The Hacker News
βœ”
152K subscribers
1.93K photos
10 videos
3 files
7.85K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
Hackers are using trusted apps to attack.

ThreatLocker’s Ringfencingβ„’ stops them β€” blocking PowerShell, macros, and other risky actions before they spread.

Learn how it works β†’ https://thehackernews.com/2025/11/application-containment-how-to-use.html
πŸ€”7
☁️ Your cloud is growing faster than your security.
πŸ” One stolen login could bring it all down.

Join the LIVE session next week and learn how top teams lock it down β€” without slowing down devs.

πŸ‘‰ Save your spot now β†’ https://thehacker.news/securing-cloud-workloads
⚑11
🚨 A new WhatsApp worm is spreading fast in Brazil.

It hijacks chats, sends fake messages to all your contacts, and installs a program that steals bank and crypto logins.

... and it updates itself through an email inbox to stay hidden.

Read here ↓ https://thehackernews.com/2025/11/python-based-whatsapp-worm-spreads.html
🀯14😁9πŸ”₯7😱3⚑1
⚠️ Hackers are exploiting a new 7-Zip flaw right now.

A simple ZIP file can break into Windows through a hidden link trick.

The bug’s been patched β€” but many still haven’t updated.

Details here (CVE-2025-11001) ↓ https://thehackernews.com/2025/11/hackers-actively-exploiting-7-zip.html
πŸ‘18πŸ”₯7πŸ€”5😱3
🚨 Hackers are running fake ads for popular apps β€” and they look 100% real.

Click one, and you install TamperedChef, a backdoor that lets attackers control your computer.

Experts say it’s still spreading.

Read here β†’ https://thehackernews.com/2025/11/tamperedchef-malware-spreads-via-fake.html
πŸ”₯7πŸ‘5
⚑ Iranian hackers helped aim real missiles.

They broke into ship tracking systems and live cameras β€” then the ships got attacked days later.

Amazon says this marks a new kind of war: where hacking meets real-world strikes.

More on how it happened ↓ https://thehackernews.com/2025/11/iran-linked-hackers-mapped-ship-ais.html
πŸ”₯26🀯10😁8πŸ‘4πŸ‘4
πŸ”’ New Android malware can read your private chats β€” even on Signal, WhatsApp, and Telegram.

It records your screen after messages are decrypted, stealing passwords and banking logins.

It even fakes system updates to hide what it’s doing.

Full story ↓ https://thehackernews.com/2025/11/new-sturnus-android-trojan-quietly.html
πŸ”₯19😱9😁6πŸ‘5🀯1
This week's ThreatsDay looks at big cyber news from around the world:

πŸ”Ή Russian hackers got arrested
πŸ”Ή Chinese spies are using LinkedIn to find secrets
πŸ”Ή People caught washing dirty money with crypto
πŸ”Ή New hidden bugs found in phones, computers, and smart home gadgets
πŸ”Ή ... and many more.

🌐 Zero-day attacks β€’ Spying β€’ Crypto crime β€’ Bugs in everyday devices β€’ Moving malware

Read all critical stories here β†’ https://thehackernews.com/2025/11/threatsday-bulletin-0-days-linkedin.html
πŸ”₯8😁2
JSGuLdr: Multi-Stage Loader Delivering PhantomStealer

#ANYRUN researchers identified #JSGuLdr, a multi-stage JavaScript-to-PowerShell loader used to deliver #PhantomStealer. A JScript file triggers PowerShell through an Explorer COM call, pulls the second stage from %APPDATA%\Registreri62, then uses Net.WebClient to fetch an encrypted payload from Google Drive into %APPDATA%\Autorise131[.]Tel. The payload is decoded in memory and loaded, with PhantomStealerinjected into msiexec.exe.

Execution chain: wscript.exe ➑️ explorer.exe (svchost.exe) ➑️ explorer.exe (COM) ➑️ powershell.exe ➑️ msiexec.exe

πŸ‘‰ See analysis session: https://app.any.run/tasks/7b295f6f-5f16-4a44-a02b-5d59fd4b1e8f?utm_source=tg_thehackernews&utm_medium=post&utm_campaign=techpost&utm_content=task&utm_term=201125

πŸ‘‰ Read full analysis: https://t.iss.one/anyrun_app/698
⚑7πŸ‘3πŸ‘1
WhatsApp accounts are being hijacked worldwide via fake WhatsApp Web pages that mimic the official interface exactly β€” including auto-detected language and country flag.

You scan QR or type code β†’ they take your account β†’ message your friends for money + steal everything.

