
- New MongoDB Flaw Lets Unauthenticated Attackers Read Uninitialized Memoryby info@thehackernews.com (The Hacker News) (The Hacker News) on December 27, 2025 at 7:52 am
A high-severity security flaw has been disclosed in MongoDB that could allow unauthenticated users to read uninitialized heap memory. The vulnerability, tracked as CVE-2025-14847 […]
- Trust Wallet Chrome Extension Breach Caused $7 Million Crypto Loss via Malicious Codeby info@thehackernews.com (The Hacker News) (The Hacker News) on December 26, 2025 at 3:31 pm
Trust Wallet is urging users to update its Google Chrome extension to the latest version following what it described as a “security incident” that led to the loss of approximately […]
- China-Linked Evasive Panda Ran DNS Poisoning Campaign to Deliver MgBot Malwareby info@thehackernews.com (The Hacker News) (The Hacker News) on December 26, 2025 at 2:44 pm
A China-linked advanced persistent threat (APT) group has been attributed to a highly-targeted cyber espionage campaign in which the adversary poisoned Domain Name System (DNS) […]
- Critical LangChain Core Vulnerability Exposes Secrets via Serialization Injectionby info@thehackernews.com (The Hacker News) (The Hacker News) on December 26, 2025 at 9:27 am
A critical security flaw has been disclosed in LangChain Core that could be exploited by an attacker to steal sensitive secrets and even influence large language model (LLM) […]
- ThreatsDay Bulletin: Stealth Loaders, AI Chatbot Flaws AI Exploits, Docker Hack, and 15 More Storiesby info@thehackernews.com (The Hacker News) (The Hacker News) on December 25, 2025 at 2:01 pm
Itβs getting harder to tell where normal tech ends and malicious intent begins. Attackers are no longer just breaking in β theyβre blending in, hijacking everyday tools, […]
- LastPass 2022 Breach Led to Years-Long Cryptocurrency Thefts, TRM Labs Findsby info@thehackernews.com (The Hacker News) (The Hacker News) on December 25, 2025 at 12:46 pm
The encrypted vault backups stolen from the 2022 LastPass data breach have enabled bad actors to take advantage of weak master passwords to crack them open and drain […]
- Fortinet Warns of Active Exploitation of FortiOS SSL VPN 2FA Bypass Vulnerabilityby info@thehackernews.com (The Hacker News) (The Hacker News) on December 25, 2025 at 8:22 am
Fortinet on Wednesday said it observed “recent abuse” of a five-year-old security flaw in FortiOS SSL VPN in the wild under certain configurations. The vulnerability in question […]
- CISA Flags Actively Exploited Digiever NVR Vulnerability Allowing Remote Code Executionby info@thehackernews.com (The Hacker News) (The Hacker News) on December 25, 2025 at 8:07 am
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a security flaw impacting Digiever DS-2105 Pro network video recorders (NVRs) to its Known Exploited […]
- New MacSync macOS Stealer Uses Signed App to Bypass Apple Gatekeeperby info@thehackernews.com (The Hacker News) (The Hacker News) on December 24, 2025 at 4:23 pm
Cybersecurity researchers have discovered a new variant of a macOS information stealer called MacSync that’s delivered by means of a digitally signed, notarized Swift application […]
- Nomani Investment Scam Surges 62% Using AI Deepfake Ads on Social Mediaby info@thehackernews.com (The Hacker News) (The Hacker News) on December 24, 2025 at 1:08 pm
The fraudulent investment scheme known as Nomani has witnessed an increase by 62%, according to data from ESET, as campaigns distributing the threat have also expanded beyond […]
- Attacks are Evolving: 3 Ways to Protect Your Business in 2026by info@thehackernews.com (The Hacker News) (The Hacker News) on December 24, 2025 at 11:30 am
Every year, cybercriminals find new ways to steal money and data from businesses. Breaching a business network, extracting sensitive data, and selling it on the dark web has […]
- SEC Files Charges Over $14 Million Crypto Scam Using Fake AI-Themed Investment Tipsby info@thehackernews.com (The Hacker News) (The Hacker News) on December 24, 2025 at 9:19 am
The U.S. Securities and Exchange Commission (SEC) has filed charges against multiple companies for their alleged involvement in an elaborate cryptocurrency scam that swindled more […]
- Italy Fines Apple β¬98.6 Million Over ATT Rules Limiting App Store Competitionby info@thehackernews.com (The Hacker News) (The Hacker News) on December 24, 2025 at 6:15 am
