RondoDox Botnet Exploits Critical React2Shell Flaw to Hijack IoT Devices and Web Servers
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 01/01/2026 09:19
Cybersecurity researchers have disclosed details of a persistent nine-month-long campaign that has targeted Internet of Things (IoT) devices and web applications to enroll them into a botnet known as RondoDox. As of December 2025, the activity has...
Lire l'article →
How To Browse Faster and Get More Done Using Adapt Browser
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 01/01/2026 05:47
As web browsers evolve into all-purpose platforms, performance and productivity often suffer. Feature overload, excessive background processes, and fragmented workflows can slow down browsing sessions and introduce unnecessary friction, especially...
Lire l'article →
Trust Wallet Chrome Extension Hack Drains $8.5M via Shai-Hulud Supply Chain Attack
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 31/12/2025 16:29
Trust Wallet on Tuesday revealed that the second iteration of the Shai-Hulud (aka Sha1-Hulud) supply chain outbreak in November 2025 was likely responsible for the hack of its Google Chrome extension, ultimately resulting in the theft of...
Lire l'article →
DarkSpectre Browser Extension Campaigns Exposed After Impacting 8.8 Million Users Worldwide
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 31/12/2025 16:14
The threat actor behind two malicious browser extension campaigns, ShadyPanda and GhostPoster, has been attributed to a third attack campaign codenamed DarkSpectre that has impacted 2.2 million users of Google Chrome, Microsoft Edge, and Mozilla...
Lire l'article →
Critical CVSS 9.8 Flaw Found in IBM API Connect Authentication System
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 31/12/2025 13:37
IBM has disclosed details of a critical security flaw in API Connect that could allow attackers to gain remote access to the application. The vulnerability, tracked as CVE-2025-13915, is rated 9.8 out of a maximum of 10.0 on the CVSS scoring system....
Lire l'article →
Researchers Spot Modified Shai-Hulud Worm Testing Payload on npm Registry
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 31/12/2025 13:29
Cybersecurity researchers have disclosed details of what appears to be a new strain of Shai Hulud on the npm registry with slight modifications from the previous wave observed last month. The npm package that embeds the novel Shai Hulud strain is...
Lire l'article →
U.S. Treasury Lifts Sanctions on Three Individuals Linked to Intellexa and Predator Spyware
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 31/12/2025 05:17
The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) on Tuesday removed three individuals linked to the Intellexa Consortium, the holding company behind a commercial spyware known as Predator, from the specially designated...
Lire l'article →
CSA Issues Alert on Critical SmarterMail Bug Allowing Remote Code Execution
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 30/12/2025 16:28
The Cyber Security Agency of Singapore (CSA) has issued a bulletin warning of a maximum-severity security flaw in SmarterTools SmarterMail email software that could be exploited to achieve remote code execution. The vulnerability, tracked as...
Lire l'article →
Silver Fox Targets Indian Users With Tax-Themed Emails Delivering ValleyRAT Malware
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 30/12/2025 10:46
The threat actor known as Silver Fox has turned its focus to India, using income tax-themed lures in phishing campaigns to distribute a modular remote access trojan called ValleyRAT (aka Winos 4.0). "This sophisticated attack leverages a complex...
Lire l'article →
How to Integrate AI into Modern SOC Workflows
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 30/12/2025 09:30
Artificial intelligence (AI) is making its way into security operations quickly, but many practitioners are still struggling to turn early experimentation into consistent operational value. This is because SOCs are adopting AI without an intentional...
Lire l'article →
Mustang Panda Uses Signed Kernel-Mode Rootkit to Load TONESHELL Backdoor
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 30/12/2025 08:35
The Chinese hacking group known as Mustang Panda (aka HoneyMyte) has leveraged a previously undocumented kernel-mode rootkit driver to deliver a new variant of backdoor dubbed TONESHELL in a cyber attack detected in mid-2025 targeting an unspecified...
Lire l'article →
⚡ Weekly Recap: MongoDB Attacks, Wallet Breaches, Android Spyware, Insider Crime & More
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 29/12/2025 13:38
Last week’s cyber news in 2025 was not about one big incident. It was about many small cracks opening at the same time. Tools people trust every day behave in unexpected ways. Old flaws resurfaced. New ones were used almost immediately. A common...
Lire l'article →
MongoDB Vulnerability CVE-2025-14847 Under Active Exploitation Worldwide
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 29/12/2025 09:46
A recently disclosed security vulnerability in MongoDB has come under active exploitation in the wild, with over 87,000 potentially susceptible instances identified across the world. The vulnerability in question is CVE-2025-14847 (CVSS score: 8.7),...
Lire l'article →
27 Malicious npm Packages Used as Phishing Infrastructure to Steal Login Credentials
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 29/12/2025 09:44
Cybersecurity researchers have disclosed details of what has been described as a "sustained and targeted" spear-phishing campaign that has published over two dozen packages to the npm registry to facilitate credential theft. The activity, which...
Lire l'article →
Traditional Security Frameworks Leave Organizations Exposed to AI-Specific Attack Vectors
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 29/12/2025 06:34
In December 2024, the popular Ultralytics AI library was compromised, installing malicious code that hijacked system resources for cryptocurrency mining. In August 2025, malicious Nx packages leaked 2,349 GitHub, cloud, and AI credentials....
Lire l'article →
New MongoDB Flaw Lets Unauthenticated Attackers Read Uninitialized Memory
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 27/12/2025 07:52
A high-severity security flaw has been disclosed in MongoDB that could allow unauthenticated users to read uninitialized heap memory. The vulnerability, tracked as CVE-2025-14847 (CVSS score: 8.7), has been described as a case of improper handling...
Lire l'article →
Trust Wallet Chrome Extension Breach Caused $7 Million Crypto Loss via Malicious Code
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 26/12/2025 15:31
Trust Wallet is urging users to update its Google Chrome extension to the latest version following what it described as a "security incident" that led to the loss of approximately $7 million. The issue, the multi‑chain, non‑custodial cryptocurrency...
Lire l'article →
China-Linked Evasive Panda Ran DNS Poisoning Campaign to Deliver MgBot Malware
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 26/12/2025 14:44
A China-linked advanced persistent threat (APT) group has been attributed to a highly-targeted cyber espionage campaign in which the adversary poisoned Domain Name System (DNS) requests to deliver its signature MgBot backdoor in attacks targeting...
Lire l'article →
Critical LangChain Core Vulnerability Exposes Secrets via Serialization Injection
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 26/12/2025 09:27
A critical security flaw has been disclosed in LangChain Core that could be exploited by an attacker to steal sensitive secrets and even influence large language model (LLM) responses through prompt injection. LangChain Core (i.e., langchain-core)...
Lire l'article →
ThreatsDay Bulletin: Stealth Loaders, AI Chatbot Flaws AI Exploits, Docker Hack, and 15 More Stories
The Hacker News
• 👤 info@thehackernews.com (The Hacker News)
• 25/12/2025 14:01
It’s getting harder to tell where normal tech ends and malicious intent begins. Attackers are no longer just breaking in — they’re blending in, hijacking everyday tools, trusted apps, and even AI assistants. What used to feel like clear-cut “hacker...
Lire l'article →