ch
Feedback
The Hacker News

The Hacker News

前往频道在 Telegram

⭐ Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. 📨 Contact: admin@thehackernews.com 🌐 Website: https://thehackernews.com

显示更多
2025 年数字统计snowflakes fon
card fon
153 612
订阅者
+9424 小时
+3767
+1 46330
帖子存档
照片不可用在 Telegram 中显示
⚠️ Holiday shopping means hacker season. Bots hit hardest around Black Friday & Christmas. Reused passwords = easy targets. Block breached logins + secure vendor accounts now. 🔗 Read ↓ https://thehackernews.com/2025/12/how-can-retailers-cyber-prepare-for.html
显示全部...
11
照片不可用在 Telegram 中显示
⚠️ Three new Android threats just dropped: • FvncBot – fake “mBank” app that logs keys, streams screens, and steals banking data. • SeedSnatcher – spreads via Telegram to steal crypto seed phrases and 2FA codes. • ClayRat – upgraded spyware faking YouTube & taxi apps for full device control. All abuse Android’s accessibility features. 🔗 Read here ↓ https://thehackernews.com/2025/12/android-malware-fvncbot-seedsnatcher.html
显示全部...
🔥 13👍 4🤯 4😁 3👏 2
照片不可用在 Telegram 中显示
⚠️ Hackers are exploiting a bug in the Sneeit Framework plugin (CVE-2025-6389) to run code on servers and create admin accounts on WordPress sites. ⚠️ Separately, a flaw in ICTBroadcast (CVE-2025-2611) lets attackers use the BROADCAST cookie for unauthenticated remote shell access on exposed hosts. 🔗 Read ↓ https://thehackernews.com/2025/12/sneeit-wordpress-rce-exploited-in-wild.html
显示全部...
🤔 10👍 3😱 2
照片不可用在 Telegram 中显示
⚠️ Iran’s MuddyWater hackers are using a new backdoor called "UDPGangster" that hides in fake “election seminar” Word files. It only runs after checking if your computer is real — not a sandbox — then steals data over UDP to dodge detection. 🔗 Read → https://thehackernews.com/2025/12/muddywater-deploys-udpgangster-backdoor.html
显示全部...
😁 17🔥 11🤯 8 4👏 4🤔 2
照片不可用在 Telegram 中显示
🛑 Over 30 security flaws found in AI-powered coding tools like Copilot, Cursor, and Zed — letting hackers steal data or run malicious code without you doing a thing. Researchers are calling it “IDEsaster.” 🔗 Details here → https://thehackernews.com/2025/12/researchers-uncover-30-flaws-in-ai.html
显示全部...
😁 32👍 15🤯 12🔥 1
照片不可用在 Telegram 中显示
CISA added the new 10.0-rated React RCE flaw (CVE-2025-55182) to its exploited list. 🕒 Exploited within hours by Chinese hackers. 💥 Affects Next.js, React Router, Vite, Waku & more. 💰 Some attacks dropped crypto-miners & stole AWS creds. 🔗 Read: https://thehackernews.com/2025/12/critical-react2shell-flaw-added-to-cisa.html
显示全部...
🔥 19👍 11👏 4😁 4🤯 2
照片不可用在 Telegram 中显示
🚨 WARNING: A new attack can trick Perplexity’s Comet browser into deleting your Google Drive. Just one normal-looking email with hidden cleanup instructions can make the AI agent erase real files — no exploit, no warning. 🔗 Details here → https://thehackernews.com/2025/12/zero-click-agentic-browser-attack-can.html
显示全部...
🤯 23😁 14🔥 8
照片不可用在 Telegram 中显示
🧩 57% of SMBs say cybersecurity is a top priority — yet they still turn down MSPs. ➡ The issue isn’t interest. It’s confusion. ➡ They’re tired of jargon, fear, and hard selling. “Getting to Yes” helps MSPs explain security in plain business terms — and win trust. 👉 See how it’s done → https://thehackernews.com/2025/12/getting-to-yes-anti-sales-guide-for-msps.html
显示全部...
👍 4
照片不可用在 Telegram 中显示
🚨 Critical Apache Tika flaw (CVE-2025-66516) just dropped — CVSS 10.0. A single fake PDF can trigger an XXE attack, letting hackers read server files or run code. 🔗 Read ↓ https://thehackernews.com/2025/12/critical-xxe-bug-cve-2025-66516-cvss.html Update to v3.2.2 now.
显示全部...
🔥 13🤔 5😱 1
照片不可用在 Telegram 中显示
⚠️ Within HOURS of disclosure, two China-linked hacking groups weaponized a critical React flaw (CVE-2025-55182). They’re already scanning the web for unpatched apps. Update to React 19.0.1+ now. 🔗 Read ↓ https://thehackernews.com/2025/12/chinese-hackers-have-started-exploiting.html
