TGINSIGHT CHAT
The Hacker News
@thehackernews
Technologies⭐ Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. 📨 Contact: [email protected] 🌐 Website: https://thehackernews.com
Recent posts
Page 85 of 85 · 1,016 posts
Posted Nov 21
⚖️ The SEC just ended its case against SolarWinds — the company hit by the big 2020 hack. After two years of blaming its security chief, the case was quietly dropped. Now many wonder if anyone will be held responsible next time ↓ https://thehackernews.com/2025/11/sec-drops-solarwinds-case-after-years.html
Posted Nov 21
🚨 Salesforce found unusual activity in Gainsight apps and cut off their access. Hackers linked to ShinyHunters may have used those apps to steal Salesforce data from nearly 1,000 companies. Gainsight was also hit in a similar attack earlier this year. Full story ↓ https://thehackernews.com/2025/11/salesforce-flags-unauthorized-data.html
Posted Nov 21
🚨 ThreatsDay Bulletin — The EU wants to rewrite its privacy rules. New proposal would let companies use personal data to train AI without consent, if done for “legitimate interest.” Critics say it’s a major rollback of GDPR and a win for Big Tech. Read more ↓ https://thehackernews.com/2025/11/threatsday-bulletin-0-days-linkedin.html#eu-rewires-privacy-playbook
Posted Nov 20
🚨 Hackers are exploiting a 2-year-old authentication flaw (CVE-2023-48022) in the Ray AI framework to take over NVIDIA GPU clusters and run a self-spreading crypto-mining botnet called ShadowRay 2.0. The bug remains unpatched by design, and over 230,000 Ray servers are exposed online. Read about it here ↓ https://thehackernews.com/2025/11/shadowray-20-exploits-unpatched-ray.html
Posted Nov 20
Hackers made a new botnet called Tsundere — it’s spreading through fake game downloads like Valorant and CS2. It hides its servers on the Ethereum blockchain, making it almost impossible to shut down. Researchers say it’s still active. Read more ↓ https://thehackernews.com/2025/11/tsundere-botnet-expands-using-game.html
Posted Nov 20
WhatsApp accounts are being hijacked worldwide via fake WhatsApp Web pages that mimic the official interface exactly — including auto-detected language and country flag. You scan QR or type code → they take your account → message your friends for money + steal everything. Check the new CTM360 report – see exactly how the fake pages look and how to stay safe ↓ https://thehackernews.com/2025/11/ctm360-exposes-global-whatsapp.html
Posted Nov 20
JSGuLdr: Multi-Stage Loader Delivering PhantomStealer #ANYRUN researchers identified #JSGuLdr, a multi-stage JavaScript-to-PowerShell loader used to deliver #PhantomStealer. A JScript file triggers PowerShell through an Explorer COM call, pulls the second stage from %APPDATA%\Registreri62, then uses Net.WebClient to fetch an encrypted payload from Google Drive into %APPDATA%\Autorise131[.]Tel. The payload is decoded in memory and loaded, with PhantomStealerinjected into msiexec.exe. Execution chain: wscript.exe ➡️ explorer.exe (svchost.exe) ➡️ explorer.exe (COM) ➡️ powershell.exe ➡️ msiexec.exe 👉 See analysis session: https://app.any.run/tasks/7b295f6f-5f16-4a44-a02b-5d59fd4b1e8f?utm_source=tg_thehackernews&utm_medium=post&utm_campaign=techpost&utm_content=task&utm_term=201125 👉 Read full analysis: https://t.me/anyrun_app/698
Hashtags
Posted Nov 20
This week's ThreatsDay looks at big cyber news from around the world: 🔹 Russian hackers got arrested 🔹 Chinese spies are using LinkedIn to find secrets 🔹 People caught washing dirty money with crypto 🔹 New hidden bugs found in phones, computers, and smart home gadgets 🔹 ... and many more. 🌐 Zero-day attacks • Spying • Crypto crime • Bugs in everyday devices • Moving malware Read all critical stories here → https://thehackernews.com/2025/11/threatsday-bulletin-0-days-linkedin.html