The Hacker News
Kanalga Telegramโda oโtish
โญ Official THN Telegram Channel โ A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. ๐จ Contact: admin@thehackernews.com ๐ Website: https://thehackernews.com
Ko'proq ko'rsatish2025 yil raqamlarda

153 640
Obunachilar
+4924 soatlar
+3847 kunlar
+1 47630 kunlar
Postlar arxiv
Photo unavailableShow in Telegram
We say โtrust but verify.โ
In SaaS, most teams trust onceโand never verify again. Old tokens stay valid. Apps keep broad access.
Thatโs how attackers move in quietly.
Gal Nakash explains why Zero Trust fails in practice and what to fix โ https://thehackernews.com/expert-insights/2025/11/the-problem-with-trust-but-verify-is.html
๐ค 9๐ฅ 4๐ 4๐ 2
Photo unavailableShow in Telegram
Fortinet has confirmed a new FortiWeb flaw โ CVE-2025-58034 โ already exploited in the wild.
It lets authenticated attackers execute OS commands via crafted requests.
Full story โ https://thehackernews.com/2025/11/fortinet-warns-of-new-fortiweb-cve-2025.html
๐ 8๐ 7โก 3
00:12
Video unavailableShow in Telegram
๐จ Hackers just upgraded their phishing game. A fake Microsoft login now looks 100% real โ even showing a real URL and CAPTCHA check.
Itโs part of a new โSneaky 2FAโ phishing kit that lets anyone steal accounts without real skills.
Even pros are getting tricked.
Hereโs how it works โ https://thehackernews.com/2025/11/sneaky-2fa-phishing-kit-adds-bitb-pop.html
browser.gif.mp40.45 KB
๐ฅ 20๐คฏ 6๐ 4๐ 2
Photo unavailableShow in Telegram
Meta just expanded WhatsAppโs security research.
๐น New โResearch Proxyโ tool lets experts dig deeper
๐น$4M paid to bug hunters this year
Big money. Bigger stakes.
Read here โ https://thehackernews.com/2025/11/meta-expands-whatsapp-security-research.html
๐ 12๐ 2๐ค 2
Photo unavailableShow in Telegram
โ๏ธ Your cloud might already be wide open.
One weak access rule can expose everything โ data, customers, compliance.
Join our free WEBINAR with CyberArk experts to learn simple ways to close those gaps fast & keep your data safe.
Save your spot now โ https://thehackernews.com/2025/11/learn-how-leading-companies-secure.html
๐ 5๐ 2๐ฅ 1
Photo unavailableShow in Telegram
๐ A U.S. real-estate giant was nearly hacked โ through a fake Microsoft Teams chat.
Attackers used Tuoni, a free red-team tool from GitHub, to run hidden code straight in memory.
Even the script showed signs of AI-written code.
How ethical hacking tools are turning against us โ https://thehackernews.com/2025/11/researchers-detail-tuoni-c2s-role-in.html
๐ 8๐ฅ 4๐ 3
Photo unavailableShow in Telegram
Iranโs UNC1549 hackers hit defense networks without even touching them.
They broke in through third-party Citrix and Azure accounts and dropped backdoors โ TWOSTROKE and DEEPROOT โ that can sit quiet for months.
Theyโre now active across the Middle Eastโs aerospace supply chain.
Read this latest report โ https://thehackernews.com/2025/11/iranian-hackers-use-deeproot-and.html
๐ 11๐ฑ 5๐ 2๐ฅ 1
Photo unavailableShow in Telegram
๐ค Most cyberattacks donโt start with hackers โ they start with machine accounts.
Non-human identities now outnumber people 50 to 1, and most orgs still canโt see or secure them.
A new approach called Identity Security Fabric fixes that.
Read how it works โ https://thehackernews.com/2025/11/beyond-iam-silos-why-identity-security.html
๐ 7๐ 4๐ 2
Photo unavailableShow in Telegram
Dev teams often waste valuable time and effort sifting through vulnerabilitiesโฆ just to determine if a container is safe.
ActiveStateโs new Secure Container Image Catalog simplifies how teams find, compare, and pull secure containers.
The growing catalog, which offers free container images for languages like Python and Java, provides:
๐น Real-time vulnerability insights and VEX advisories
๐น Full SBOMs and component details for complete transparency
๐น Reliable architecture and compatibility data
๐น The ability to directly compare and pull secure images
Check out the catalog to simplify your container image selection: https://thn.news/state-images
๐ฅ 5
Photo unavailableShow in Telegram
โ ๏ธ Seven npm packages were caught hiding crypto scams.
