The Hacker News
Kanalga Telegramโda oโtish
โญ Official THN Telegram Channel โ A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. ๐จ Contact: admin@thehackernews.com ๐ Website: https://thehackernews.com
Ko'proq ko'rsatish153 046
Obunachilar
+6424 soatlar
+3297 kunlar
+1 41630 kunlar
Postlar arxiv
Photo unavailableShow in Telegram
โ ๏ธ Microsoft just fixed 56 Windows bugs โ oneโs already being exploited.
It hides in the Cloud Files driver used by OneDrive, Google Drive, and iCloud โ even if those apps arenโt installed. Hackers can chain it with phishing to gain SYSTEM access.
Plus: 2 zero-days in PowerShell and GitHub Copilot for JetBrains.
๐ Details โ https://thehackernews.com/2025/12/microsoft-issues-security-fixes-for-56.html
๐ฅ 14๐ 5๐ 4
Photo unavailableShow in Telegram
โ ๏ธ Fortinet, Ivanti & SAP just fixed critical bugs that let attackers break in or run code remotely.
โ Fortinet: auth bypass via fake SAML login.
โ Ivanti: admin takeover through poisoned dashboards.
โ SAP: code injection in Solution Manager (CVSS 9.9).
๐Patch Now: https://thehackernews.com/2025/12/fortinet-ivanti-and-sap-issue-urgent.html
๐ 7๐ 2
Photo unavailableShow in Telegram
๐จ North Korean hackers are exploiting the new React2Shell bug (10.0-severity) to drop EtherRAT โ malware that hides its commands inside Ethereum smart contracts.
It even makes 9 blockchain nodes โvoteโ to pick its server, so takedowns fail.
๐ Read now โ https://thehackernews.com/2025/12/north-korea-linked-actors-exploit.html
๐ฅ 22๐คฏ 7๐ 5๐ฑ 4๐ 3๐ 1
Photo unavailableShow in Telegram
โ ๏ธ 4 hacker groups are now using the same malware tool โ CastleLoader.
Itโs sold as malware-for-hire by a group called GrayBravo. Theyโre hitting targets from logistics to IT using fake online Booking pages and software updates.
Each attack links back to the same control servers โ built to spread fast.
๐ Read โ https://thehackernews.com/2025/12/four-threat-clusters-using-castleloader.html
๐ฅ 13
Photo unavailableShow in Telegram
GTG-1002 changed the rules.
An AI-driven attack hit dozens of companiesโ80% run autonomously, at machine speed.
The real threat? SaaS tokens that stay trusted forever after one approval.
Static trust canโt defend against dynamic attackers.
๐ Learn more: https://thehackernews.com/expert-insights/2025/12/what-gtg-1002-and-claude-style-attacks.html
๐ฅ 10
Photo unavailableShow in Telegram
๐จ Storm-0249 just changed tactics.
The hacker group Microsoft flagged in 2024 is now faking Microsoft domains and abusing real security tools like SentinelOne to sneak in ransomware.
Theyโre using PowerShell commands that never drop filesโmaking them almost invisible.
๐ Read โ https://thehackernews.com/2025/12/storm-0249-escalates-ransomware-attacks.html
๐ฅ 15
Photo unavailableShow in Telegram
๐ก Most Zero Trust tools still donโt talk to each other โ so access decisions lag behind real risks.
A MongoDB engineer built a workflow using Tines that lets Kolide send real-time device alerts to Okta through the Shared Signals Framework.
Finally, Zero Trust that actually works in sync.
๐ Read: https://thehackernews.com/2025/12/how-to-streamline-zero-trust-using.html
๐ 15
Photo unavailableShow in Telegram
๐ฅ You can win $20K for breaking Googleโs new Chrome security feature.
Google just added the โUser Alignment Critic,โ a safeguard that uses a second model to double-check Chromeโs AI agent and block prompt attacks or data leaks.
๐ Read: https://thehackernews.com/2025/12/google-adds-layered-defenses-to-chrome.html
๐ 21๐ฅ 7๐ค 7
Photo unavailableShow in Telegram
๐จ Hackers are uploading fake resumes on Indeed and JazzHR to breach Canadian companies.
80% of attacks in this campaign hit Canada.
The โPDFsโ actually launch QWCrypt ransomware through a tool called RedLoader.
๐ Read: https://thehackernews.com/2025/12/stac6565-targets-canada-in-80-of.html
๐ฑ 13๐ 6๐ 5
Photo unavailableShow in Telegram
โ ๏ธ Researchers found malicious packages in VS Code, Go, npm, and Rust stealing developer data.
They mimicked themes, AI tools, and libraries to grab screenshots, Wi-Fi passwords, and browser cookies.
๐ Find details here โ https://thehackernews.com/2025/12/researchers-find-malicious-vs-code-go.html
๐คฏ 16๐ 5๐ค 4๐ฅ 2๐ 2
Photo unavailableShow in Telegram
โ ๏ธ Hackers are hiding malware in normal websites.