Apple has been fined β¬98.6 million ($116 million) by Italy’s antitrust authority after finding that the company’s App Tracking Transparency (ATT) privacy framework restricted […]
- Two Chrome Extensions Caught Secretly Stealing Credentials from Over 170 Sitesby info@thehackernews.com (The Hacker News) (The Hacker News) on December 23, 2025 at 2:42 pm
Cybersecurity researchers have discovered two malicious Google Chrome extensions with the same name and published by the same developer that come with capabilities to intercept […]
- INTERPOL Arrests 574 in Africa; Ukrainian Ransomware Affiliate Pleads Guiltyby info@thehackernews.com (The Hacker News) (The Hacker News) on December 23, 2025 at 11:35 am
A law enforcement operation coordinated by INTERPOL has led to the recovery of $3 million and the arrest of 574 suspects by authorities from 19 countries, amidst a continued […]
- Passwd: A walkthrough of the Google Workspace Password Managerby info@thehackernews.com (The Hacker News) (The Hacker News) on December 23, 2025 at 11:30 am
Passwd is designed specifically for organizations operating within Google Workspace. Rather than competing as a general consumer password manager, its purpose is narrow, and […]
- U.S. DoJ Seizes Fraud Domain Behind $14.6 Million Bank Account Takeover Schemeby info@thehackernews.com (The Hacker News) (The Hacker News) on December 23, 2025 at 8:15 am
The U.S. Justice Department (DoJ) on Monday announced the seizure of a web domain and database that it said was used to further a criminal scheme designed to target and defraud […]
- Critical n8n Flaw (CVSS 9.9) Enables Arbitrary Code Execution Across Thousands of Instancesby info@thehackernews.com (The Hacker News) (The Hacker News) on December 23, 2025 at 7:34 am
A critical security vulnerability has been disclosed in the n8n workflow automation platform that, if successfully exploited, could result in arbitrary code execution under […]
- FCC Bans Foreign-Made Drones and Key Parts Over U.S. National Security Risksby info@thehackernews.com (The Hacker News) (The Hacker News) on December 23, 2025 at 6:58 am
The U.S. Federal Communications Commission (FCC) on Monday announced a ban on all drones and critical components made in a foreign country, citing national security concerns. To […]
- Fake WhatsApp API Package on npm Steals Messages, Contacts, and Login Tokensby info@thehackernews.com (The Hacker News) (The Hacker News) on December 22, 2025 at 4:28 pm
Cybersecurity researchers have disclosed details of a new malicious package on the npm repository that works as a fully functional WhatsApp API, but also contains the ability to […]
- β‘ Weekly Recap: Firewall Exploits, AI Data Theft, Android Hacks, APT Attacks, Insider Leaks & Moreby info@thehackernews.com (The Hacker News) (The Hacker News) on December 22, 2025 at 12:00 pm
Cyber threats last week showed how attackers no longer need big hacks to cause big damage. Theyβre going after the everyday tools we trust most β firewalls, browser add-ons, […]
- How to Browse the Web More Sustainably With a Green Browserby info@thehackernews.com (The Hacker News) (The Hacker News) on December 22, 2025 at 11:55 am
As the internet becomes an essential part of daily life, its environmental footprint continues to grow.Β Data centers, constant connectivity, and resource-heavy browsing habits […]
- Android Malware Operations Merge Droppers, SMS Theft, and RAT Capabilities at Scaleby info@thehackernews.com (The Hacker News) (The Hacker News) on December 22, 2025 at 6:11 am
Threat actors have been observed leveraging malicious dropper apps masquerading as legitimate applications to deliver an Android SMS stealer dubbed Wonderland in mobile attacks […]
- Iranian Infy APT Resurfaces with New Malware Activity After Years of Silenceby info@thehackernews.com (The Hacker News) (The Hacker News) on December 21, 2025 at 4:22 am
Threat hunters have discerned new activity associated with an Iranian threat actor known as Infy (aka Prince of Persia), nearly five years after the hacking group was observed […]
- U.S. DOJ Charges 54 in ATM Jackpotting Scheme Using Ploutus Malwareby info@thehackernews.com (The Hacker News) (The Hacker News) on December 20, 2025 at 1:48 pm
The U.S. Department of Justice (DoJ) this week announced the indictment of 54 individuals in connection with a multi-million dollar ATM jackpotting scheme. The large-scale […]
