uz
Feedback
The Hacker News

The Hacker News

Kanalga Telegramโ€™da oโ€˜tish

โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. ๐Ÿ“จ Contact: admin@thehackernews.com ๐ŸŒ Website: https://thehackernews.com

Ko'proq ko'rsatish
2025 yil raqamlardasnowflakes fon
card fon
153 640
Obunachilar
+4924 soatlar
+3847 kunlar
+1 47630 kunlar
Postlar arxiv
Photo unavailableShow in Telegram
We say โ€œtrust but verify.โ€ In SaaS, most teams trust onceโ€”and never verify again. Old tokens stay valid. Apps keep broad access. Thatโ€™s how attackers move in quietly. Gal Nakash explains why Zero Trust fails in practice and what to fix โ†“ https://thehackernews.com/expert-insights/2025/11/the-problem-with-trust-but-verify-is.html
Hammasini ko'rsatish...
๐Ÿค” 9๐Ÿ”ฅ 4๐Ÿ‘ 4๐Ÿ˜ 2
Photo unavailableShow in Telegram
Fortinet has confirmed a new FortiWeb flaw โ€” CVE-2025-58034 โ€” already exploited in the wild. It lets authenticated attackers execute OS commands via crafted requests. Full story โ†“ https://thehackernews.com/2025/11/fortinet-warns-of-new-fortiweb-cve-2025.html
Hammasini ko'rsatish...
๐Ÿ‘ 8๐Ÿ˜ 7โšก 3
00:12
Video unavailableShow in Telegram
๐Ÿšจ Hackers just upgraded their phishing game. A fake Microsoft login now looks 100% real โ€” even showing a real URL and CAPTCHA check. Itโ€™s part of a new โ€œSneaky 2FAโ€ phishing kit that lets anyone steal accounts without real skills. Even pros are getting tricked. Hereโ€™s how it works โ†“ https://thehackernews.com/2025/11/sneaky-2fa-phishing-kit-adds-bitb-pop.html
Hammasini ko'rsatish...
browser.gif.mp40.45 KB
๐Ÿ”ฅ 20๐Ÿคฏ 6๐Ÿ‘ 4๐Ÿ˜ 2
Photo unavailableShow in Telegram
Meta just expanded WhatsAppโ€™s security research. ๐Ÿ”น New โ€œResearch Proxyโ€ tool lets experts dig deeper ๐Ÿ”น$4M paid to bug hunters this year Big money. Bigger stakes. Read here โ†“ https://thehackernews.com/2025/11/meta-expands-whatsapp-security-research.html
Hammasini ko'rsatish...
๐Ÿ˜ 12๐Ÿ‘ 2๐Ÿค” 2
Photo unavailableShow in Telegram
โ˜๏ธ Your cloud might already be wide open. One weak access rule can expose everything โ€” data, customers, compliance. Join our free WEBINAR with CyberArk experts to learn simple ways to close those gaps fast & keep your data safe. Save your spot now โ†’ https://thehackernews.com/2025/11/learn-how-leading-companies-secure.html
Hammasini ko'rsatish...
๐Ÿ˜ 5๐Ÿ‘ 2๐Ÿ”ฅ 1
Photo unavailableShow in Telegram
๐Ÿ  A U.S. real-estate giant was nearly hacked โ€” through a fake Microsoft Teams chat. Attackers used Tuoni, a free red-team tool from GitHub, to run hidden code straight in memory. Even the script showed signs of AI-written code. How ethical hacking tools are turning against us โ†’ https://thehackernews.com/2025/11/researchers-detail-tuoni-c2s-role-in.html
Hammasini ko'rsatish...
