
- Researchers Uncover 30+ Flaws in AI Coding Tools Enabling Data Theft and RCE Attacksby info@thehackernews.com (The Hacker News) (The Hacker News) on December 6, 2025 at 3:24 pm
Over 30 security vulnerabilities have been disclosed in various artificial intelligence (AI)-powered Integrated Development Environments (IDEs) that combine prompt injection […]
- Critical React2Shell Flaw Added to CISA KEV After Confirmed Active Exploitationby info@thehackernews.com (The Hacker News) (The Hacker News) on December 6, 2025 at 11:40 am
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday formally added a critical security flaw impacting React Server Components (RSC) to its Known Exploited […]
- Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emailsby info@thehackernews.com (The Hacker News) (The Hacker News) on December 5, 2025 at 5:53 pm
A new agentic browser attack targeting Perplexity’s Comet browser that’s capable of turning a seemingly innocuous email into a destructive action that wipes a user’s entire Google […]
- Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patchby info@thehackernews.com (The Hacker News) (The Hacker News) on December 5, 2025 at 4:23 pm
A critical security flaw has been disclosed in Apache Tika that could result in an XML external entity (XXE) injection attack. The vulnerability, tracked as CVE-2025-66516, is […]
- Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerabilityby info@thehackernews.com (The Hacker News) (The Hacker News) on December 5, 2025 at 2:10 pm
Two hacking groups with ties to China have been observed weaponizing the newly disclosed security flaw in React Server Components (RSC) within hours of it becoming public […]
- Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Deliveryby info@thehackernews.com (The Hacker News) (The Hacker News) on December 5, 2025 at 11:47 am
A human rights lawyer from Pakistan’s Balochistan province received a suspicious link on WhatsApp from an unknown number, marking the first time a civil society member in the […]
- “Getting to Yes”: An Anti-Sales Guide for MSPsby info@thehackernews.com (The Hacker News) (The Hacker News) on December 5, 2025 at 11:30 am
Most MSPs and MSSPs know how to deliver effective security. The challenge is helping prospects understand why it matters in business terms. Too often, sales conversations stall […]
- CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systemsby info@thehackernews.com (The Hacker News) (The Hacker News) on December 5, 2025 at 8:14 am
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday released details of a backdoor named BRICKSTORM that has been put to use by state-sponsored threat […]
- JPCERT Confirms Active Command Injection Attacks on Array AG Gatewaysby info@thehackernews.com (The Hacker News) (The Hacker News) on December 5, 2025 at 5:40 am
A command injection vulnerability in Array Networks AG Series secure access gateways has been exploited in the wild since August 2025, according to an alert issued by JPCERT/CC […]
- Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in Chinaby info@thehackernews.com (The Hacker News) (The Hacker News) on December 4, 2025 at 5:25 pm
The threat actor known as Silver Fox has been spotted orchestrating a false flag operation to mimic a Russian threat group in attacks targeting organizations in China. The search […]
- ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blastsβ and 15 More Storiesby info@thehackernews.com (The Hacker News) (The Hacker News) on December 4, 2025 at 11:58 am
Think your Wi-Fi is safe? Your coding tools? Or even your favorite financial apps? This week proves again how hackers, companies, and governments are all locked in a nonstop race […]
- 5 Threats That Reshaped Web Security This Year [2025]by info@thehackernews.com (The Hacker News) (The Hacker News) on December 4, 2025 at 11:30 am
As 2025 draws to a close, security professionals face a sobering realization: the traditional playbook for web security has become dangerously obsolete. AI-powered attacks, […]
- GoldFactory Hits Southeast Asia with Modified Banking Apps Driving 11,000+ Infectionsby info@thehackernews.com (The Hacker News) (The Hacker News) on December 4, 2025 at 9:27 am
Cybercriminals associated with a financially motivated group known as GoldFactory have been observed staging a fresh round of attacks targeting mobile users in Indonesia, […]
