The Hacker News
βœ”
152K subscribers
1.93K photos
10 videos
3 files
7.85K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
Meta just expanded WhatsApp’s security research.

πŸ”Ή New β€œResearch Proxy” tool lets experts dig deeper
πŸ”Ή$4M paid to bug hunters this year

Big money. Bigger stakes.

Read here ↓ https://thehackernews.com/2025/11/meta-expands-whatsapp-security-research.html
😁12πŸ‘2πŸ€”2
This media is not supported in your browser
VIEW IN TELEGRAM
🚨 Hackers just upgraded their phishing game. A fake Microsoft login now looks 100% real β€” even showing a real URL and CAPTCHA check.

It’s part of a new β€œSneaky 2FA” phishing kit that lets anyone steal accounts without real skills.

Even pros are getting tricked.

Here’s how it works ↓ https://thehackernews.com/2025/11/sneaky-2fa-phishing-kit-adds-bitb-pop.html
πŸ”₯20🀯6πŸ‘4😁2
Fortinet has confirmed a new FortiWeb flaw β€” CVE-2025-58034 β€” already exploited in the wild.

It lets authenticated attackers execute OS commands via crafted requests.

Full story ↓ https://thehackernews.com/2025/11/fortinet-warns-of-new-fortiweb-cve-2025.html
πŸ‘8😁7⚑3
We say β€œtrust but verify.”

In SaaS, most teams trust onceβ€”and never verify again. Old tokens stay valid. Apps keep broad access.

That’s how attackers move in quietly.

Gal Nakash explains why Zero Trust fails in practice and what to fix ↓ https://thehackernews.com/expert-insights/2025/11/the-problem-with-trust-but-verify-is.html
πŸ€”9πŸ”₯4πŸ‘4😁2
🚨 Hackers turned software updates into malware.

ESET found a China-linked group called PlushDaemon using a tool named EdgeStepper to hijack internet routers and reroute updates straight to fake servers.

So that β€œsafe update”? It could install spyware instead.

Full story ↓ https://thehackernews.com/2025/11/edgestepper-implant-reroutes-dns.html
πŸ”₯9πŸ‘5😁4πŸ‘2
🚨 New exploit found in ServiceNow’s Now Assist AI platform.

Researchers showed one AI agent could recruit others to steal data and send emails β€” even with protections enabled.

Misconfigurations, not models, opened the door.

How it happened ↓ https://thehackernews.com/2025/11/servicenow-ai-agents-can-be-tricked.html
πŸ‘5πŸ‘2
πŸ•΅οΈβ€β™‚οΈ How many AI assets are running in your organization right now? If you can’t answer that, you’re not alone.

From hidden models in Jupyter notebooks to AI-powered features buried in SaaS tools, AI is spreading faster than most teams can track.

Tomorrow! Join this live webinar to learn:
πŸ”Ή How to discover and catalog AI assets you didn’t know existed
πŸ”Ή Why AI inventory is the foundation for effective AI security and governance

πŸ‘‰ https://thn.news/guide-ai-inventory
πŸ‘6😁6
⚠️ Hackers just took over tens of thousands of old ASUS routers around the world.

They used six known bugs to build a massive hidden network β€” still active right now. Each router even shares a weird 100-year security certificate.

Full story β†’ https://thehackernews.com/2025/11/wrthug-exploits-six-asus-wrt-flaws-to.html
πŸ‘13😁5πŸ”₯4
Hackers are using trusted apps to attack.

ThreatLocker’s Ringfencingβ„’ stops them β€” blocking PowerShell, macros, and other risky actions before they spread.

Learn how it works β†’ https://thehackernews.com/2025/11/application-containment-how-to-use.html
πŸ€”7
☁️ Your cloud is growing faster than your security.
πŸ” One stolen login could bring it all down.

Join the LIVE session next week and learn how top teams lock it down β€” without slowing down devs.

πŸ‘‰ Save your spot now β†’ https://thehacker.news/securing-cloud-workloads
⚑11
🚨 A new WhatsApp worm is spreading fast in Brazil.

It hijacks chats, sends fake messages to all your contacts, and installs a program that steals bank and crypto logins.

... and it updates itself through an email inbox to stay hidden.

Read here ↓ https://thehackernews.com/2025/11/python-based-whatsapp-worm-spreads.html
🀯14😁9πŸ”₯7😱3⚑1
⚠️ Hackers are exploiting a new 7-Zip flaw right now.

A simple ZIP file can break into Windows through a hidden link trick.

The bug’s been patched β€” but many still haven’t updated.