๐Ÿ˜ 8๐Ÿ”ฅ 4๐Ÿ‘ 3
Photo unavailableShow in Telegram
Iranโ€™s UNC1549 hackers hit defense networks without even touching them. They broke in through third-party Citrix and Azure accounts and dropped backdoors โ€” TWOSTROKE and DEEPROOT โ€” that can sit quiet for months. Theyโ€™re now active across the Middle Eastโ€™s aerospace supply chain. Read this latest report โ†“ https://thehackernews.com/2025/11/iranian-hackers-use-deeproot-and.html
Hammasini ko'rsatish...
๐Ÿ‘ 11๐Ÿ˜ฑ 5๐Ÿ‘ 2๐Ÿ”ฅ 1
Photo unavailableShow in Telegram
๐Ÿค– Most cyberattacks donโ€™t start with hackers โ€” they start with machine accounts. Non-human identities now outnumber people 50 to 1, and most orgs still canโ€™t see or secure them. A new approach called Identity Security Fabric fixes that. Read how it works โ†“ https://thehackernews.com/2025/11/beyond-iam-silos-why-identity-security.html
Hammasini ko'rsatish...
๐Ÿ‘ 7๐Ÿ˜ 4๐Ÿ‘ 2
Photo unavailableShow in Telegram
Dev teams often waste valuable time and effort sifting through vulnerabilitiesโ€ฆ just to determine if a container is safe. ActiveStateโ€™s new Secure Container Image Catalog simplifies how teams find, compare, and pull secure containers. The growing catalog, which offers free container images for languages like Python and Java, provides: ๐Ÿ”น Real-time vulnerability insights and VEX advisories ๐Ÿ”น Full SBOMs and component details for complete transparency ๐Ÿ”น Reliable architecture and compatibility data ๐Ÿ”น The ability to directly compare and pull secure images Check out the catalog to simplify your container image selection: https://thn.news/state-images
Hammasini ko'rsatish...
๐Ÿ”ฅ 5
Photo unavailableShow in Telegram
โš ๏ธ Seven npm packages were caught hiding crypto scams. They used a cloaking tool called Adspect to dodge detection โ€” even blocking dev tools to stay invisible. Learn more โ†“ https://thehackernews.com/2025/11/seven-npm-packages-use-adspect-cloaking.html
Hammasini ko'rsatish...
๐Ÿ‘ 9
Photo unavailableShow in Telegram
๐Ÿ”ฅ Microsoft stopped the biggest DDoS attack ever seen in the cloud โ€” 5.72 Tbps from over 500,000 hacked routers and cameras. The attack came from an IoT botnet called AISURU. The devices are still infected โ€” and could strike again. Read here โ†’ https://thehackernews.com/2025/11/microsoft-mitigates-record-572-tbps.html
Hammasini ko'rsatish...
๐Ÿ˜ 27๐Ÿ‘ 6๐Ÿ‘ 5
Photo unavailableShow in Telegram
๐Ÿ”ด Google confirms new Chrome zero-day under attack. The flaw โ€” CVE-2025-13223 โ€” lets hackers run code through a crafted web page. Itโ€™s the third V8 exploit this year, and itโ€™s already being used in the wild. Patch now โ†“ https://thehackernews.com/2025/11/google-issues-security-fix-for-actively.html
Hammasini ko'rsatish...
๐Ÿ˜ฑ 19๐Ÿ”ฅ 11๐Ÿ‘ 4๐Ÿ‘ 4๐Ÿ˜ 2
Photo unavailableShow in Telegram
โšก Hackers are using fake reCAPTCHA pop-ups to install Amatera Stealer โ€” malware that steals crypto, passwords, and messages. It hides inside Windows files and skips computers with nothing valuable. Full details โ†“ https://thehackernews.com/2025/11/new-evalusion-clickfix-campaign.html
Hammasini ko'rsatish...
