The Hacker News
βœ”
152K subscribers
1.93K photos
10 videos
3 files
7.85K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
This week's ThreatsDay looks at big cyber news from around the world:

πŸ”Ή Russian hackers got arrested
πŸ”Ή Chinese spies are using LinkedIn to find secrets
πŸ”Ή People caught washing dirty money with crypto
πŸ”Ή New hidden bugs found in phones, computers, and smart home gadgets
πŸ”Ή ... and many more.

🌐 Zero-day attacks β€’ Spying β€’ Crypto crime β€’ Bugs in everyday devices β€’ Moving malware

Read all critical stories here β†’ https://thehackernews.com/2025/11/threatsday-bulletin-0-days-linkedin.html
πŸ”₯8😁2
JSGuLdr: Multi-Stage Loader Delivering PhantomStealer

#ANYRUN researchers identified #JSGuLdr, a multi-stage JavaScript-to-PowerShell loader used to deliver #PhantomStealer. A JScript file triggers PowerShell through an Explorer COM call, pulls the second stage from %APPDATA%\Registreri62, then uses Net.WebClient to fetch an encrypted payload from Google Drive into %APPDATA%\Autorise131[.]Tel. The payload is decoded in memory and loaded, with PhantomStealerinjected into msiexec.exe.

Execution chain: wscript.exe ➑️ explorer.exe (svchost.exe) ➑️ explorer.exe (COM) ➑️ powershell.exe ➑️ msiexec.exe

πŸ‘‰ See analysis session: https://app.any.run/tasks/7b295f6f-5f16-4a44-a02b-5d59fd4b1e8f?utm_source=tg_thehackernews&utm_medium=post&utm_campaign=techpost&utm_content=task&utm_term=201125

πŸ‘‰ Read full analysis: https://t.iss.one/anyrun_app/698
⚑7πŸ‘3πŸ‘1
WhatsApp accounts are being hijacked worldwide via fake WhatsApp Web pages that mimic the official interface exactly β€” including auto-detected language and country flag.

You scan QR or type code β†’ they take your account β†’ message your friends for money + steal everything.

Check the new CTM360 report – see exactly how the fake pages look and how to stay safe ↓ https://thehackernews.com/2025/11/ctm360-exposes-global-whatsapp.html
😁12🀯4πŸ‘2πŸ‘1
Hackers made a new botnet called Tsundere β€” it’s spreading through fake game downloads like Valorant and CS2.

It hides its servers on the Ethereum blockchain, making it almost impossible to shut down.

Researchers say it’s still active.

Read more ↓ https://thehackernews.com/2025/11/tsundere-botnet-expands-using-game.html
😱17⚑5πŸ‘2
🚨 Hackers are exploiting a 2-year-old authentication flaw (CVE-2023-48022) in the Ray AI framework to take over NVIDIA GPU clusters and run a self-spreading crypto-mining botnet called ShadowRay 2.0.

The bug remains unpatched by design, and over 230,000 Ray servers are exposed online.

Read about it here ↓ https://thehackernews.com/2025/11/shadowray-20-exploits-unpatched-ray.html
πŸ‘15πŸ”₯5
🚨 ThreatsDay Bulletin β€” The EU wants to rewrite its privacy rules.

New proposal would let companies use personal data to train AI without consent, if done for β€œlegitimate interest.”

Critics say it’s a major rollback of GDPR and a win for Big Tech.

Read more ↓ https://thehackernews.com/2025/11/threatsday-bulletin-0-days-linkedin.html#eu-rewires-privacy-playbook
😱11πŸ‘4🀯4
🚨 Salesforce found unusual activity in Gainsight apps and cut off their access.

Hackers linked to ShinyHunters may have used those apps to steal Salesforce data from nearly 1,000 companies.

Gainsight was also hit in a similar attack earlier this year.

Full story ↓ https://thehackernews.com/2025/11/salesforce-flags-unauthorized-data.html
πŸ‘6😁3🀯1
βš–οΈ The SEC just ended its case against SolarWinds β€” the company hit by the big 2020 hack.

After two years of blaming its security chief, the case was quietly dropped.

Now many wonder if anyone will be held responsible next time ↓ https://thehackernews.com/2025/11/sec-drops-solarwinds-case-after-years.html
😁9πŸ‘3πŸ”₯3πŸ‘1
⚠️ A hacking group linked to China just pulled a big one.

They used a marketing firm’s code to infect 1,000+ websites with a fake πŸ”” Chrome update.

Click it β€” and you get BADAUDIO, new malware made to spy for months.