Check the new CTM360 report – see exactly how the fake pages look and how to stay safe ↓ https://thehackernews.com/2025/11/ctm360-exposes-global-whatsapp.html
😁12🀯4πŸ‘2πŸ‘1
Hackers made a new botnet called Tsundere β€” it’s spreading through fake game downloads like Valorant and CS2.

It hides its servers on the Ethereum blockchain, making it almost impossible to shut down.

Researchers say it’s still active.

Read more ↓ https://thehackernews.com/2025/11/tsundere-botnet-expands-using-game.html
😱17⚑5πŸ‘2
🚨 Hackers are exploiting a 2-year-old authentication flaw (CVE-2023-48022) in the Ray AI framework to take over NVIDIA GPU clusters and run a self-spreading crypto-mining botnet called ShadowRay 2.0.

The bug remains unpatched by design, and over 230,000 Ray servers are exposed online.

Read about it here ↓ https://thehackernews.com/2025/11/shadowray-20-exploits-unpatched-ray.html
πŸ‘15πŸ”₯5
🚨 ThreatsDay Bulletin β€” The EU wants to rewrite its privacy rules.

New proposal would let companies use personal data to train AI without consent, if done for β€œlegitimate interest.”

Critics say it’s a major rollback of GDPR and a win for Big Tech.

Read more ↓ https://thehackernews.com/2025/11/threatsday-bulletin-0-days-linkedin.html#eu-rewires-privacy-playbook
😱11πŸ‘4🀯4
🚨 Salesforce found unusual activity in Gainsight apps and cut off their access.

Hackers linked to ShinyHunters may have used those apps to steal Salesforce data from nearly 1,000 companies.

Gainsight was also hit in a similar attack earlier this year.

Full story ↓ https://thehackernews.com/2025/11/salesforce-flags-unauthorized-data.html
πŸ‘6😁3🀯1
βš–οΈ The SEC just ended its case against SolarWinds β€” the company hit by the big 2020 hack.

After two years of blaming its security chief, the case was quietly dropped.

Now many wonder if anyone will be held responsible next time ↓ https://thehackernews.com/2025/11/sec-drops-solarwinds-case-after-years.html
😁9πŸ‘3πŸ”₯3πŸ‘1
⚠️ A hacking group linked to China just pulled a big one.

They used a marketing firm’s code to infect 1,000+ websites with a fake πŸ”” Chrome update.

Click it β€” and you get BADAUDIO, new malware made to spy for months.

Full story ↓ https://thehackernews.com/2025/11/apt24-deploys-badaudio-in-years-long.html
πŸ”₯11😁4πŸ‘3🀯2
Every phone could be a way in for hackers.

Samsung Galaxy devices check their security before they connect to your network.

That means real Zero Trustβ€”built into the device itself.

Read ↓ https://thehackernews.com/2025/11/why-it-admins-choose-samsung-for-mobile.html
πŸ‘10πŸ€”5😁4
🚨 Google just made Android and iPhone share files directly using Quick Share and AirDrop.

It’s built in Rust for stronger security, and a small info leak found in testing is already fixed.

Full details ↓ https://thehackernews.com/2025/11/google-adds-airdrop-compatibility-to.html
πŸ”₯19πŸ‘7πŸ‘6πŸ€”2🀯2
🚨 Grafana fixed a major security bug (CVSS 10.0) that could let attackers sign in as admin users.

It affects Grafana Enterprise 12.0.0–12.2.1 if SCIM provisioning is turned on β€” a number like β€œ1” could trick the system into giving admin access.

Update now to stay safe. Read more ↓ https://thehackernews.com/2025/11/grafana-patches-cvss-100-scim-flaw.html
πŸ‘26πŸ‘1
🚨 CISA warns Oracle Identity Manager flaw (CVE-2025-61757) is under active attack.

Hackers can run code without login by adding ?WSDL or ;.wadl to URLs β€” a tiny trick that opens locked systems.

Exploited since August. Patch by Dec 12.

Full details ↓ https://thehackernews.com/2025/11/cisa-warns-of-actively-exploited.html
πŸ‘12🀯1
🚨 Hackers found a new way to phish β€” through browser notifications.

A new tool called Matrix Push C2 lets attackers send fake alerts that look like real ones from PayPal, Netflix, or TikTok.

No downloads. No malware file. Just one click β€” and your data’s theirs.

Learn more ↓ https://thehackernews.com/2025/11/matrix-push-c2-uses-browser.html
πŸ”₯29πŸ‘9