Category: TheHackerNews

Rogue NuGet Package Poses as Tracer.Fody, Steals Cryptocurrency Wallet Data
16
Dec
2025

Rogue NuGet Package Poses as Tracer.Fody, Steals Cryptocurrency Wallet Data

Dec 16, 2025Ravie LakshmananCybersecurity / Cryptocurrency Cybersecurity researchers have discovered a new malicious NuGet package that typosquats and impersonates the…

Amazon Exposes Years-Long GRU Cyber Campaign Targeting Energy and Cloud Infrastructure
16
Dec
2025

Amazon Exposes Years-Long GRU Cyber Campaign Targeting Energy and Cloud Infrastructure

Dec 16, 2025Ravie LakshmananCloud Security / Vulnerability Amazon’s threat intelligence team has disclosed details of a “years-long” Russian state-sponsored campaign…

Data Security and Privacy
16
Dec
2025

Why Data Security and Privacy Need to Start in Code

AI-assisted coding and AI app generation platforms have created an unprecedented surge in software development. Companies are now facing rapid…

Fortinet FortiGate Under Active Attack Through SAML SSO Authentication Bypass
16
Dec
2025

Fortinet FortiGate Under Active Attack Through SAML SSO Authentication Bypass

Dec 16, 2025Ravie LakshmananNetwork Security / Vulnerability Threat actors have begun to exploit two newly disclosed security flaws in Fortinet…

React2Shell Vulnerability Actively Exploited to Deploy Linux Backdoors
16
Dec
2025

React2Shell Vulnerability Actively Exploited to Deploy Linux Backdoors

The security vulnerability known as React2Shell is being exploited by threat actors to deliver malware families like KSwapDoor and ZnDoor,…

Google to Shut Down Dark Web Monitoring Tool in February 2026
16
Dec
2025

Google to Shut Down Dark Web Monitoring Tool in February 2026

Dec 16, 2025Ravie LakshmananDark Web / Online Safety Google has announced that it’s discontinuing its dark web report tool in…

Featured Chrome Browser Extension
15
Dec
2025

Featured Chrome Browser Extension Caught Intercepting Millions of Users’ AI Chats

A Google Chrome extension with a “Featured” badge and six million users has been observed silently gathering every prompt entered…

FreePBX Patches Critical SQLi, File-Upload, and AUTHTYPE Bypass Flaws Enabling RCE
15
Dec
2025

FreePBX Patches Critical SQLi, File-Upload, and AUTHTYPE Bypass Flaws Enabling RCE

Dec 15, 2025Ravie LakshmananVulnerability / Software Security Multiple security vulnerabilities have been disclosed in the open-source private branch exchange (PBX)…

A Browser Extension Risk Guide After the ShadyPanda Campaign
15
Dec
2025

A Browser Extension Risk Guide After the ShadyPanda Campaign

In early December 2025, security researchers exposed a cybercrime campaign that had quietly hijacked popular Chrome and Edge browser extensions…

Phantom Stealer Spread by ISO Phishing Emails Hitting Russian Finance Sector
15
Dec
2025

Phantom Stealer Spread by ISO Phishing Emails Hitting Russian Finance Sector

Dec 15, 2025Ravie LakshmananMalware / Cybercrime Cybersecurity researchers have disclosed details of an active phishing campaign that’s targeting a wide…

VolkLocker Ransomware Exposed by Hard-Coded Master Key Allowing Free Decryption
15
Dec
2025

VolkLocker Ransomware Exposed by Hard-Coded Master Key Allowing Free Decryption

Dec 15, 2025Ravie LakshmananRansomware / Cybercrime The pro-Russian hacktivist group known as CyberVolk (aka GLORIAMIST) has resurfaced with a new…

CISA Adds Actively Exploited Sierra Wireless Router Flaw Enabling RCE Attacks
13
Dec
2025

CISA Adds Actively Exploited Sierra Wireless Router Flaw Enabling RCE Attacks

Dec 13, 2025Ravie LakshmananNetwork Security / Vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a high-severity…