uz
Feedback
The Hacker News

The Hacker News

Kanalga Telegramโ€™da oโ€˜tish

โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. ๐Ÿ“จ Contact: admin@thehackernews.com ๐ŸŒ Website: https://thehackernews.com

Ko'proq ko'rsatish
153 046
Obunachilar
+6424 soatlar
+3297 kunlar
+1 41630 kunlar
Postlar arxiv
Photo unavailableShow in Telegram
โš ๏ธ Microsoft just fixed 56 Windows bugs โ€” oneโ€™s already being exploited. It hides in the Cloud Files driver used by OneDrive, Google Drive, and iCloud โ€” even if those apps arenโ€™t installed. Hackers can chain it with phishing to gain SYSTEM access. Plus: 2 zero-days in PowerShell and GitHub Copilot for JetBrains. ๐Ÿ”— Details โ†“ https://thehackernews.com/2025/12/microsoft-issues-security-fixes-for-56.html
Hammasini ko'rsatish...
๐Ÿ”ฅ 14๐Ÿ˜ 5๐Ÿ‘ 4
Photo unavailableShow in Telegram
โš ๏ธ Fortinet, Ivanti & SAP just fixed critical bugs that let attackers break in or run code remotely. โžœ Fortinet: auth bypass via fake SAML login. โžœ Ivanti: admin takeover through poisoned dashboards. โžœ SAP: code injection in Solution Manager (CVSS 9.9). ๐Ÿ”—Patch Now: https://thehackernews.com/2025/12/fortinet-ivanti-and-sap-issue-urgent.html
Hammasini ko'rsatish...
๐Ÿ‘ 7๐Ÿ˜ 2
Photo unavailableShow in Telegram
๐Ÿšจ North Korean hackers are exploiting the new React2Shell bug (10.0-severity) to drop EtherRAT โ€” malware that hides its commands inside Ethereum smart contracts. It even makes 9 blockchain nodes โ€œvoteโ€ to pick its server, so takedowns fail. ๐Ÿ”— Read now โ†“ https://thehackernews.com/2025/12/north-korea-linked-actors-exploit.html
Hammasini ko'rsatish...
๐Ÿ”ฅ 22๐Ÿคฏ 7๐Ÿ‘ 5๐Ÿ˜ฑ 4๐Ÿ˜ 3๐Ÿ‘ 1
Photo unavailableShow in Telegram
โš ๏ธ 4 hacker groups are now using the same malware tool โ€” CastleLoader. Itโ€™s sold as malware-for-hire by a group called GrayBravo. Theyโ€™re hitting targets from logistics to IT using fake online Booking pages and software updates. Each attack links back to the same control servers โ€” built to spread fast. ๐Ÿ”— Read โ†“ https://thehackernews.com/2025/12/four-threat-clusters-using-castleloader.html
Hammasini ko'rsatish...
๐Ÿ”ฅ 13
Photo unavailableShow in Telegram
GTG-1002 changed the rules. An AI-driven attack hit dozens of companiesโ€”80% run autonomously, at machine speed. The real threat? SaaS tokens that stay trusted forever after one approval. Static trust canโ€™t defend against dynamic attackers. ๐Ÿ”— Learn more: https://thehackernews.com/expert-insights/2025/12/what-gtg-1002-and-claude-style-attacks.html
Hammasini ko'rsatish...
๐Ÿ”ฅ 10
Photo unavailableShow in Telegram
๐Ÿšจ Storm-0249 just changed tactics. The hacker group Microsoft flagged in 2024 is now faking Microsoft domains and abusing real security tools like SentinelOne to sneak in ransomware. Theyโ€™re using PowerShell commands that never drop filesโ€”making them almost invisible. ๐Ÿ”— Read โ†“ https://thehackernews.com/2025/12/storm-0249-escalates-ransomware-attacks.html
Hammasini ko'rsatish...
