The Hacker News
Kanalga Telegramโda oโtish
โญ Official THN Telegram Channel โ A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. ๐จ Contact: admin@thehackernews.com ๐ Website: https://thehackernews.com
Ko'proq ko'rsatish2025 yil raqamlarda

153 649
Obunachilar
+4924 soatlar
+3847 kunlar
+1 47630 kunlar
Postlar arxiv
Photo unavailableShow in Telegram
Chinese hackers used old bugs like Log4j and Struts to break into U.S. policy networks.
Then they hid using msbuild.exe and a fake system task to stay inside.
Old tricks. New targets.
Read the details โ https://thehackernews.com/2025/11/from-log4j-to-iis-chinas-hackers-turn.html
๐ 11๐ฅ 6๐ค 4๐ 3โก 1๐ 1
Photo unavailableShow in Telegram
๐จ WARNING: Malicious NuGet packages were caught hiding delayed payloadsโset to fire off years from now, in 2027โ2028.
They look harmless. Some even helpful. But one, Sharp7Extend, quietly sabotages PLCsโcrashing processes or corrupting writes after a short delay.
Nearly 10K downloads before anyone noticed.
Hereโs whatโs really going on โ https://thehackernews.com/2025/11/hidden-logic-bombs-in-malware-laced.html
๐ฅ 12๐ 6๐ 4
Photo unavailableShow in Telegram
Your company's logins could be on the dark web right now, and they could sell for as little as $15.
It only takes one click for hackers to walk right in.
Find out if your companyโs credentials are exposed โ https://thehackernews.com/2025/11/enterprise-credentials-at-risk-same-old.html
๐ 6๐คฏ 6
Photo unavailableShow in Telegram
Google just launched a new form to report extortion scams on Google Maps.
Scammers are posting fake 1โญ reviews, then asking business owners to pay up to remove them.
This new tool is meant to stop the surge in โreview bombingโ hitting small businesses.
Read how it works โ https://thehackernews.com/2025/11/google-launches-new-maps-feature-to.html
๐ค 12๐ 7๐ฅ 5๐ 5๐ฑ 1
Photo unavailableShow in Telegram
ChatGPT just helped researchers crack XLoader malware in hours โ work that used to take days.
AI unpacked the code, found keys, and exposed C2 domains. Big shift for malware analysis.
Check this story โ https://thehackernews.com/2025/11/threatsday-bulletin-ai-tools-in-malware.html#ai-speeds-triage-but-human-skill-still-needed
๐ฅ 22๐ 12๐ 5๐ 1
Photo unavailableShow in Telegram
A fake VS Code extension made with AI just showed up on the Marketplace.
It ran ransomware on install โ zipping, encrypting, and uploading files, all by itself.
Microsoft took it down quickly, but the developer accidentally left the control keys and decryption tools inside.
Hereโs what happened and how it worked โ https://thehackernews.com/2025/11/vibe-coded-malicious-vs-code-extension.html
๐ 10๐ 10๐ 4๐ฅ 1
Photo unavailableShow in Telegram
Redis added an AI agent (Prophet Security) to its SOC, working alongside their MDR team.
The result: investigations that took hours now take about 10 minutes.
AI handles the routine alerts so humans can focus on real threats.
Hereโs what actually worked โ https://thehackernews.com/expert-insights/2025/11/implementing-ai-in-soc-lessons-learned.html
๐ 15๐ค 9๐ 4๐ฅ 4
Photo unavailableShow in Telegram
โ ๏ธ A Russia-linked group posed as ESET to hack Ukrainian organizations.
They sent fake ESET installers that looked real โ but quietly installed a backdoor using the Tor network.
Experts call the group InedibleOchotense, tied to Sandworm.
Full story โ https://thehackernews.com/2025/11/trojanized-eset-installers-drop.html
๐คฏ 9๐ฅ 7๐ 4๐ 3๐ 1
Photo unavailableShow in Telegram
๐จ Cisco warns hackers are targeting unpatched Secure Firewall ASA & FTD devices with a new attack variant exploiting two flaws โ CVE-2025-20333 and CVE-2025-20362.
The attacks can crash devices (DoS) or let attackers run code as root.
Details here โ https://thehackernews.com/2025/11/cisco-warns-of-new-firewall-attack.html
๐ 7๐ 6๐ฅ 1
Photo unavailableShow in Telegram
New cyber rules mean every breach test counts. Most teams still run them in Excel.