Details here (CVE-2025-11001) ↓ https://thehackernews.com/2025/11/hackers-actively-exploiting-7-zip.html
πŸ‘18πŸ”₯7πŸ€”5😱3
🚨 Hackers are running fake ads for popular apps β€” and they look 100% real.

Click one, and you install TamperedChef, a backdoor that lets attackers control your computer.

Experts say it’s still spreading.

Read here β†’ https://thehackernews.com/2025/11/tamperedchef-malware-spreads-via-fake.html
πŸ”₯7πŸ‘5
⚑ Iranian hackers helped aim real missiles.

They broke into ship tracking systems and live cameras β€” then the ships got attacked days later.

Amazon says this marks a new kind of war: where hacking meets real-world strikes.

More on how it happened ↓ https://thehackernews.com/2025/11/iran-linked-hackers-mapped-ship-ais.html
πŸ”₯26🀯10😁8πŸ‘4πŸ‘4
πŸ”’ New Android malware can read your private chats β€” even on Signal, WhatsApp, and Telegram.

It records your screen after messages are decrypted, stealing passwords and banking logins.

It even fakes system updates to hide what it’s doing.

Full story ↓ https://thehackernews.com/2025/11/new-sturnus-android-trojan-quietly.html
πŸ”₯19😱9😁6πŸ‘5🀯1
This week's ThreatsDay looks at big cyber news from around the world:

πŸ”Ή Russian hackers got arrested
πŸ”Ή Chinese spies are using LinkedIn to find secrets
πŸ”Ή People caught washing dirty money with crypto
πŸ”Ή New hidden bugs found in phones, computers, and smart home gadgets
πŸ”Ή ... and many more.

🌐 Zero-day attacks β€’ Spying β€’ Crypto crime β€’ Bugs in everyday devices β€’ Moving malware

Read all critical stories here β†’ https://thehackernews.com/2025/11/threatsday-bulletin-0-days-linkedin.html
πŸ”₯8😁2
JSGuLdr: Multi-Stage Loader Delivering PhantomStealer

#ANYRUN researchers identified #JSGuLdr, a multi-stage JavaScript-to-PowerShell loader used to deliver #PhantomStealer. A JScript file triggers PowerShell through an Explorer COM call, pulls the second stage from %APPDATA%\Registreri62, then uses Net.WebClient to fetch an encrypted payload from Google Drive into %APPDATA%\Autorise131[.]Tel. The payload is decoded in memory and loaded, with PhantomStealerinjected into msiexec.exe.

Execution chain: wscript.exe ➑️ explorer.exe (svchost.exe) ➑️ explorer.exe (COM) ➑️ powershell.exe ➑️ msiexec.exe

πŸ‘‰ See analysis session: https://app.any.run/tasks/7b295f6f-5f16-4a44-a02b-5d59fd4b1e8f?utm_source=tg_thehackernews&utm_medium=post&utm_campaign=techpost&utm_content=task&utm_term=201125

πŸ‘‰ Read full analysis: https://t.iss.one/anyrun_app/698
⚑7πŸ‘3πŸ‘1
WhatsApp accounts are being hijacked worldwide via fake WhatsApp Web pages that mimic the official interface exactly β€” including auto-detected language and country flag.

You scan QR or type code β†’ they take your account β†’ message your friends for money + steal everything.

Check the new CTM360 report – see exactly how the fake pages look and how to stay safe ↓ https://thehackernews.com/2025/11/ctm360-exposes-global-whatsapp.html
😁12🀯4πŸ‘2πŸ‘1
Hackers made a new botnet called Tsundere β€” it’s spreading through fake game downloads like Valorant and CS2.

It hides its servers on the Ethereum blockchain, making it almost impossible to shut down.

Researchers say it’s still active.

Read more ↓ https://thehackernews.com/2025/11/tsundere-botnet-expands-using-game.html
😱17⚑5πŸ‘2
🚨 Hackers are exploiting a 2-year-old authentication flaw (CVE-2023-48022) in the Ray AI framework to take over NVIDIA GPU clusters and run a self-spreading crypto-mining botnet called ShadowRay 2.0.

The bug remains unpatched by design, and over 230,000 Ray servers are exposed online.

Read about it here ↓ https://thehackernews.com/2025/11/shadowray-20-exploits-unpatched-ray.html
πŸ‘15πŸ”₯5
🚨 ThreatsDay Bulletin β€” The EU wants to rewrite its privacy rules.

New proposal would let companies use personal data to train AI without consent, if done for β€œlegitimate interest.”

Critics say it’s a major rollback of GDPR and a win for Big Tech.

Read more ↓ https://thehackernews.com/2025/11/threatsday-bulletin-0-days-linkedin.html#eu-rewires-privacy-playbook
😱11πŸ‘4🀯4