The Hacker News
βœ”
152K subscribers
1.88K photos
10 videos
3 files
7.79K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
🚨 Major AI engines from Meta, Nvidia, Microsoft, and PyTorch were hit by the same critical bug.

It lets attackers run code on remote systems β€” all because of a reused unsafe pattern in ZeroMQ and Python pickle.

Some systems are still not fixed.

Read the full story ↓ https://thehackernews.com/2025/11/researchers-find-serious-ai-bugs.html
😁8
🚨 North Korean hackers have a new trick.

They’re hiding malware inside fake API keys on GitHub β€” using JSON Keeper and other legit tools to stay invisible.

The attack installs β€œBeaverTail” to steal data and drop a Python backdoor.

See how it works ↓ https://thehackernews.com/2025/11/north-korean-hackers-turn-json-services.html
πŸ€”7⚑5πŸ‘2
πŸ”” Update: Fortinet has assigned CVE-2025-64446 (CVSS 9.1) β€” a path traversal flaw letting attackers run admin commands via crafted HTTP/S requests.

CISA added it to KEV β€” deadline: Nov 21.

Exploited in the wild.

Patch now ‡️ https://thehackernews.com/2025/11/fortinet-fortiweb-flaw-actively.html
πŸ”₯12🀯2⚑1😁1
The U.S. just uncovered how North Korea used fake β€œremote IT jobs” to sneak millions past sanctions.

πŸ‘€ 5 Americans pleaded guilty
🏒 136 U.S. companies hit
πŸ’° $2.2M sent to North Korea

Read the details ↓ https://thehackernews.com/2025/11/five-us-citizens-plead-guilty-to.html
😁17🀯5😱4πŸ”₯1
🚨 A new botnet called RondoDox is attacking unpatched XWiki servers through a critical bug (CVE-2025-24893, score 9.8).

Hackers are using it to spread crypto miners and DDoS tools.

Learn more ↓ https://thehackernews.com/2025/11/rondodox-exploits-unpatched-xwiki.html
πŸ‘2