显示全部...
🤯 7🔥 4
照片不可用在 Telegram 中显示
🚨 A lawyer in Pakistan was hacked with Predator — the first known spyware attack on a civil society member. It started with a link on WhatsApp, but new leaks show Predator can also spread through ads — no click needed. It can read chats, record audio, take photos — and Intellexa may still access customer systems remotely. 🔗 Read → https://thehackernews.com/2025/12/intellexa-leaks-reveal-zero-days-and.html
显示全部...
😁 9😱 5🔥 2👏 1
照片不可用在 Telegram 中显示
🚨 CISA just warned about a new Chinese state-backed hack tool called BRICKSTORM — a backdoor found in VMware and Windows systems used by U.S. government and tech networks. It can reinstall itself if removed, hide in normal traffic, and give hackers full remote control. 🔗Read → https://thehackernews.com/2025/12/cisa-reports-prc-hackers-using.html
显示全部...
🤯 20🔥 6👏 3😁 2
照片不可用在 Telegram 中显示
⚠️ Hackers are exploiting a command injection bug in Array Networks AG Series gateways — active since August 2025. It lets attackers run any command on systems using “DesktopDirect” remote access. 🔗 Details → https://thehackernews.com/2025/12/jpcert-confirms-active-command.html
显示全部...
🔥 9😁 4👍 3
照片不可用在 Telegram 中显示
🚨 A fake Microsoft Teams installer is spreading malware in China. Hackers called "Silver Fox" made it look like a Russian attack to hide their tracks. It installs ValleyRAT, giving full remote access to victims. 🔗 Read: https://thehackernews.com/2025/12/silver-fox-uses-fake-microsoft-teams.html
显示全部...
😁 14🔥 12
照片不可用在 Telegram 中显示
🚨 AI tools are now running inside your browser — reading data, following hidden prompts, and moving info across tabs. IT can’t see it. Security can’t stop it. Seraphic Security’s Suresh Batchu calls this the next big blind spot: Shadow AI in the enterprise browser. 🔗 Read ↓ https://thehackernews.com/expert-insights/2025/12/shadow-ai-in-browser-next-enterprise.html
显示全部...
🤯 13😁 6🤔 3👍 2
照片不可用在 Telegram 中显示
✈️ Hackers faking airport Wi-Fi. 💻 Malware hiding inside coding tools. 🤖 AI rewriting security playbooks. That’s just the start — and 15+ more stories inside. 📰 This week’s ThreatsDay Bulletin uncovers the sneakiest hacks, scams, and “too-smart” malware out there. 🔗 Catch up before they catch you → https://thehackernews.com/2025/12/threatsday-bulletin-wi-fi-hack-npm-worm.html
显示全部...
👏 9🤔 4
照片不可用在 Telegram 中显示
🤖💥 AI-built code just broke web security in 2025. One bug in a “vibe coding” platform let anyone access private apps — no login needed. ⚠️ 45% of AI-written code had exploitable flaws. 🏢 Even big firms like Wix had to patch fast. The fix? Treat all AI code as untrusted. 🔗 Read here → https://thehackernews.com/2025/12/5-threats-that-reshaped-web-security.html
显示全部...
😁 10🤯 8 4👍 1
照片不可用在 Telegram 中显示
🚨 Thousands hacked after downloading what looked like “official” government apps. They were fake versions of real banking apps, modified by hackers from GoldFactory to include malware. So far, over 11,000 phones in Southeast Asia have been infected. 🔗 Details ↓ https://thehackernews.com/2025/12/goldfactory-hits-southeast-asia-with.html
显示全部...
🤯 14👏 5🔥 3😁 2
照片不可用在 Telegram 中显示
🚨 Cloudflare just stopped the largest DDoS attack ever — a 29.7 Tbps strike from the AISURU botnet that used up to 4 million hacked devices. It hit 15,000 ports every second for 69 seconds before being blocked. 🔗 Details: https://thehackernews.com/2025/12/record-297-tbps-ddos-attack-linked-to.html
显示全部...
🔥 37😱 13😁 8👍 7
照片不可用在 Telegram 中显示
⚠️ URGENT: A 10.0-severity bug just hit React Server Components and Next.js. It lets anyone run code on your server — even without logging in. 🔗 Details → https://thehackernews.com/2025/12/critical-rsc-bugs-in-react-and-nextjs.html ⚙️ Fix: update to patched versions now.
显示全部...
👏 12🤯 7😁 5😱 3 2