uz
Feedback
The Hacker News

The Hacker News

Kanalga Telegram’da oβ€˜tish

⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. πŸ“¨ Contact: admin@thehackernews.com 🌐 Website: https://thehackernews.com

Ko'proq ko'rsatish
2025 yil raqamlardasnowflakes fon
card fon
153 622
Obunachilar
+9424 soatlar
+3767 kunlar
+1 46330 kunlar
Postlar arxiv
Photo unavailableShow in Telegram
⚑ New Cyber Recap is live. πŸ› npm worm returns πŸ“§ M365 email + token raids πŸ“± spyware on chat apps 🧱 Firefox RCE + hot CVEs πŸ’Έ Cryptomixer takedown If you ship code, manage access, or touch cloud… this one’s worth 3 minutes. Read: https://thehackernews.com/2025/12/weekly-recap-hot-cves-npm-worm-returns.html
Hammasini ko'rsatish...
πŸ”₯ 7🀯 3
Photo unavailableShow in Telegram
🚨 The browser just became your riskiest employee. New AI browsers like ChatGPT Atlas can act on your behalf β€” booking, buying, sending data. One hidden command can turn them against you. Join this expert webinar to learn how to spot and stop these new AI browser threats ↓ https://thehackernews.com/2025/12/webinar-agentic-trojan-horse-why-new-ai.html
Hammasini ko'rsatish...
πŸ”₯ 7⚑ 2πŸ‘ 2
Photo unavailableShow in Telegram
🚨 Webinar Alert: Resilient Patching β€” Guardrails for Community Repos You trust your patching tools. Attackers trust that too. A single unsafe package on Chocolatey or Winget can flip your defenses against you. Learn how top teams patch fast, safe, and under control. πŸ‘‰ Register & get the full playbook β†’ https://thehacker.news/resilient-patching
Hammasini ko'rsatish...
πŸ‘ 6
Photo unavailableShow in Telegram
🚨 New Android malware Albiriox is being sold as a service. It can remotely control phones, stream screens from banking apps, and fake updates to steal logins. It even bypasses Android’s screen protections. Read about it here β†’ https://thehackernews.com/2025/12/new-albiriox-maas-malware-targets-400.html Spread via fake Google Play links, it’s already targeting users in Austria.
Hammasini ko'rsatish...
😱 13πŸ”₯ 5🀯 5⚑ 4πŸ‘ 3
Photo unavailableShow in Telegram
🚨 Tomiris is back β€” and harder to spot. Kaspersky reports the group is using Telegram & Discord as C2 servers to hide attacks on government networks in Russia & Central Asia. Its new malware β€” written in Python, Rust, Go, PowerShell & C#. Full details ↓ https://thehackernews.com/2025/12/tomiris-shifts-to-public-service.html
Hammasini ko'rsatish...
😁 15πŸ‘ 5
Photo unavailableShow in Telegram
🚨 CISA added a real-world exploited flaw in OpenPLC ScadaBR to its Known Exploited Vulnerabilities list. Hackers used the bug (CVE-2021-26829) to deface a fake water plant system in under 26 hours β€” disabling logs and alarms. Read β†’ https://thehackernews.com/2025/11/cisa-adds-actively-exploited-xss-bug.html
Hammasini ko'rsatish...
πŸ‘ 18πŸ”₯ 9⚑ 5
Photo unavailableShow in Telegram
⚠️ Researchers found old Python code that could expose projects to a supply chain attack. Some PyPI packages β€” including Tornado and slapos.core β€” still call an expired domain that anyone could buy and use to run malicious code. Details ↓ https://thehackernews.com/2025/11/legacy-python-bootstrap-scripts-create.html
Hammasini ko'rsatish...
πŸ”₯ 11😱 7
Photo unavailableShow in Telegram
🚨 North Korean hackers uploaded 197 malicious npm packages (31K+ downloads). They drop a new OtterCookie variant that steals passwords, crypto data, and screenshots β€” all from a fake job interview setup. Details here ↓ https://thehackernews.com/2025/11/north-korean-hackers-deploy-197-npm.html
Hammasini ko'rsatish...
πŸ‘ 8πŸ”₯ 6😱 5πŸ‘ 3🀯 1
Photo unavailableShow in Telegram
VPNs weren’t built for today’s hybrid networks. Hackers now exploit them as entry points to steal admin creds. Remote Privileged Access Management (RPAM) closes that gap β€” no VPNs, no shared passwords, full session tracking. Why it’s replacing PAM β†’ https://thehackernews.com/2025/11/why-organizations-are-turning-to-rpam.html
Hammasini ko'rsatish...
πŸ”₯ 14🀯 6πŸ‘ 3😁 1
Photo unavailableShow in Telegram
Hackers posing as Kyrgyzstan’s Justice Ministry are spreading 2013-era NetSupport RAT across Kyrgyzstan and Uzbekistan using fake PDFs and old Java tricksβ€”blocking outsiders to hide the attack. Old tools. New victims. β†’ https://thehackernews.com/2025/11/bloody-wolf-expands-java-based.html
