Category: TheHackerNews

Apple Issues Security Updates After Two WebKit Flaws Found Exploited in the Wild
13
Dec
2025

Apple Issues Security Updates After Two WebKit Flaws Found Exploited in the Wild

Dec 13, 2025Ravie LakshmananZero-Day / Vulnerability Apple on Friday released security updates for iOS, iPadOS, macOS, tvOS, watchOS, visionOS, and…

Fake OSINT and GPT Utility GitHub Repos Spread PyStoreRAT Malware Payloads
12
Dec
2025

Fake OSINT and GPT Utility GitHub Repos Spread PyStoreRAT Malware Payloads

Cybersecurity researchers are calling attention to a new campaign that’s leveraging GitHub-hosted Python repositories to distribute a previously undocumented JavaScript-based…

New Advanced Phishing Kits Use AI and MFA Bypass Tactics to Steal Credentials at Scale
12
Dec
2025

New Advanced Phishing Kits Use AI and MFA Bypass Tactics to Steal Credentials at Scale

Cybersecurity researchers have documented four new phishing kits named BlackForce, GhostFrame, InboxPrime AI, and Spiderman that are capable of facilitating…

Securing GenAI in the Browser
12
Dec
2025

Policy, Isolation, and Data Controls That Actually Work

The browser has become the main interface to GenAI for most enterprises: from web-based LLMs and copilots, to GenAI‑powered extensions…

React2Shell Exploitation Escalates into Large-Scale Global Attacks, Forcing Emergency Mitigation
12
Dec
2025

React2Shell Exploitation Escalates into Large-Scale Global Attacks, Forcing Emergency Mitigation

Dec 12, 2025Ravie LakshmananVulnerability / Threat Intelligence The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has urged federal agencies to…

New React RSC Vulnerabilities Enable DoS and Source Code Exposure
12
Dec
2025

New React RSC Vulnerabilities Enable DoS and Source Code Exposure

Dec 12, 2025Ravie LakshmananSoftware Security / Vulnerability The React team has released fixes for two new types of flaws in…

CISA Flags Actively Exploited GeoServer XXE Flaw in Updated KEV Catalog
12
Dec
2025

CISA Flags Actively Exploited GeoServer XXE Flaw in Updated KEV Catalog

Dec 12, 2025Ravie LakshmananVulnerability / Server Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a high-severity…

NANOREMOTE Malware Uses Google Drive API for Hidden Control on Windows Systems
11
Dec
2025

NANOREMOTE Malware Uses Google Drive API for Hidden Control on Windows Systems

Dec 11, 2025Ravie LakshmananCyber Espionage / Windows Security Cybersecurity researchers have disclosed details of a new fully-featured Windows backdoor called…

The Impact of Robotic Process Automation (RPA) on Identity and Access Management
11
Dec
2025

The Impact of Robotic Process Automation (RPA) on Identity and Access Management

Dec 11, 2025The Hacker NewsAutomation / Compliance As enterprises refine their strategies for handling Non-Human Identities (NHIs), Robotic Process Automation…

WIRTE Leverages AshenLoader Sideloading to Install the AshTag Espionage Backdoor
11
Dec
2025

WIRTE Leverages AshenLoader Sideloading to Install the AshTag Espionage Backdoor

Dec 11, 2025Ravie LakshmananCyberwarfare / Threat Intelligence An advanced persistent threat (APT) known as WIRTE has been attributed to attacks…

Unpatched Gogs Zero-Day Exploited Across 700+ Instances Amid Active Attacks
11
Dec
2025

Unpatched Gogs Zero-Day Exploited Across 700+ Instances Amid Active Attacks

Dec 11, 2025Ravie LakshmananVulnerability / Cloud Security A high-severity unpatched security vulnerability in Gogs has come under active exploitation, with…

Chrome Targeted by Active In-the-Wild Exploit Tied to Undisclosed High-Severity Flaw
11
Dec
2025

Chrome Targeted by Active In-the-Wild Exploit Tied to Undisclosed High-Severity Flaw

Dec 11, 2025Ravie LakshmananZero-Day / Vulnerability Google on Wednesday shipped security updates for its Chrome browser to address three security…