๐Ÿ˜ 32๐Ÿ”ฅ 9๐Ÿ‘ 8๐Ÿ‘ 3
Photo unavailableShow in Telegram
๐Ÿ›ก๏ธ Missed the latest threats? Cyber moves fast โ€” catch up faster. โšก Fortinet flaw exploited ๐Ÿค– Chinaโ€™s AI-driven ops ๐Ÿ“‰ PhaaS shutdown ๐Ÿ’ฐ Fake crypto apps ๐Ÿ“ฆ Supply chain abuse ๐Ÿ”— All in one sharp recap: https://thehackernews.com/2025/11/weekly-recap-fortinet-exploited-chinas.html
Hammasini ko'rsatish...
๐Ÿ”ฅ 10๐Ÿ‘ 3๐Ÿ˜ 3๐Ÿคฏ 3
Photo unavailableShow in Telegram
๐Ÿšจ 1 in 3 phishing attacks no longer come from email. Theyโ€™re sliding into LinkedIn DMsโ€”impersonating execs, hijacking accounts, and stealing access to Microsoft & Google workspaces. The worst part? Security teams canโ€™t even see it happening. Find out how it works โ†“ https://thehackernews.com/2025/11/5-reasons-why-attackers-are-phishing.html
Hammasini ko'rsatish...
โšก 10๐Ÿค” 6๐Ÿ‘ 3๐Ÿ‘ 2
Photo unavailableShow in Telegram
๐Ÿšจ Hackers are using fake Chrome and Teams apps to spread a new virus. Itโ€™s called RONINGLOADER, and it installs a changed version of Gh0st RAT. ๐Ÿ˜ฌ It shuts down antivirus tools with real Windows drivers and hides inside regsvr32.exe. Read the full story โ†“ https://thehackernews.com/2025/11/dragon-breath-uses-roningloader-to.html
Hammasini ko'rsatish...
๐Ÿ‘ 9๐Ÿ”ฅ 6
Photo unavailableShow in Telegram
๐Ÿšจ Big win for Android security. Google says Rust cut memory bugs by 1000x โ€” and made coding faster too. Fewer crashes, fewer rollbacks, quicker reviews. Even an 8.1-rated bug in โ€œunsafeโ€ Rust couldnโ€™t get through. Learn more โ†“ https://thehackernews.com/2025/11/rust-adoption-drives-android-memory.html
Hammasini ko'rsatish...
๐Ÿค” 16๐Ÿ‘ 8๐Ÿ”ฅ 7๐Ÿ˜ 2
Photo unavailableShow in Telegram
๐Ÿšจ A new botnet called RondoDox is attacking unpatched XWiki servers through a critical bug (CVE-2025-24893, score 9.8). Hackers are using it to spread crypto miners and DDoS tools. Learn more โ†“ https://thehackernews.com/2025/11/rondodox-exploits-unpatched-xwiki.html
Hammasini ko'rsatish...
๐Ÿ‘ 11
Photo unavailableShow in Telegram
The U.S. just uncovered how North Korea used fake โ€œremote IT jobsโ€ to sneak millions past sanctions. ๐Ÿ‘ค 5 Americans pleaded guilty ๐Ÿข 136 U.S. companies hit ๐Ÿ’ฐ $2.2M sent to North Korea Read the details โ†“ https://thehackernews.com/2025/11/five-us-citizens-plead-guilty-to.html
Hammasini ko'rsatish...
๐Ÿ˜ 22๐Ÿคฏ 7๐Ÿ˜ฑ 5๐Ÿ”ฅ 2๐Ÿ‘ 1
Photo unavailableShow in Telegram
๐Ÿ”” Update: Fortinet has assigned CVE-2025-64446 (CVSS 9.1) โ€” a path traversal flaw letting attackers run admin commands via crafted HTTP/S requests. CISA added it to KEV โ€” deadline: Nov 21. Exploited in the wild. Patch now โคต๏ธ https://thehackernews.com/2025/11/fortinet-fortiweb-flaw-actively.html
Hammasini ko'rsatish...
๐Ÿ”ฅ 13๐Ÿคฏ 3โšก 1๐Ÿ˜ 1