The Hacker News
βœ”
152K subscribers
1.95K photos
11 videos
3 files
7.86K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
🚨 A Chrome extension is stealing crypto.

β€œCrypto Copilot” looks like a trading tool for X β€” but it secretly adds a hidden Solana transfer and sends your money to a hacker’s wallet.

It’s still live on the Chrome Web Store.

Full story ↓ https://thehackernews.com/2025/11/chrome-extension-caught-injecting.html
πŸ‘6😁5😱1
⚠️ Hackers love community update tools.
Why? Because anyone can upload a package.
One bad update = hacked systems.

πŸ”’ Join our free live webinar with Action1 CTO Gene Moody β€” see how to patch safely without slowing down.

Save your spot ↓ https://thehackernews.com/2025/11/webinar-learn-to-spot-risks-and-patch.html
πŸ‘5
Media is too big
VIEW IN TELEGRAM
πŸ€– We talk a lot about securing AI.

Almost no one talks about where it’s actually hiding.

NetworkChuck just dropped a video with Wiz, showing how they’re finding hidden AI risksβ€”β€œshadow AI”—before attackers do. It’s a smart look at where cloud security is headed next.

πŸš€See Wiz in Action β†’ https://thn.news/cloud-security-demo
😁13πŸ‘8πŸ”₯3
πŸ”₯ Hackers hit South Korea’s banks through one IT vendor β€” spreading Qilin ransomware to 28 firms and stealing 2 TB of data.

Evidence suggests Russian and North Korean groups worked together.

Full story ↓ https://thehackernews.com/2025/11/qilin-ransomware-turns-south-korean-msp.html
🀯20πŸ”₯8😱6😁3
⚠️ Eight β€œadvanced” tools failed at once.

A phishing attack slipped past all of them and reached exec inboxes. Only one thing stopped it β€” a strong SOC.

πŸ”— Learn why your β€œfirst line” is useless without the last ↓ https://thehackernews.com/2025/11/when-your-2m-security-detection-fails.html
πŸ‘12
⚠️ Hundreds of Maven packages just got caught running Shai-Hulud v2 β€” the same malware that hijacked npm.

It spread through automated rebuilds, infecting devs who never used npm.

Hiding in the Bun runtime, it steals GitHub + cloud creds and self-replicates like a worm β€” already leaking 11,000+ secrets across 4,600 repos.

Details here ↓ https://thehackernews.com/2025/11/shai-hulud-v2-campaign-spreads-from-npm.html
πŸ‘11πŸ”₯6
πŸ›‘ Gainsight just revealed more customers were affected than originally disclosed.

Salesforce revoked all Gainsight access tokens after the breach tied to ShinyHunters β€” and the same user-agent from prior Salesloft attacks popped up again.

The full scope remains unknown.

Read here β†’ https://thehackernews.com/2025/11/gainsight-expands-impacted-customer.html
😱6πŸ‘5
🚨 New ThreatsDay Bulletin is live!

πŸ€– AI malware that learns your habits
πŸ“ž Voice bots turned into attack tools
πŸ’Έ Crypto rings laundering billions
πŸ”Œ IoT gear under siege again
🌍 Smishing scams spreading worldwide

All that and 20+ more stories shaping the week in cybersecurity.

πŸ”— Read now: https://thehackernews.com/2025/11/threatsday-bulletin-ai-malware-voice.html
πŸ”₯7πŸ€”5
Microsoft will block all non-Microsoft scripts on Entra ID logins starting Oct 2026.

If your sign-in flow or browser extension injects any code, it may break β€” so test ASAP.

The new Content Security Policy only lets trusted Microsoft-hosted scripts.

Read more β†’ https://thehackernews.com/2025/11/microsoft-to-block-unauthorized-scripts.html
πŸ€”12πŸ‘8😁2
Hackers posing as Kyrgyzstan’s Justice Ministry are spreading 2013-era NetSupport RAT across Kyrgyzstan and Uzbekistan using fake PDFs and old Java tricksβ€”blocking outsiders to hide the attack.

Old tools. New victims. β†’ https://thehackernews.com/2025/11/bloody-wolf-expands-java-based.html
πŸ”₯19πŸ‘4😁4πŸ‘1
VPNs weren’t built for today’s hybrid networks. Hackers now exploit them as entry points to steal admin creds.

Remote Privileged Access Management (RPAM) closes that gap β€” no VPNs, no shared passwords, full session tracking.

Why it’s replacing PAM β†’ https://thehackernews.com/2025/11/why-organizations-are-turning-to-rpam.html
πŸ”₯14🀯5πŸ‘3😁1
🚨 North Korean hackers uploaded 197 malicious npm packages (31K+ downloads).

They drop a new OtterCookie variant that steals passwords, crypto data, and screenshots β€” all from a fake job interview setup.

Details here ↓ https://thehackernews.com/2025/11/north-korean-hackers-deploy-197-npm.html
πŸ‘7😱4πŸ”₯3πŸ‘2
⚠️ Researchers found old Python code that could expose projects to a supply chain attack.

Some PyPI packages β€” including Tornado and slapos.core β€” still call an expired domain that anyone could buy and use to run malicious code.

Details ↓ https://thehackernews.com/2025/11/legacy-python-bootstrap-scripts-create.html
πŸ”₯7