The Hacker News
βœ”
152K subscribers
1.87K photos
10 videos
3 files
7.78K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
77% of employees paste sensitive data into GenAI tools.
Most use personal accounts, so IT can’t see it.

It’s all happening in the browser β€” and old DLP tools miss it completely.

The browser just became the biggest data leak in the enterprise ↓ https://thehackernews.com/2025/11/new-browser-security-report-reveals.html
😁18πŸ‘7🀯1
North Korea’s Konni group just pulled off something wild β€” they turned Google’s own Find Hub into a weapon.

By stealing Google logins, they could remotely wipe Android phones, erasing data and covering their tracks.

It all started with a fake β€œStress Clear” app, signed with a real Chinese company’s certificate.

Full story ↓ https://thehackernews.com/2025/11/konni-hackers-turn-googles-find-hub.html
πŸ‘10😁5πŸ‘1
🚨 UNC6485 is weaponizing CVE-2025-12480 (CVSS 9.1).

They bypassed Triofox auth, ran setup to create an admin, then pointed the antivirus path at centre_report.bat to run code as SYSTEM.

Read ↓ https://thehackernews.com/2025/11/hackers-exploiting-triofox-flaw-to.html
πŸ‘12😁6πŸ”₯2🀯1
Hackers aren’t after people anymore β€” they’re after bots.

API keys and tokens now run much of your SaaS, often with full access.

One stolen token let attackers break into hundreds of Salesforce accounts.

See how it happened ↓ https://thehackernews.com/expert-insights/2025/11/whos-really-using-your-saas-rise-of-non.html
πŸ‘14πŸ”₯2πŸ‘2😁2
A fake npm package was caught pretending to be GitHub’s real one.

~acitons/artifact (with the typo) tried to steal build tokens from GitHub repos.

It ran a postinstall script that sent secrets to a fake GitHub site.

Full story ↓ https://thehackernews.com/2025/11/researchers-detect-malicious-npm.html
πŸ”₯10πŸ‘2πŸ‘2
🚨 🚨 New Android RAT β€” β€œFantasy Hub” β€” is on sale on Russian Telegram: $200/week or $4,500/year.

It turns any app into spyware, pretends to be a Play update, hijacks SMS to steal 2FA, and streams camera/mic in real time via WebRTC.

Novices can buy and run it. If you use BYOD or mobile banking, read more ↓ https://thehackernews.com/2025/11/android-trojan-fantasy-hub-malware.html
πŸ”₯16😁7πŸ‘3
AI-driven supply chain attacks jumped 156% last year.

This new malware rewrites itself, looks like real code, and waits weeks before hitting. Most security tools can’t spot it.

See what CISOs are doing to fight back ↓ https://thehackernews.com/2025/11/cisos-expert-guide-to-ai-supply-chain.html
πŸ”₯6πŸ‘3😁3
🚨 GootLoader is back β€” and smarter.

Huntress found 3 new cases since Oct 27. In 2 of them, attackers took full control in under 17 hours.

Now it hides fake PDFs using special web fonts so the files look safe. ZIPs fool scanners but open real malware on Windows.

Details ↓ https://thehackernews.com/2025/11/gootloader-is-back-using-new-font-trick.html
πŸ‘8πŸ”₯3😁3
A new malware called Maverick is spreading through WhatsApp Web.

It can copy your Chrome data to skip QR logins, turn off Defender, and message your contacts from your account.

Full story ↓ https://thehackernews.com/2025/11/whatsapp-malware-maverick-hijacks.html
😱17πŸ”₯6πŸ‘4😁4
This media is not supported in your browser
VIEW IN TELEGRAM
πŸ”₯ Google just launched Private AI Compute β€” a new cloud system that runs AI without letting Google see your data.

It keeps Gemini models inside secure, encrypted hardware to protect privacy.

Auditors did find small flaws that could, in rare cases, expose users β€” but Google says fixes are on the way.

