The Hacker News
βœ”
151K subscribers
1.85K photos
10 videos
3 files
7.77K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
⚠️ Researchers have found 7 new ways to hack ChatGPT (GPT-4o and GPT-5), including zero-click attacks that can steal chat history and even poison your AI's memory.

OpenAI fixed some of them... but not all of them.

Details here β†’ https://thehackernews.com/2025/11/researchers-find-chatgpt.html
πŸ‘18⚑4😁1
⚑ Google spotted malware that uses Gemini AI to rewrite its own code.

It’s called PROMPTFLUX β€” a simple script that asks Gemini for new ways to hide from antivirus tools.

More information ↓ https://thehackernews.com/2025/11/google-uncovers-promptflux-malware-that.html
😁30πŸ”₯12πŸ€”5🀯4
SonicWall just confirmed the September breach was done by a state-backed hacker group.

They got in through one API call and accessed firewall backups β€” no ransom, just quiet data theft.

Here’s what happened ↓ https://thehackernews.com/2025/11/sonicwall-confirms-state-sponsored.html
πŸ‘8πŸ‘4🀯3😁2
⚑ Hackers turned Windows against itself.

Curly COMrades is using Microsoft's Hyper-V to run small Linux virtual machines inside Windows 10.

This is a sneaky way to get their malware past EDR tools.

Read the whole story ↓ https://thehackernews.com/2025/11/hackers-weaponize-windows-hyper-v-to.html
πŸ‘14πŸ”₯6πŸ€”4😱3πŸ‘1😁1
Over 600 companies say they offer MDR.
Gartner’s new report shows only a few truly deliver.

It also highlights a big gap β€” most rely too much on automation, not enough on real human response.

Worth a read β†’ https://thehackernews.com/2025/11/bitdefender-named-representative-vendor.html
⚑9
πŸ›‘οΈ ThreatsDay Bulletin is out!

πŸ”Ή Cyber threats are getting personal.
πŸ”Ή AI helps stop attacks β€” but it’s also powering them.
πŸ”Ή Botnets, fake apps, and scams are growing fast.

Here’s what’s really happening this week in cyber β†’ https://thehackernews.com/2025/11/threatsday-bulletin-ai-tools-in-malware.html
πŸ”₯7πŸ‘4😁4
New cyber rules mean every breach test counts. Most teams still run them in Excel.

At Georgetown, gain the tactical skills to plan for and respond to information security threats.

Attend our Nov. 19 webinar β†’ https://thn.news/cyber-risk-webinar-in
πŸ‘6😁6
🚨 Cisco warns hackers are targeting unpatched Secure Firewall ASA & FTD devices with a new attack variant exploiting two flaws β€” CVE-2025-20333 and CVE-2025-20362.

The attacks can crash devices (DoS) or let attackers run code as root.

Details here ↓ https://thehackernews.com/2025/11/cisco-warns-of-new-firewall-attack.html
😁6πŸ‘5πŸ”₯1
⚠️ A Russia-linked group posed as ESET to hack Ukrainian organizations.

They sent fake ESET installers that looked real β€” but quietly installed a backdoor using the Tor network.

Experts call the group InedibleOchotense, tied to Sandworm.

Full story β†’ https://thehackernews.com/2025/11/trojanized-eset-installers-drop.html
🀯8πŸ”₯7πŸ‘4😁3πŸ‘1
Redis added an AI agent (Prophet Security) to its SOC, working alongside their MDR team.

The result: investigations that took hours now take about 10 minutes.

AI handles the routine alerts so humans can focus on real threats.

Here’s what actually worked ↓ https://thehackernews.com/expert-insights/2025/11/implementing-ai-in-soc-lessons-learned.html
😁15πŸ€”9πŸ‘4πŸ”₯4
A fake VS Code extension made with AI just showed up on the Marketplace.

It ran ransomware on install β€” zipping, encrypting, and uploading files, all by itself.

Microsoft took it down quickly, but the developer accidentally left the control keys and decryption tools inside.

Here’s what happened and how it worked ↓ https://thehackernews.com/2025/11/vibe-coded-malicious-vs-code-extension.html
πŸ‘10😁10πŸ‘4πŸ”₯1
ChatGPT just helped researchers crack XLoader malware in hours β€” work that used to take days.