๐Ÿ”ฅ 15
Photo unavailableShow in Telegram
๐Ÿ’ก Most Zero Trust tools still donโ€™t talk to each other โ€” so access decisions lag behind real risks. A MongoDB engineer built a workflow using Tines that lets Kolide send real-time device alerts to Okta through the Shared Signals Framework. Finally, Zero Trust that actually works in sync. ๐Ÿ”— Read: https://thehackernews.com/2025/12/how-to-streamline-zero-trust-using.html
Hammasini ko'rsatish...
๐Ÿ‘ 15
Photo unavailableShow in Telegram
๐Ÿ”ฅ You can win $20K for breaking Googleโ€™s new Chrome security feature. Google just added the โ€œUser Alignment Critic,โ€ a safeguard that uses a second model to double-check Chromeโ€™s AI agent and block prompt attacks or data leaks. ๐Ÿ”— Read: https://thehackernews.com/2025/12/google-adds-layered-defenses-to-chrome.html
Hammasini ko'rsatish...
๐Ÿ˜ 21๐Ÿ”ฅ 7๐Ÿค” 7
Photo unavailableShow in Telegram
๐Ÿšจ Hackers are uploading fake resumes on Indeed and JazzHR to breach Canadian companies. 80% of attacks in this campaign hit Canada. The โ€œPDFsโ€ actually launch QWCrypt ransomware through a tool called RedLoader. ๐Ÿ”— Read: https://thehackernews.com/2025/12/stac6565-targets-canada-in-80-of.html
Hammasini ko'rsatish...
๐Ÿ˜ฑ 13๐Ÿ‘ 6๐Ÿ˜ 5
Photo unavailableShow in Telegram
โš ๏ธ Researchers found malicious packages in VS Code, Go, npm, and Rust stealing developer data. They mimicked themes, AI tools, and libraries to grab screenshots, Wi-Fi passwords, and browser cookies. ๐Ÿ”— Find details here โ†“ https://thehackernews.com/2025/12/researchers-find-malicious-vs-code-go.html
Hammasini ko'rsatish...
๐Ÿคฏ 16๐Ÿ˜ 5๐Ÿค” 4๐Ÿ”ฅ 2๐Ÿ‘ 2
Photo unavailableShow in Telegram
โš ๏ธ Hackers are hiding malware in normal websites. A new attack called JS#SMUGGLER plants code that quietly runs PowerShell through mshta.exe to install NetSupport RAT โ€” giving attackers full control of your computer. It even checks your device type to avoid being caught. ๐Ÿ”— Read โ†“ https://thehackernews.com/2025/12/experts-confirm-jssmuggler-uses.html
Hammasini ko'rsatish...
๐Ÿค” 16๐Ÿคฏ 10๐Ÿ‘ 5๐Ÿ”ฅ 2๐Ÿ˜ 2
Photo unavailableShow in Telegram
Catch the the latest CybersecurityRecap for: ๐Ÿ’ฅ USB drives spreading crypto miners. ๐Ÿ’ฐ Fake investment sites busted. ๐Ÿ€ CastleRAT creeping through networks. โš–๏ธ Portugal shields ethical hackers. ๐Ÿ’ธ Ransomware payouts falling fast. ๐Ÿ‘‰ Get the full stories, latest tools, and expert webinars in the latest recap: https://thehackernews.com/2025/12/weekly-recap-usb-malware-react2shell.html
Hammasini ko'rsatish...
โšก 6๐Ÿ‘ 4๐Ÿ‘ 1๐Ÿ”ฅ 1๐Ÿ˜ 1
Photo unavailableShow in Telegram
โš ๏ธ Holiday shopping means hacker season. Bots hit hardest around Black Friday & Christmas. Reused passwords = easy targets. Block breached logins + secure vendor accounts now. ๐Ÿ”— Read โ†“ https://thehackernews.com/2025/12/how-can-retailers-cyber-prepare-for.html
Hammasini ko'rsatish...
โšก 11
Photo unavailableShow in Telegram
โš ๏ธ Three new Android threats just dropped: โ€ข FvncBot โ€“ fake โ€œmBankโ€ app that logs keys, streams screens, and steals banking data. โ€ข SeedSnatcher โ€“ spreads via Telegram to steal crypto seed phrases and 2FA codes. โ€ข ClayRat โ€“ upgraded spyware faking YouTube & taxi apps for full device control. All abuse Androidโ€™s accessibility features. ๐Ÿ”— Read here โ†“ https://thehackernews.com/2025/12/android-malware-fvncbot-seedsnatcher.html
Hammasini ko'rsatish...
