The Hacker News
โœ”
152K subscribers
1.94K photos
11 videos
3 files
7.86K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: [email protected]

๐ŸŒ Website: https://thehackernews.com
Download Telegram
1 in 5 DevOps, Security, Product, and Developer professionals say vulnerable and outdated components are their biggest security concern.

If youโ€™re building or running container-based systems, this is your cue to pause and ask: Do you know which container images are hardened, which ones still carry drift, and how youโ€™ll prove theyโ€™re safe before they hit production?

This checklist is designed for teams to consistently build hardened, trustworthy containers by covering four key areas: base image selection, application-dependency management, minimization & hardening, and signing/verification.

๐Ÿ‘‰ Download the checklist here: https://thn.news/container-checklist
๐Ÿ‘8
๐Ÿšจ Hackers built fake adult sites that show a fake Windows update.

It tells you to copy and paste a โ€œfixโ€ โ€” but that command secretly installs up to 8 programs that steal passwords and data.

Researchers call it JackFix, part of the ClickFix trend now behind nearly half of all breaches.

Details โ†“ https://thehackernews.com/2025/11/jackfix-uses-fake-windows-update-pop.html
๐Ÿ˜28๐Ÿ‘8๐Ÿคฏ7
๐Ÿšจ WARNING: Over 80,000 files with passwords and keys from governments, banks, and tech firms were found online โ€” all pasted into public code tools like JSONFormatter and CodeBeautify.

Hackers are already scraping and using the data.
And yes โ€” itโ€™s still live.

Details here โ†’ https://thehackernews.com/2025/11/years-of-jsonformatter-and-codebeautify.html
๐Ÿ˜16๐Ÿค”11๐Ÿคฏ10๐Ÿ”ฅ6๐Ÿ‘2
๐Ÿšจ FBI ALERT: Scammers are posing as banks to steal logins โ€” causing $262M in losses this year.

Now theyโ€™re using AI to create fake Black Friday sites and ads that look real.

They trick people into handing over passwords and money.

Learn more โ†“ https://thehackernews.com/2025/11/fbi-reports-262m-in-ato-fraud-as.html
๐Ÿคฏ8๐Ÿ˜6๐Ÿ”ฅ4
Russiaโ€™s GRU tried a new way to spread RomCom malware.

For the first time, they used SocGholish โ€” fake browser update malware โ€” to target a U.S. engineering firm linked to Ukraine.

The attack went from click to malware in under 30 minutes.

Read the latest report โ†“ https://thehackernews.com/2025/11/romcom-uses-socgholish-fake-update.html
๐Ÿ”ฅ16๐Ÿ˜3
๐Ÿšจ A Chrome extension is stealing crypto.

โ€œCrypto Copilotโ€ looks like a trading tool for X โ€” but it secretly adds a hidden Solana transfer and sends your money to a hackerโ€™s wallet.

Itโ€™s still live on the Chrome Web Store.

Full story โ†“ https://thehackernews.com/2025/11/chrome-extension-caught-injecting.html
๐Ÿ˜5๐Ÿ‘3
โš ๏ธ Hackers love community update tools.
Why? Because anyone can upload a package.
One bad update = hacked systems.

๐Ÿ”’ Join our free live webinar with Action1 CTO Gene Moody โ€” see how to patch safely without slowing down.

Save your spot โ†“ https://thehackernews.com/2025/11/webinar-learn-to-spot-risks-and-patch.html
๐Ÿ‘4
Media is too big
VIEW IN TELEGRAM
๐Ÿค– We talk a lot about securing AI.

Almost no one talks about where itโ€™s actually hiding.

NetworkChuck just dropped a video with Wiz, showing how theyโ€™re finding hidden AI risksโ€”โ€œshadow AIโ€โ€”before attackers do. Itโ€™s a smart look at where cloud security is headed next.

๐Ÿš€See Wiz in Action โ†’ https://thn.news/cloud-security-demo
๐Ÿ˜11๐Ÿ‘4๐Ÿ”ฅ2
๐Ÿ”ฅ Hackers hit South Koreaโ€™s banks through one IT vendor โ€” spreading Qilin ransomware to 28 firms and stealing 2 TB of data.

Evidence suggests Russian and North Korean groups worked together.

Full story โ†“ https://thehackernews.com/2025/11/qilin-ransomware-turns-south-korean-msp.html
๐Ÿคฏ14๐Ÿ”ฅ6๐Ÿ˜ฑ6๐Ÿ˜3
โš ๏ธ Eight โ€œadvancedโ€ tools failed at once.

A phishing attack slipped past all of them and reached exec inboxes. Only one thing stopped it โ€” a strong SOC.

๐Ÿ”— Learn why your โ€œfirst lineโ€ is useless without the last โ†“ https://thehackernews.com/2025/11/when-your-2m-security-detection-fails.html
๐Ÿ‘6
โš ๏ธ Hundreds of Maven packages just got caught running Shai-Hulud v2 โ€” the same malware that hijacked npm.

It spread through automated rebuilds, infecting devs who never used npm.

Hiding in the Bun runtime, it steals GitHub + cloud creds and self-replicates like a worm โ€” already leaking 11,000+ secrets across 4,600 repos.

Details here โ†“ https://thehackernews.com/2025/11/shai-hulud-v2-campaign-spreads-from-npm.html
๐Ÿ‘8๐Ÿ”ฅ3