Category: TheHackerNews

Konni Hackers Turn Google's Find Hub into a Remote Data-Wiping Weapon
11
Nov
2025

Konni Hackers Turn Google’s Find Hub into a Remote Data-Wiping Weapon

The North Korea-affiliated threat actor known as Konni (aka Earth Imp, Opal Sleet, Osmium, TA406, and Vedalia) has been attributed…

Hackers Exploiting Triofox Flaw to Install Remote Access Tools via Antivirus Feature
11
Nov
2025

Hackers Exploiting Triofox Flaw to Install Remote Access Tools via Antivirus Feature

Nov 10, 2025Ravie LakshmananVulnerability / Incident Response Google’s Mandiant Threat Defense on Monday said it discovered n-day exploitation of a…

New Browser Security Report Reveals Emerging Threats for Enterprises
10
Nov
2025

New Browser Security Report Reveals Emerging Threats for Enterprises

According to the new Browser Security Report 2025, security leaders are discovering that most identity, SaaS, and AI-related risks converge…

GlassWorm Malware Discovered in Three VS Code Extensions with Thousands of Installs
10
Nov
2025

GlassWorm Malware Discovered in Three VS Code Extensions with Thousands of Installs

Nov 10, 2025Ravie LakshmananMalware / Threat Intelligence Cybersecurity researchers have disclosed a new set of three extensions associated with the…

ClickFix Phishing Attacks
10
Nov
2025

Large-Scale ClickFix Phishing Attacks Target Hotel Systems with PureRAT Malware

Cybersecurity researchers have called attention to a massive phishing campaign targeting the hospitality industry that lures hotel managers to ClickFix-style…

Microsoft Uncovers 'Whisper Leak' Attack That Identifies AI Chat Topics in Encrypted Traffic
08
Nov
2025

Microsoft Uncovers ‘Whisper Leak’ Attack That Identifies AI Chat Topics in Encrypted Traffic

Microsoft has disclosed details of a novel side-channel attack targeting remote language models that could enable a passive adversary with…

Samsung Zero-Click Flaw Exploited to Deploy LANDFALL Android Spyware via WhatsApp
07
Nov
2025

Samsung Zero-Click Flaw Exploited to Deploy LANDFALL Android Spyware via WhatsApp

Nov 07, 2025Ravie LakshmananMobile Security / Vulnerability A now-patched security flaw in Samsung Galaxy Android devices was exploited as a…

From Log4j to IIS, China's Hackers Turn Legacy Bugs into Global Espionage Tools
07
Nov
2025

From Log4j to IIS, China’s Hackers Turn Legacy Bugs into Global Espionage Tools

A China-linked threat actor has been attributed to a cyber attack targeting an U.S. non-profit organization with an aim to…

Hidden Logic Bombs in Malware-Laced NuGet Packages Set to Detonate Years After Installation
07
Nov
2025

Hidden Logic Bombs in Malware-Laced NuGet Packages Set to Detonate Years After Installation

Nov 07, 2025Ravie LakshmananSupply Chain Attack / Malware A set of nine malicious NuGet packages has been identified as capable…

Enterprise Credentials at Risk – Same Old, Same Old?
07
Nov
2025

Enterprise Credentials at Risk – Same Old, Same Old?

Nov 07, 2025The Hacker NewsData Protection / Cloud Security Imagine this: Sarah from accounting gets what looks like a routine…

Google Launches New Maps Feature to Help Businesses Report Review-Based Extortion Attempts
07
Nov
2025

Google Launches New Maps Feature to Help Businesses Report Review-Based Extortion Attempts

Nov 07, 2025Ravie LakshmananData Protection / Malware Google on Thursday said it’s rolling out a dedicated form to allow businesses…

Vibe-Coded Malicious VS Code Extension Found with Built-In Ransomware Capabilities
07
Nov
2025

Vibe-Coded Malicious VS Code Extension Found with Built-In Ransomware Capabilities

Cybersecurity researchers have flagged a malicious Visual Studio Code (VS Code) extension with basic ransomware capabilities that appears to be…