๐Ÿ”ฅ 13๐Ÿ‘ 4๐Ÿคฏ 4๐Ÿ˜ 3๐Ÿ‘ 2
Photo unavailableShow in Telegram
โš ๏ธ Hackers are exploiting a bug in the Sneeit Framework plugin (CVE-2025-6389) to run code on servers and create admin accounts on WordPress sites. โš ๏ธ Separately, a flaw in ICTBroadcast (CVE-2025-2611) lets attackers use the BROADCAST cookie for unauthenticated remote shell access on exposed hosts. ๐Ÿ”— Read โ†“ https://thehackernews.com/2025/12/sneeit-wordpress-rce-exploited-in-wild.html
Hammasini ko'rsatish...
๐Ÿค” 10๐Ÿ‘ 3๐Ÿ˜ฑ 2
Photo unavailableShow in Telegram
โš ๏ธ Iranโ€™s MuddyWater hackers are using a new backdoor called "UDPGangster" that hides in fake โ€œelection seminarโ€ Word files. It only runs after checking if your computer is real โ€” not a sandbox โ€” then steals data over UDP to dodge detection. ๐Ÿ”— Read โ†’ https://thehackernews.com/2025/12/muddywater-deploys-udpgangster-backdoor.html
Hammasini ko'rsatish...
๐Ÿ˜ 17๐Ÿ”ฅ 11๐Ÿคฏ 8โšก 4๐Ÿ‘ 4๐Ÿค” 2
Photo unavailableShow in Telegram
๐Ÿ›‘ Over 30 security flaws found in AI-powered coding tools like Copilot, Cursor, and Zed โ€” letting hackers steal data or run malicious code without you doing a thing. Researchers are calling it โ€œIDEsaster.โ€ ๐Ÿ”— Details here โ†’ https://thehackernews.com/2025/12/researchers-uncover-30-flaws-in-ai.html
Hammasini ko'rsatish...
๐Ÿ˜ 32๐Ÿ‘ 15๐Ÿคฏ 12๐Ÿ”ฅ 1
Photo unavailableShow in Telegram
CISA added the new 10.0-rated React RCE flaw (CVE-2025-55182) to its exploited list. ๐Ÿ•’ Exploited within hours by Chinese hackers. ๐Ÿ’ฅ Affects Next.js, React Router, Vite, Waku & more. ๐Ÿ’ฐ Some attacks dropped crypto-miners & stole AWS creds. ๐Ÿ”— Read: https://thehackernews.com/2025/12/critical-react2shell-flaw-added-to-cisa.html
Hammasini ko'rsatish...
๐Ÿ”ฅ 19๐Ÿ‘ 11๐Ÿ‘ 4๐Ÿ˜ 4๐Ÿคฏ 2
Photo unavailableShow in Telegram
๐Ÿšจ WARNING: A new attack can trick Perplexityโ€™s Comet browser into deleting your Google Drive. Just one normal-looking email with hidden cleanup instructions can make the AI agent erase real files โ€” no exploit, no warning. ๐Ÿ”— Details here โ†’ https://thehackernews.com/2025/12/zero-click-agentic-browser-attack-can.html
Hammasini ko'rsatish...
๐Ÿคฏ 23๐Ÿ˜ 14๐Ÿ”ฅ 8
Photo unavailableShow in Telegram
๐Ÿงฉ 57% of SMBs say cybersecurity is a top priority โ€” yet they still turn down MSPs. โžก The issue isnโ€™t interest. Itโ€™s confusion. โžก Theyโ€™re tired of jargon, fear, and hard selling. โ€œGetting to Yesโ€ helps MSPs explain security in plain business terms โ€” and win trust. ๐Ÿ‘‰ See how itโ€™s done โ†’ https://thehackernews.com/2025/12/getting-to-yes-anti-sales-guide-for-msps.html
Hammasini ko'rsatish...
๐Ÿ‘ 4