AI unpacked the code, found keys, and exposed C2 domains. Big shift for malware analysis.

Check this story ↓ https://thehackernews.com/2025/11/threatsday-bulletin-ai-tools-in-malware.html#ai-speeds-triage-but-human-skill-still-needed
πŸ”₯21😁12πŸ‘5πŸ‘1
Google just launched a new form to report extortion scams on Google Maps.

Scammers are posting fake 1⭐ reviews, then asking business owners to pay up to remove them.

This new tool is meant to stop the surge in β€œreview bombing” hitting small businesses.

Read how it works ↓ https://thehackernews.com/2025/11/google-launches-new-maps-feature-to.html
πŸ€”12😁7πŸ”₯5πŸ‘5😱1
Your company's logins could be on the dark web right now, and they could sell for as little as $15.

It only takes one click for hackers to walk right in.

Find out if your company’s credentials are exposed β†’ https://thehackernews.com/2025/11/enterprise-credentials-at-risk-same-old.html
😁6🀯6
🚨 WARNING: Malicious NuGet packages were caught hiding delayed payloadsβ€”set to fire off years from now, in 2027–2028.

They look harmless. Some even helpful. But one, Sharp7Extend, quietly sabotages PLCsβ€”crashing processes or corrupting writes after a short delay.

Nearly 10K downloads before anyone noticed.

Here’s what’s really going on ↓ https://thehackernews.com/2025/11/hidden-logic-bombs-in-malware-laced.html
πŸ”₯12πŸ‘6πŸ‘4
Chinese hackers used old bugs like Log4j and Struts to break into U.S. policy networks.

Then they hid using msbuild.exe and a fake system task to stay inside.

Old tricks. New targets.

Read the details ↓ https://thehackernews.com/2025/11/from-log4j-to-iis-chinas-hackers-turn.html
πŸ‘11πŸ”₯6πŸ€”4πŸ‘2⚑1😁1
A single image file could hijack Galaxy phones.

Attackers hid a ZIP inside DNG photos sent over WhatsApp, exploiting a zero-day in Samsung’s image codec (CVE-2025-21042).

The implant β€” called LANDFALL β€” gave full spyware access.

Full report β†’ https://thehackernews.com/2025/11/samsung-zero-click-flaw-exploited-to.html
πŸ”₯15😁9😱6πŸ‘3🀯2
Attackers are now using your cloud tools against you.

Fortinet uncovered a new campaign where stolen AWS credentials were used to run quiet recon and launch fraud from inside trusted environments.

No malware. No noise. Just normal-looking API traffic doing damage.

Read this story β†’ https://thehackernews.com/2025/11/threatsday-bulletin-ai-tools-in-malware.html#researchers-uncover-large-scale-aws-abuse-network
πŸ”₯16πŸ‘5😁5
πŸ”₯ Wild find from Microsoft.

Even when your AI chats are encrypted, someone watching the network can still guess what you’re talking about.

They call it "Whisper Leak" side-channel attack.

And in tests, models like OpenAI and Mistral gave away topics with 98% accuracy.

Worth your attention ↓ https://thehackernews.com/2025/11/microsoft-uncovers-whisper-leak-attack.html
πŸ”₯22😱13😁5πŸ€”5πŸ‘3πŸ‘1
🚨 Three VS Code extensions β€” downloaded over 10,000 times β€” turned out to be part of a revived GlassWorm attack.

And... it spreads on its own. One infected developer can quietly compromise an entire team.

They're stealing credentials for GitHub, VSX, and crypto wallets while hiding in plain sight with invisible Unicode characters.

Read the whole story ↓ https://thehackernews.com/2025/11/glassworm-malware-discovered-in-three.html
⚑9πŸ‘4πŸ”₯2πŸ‘2🀯2😁1
⚠️ Hackers are posing as Booking[.]com to target hotels.

Fake β€œsecurity” emails trick managers into running a PowerShell script that installs PureRAT β€” giving full access to hotel systems.

Stolen logins and card data are being sold online.

More information here β†’ https://thehackernews.com/2025/11/large-scale-clickfix-phishing-attacks.html
😁9πŸ‘7