OOh yeah oooh ooh oooh
The Hacker News Most trusted, widely-read independent cybersecurity news source for everyone; supported by hackers and IT professionals — Send TIPs to admin@thehackernews.com
- Enterprise Credentials at Risk – Same Old, Same Old?by info@thehackernews.com (The Hacker News) on November 7, 2025 at 10:30 am
Imagine this: Sarah from accounting gets what looks like a routine password reset email from your organization’s cloud provider. She clicks the link, types in her credentials, and goes back to her spreadsheet. But unknown to her, she’s just made a big mistake. Sarah just accidentally handed over her login details to cybercriminals who are laughing all the way to their dark web
- Google Launches New Maps Feature to Help Businesses Report Review-Based Extortion Attemptsby info@thehackernews.com (The Hacker News) on November 7, 2025 at 9:15 am
Google on Thursday said it’s rolling out a dedicated form to allow businesses listed on Google Maps to report extortion attempts made by threat actors who post inauthentic bad reviews on the platform and demand ransoms to remove the negative comments. The approach is designed to tackle a common practice called review bombing, where online users intentionally post negative user reviews in an
- Vibe-Coded Malicious VS Code Extension Found with Built-In Ransomware Capabilitiesby info@thehackernews.com (The Hacker News) on November 7, 2025 at 6:48 am
Cybersecurity researchers have flagged a malicious Visual Studio Code (VS Code) extension with basic ransomware capabilities that appears to be created with the help of artificial intelligence – in other words, vibe-coded. Secure Annex researcher John Tuckner, who flagged the extension “susvsex,” said it does not attempt to hide its malicious functionality. The extension was uploaded on
- Trojanized ESET Installers Drop Kalambur Backdoor in Phishing Attacks on Ukraineby info@thehackernews.com (The Hacker News) on November 6, 2025 at 3:31 pm
A previously unknown threat activity cluster has been observed impersonating Slovak cybersecurity company ESET as part of phishing attacks targeting Ukrainian entities. The campaign, detected in May 2025, is tracked by the security outfit under the moniker InedibleOchotense, describing it as Russia-aligned. “InedibleOchotense sent spear-phishing emails and Signal text messages, containing a link
- Cisco Warns of New Firewall Attack Exploiting CVE-2025-20333 and CVE-2025-20362by info@thehackernews.com (The Hacker News) on November 6, 2025 at 2:58 pm
Cisco on Wednesday disclosed that it became aware of a new attack variant that’s designed to target devices running Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software releases that are susceptible to CVE-2025-20333 and CVE-2025-20362. “This attack can cause unpatched devices to unexpectedly reload, leading to denial-of-service





