A fake VS Code extension made with AI just showed up on the Marketplace.
It ran ransomware on install โ zipping, encrypting, and uploading files, all by itself.
Microsoft took it down quickly, but the developer accidentally left the control keys and decryption tools inside.
Hereโs what happened and how it worked โ https://thehackernews.com/2025/11/vibe-coded-malicious-vs-code-extension.html
It ran ransomware on install โ zipping, encrypting, and uploading files, all by itself.
Microsoft took it down quickly, but the developer accidentally left the control keys and decryption tools inside.
Hereโs what happened and how it worked โ https://thehackernews.com/2025/11/vibe-coded-malicious-vs-code-extension.html
๐8๐7๐2
ChatGPT just helped researchers crack XLoader malware in hours โ work that used to take days.
AI unpacked the code, found keys, and exposed C2 domains. Big shift for malware analysis.
Check this story โ https://thehackernews.com/2025/11/threatsday-bulletin-ai-tools-in-malware.html#ai-speeds-triage-but-human-skill-still-needed
AI unpacked the code, found keys, and exposed C2 domains. Big shift for malware analysis.
Check this story โ https://thehackernews.com/2025/11/threatsday-bulletin-ai-tools-in-malware.html#ai-speeds-triage-but-human-skill-still-needed
๐ฅ17๐10๐4
Google just launched a new form to report extortion scams on Google Maps.
Scammers are posting fake 1โญ reviews, then asking business owners to pay up to remove them.
This new tool is meant to stop the surge in โreview bombingโ hitting small businesses.
Read how it works โ https://thehackernews.com/2025/11/google-launches-new-maps-feature-to.html
Scammers are posting fake 1โญ reviews, then asking business owners to pay up to remove them.
This new tool is meant to stop the surge in โreview bombingโ hitting small businesses.
Read how it works โ https://thehackernews.com/2025/11/google-launches-new-maps-feature-to.html
๐ค11๐6๐ฅ5๐2
Your company's logins could be on the dark web right now, and they could sell for as little as $15.
It only takes one click for hackers to walk right in.
Find out if your companyโs credentials are exposed โ https://thehackernews.com/2025/11/enterprise-credentials-at-risk-same-old.html
It only takes one click for hackers to walk right in.
Find out if your companyโs credentials are exposed โ https://thehackernews.com/2025/11/enterprise-credentials-at-risk-same-old.html
๐คฏ5๐4
๐จ WARNING: Malicious NuGet packages were caught hiding delayed payloadsโset to fire off years from now, in 2027โ2028.
They look harmless. Some even helpful. But one, Sharp7Extend, quietly sabotages PLCsโcrashing processes or corrupting writes after a short delay.
Nearly 10K downloads before anyone noticed.
Hereโs whatโs really going on โ https://thehackernews.com/2025/11/hidden-logic-bombs-in-malware-laced.html
They look harmless. Some even helpful. But one, Sharp7Extend, quietly sabotages PLCsโcrashing processes or corrupting writes after a short delay.
Nearly 10K downloads before anyone noticed.
Hereโs whatโs really going on โ https://thehackernews.com/2025/11/hidden-logic-bombs-in-malware-laced.html
๐ฅ12๐5๐4