π¨ Thousands hacked after downloading what looked like βofficialβ government apps.
They were fake versions of real banking apps, modified by hackers from GoldFactory to include malware.
So far, over 11,000 phones in Southeast Asia have been infected.
π Details β https://thehackernews.com/2025/12/goldfactory-hits-southeast-asia-with.html
They were fake versions of real banking apps, modified by hackers from GoldFactory to include malware.
So far, over 11,000 phones in Southeast Asia have been infected.
π Details β https://thehackernews.com/2025/12/goldfactory-hits-southeast-asia-with.html
π€―14π5π₯3π2
π€π₯ AI-built code just broke web security in 2025.
One bug in a βvibe codingβ platform let anyone access private apps β no login needed.
β οΈ 45% of AI-written code had exploitable flaws.
π’ Even big firms like Wix had to patch fast.
The fix? Treat all AI code as untrusted.
π Read here β https://thehackernews.com/2025/12/5-threats-that-reshaped-web-security.html
One bug in a βvibe codingβ platform let anyone access private apps β no login needed.
β οΈ 45% of AI-written code had exploitable flaws.
π’ Even big firms like Wix had to patch fast.
The fix? Treat all AI code as untrusted.
π Read here β https://thehackernews.com/2025/12/5-threats-that-reshaped-web-security.html
π€―7π6β‘3
βοΈ Hackers faking airport Wi-Fi.
π» Malware hiding inside coding tools.
π€ AI rewriting security playbooks.
Thatβs just the start β and 15+ more stories inside.
π° This weekβs ThreatsDay Bulletin uncovers the sneakiest hacks, scams, and βtoo-smartβ malware out there.
π Catch up before they catch you β https://thehackernews.com/2025/12/threatsday-bulletin-wi-fi-hack-npm-worm.html
π» Malware hiding inside coding tools.
π€ AI rewriting security playbooks.
Thatβs just the start β and 15+ more stories inside.
π° This weekβs ThreatsDay Bulletin uncovers the sneakiest hacks, scams, and βtoo-smartβ malware out there.
π Catch up before they catch you β https://thehackernews.com/2025/12/threatsday-bulletin-wi-fi-hack-npm-worm.html
π8π€4
π¨ AI tools are now running inside your browser β reading data, following hidden prompts, and moving info across tabs.
IT canβt see it. Security canβt stop it.
Seraphic Securityβs Suresh Batchu calls this the next big blind spot: Shadow AI in the enterprise browser.
π Read β https://thehackernews.com/expert-insights/2025/12/shadow-ai-in-browser-next-enterprise.html
IT canβt see it. Security canβt stop it.
Seraphic Securityβs Suresh Batchu calls this the next big blind spot: Shadow AI in the enterprise browser.
π Read β https://thehackernews.com/expert-insights/2025/12/shadow-ai-in-browser-next-enterprise.html
π€―12π5π€3π1
π¨ A fake Microsoft Teams installer is spreading malware in China.
Hackers called "Silver Fox" made it look like a Russian attack to hide their tracks.
It installs ValleyRAT, giving full remote access to victims.
π Read: https://thehackernews.com/2025/12/silver-fox-uses-fake-microsoft-teams.html
Hackers called "Silver Fox" made it look like a Russian attack to hide their tracks.
It installs ValleyRAT, giving full remote access to victims.
π Read: https://thehackernews.com/2025/12/silver-fox-uses-fake-microsoft-teams.html
π14π₯11
β οΈ Hackers are exploiting a command injection bug in Array Networks AG Series gateways β active since August 2025.
It lets attackers run any command on systems using βDesktopDirectβ remote access.
π Details β https://thehackernews.com/2025/12/jpcert-confirms-active-command.html
It lets attackers run any command on systems using βDesktopDirectβ remote access.
π Details β https://thehackernews.com/2025/12/jpcert-confirms-active-command.html
π₯9π4π3
π¨ CISA just warned about a new Chinese state-backed hack tool called BRICKSTORM β a backdoor found in VMware and Windows systems used by U.S. government and tech networks.
It can reinstall itself if removed, hide in normal traffic, and give hackers full remote control.
πRead β https://thehackernews.com/2025/12/cisa-reports-prc-hackers-using.html
It can reinstall itself if removed, hide in normal traffic, and give hackers full remote control.
πRead β https://thehackernews.com/2025/12/cisa-reports-prc-hackers-using.html
π€―15π₯5π2π1
π¨ A lawyer in Pakistan was hacked with Predator β the first known spyware attack on a civil society member.
It started with a link on WhatsApp, but new leaks show Predator can also spread through ads β no click needed.
It can read chats, record audio, take photos β and Intellexa may still access customer systems remotely.
π Read β https://thehackernews.com/2025/12/intellexa-leaks-reveal-zero-days-and.html
It started with a link on WhatsApp, but new leaks show Predator can also spread through ads β no click needed.
It can read chats, record audio, take photos β and Intellexa may still access customer systems remotely.
π Read β https://thehackernews.com/2025/12/intellexa-leaks-reveal-zero-days-and.html
π7π±3
β οΈ Within HOURS of disclosure, two China-linked hacking groups weaponized a critical React flaw (CVE-2025-55182).
Theyβre already scanning the web for unpatched apps.
Update to React 19.0.1+ now.
π Read β https://thehackernews.com/2025/12/chinese-hackers-have-started-exploiting.html
Theyβre already scanning the web for unpatched apps.
Update to React 19.0.1+ now.
π Read β https://thehackernews.com/2025/12/chinese-hackers-have-started-exploiting.html
π€―2π₯1
π¨ Critical Apache Tika flaw (CVE-2025-66516) just dropped β CVSS 10.0.
A single fake PDF can trigger an XXE attack, letting hackers read server files or run code.
π Read β https://thehackernews.com/2025/12/critical-xxe-bug-cve-2025-66516-cvss.html
Update to v3.2.2 now.
A single fake PDF can trigger an XXE attack, letting hackers read server files or run code.
π Read β https://thehackernews.com/2025/12/critical-xxe-bug-cve-2025-66516-cvss.html
Update to v3.2.2 now.
π₯8π€3
π§© 57% of SMBs say cybersecurity is a top priority β yet they still turn down MSPs.
β‘ The issue isnβt interest. Itβs confusion.
β‘ Theyβre tired of jargon, fear, and hard selling.
βGetting to Yesβ helps MSPs explain security in plain business terms β and win trust.
π See how itβs done β https://thehackernews.com/2025/12/getting-to-yes-anti-sales-guide-for-msps.html
β‘ The issue isnβt interest. Itβs confusion.
β‘ Theyβre tired of jargon, fear, and hard selling.
βGetting to Yesβ helps MSPs explain security in plain business terms β and win trust.
π See how itβs done β https://thehackernews.com/2025/12/getting-to-yes-anti-sales-guide-for-msps.html
π3
π¨ WARNING: A new attack can trick Perplexityβs Comet browser into deleting your Google Drive.
Just one normal-looking email with hidden cleanup instructions can make the AI agent erase real files β no exploit, no warning.
π Details here β https://thehackernews.com/2025/12/zero-click-agentic-browser-attack-can.html
Just one normal-looking email with hidden cleanup instructions can make the AI agent erase real files β no exploit, no warning.
π Details here β https://thehackernews.com/2025/12/zero-click-agentic-browser-attack-can.html
π€―12π5π₯4