A new attack called JS#SMUGGLER plants code that quietly runs PowerShell through mshta.exe to install NetSupport RAT โ giving attackers full control of your computer.
It even checks your device type to avoid being caught.
๐ Read โ https://thehackernews.com/2025/12/experts-confirm-jssmuggler-uses.html
๐ค 16๐คฏ 10๐ 5๐ฅ 2๐ 2
Photo unavailableShow in Telegram
Catch the the latest CybersecurityRecap for:
๐ฅ USB drives spreading crypto miners.
๐ฐ Fake investment sites busted.
๐ CastleRAT creeping through networks.
โ๏ธ Portugal shields ethical hackers.
๐ธ Ransomware payouts falling fast.
๐ Get the full stories, latest tools, and expert webinars in the latest recap: https://thehackernews.com/2025/12/weekly-recap-usb-malware-react2shell.html
โก 6๐ 4๐ 1๐ฅ 1๐ 1
Photo unavailableShow in Telegram
โ ๏ธ Holiday shopping means hacker season.
Bots hit hardest around Black Friday & Christmas.
Reused passwords = easy targets.
Block breached logins + secure vendor accounts now.
๐ Read โ https://thehackernews.com/2025/12/how-can-retailers-cyber-prepare-for.html
โก 11
Photo unavailableShow in Telegram
โ ๏ธ Three new Android threats just dropped:
โข FvncBot โ fake โmBankโ app that logs keys, streams screens, and steals banking data.
โข SeedSnatcher โ spreads via Telegram to steal crypto seed phrases and 2FA codes.
โข ClayRat โ upgraded spyware faking YouTube & taxi apps for full device control.
All abuse Androidโs accessibility features.
๐ Read here โ https://thehackernews.com/2025/12/android-malware-fvncbot-seedsnatcher.html
๐ฅ 13๐ 4๐คฏ 4๐ 3๐ 2
Photo unavailableShow in Telegram
โ ๏ธ Hackers are exploiting a bug in the Sneeit Framework plugin (CVE-2025-6389) to run code on servers and create admin accounts on WordPress sites.
โ ๏ธ Separately, a flaw in ICTBroadcast (CVE-2025-2611) lets attackers use the BROADCAST cookie for unauthenticated remote shell access on exposed hosts.
๐ Read โ https://thehackernews.com/2025/12/sneeit-wordpress-rce-exploited-in-wild.html
๐ค 10๐ 3๐ฑ 2
Photo unavailableShow in Telegram
โ ๏ธ Iranโs MuddyWater hackers are using a new backdoor called "UDPGangster" that hides in fake โelection seminarโ Word files.
It only runs after checking if your computer is real โ not a sandbox โ then steals data over UDP to dodge detection.
๐ Read โ https://thehackernews.com/2025/12/muddywater-deploys-udpgangster-backdoor.html
๐ 17๐ฅ 11๐คฏ 8โก 4๐ 4๐ค 2
Photo unavailableShow in Telegram
๐ Over 30 security flaws found in AI-powered coding tools like Copilot, Cursor, and Zed โ letting hackers steal data or run malicious code without you doing a thing.
Researchers are calling it โIDEsaster.โ
๐ Details here โ https://thehackernews.com/2025/12/researchers-uncover-30-flaws-in-ai.html
๐ 32๐ 15๐คฏ 12๐ฅ 1
Photo unavailableShow in Telegram
CISA added the new 10.0-rated React RCE flaw (CVE-2025-55182) to its exploited list.
๐ Exploited within hours by Chinese hackers.
๐ฅ Affects Next.js, React Router, Vite, Waku & more.
๐ฐ Some attacks dropped crypto-miners & stole AWS creds.
๐ Read: https://thehackernews.com/2025/12/critical-react2shell-flaw-added-to-cisa.html
๐ฅ 19๐ 11๐ 4๐ 4๐คฏ 2
Photo unavailableShow in Telegram
๐จ WARNING: A new attack can trick Perplexityโs Comet browser into deleting your Google Drive.
Just one normal-looking email with hidden cleanup instructions can make the AI agent erase real files โ no exploit, no warning.
๐ Details here โ https://thehackernews.com/2025/12/zero-click-agentic-browser-attack-can.html
๐คฏ 23๐ 14๐ฅ 8
Photo unavailableShow in Telegram
๐งฉ 57% of SMBs say cybersecurity is a top priority โ yet they still turn down MSPs.
โก The issue isnโt interest. Itโs confusion.
โก Theyโre tired of jargon, fear, and hard selling.
โGetting to Yesโ helps MSPs explain security in plain business terms โ and win trust.
๐ See how itโs done โ https://thehackernews.com/2025/12/getting-to-yes-anti-sales-guide-for-msps.html
๐ 4