They used a cloaking tool called Adspect to dodge detection โ even blocking dev tools to stay invisible.
Learn more โ https://thehackernews.com/2025/11/seven-npm-packages-use-adspect-cloaking.html
๐ 9
Photo unavailableShow in Telegram
๐ฅ Microsoft stopped the biggest DDoS attack ever seen in the cloud โ 5.72 Tbps from over 500,000 hacked routers and cameras.
The attack came from an IoT botnet called AISURU.
The devices are still infected โ and could strike again.
Read here โ https://thehackernews.com/2025/11/microsoft-mitigates-record-572-tbps.html
๐ 27๐ 6๐ 5
Photo unavailableShow in Telegram
๐ด Google confirms new Chrome zero-day under attack.
The flaw โ CVE-2025-13223 โ lets hackers run code through a crafted web page.
Itโs the third V8 exploit this year, and itโs already being used in the wild.
Patch now โ https://thehackernews.com/2025/11/google-issues-security-fix-for-actively.html
๐ฑ 19๐ฅ 11๐ 4๐ 4๐ 2
Photo unavailableShow in Telegram
โก Hackers are using fake reCAPTCHA pop-ups to install Amatera Stealer โ malware that steals crypto, passwords, and messages.
It hides inside Windows files and skips computers with nothing valuable.
Full details โ https://thehackernews.com/2025/11/new-evalusion-clickfix-campaign.html
๐ 32๐ฅ 9๐ 8๐ 3
Photo unavailableShow in Telegram
๐ก๏ธ Missed the latest threats? Cyber moves fast โ catch up faster.
โก Fortinet flaw exploited
๐ค Chinaโs AI-driven ops
๐ PhaaS shutdown
๐ฐ Fake crypto apps
๐ฆ Supply chain abuse
๐ All in one sharp recap: https://thehackernews.com/2025/11/weekly-recap-fortinet-exploited-chinas.html
๐ฅ 10๐ 3๐ 3๐คฏ 3
Photo unavailableShow in Telegram
๐จ 1 in 3 phishing attacks no longer come from email.
Theyโre sliding into LinkedIn DMsโimpersonating execs, hijacking accounts, and stealing access to Microsoft & Google workspaces.
The worst part? Security teams canโt even see it happening.
Find out how it works โ https://thehackernews.com/2025/11/5-reasons-why-attackers-are-phishing.html
โก 10๐ค 6๐ 3๐ 2
Photo unavailableShow in Telegram
๐จ Hackers are using fake Chrome and Teams apps to spread a new virus. Itโs called RONINGLOADER, and it installs a changed version of Gh0st RAT.
๐ฌ It shuts down antivirus tools with real Windows drivers and hides inside regsvr32.exe.
Read the full story โ https://thehackernews.com/2025/11/dragon-breath-uses-roningloader-to.html
๐ 9๐ฅ 6
Photo unavailableShow in Telegram
๐จ Big win for Android security.
Google says Rust cut memory bugs by 1000x โ and made coding faster too.
Fewer crashes, fewer rollbacks, quicker reviews. Even an 8.1-rated bug in โunsafeโ Rust couldnโt get through.
Learn more โ https://thehackernews.com/2025/11/rust-adoption-drives-android-memory.html
๐ค 16๐ 8๐ฅ 7๐ 2
Photo unavailableShow in Telegram
๐จ A new botnet called RondoDox is attacking unpatched XWiki servers through a critical bug (CVE-2025-24893, score 9.8).
Hackers are using it to spread crypto miners and DDoS tools.
Learn more โ https://thehackernews.com/2025/11/rondodox-exploits-unpatched-xwiki.html
๐ 11
Photo unavailableShow in Telegram
The U.S. just uncovered how North Korea used fake โremote IT jobsโ to sneak millions past sanctions.
๐ค 5 Americans pleaded guilty
๐ข 136 U.S. companies hit
๐ฐ $2.2M sent to North Korea
Read the details โ https://thehackernews.com/2025/11/five-us-citizens-plead-guilty-to.html
๐ 22๐คฏ 7๐ฑ 5๐ฅ 2๐ 1
Photo unavailableShow in Telegram
๐ Update: Fortinet has assigned CVE-2025-64446 (CVSS 9.1) โ a path traversal flaw letting attackers run admin commands via crafted HTTP/S requests.
CISA added it to KEV โ deadline: Nov 21.
Exploited in the wild.
Patch now โคต๏ธ https://thehackernews.com/2025/11/fortinet-fortiweb-flaw-actively.html
๐ฅ 13๐คฏ 3โก 1๐ 1