Full story ↓ https://thehackernews.com/2025/11/apt24-deploys-badaudio-in-years-long.html
πŸ”₯11😁4πŸ‘3🀯2
Every phone could be a way in for hackers.

Samsung Galaxy devices check their security before they connect to your network.

That means real Zero Trustβ€”built into the device itself.

Read ↓ https://thehackernews.com/2025/11/why-it-admins-choose-samsung-for-mobile.html
πŸ‘10πŸ€”5😁4
🚨 Google just made Android and iPhone share files directly using Quick Share and AirDrop.

It’s built in Rust for stronger security, and a small info leak found in testing is already fixed.

Full details ↓ https://thehackernews.com/2025/11/google-adds-airdrop-compatibility-to.html
πŸ”₯19πŸ‘7πŸ‘6πŸ€”2🀯2
🚨 Grafana fixed a major security bug (CVSS 10.0) that could let attackers sign in as admin users.

It affects Grafana Enterprise 12.0.0–12.2.1 if SCIM provisioning is turned on β€” a number like β€œ1” could trick the system into giving admin access.

Update now to stay safe. Read more ↓ https://thehackernews.com/2025/11/grafana-patches-cvss-100-scim-flaw.html
πŸ‘26πŸ‘1
🚨 CISA warns Oracle Identity Manager flaw (CVE-2025-61757) is under active attack.

Hackers can run code without login by adding ?WSDL or ;.wadl to URLs β€” a tiny trick that opens locked systems.

Exploited since August. Patch by Dec 12.

Full details ↓ https://thehackernews.com/2025/11/cisa-warns-of-actively-exploited.html
πŸ‘12🀯1
🚨 Hackers found a new way to phish β€” through browser notifications.

A new tool called Matrix Push C2 lets attackers send fake alerts that look like real ones from PayPal, Netflix, or TikTok.

No downloads. No malware file. Just one click β€” and your data’s theirs.

Learn more ↓ https://thehackernews.com/2025/11/matrix-push-c2-uses-browser.html
πŸ”₯29πŸ‘9
🚨 China’s hacker group APT31 broke into Russia’s IT companies β€” and stayed hidden for almost two years.

They used Yandex Cloud, OneDrive, and even social media to steal data without raising alarms.

Some attacks ran on holidays when no one was watching.

Details ↓ https://thehackernews.com/2025/11/china-linked-apt31-launches-stealthy.html
πŸ”₯66🀯30😁20πŸ‘6πŸ€”3πŸ‘2😱1
🚨 Hackers are using a fixed Windows bug (CVE-2025-59287) to spread ShadowPad malware through WSUS servers.

They used normal Windows tools like curl and certutil to install it β€” a method seen before in Chinese hacking groups.

Systems patched too late may have already been compromised.

Full story ↓ https://thehackernews.com/2025/11/shadowpad-malware-actively-exploits.html
πŸ‘6πŸ‘2😁2
πŸ”΄ Researchers say China’s DeepSeek-R1 AI writes weaker code when asked about topics like Tibet or Uyghurs.

Coding mistakes go up by about 50%, even when the topic isn’t part of the task.

This bias could be a new security risk.

Full story ↓ https://thehackernews.com/2025/11/chinese-ai-model-deepseek-r1-generates.html
😁22πŸ”₯7⚑3πŸ€”2
⚑ Another week, another wave of exploits, leaks, and surprise fixes.

What’s real, what’s risky, what’s next β€” it’s all in the Cybersecurity Recap πŸ‘‰

https://thehackernews.com/2025/11/weekly-recap-fortinet-exploit-chrome-0.html
πŸ”₯5πŸ‘2
πŸ”₯ New npm attack DETECTED!

A campaign dubbed β€œSha1-Hulud: The Second Coming” has compromised hundreds of packages and over 25,000 GitHub repos.

The code runs during install, steals cloud logins, and if that fails, it deletes the user’s home folder.

Read more ↓ https://thehackernews.com/2025/11/second-sha1-hulud-wave-affects-25000.html
😁11🀯6πŸ€”2
🚨 Fluent Bit β€” deployed over 15 Billion times β€” just got hit with 5 critical CVEs.

Attackers can exploit them to run code, rewrite or delete logs, and fake telemetry across AWS, GCP & Azure.

Some of these bugs have been in Fluent Bit for over 8 years.

More details ↓ https://thehackernews.com/2025/11/new-fluent-bit-flaws-expose-cloud-to.html
😁12πŸ”₯3🀯2πŸ‘1