At Georgetown, gain the tactical skills to plan for and respond to information security threats.
Attend our Nov. 19 webinar โ https://thn.news/cyber-risk-webinar-in
๐ 8๐ 6
Photo unavailableShow in Telegram
๐ก๏ธ ThreatsDay Bulletin is out!
๐น Cyber threats are getting personal.
๐น AI helps stop attacks โ but itโs also powering them.
๐น Botnets, fake apps, and scams are growing fast.
Hereโs whatโs really happening this week in cyber โ https://thehackernews.com/2025/11/threatsday-bulletin-ai-tools-in-malware.html
๐ฅ 7๐ 4๐ 4
Photo unavailableShow in Telegram
Over 600 companies say they offer MDR.
Gartnerโs new report shows only a few truly deliver.
It also highlights a big gap โ most rely too much on automation, not enough on real human response.
Worth a read โ https://thehackernews.com/2025/11/bitdefender-named-representative-vendor.html
โก 9
Photo unavailableShow in Telegram
โก Hackers turned Windows against itself.
Curly COMrades is using Microsoft's Hyper-V to run small Linux virtual machines inside Windows 10.
This is a sneaky way to get their malware past EDR tools.
Read the whole story โ https://thehackernews.com/2025/11/hackers-weaponize-windows-hyper-v-to.html
๐ 14๐ฅ 6๐ค 4๐ฑ 3๐ 1๐ 1
Photo unavailableShow in Telegram
SonicWall just confirmed the September breach was done by a state-backed hacker group.
They got in through one API call and accessed firewall backups โ no ransom, just quiet data theft.
Hereโs what happened โ https://thehackernews.com/2025/11/sonicwall-confirms-state-sponsored.html
๐ 8๐ 4๐คฏ 3๐ 2
Photo unavailableShow in Telegram
โก Google spotted malware that uses Gemini AI to rewrite its own code.
Itโs called PROMPTFLUX โ a simple script that asks Gemini for new ways to hide from antivirus tools.
More information โ https://thehackernews.com/2025/11/google-uncovers-promptflux-malware-that.html
๐ 31๐ฅ 13๐ค 5๐คฏ 4
Photo unavailableShow in Telegram
โ ๏ธ Researchers have found 7 new ways to hack ChatGPT (GPT-4o and GPT-5), including zero-click attacks that can steal chat history and even poison your AI's memory.
OpenAI fixed some of them... but not all of them.
Details here โ https://thehackernews.com/2025/11/researchers-find-chatgpt.html
๐ 18โก 4๐ 1
Photo unavailableShow in Telegram
New Iranian threat actor identified โ UNK_SmudgedSerpent.
From June to August, they tricked U.S. academics with fake Microsoft Teams invites that secretly installed remote access tools.
Read on โ https://thehackernews.com/2025/11/mysterious-smudgedserpent-hackers.html
โก 12๐ 7๐ 1
Photo unavailableShow in Telegram
U.S. Treasury sanctioned 8 North Korean operatives and 2 banks for laundering $12.7 million in cryptocurrency to fund nuclear weapon programs and ransomware.
Their โIT workersโ posed as foreign freelancers and got hired by real companies.
Read here โ https://thehackernews.com/2025/11/us-sanctions-10-north-korean-entities.html
๐ฑ 4๐ 2๐ฅ 1๐ค 1
Photo unavailableShow in Telegram
โ ๏ธ In just 60 seconds, analysts found an entire phishing chain: a fake Microsoft 365 login hidden inside ClickUp.
Most SOCs would have spent hours poring through logs to find the same thing.
Here's how real-time analysis cuts noise, speeds detection, and prevents burnout: https://thehackernews.com/2025/11/why-soc-burnout-can-be-avoided.html
๐ฅ 5๐ค 5
Photo unavailableShow in Telegram
Many companies donโt realize this yet, but their AI agents are already acting like employees.
82% use them, and 53% handle sensitive data every day. But when staff leave, those agents keep runningโฆ still with full access.
Hereโs how to find and protect them: https://thehackernews.com/expert-insights/2025/11/governing-ai-agents-from-enterprise.html
๐คฏ 10๐ 8๐ฑ 5๐ 2