Read more ↓ https://thehackernews.com/2025/11/google-launches-private-ai-compute.html
πŸ”₯12πŸ€”7😁2😱2πŸ‘1
πŸ€– 82% of companies use AI agents.
πŸ” 53% let them access sensitive data every day.
⚠️ Most don’t know who owns or controls them.

One forgotten agent can leak everything.

How to stop it β†’ https://thehackernews.com/expert-insights/2025/11/governing-ai-agents-from-enterprise.html
😁11πŸ”₯4πŸ‘2
🚨 Microsoft just fixed a Windows flaw hackers are already exploiting in the wild.

The kernel bug (CVE-2025-62215) lets anyone with local access gain full control β€” and it’s being linked with other attacks for complete takeover.

Install the latest patches now ↓ https://thehackernews.com/2025/11/microsoft-fixes-63-security-flaws.html
πŸ‘17πŸ”₯2
Scale Container Security with Confidence β€” Live Webinar

Learn how top teams build secure, compliant containers that scale β€” without slowing delivery.

πŸ“… Nov 25 | 11 AM EST
πŸŽ™οΈ 20-Minute Session + Q&A

Save Your Seat πŸ‘‡ https://thn.news/webinar-insights
πŸ‘9
Active Directory is the single point of failure for most enterprises.

One bad password or missed update can give attackers full control. They know it. Most teams don’t act on it.

See what the latest breach exposed β†’ https://thehackernews.com/2025/11/active-directory-under-siege-why.html
πŸ”₯10πŸ‘2πŸ‘2🀯1
⚑ Hackers only need one open door. Most tools find it after they’re inside.

Dynamic Attack Surface Reduction (DASR) spots weak points as they appearβ€”and closes them fast. Fewer alerts. Stronger defense.

Join this WEBINAR to see how it works ↓ https://thehackernews.com/2025/11/webinar-learn-how-leading-security.html
🀯5⚑3πŸ‘2πŸ‘2
🚨 Amazon revealed details of attacks exploiting two recent flaws in Cisco ISE and Citrix NetScaler β€” both used as zero-days.

Hackers made a fake Cisco file that hid in memory, watched traffic, and stole access without being seen.

Full story β†’ https://thehackernews.com/2025/11/amazon-uncovers-attacks-exploited-cisco.html
πŸ”₯8😁4πŸ‘1
πŸ’» Google sued a Chinese hacker group that runs a phishing service called Lighthouse.

It tricked over 1 million people in 120 countries and made more than $1 billion using fake Google and USPS pages.

They sold the phishing kits β€” $88 a week to $1,588 a year.

Read more β†’ https://thehackernews.com/2025/11/google-sues-china-based-hackers-behind.html
πŸ‘25😱7😁3⚑1πŸ‘1
🚨 Over 43,000 fake npm packages have flooded the registry since 2024.

They don’t steal data β€” they just keep cloning themselves. A hidden script waits until someone runs node auto.js, then the cycle starts.

It went unnoticed for almost two years.

Read more β†’ https://thehackernews.com/2025/11/over-46000-fake-npm-packages-flood.html
πŸ‘6😱5
🚨 CISA says hackers are exploiting a serious WatchGuard firewall flaw (CVE-2025-9242, score 9.3).

Attackers can run code without logging in.

Over 54,000 Firebox devices are still exposed. Patch before Dec 3.

Details ↓ https://thehackernews.com/2025/11/cisa-flags-critical-watchguard-fireware.html
😱9πŸ”₯5πŸ‘1
🚨 New ThreatsDay Bulletin is out!

From AI bug bounties and data leaks to phishing kits and global cyber laws β€” here’s what’s shaping the week in cybersecurity.

πŸ‘‰ Read the full update: https://thehackernews.com/2025/11/threatsday-bulletin-cisco-0-days-ai-bug.html
πŸ‘5πŸ‘1