π¨ Major AI engines from Meta, Nvidia, Microsoft, and PyTorch were hit by the same critical bug.
It lets attackers run code on remote systems β all because of a reused unsafe pattern in ZeroMQ and Python pickle.
Some systems are still not fixed.
Read the full story β https://thehackernews.com/2025/11/researchers-find-serious-ai-bugs.html
It lets attackers run code on remote systems β all because of a reused unsafe pattern in ZeroMQ and Python pickle.
Some systems are still not fixed.
Read the full story β https://thehackernews.com/2025/11/researchers-find-serious-ai-bugs.html
π8
π¨ North Korean hackers have a new trick.
Theyβre hiding malware inside fake API keys on GitHub β using JSON Keeper and other legit tools to stay invisible.
The attack installs βBeaverTailβ to steal data and drop a Python backdoor.
See how it works β https://thehackernews.com/2025/11/north-korean-hackers-turn-json-services.html
Theyβre hiding malware inside fake API keys on GitHub β using JSON Keeper and other legit tools to stay invisible.
The attack installs βBeaverTailβ to steal data and drop a Python backdoor.
See how it works β https://thehackernews.com/2025/11/north-korean-hackers-turn-json-services.html
π€7β‘5π2
π Update: Fortinet has assigned CVE-2025-64446 (CVSS 9.1) β a path traversal flaw letting attackers run admin commands via crafted HTTP/S requests.
CISA added it to KEV β deadline: Nov 21.
Exploited in the wild.
Patch now β€΅οΈ https://thehackernews.com/2025/11/fortinet-fortiweb-flaw-actively.html
CISA added it to KEV β deadline: Nov 21.
Exploited in the wild.
Patch now β€΅οΈ https://thehackernews.com/2025/11/fortinet-fortiweb-flaw-actively.html
π₯12π€―2β‘1π1
The U.S. just uncovered how North Korea used fake βremote IT jobsβ to sneak millions past sanctions.
π€ 5 Americans pleaded guilty
π’ 136 U.S. companies hit
π° $2.2M sent to North Korea
Read the details β https://thehackernews.com/2025/11/five-us-citizens-plead-guilty-to.html
π€ 5 Americans pleaded guilty
π’ 136 U.S. companies hit
π° $2.2M sent to North Korea
Read the details β https://thehackernews.com/2025/11/five-us-citizens-plead-guilty-to.html
π17π€―5π±4π₯1
π¨ A new botnet called RondoDox is attacking unpatched XWiki servers through a critical bug (CVE-2025-24893, score 9.8).
Hackers are using it to spread crypto miners and DDoS tools.
Learn more β https://thehackernews.com/2025/11/rondodox-exploits-unpatched-xwiki.html
Hackers are using it to spread crypto miners and DDoS tools.
Learn more β https://thehackernews.com/2025/11/rondodox-exploits-unpatched-xwiki.html
π2