub app.
Details here โ https://thehackernews.com/2025/11/operation-skycloak-deploys-tor-enabled.html
๐ฑ8๐4๐คฏ2๐ฅ1
๐จ Researchers just found 4 serious flaws in Microsoft Teams that let attackers fake messages and impersonate coworkers โ no โEditedโ label, no warning.
If your team uses Teams, read this now โ https://thehackernews.com/2025/11/microsoft-teams-bugs-let-attackers.html
If your team uses Teams, read this now โ https://thehackernews.com/2025/11/microsoft-teams-bugs-let-attackers.html
๐ฑ8๐ฅ7๐3๐1
๐จ A critical CVSS 9.8 flaw in "react-native-community/cli" let anyone run OS commands on your dev machineโno login needed.
Itโs patched now, but millions of React Native devs were exposed for months.
Check your version and lock down that dev server. โ https://thehackernews.com/2025/11/critical-react-native-cli-flaw-exposed.html
Itโs patched now, but millions of React Native devs were exposed for months.
Check your version and lock down that dev server. โ https://thehackernews.com/2025/11/critical-react-native-cli-flaw-exposed.html
๐ฅ9๐3
๐ When ransomware hits, every second counts.
DOGE Big Balls spreads fast โ encrypting files and leaving ransom notes everywhere.
Wazuh detects it early, isolates the threat, and stops the damage. Hereโs how their detection rules and live response work โ https://thehackernews.com/2025/11/ransomware-defense-using-wazuh-open.html
DOGE Big Balls spreads fast โ encrypting files and leaving ransom notes everywhere.
Wazuh detects it early, isolates the threat, and stops the damage. Hereโs how their detection rules and live response work โ https://thehackernews.com/2025/11/ransomware-defense-using-wazuh-open.html
๐ฅ9
๐จ A โฌ600M crypto scam just got taken down.
9 suspects across 5 countries ran fake โinvestmentโ sites that looked 100% real. They even laundered the money on-chain โ hiding millions in plain view.
Read here โ https://thehackernews.com/2025/11/europol-and-eurojust-dismantle-600.html
9 suspects across 5 countries ran fake โinvestmentโ sites that looked 100% real. They even laundered the money on-chain โ hiding millions in plain view.
Read here โ https://thehackernews.com/2025/11/europol-and-eurojust-dismantle-600.html
๐13
๐ ๏ธ You patch daily.
๐ต๏ธ You scan weekly.
โกBut your attack surface changes every hour.
Static defenses canโt keep up.
Join The Hacker News x Bitdefender webinar to see how Dynamic Attack Surface Reduction (DASR) keeps you ahead โ https://thehacker.news/attack-surface-reduction
๐ต๏ธ You scan weekly.
โกBut your attack surface changes every hour.
Static defenses canโt keep up.
Join The Hacker News x Bitdefender webinar to see how Dynamic Attack Surface Reduction (DASR) keeps you ahead โ https://thehacker.news/attack-surface-reduction
๐ฅ5
๐ฅ Three of the internetโs most notorious hacker crews โ Scattered Spider, LAPSUS$, and ShinyHunters โ just merged into one cartel: Scattered LAPSUS$ Hunters.
Theyโve rebuilt their Telegram network 16 times in 80 days and now run extortion-as-a-service for affiliates.
Details here โ https://thehackernews.com/2025/11/a-cybercrime-merger-like-no-other.html
Theyโve rebuilt their Telegram network 16 times in 80 days and now run extortion-as-a-service for affiliates.
Details here โ https://thehackernews.com/2025/11/a-cybercrime-merger-like-no-other.html
๐12๐7๐ฅ5
CISA just added two new flaws to its list of exploited ones. One is already being used in the wild, and the other was fixed months ago but is still open on a lot of servers.
One flaw in Control Web Panel lets hackers run commands before they log in.
If you use it, patch it now.
More information โ https://thehackernews.com/2025/11/cisa-adds-gladinet-and-cwp-flaws-to-kev.html
One flaw in Control Web Panel lets hackers run commands before they log in.
If you use it, patch it now.
More information โ https://thehackernews.com/2025/11/cisa-adds-gladinet-and-cwp-flaws-to-kev.html
๐5๐ฅ4๐2
Many companies donโt realize this yet, but their AI agents are already acting like employees.
82% use them, and 53% handle sensitive data every day. But when staff leave, those agents keep runningโฆ still with full access.
Hereโs how to find and protect them: https://thehackernews.com/expert-insights/2025/11/governing-ai-agents-from-enterprise.html
82% use them, and 53% handle sensitive data every day. But when staff leave, those agents keep runningโฆ still with full access.
Hereโs how to find and protect them: https://thehackernews.com/expert-insights/2025/11/governing-ai-agents-from-enterprise.html
๐คฏ10๐5๐ฑ3๐2
โ ๏ธ In just 60 seconds, analysts found an entire phishing chain: a fake Microsoft 365 login hidden inside ClickUp.
Most SOCs would have spent hours poring through logs to find the same thing.
Here's how real-time analysis cuts noise, speeds detection, and prevents burnout: https://thehackernews.com/2025/11/why-soc-burnout-can-be-avoided.html
Most SOCs would have spent hours poring through logs to find the same thing.
Here's how real-time analysis cuts noise, speeds detection, and prevents burnout: https://thehackernews.com/2025/11/why-soc-burnout-can-be-avoided.html
๐ค5๐ฅ4