- Record 29.7 Tbps DDoS Attack Linked to AISURU Botnet with up to 4 Million Infected Hostsby info@thehackernews.com (The Hacker News) (The Hacker News) on December 4, 2025 at 6:52 am
Cloudflare on Wednesday said it detected and mitigated the largest ever distributed denial-of-service (DDoS) attack that measured at 29.7 terabits per second (Tbps). The activity, […]
- Critical RSC Bugs in React and Next.js Allow Unauthenticated Remote Code Executionby info@thehackernews.com (The Hacker News) (The Hacker News) on December 3, 2025 at 6:19 pm
A maximum-severity security flaw has been disclosed in React Server Components (RSC) that, if successfully exploited, could result in remote code execution. The vulnerability, […]
- Discover the AI Tools Fueling the Next Cybercrime Wave β Watch the Webinarby info@thehackernews.com (The Hacker News) (The Hacker News) on December 3, 2025 at 5:56 pm
Remember when phishing emails were easy to spot? Bad grammar, weird formatting, and requests from a “Prince” in a distant country? Those days are over. Today, a 16-year-old with […]
- Microsoft Silently Patches Windows LNK Flaw After Years of Active Exploitationby info@thehackernews.com (The Hacker News) (The Hacker News) on December 3, 2025 at 5:46 pm
Microsoft has silently plugged a security flaw that has been exploited by several threat actors since 2017 as part of the company’s November 2025 Patch Tuesday updates, according […]
- WordPress King Addons Flaw Under Active Attack Lets Hackers Make Admin Accountsby info@thehackernews.com (The Hacker News) (The Hacker News) on December 3, 2025 at 5:08 pm
A critical security flaw impacting a WordPress plugin known as King Addons for Elementor has come under active exploitation in the wild. The vulnerability, CVE-2025-8489 (CVSS […]
- Brazil Hit by Banking Trojan Spread via WhatsApp Worm and RelayNFC NFC Relay Fraudby info@thehackernews.com (The Hacker News) (The Hacker News) on December 3, 2025 at 3:32 pm
The threat actor known as Water Saci is actively evolving its tactics, switching to a sophisticated, highly layered infection chain that uses HTML Application (HTA) files and PDFs […]
- Chopping AI Down to Size: Turning Disruptive Technology into a Strategic Advantageby info@thehackernews.com (The Hacker News) (The Hacker News) on December 3, 2025 at 9:56 am
Most people know the story of Paul Bunyan. A giant lumberjack, a trusted axe, and a challenge from a machine that promised to outpace him. Paul doubled down on his old way of […]
- Picklescan Bugs Allow Malicious PyTorch Models to Evade Scans and Execute Codeby info@thehackernews.com (The Hacker News) (The Hacker News) on December 3, 2025 at 9:30 am
Three critical security flaws have been disclosed in an open-source utility called Picklescan that could allow malicious actors to execute arbitrary code by loading untrusted […]
- Malicious Rust Crate Delivers OS-Specific Malware to Web3 Developer Systemsby info@thehackernews.com (The Hacker News) (The Hacker News) on December 3, 2025 at 8:39 am
Cybersecurity researchers have discovered a malicious Rust package that’s capable of targeting Windows, macOS, and Linux systems, and features malicious functionality to […]
- India Orders Messaging Apps to Work Only With Active SIM Cards to Prevent Fraud and Misuseby info@thehackernews.com (The Hacker News) (The Hacker News) on December 2, 2025 at 5:46 pm
India’s Department of Telecommunications (DoT) has issued directions to app-based communication service providers to ensure that the platforms cannot be used without an active SIM […]
- Researchers Capture Lazarus APT’s Remote-Worker Scheme Live on Cameraby info@thehackernews.com (The Hacker News) (The Hacker News) on December 2, 2025 at 3:02 pm
A joint investigation led by Mauro Eldritch, founder of BCA LTD, conducted together with threat-intel initiative NorthScan and ANY.RUN, a solution for interactive malware analysis […]
- GlassWorm Returns with 24 Malicious Extensions Impersonating Popular Developer Toolsby info@thehackernews.com (The Hacker News) (The Hacker News) on December 2, 2025 at 3:01 pm
The supply chain campaign known as GlassWorm has once again reared its head, infiltrating both Microsoft Visual Studio Marketplace and Open VSX with 24 extensions impersonating […]