Hammasini ko'rsatish...
πŸ”₯ 19😁 5πŸ‘ 4πŸ‘ 1
Photo unavailableShow in Telegram
Microsoft will block all non-Microsoft scripts on Entra ID logins starting Oct 2026. If your sign-in flow or browser extension injects any code, it may break β€” so test ASAP. The new Content Security Policy only lets trusted Microsoft-hosted scripts. Read more β†’ https://thehackernews.com/2025/11/microsoft-to-block-unauthorized-scripts.html
Hammasini ko'rsatish...
πŸ€” 12πŸ‘ 9😁 3
Photo unavailableShow in Telegram
🚨 New ThreatsDay Bulletin is live! πŸ€– AI malware that learns your habits πŸ“ž Voice bots turned into attack tools πŸ’Έ Crypto rings laundering billions πŸ”Œ IoT gear under siege again 🌍 Smishing scams spreading worldwide All that and 20+ more stories shaping the week in cybersecurity. πŸ”— Read now: https://thehackernews.com/2025/11/threatsday-bulletin-ai-malware-voice.html
Hammasini ko'rsatish...
πŸ”₯ 9πŸ€” 5
Photo unavailableShow in Telegram
πŸ›‘ Gainsight just revealed more customers were affected than originally disclosed. Salesforce revoked all Gainsight access tokens after the breach tied to ShinyHunters β€” and the same user-agent from prior Salesloft attacks popped up again. The full scope remains unknown. Read here β†’ https://thehackernews.com/2025/11/gainsight-expands-impacted-customer.html
Hammasini ko'rsatish...
😱 6πŸ‘ 5
Photo unavailableShow in Telegram
⚠️ Hundreds of Maven packages just got caught running Shai-Hulud v2 β€” the same malware that hijacked npm. It spread through automated rebuilds, infecting devs who never used npm. Hiding in the Bun runtime, it steals GitHub + cloud creds and self-replicates like a worm β€” already leaking 11,000+ secrets across 4,600 repos. Details here ↓ https://thehackernews.com/2025/11/shai-hulud-v2-campaign-spreads-from-npm.html
Hammasini ko'rsatish...
πŸ‘ 12πŸ”₯ 6
Photo unavailableShow in Telegram
⚠️ Eight β€œadvanced” tools failed at once. A phishing attack slipped past all of them and reached exec inboxes. Only one thing stopped it β€” a strong SOC. πŸ”— Learn why your β€œfirst line” is useless without the last ↓ https://thehackernews.com/2025/11/when-your-2m-security-detection-fails.html
Hammasini ko'rsatish...
πŸ‘ 12
Photo unavailableShow in Telegram
πŸ”₯ Hackers hit South Korea’s banks through one IT vendor β€” spreading Qilin ransomware to 28 firms and stealing 2 TB of data. Evidence suggests Russian and North Korean groups worked together. Full story ↓ https://thehackernews.com/2025/11/qilin-ransomware-turns-south-korean-msp.html
Hammasini ko'rsatish...
🀯 21πŸ”₯ 9😱 6😁 3
01:02
Video unavailableShow in Telegram
πŸ€– We talk a lot about securing AI. Almost no one talks about where it’s actually hiding. NetworkChuck just dropped a video with Wiz, showing how they’re finding hidden AI risksβ€”β€œshadow AI”—before attackers do. It’s a smart look at where cloud security is headed next. πŸš€See Wiz in Action β†’ https://thn.news/cloud-security-demo
Hammasini ko'rsatish...
Video_Edit_Request_for_Paid_Social_-_Network_Chuck.mp4433.46 MB
😁 13πŸ‘ 9πŸ”₯ 3🀯 1
Photo unavailableShow in Telegram
⚠️ Hackers love community update tools. Why? Because anyone can upload a package. One bad update = hacked systems. πŸ”’ Join our free live webinar with Action1 CTO Gene Moody β€” see how to patch safely without slowing down. Save your spot ↓ https://thehackernews.com/2025/11/webinar-learn-to-spot-risks-and-patch.html
Hammasini ko'rsatish...
πŸ‘ 5
Photo unavailableShow in Telegram
🚨 A Chrome extension is stealing crypto. β€œCrypto Copilot” looks like a trading tool for X β€” but it secretly adds a hidden Solana transfer and sends your money to a hacker’s wallet. It’s still live on the Chrome Web Store. Full story ↓ https://thehackernews.com/2025/11/chrome-extension-caught-injecting.html
Hammasini ko'rsatish...
πŸ‘ 6😁 5😱 2
Photo unavailableShow in Telegram
Russia’s GRU tried a new way to spread RomCom malware. For the first time, they used SocGholish β€” fake browser update malware β€” to target a U.S. engineering firm linked to Ukraine. The attack went from click to malware in under 30 minutes. Read the latest report ↓ https://thehackernews.com/2025/11/romcom-uses-socgholish-fake-update.html
Hammasini ko'rsatish...
πŸ”₯ 20😁 4