Category: TheHackerNews

Microsoft to Block Unauthorized Scripts in Entra ID Logins with 2026 CSP Update
27
Nov
2025

Microsoft to Block Unauthorized Scripts in Entra ID Logins with 2026 CSP Update

Nov 27, 2025Ravie LakshmananWeb Security / Zero Trust Microsoft has announced plans to improve the security of Entra ID authentication…

Gainsight Expands Impacted Customer List Following Salesforce Security Alert
27
Nov
2025

Gainsight Expands Impacted Customer List Following Salesforce Security Alert

Nov 27, 2025Ravie LakshmananRansomware / Cloud Security Gainsight has disclosed that the recent suspicious activity targeting its applications has affected…

Shai-Hulud v2 Campaign Spreads From npm to Maven, Exposing Thousands of Secrets
26
Nov
2025

Shai-Hulud v2 Campaign Spreads From npm to Maven, Exposing Thousands of Secrets

The second wave of the Shai-Hulud supply chain attack has spilled over to the Maven ecosystem after compromising more than…

Qilin Ransomware Turns South Korean MSP Breach Into 28-Victim 'Korean Leaks' Data Heist
26
Nov
2025

Qilin Ransomware Turns South Korean MSP Breach Into 28-Victim ‘Korean Leaks’ Data Heist

South Korea’s financial sector has been targeted by what has been described as a sophisticated supply chain attack that led…

Learn to Spot Risks and Patch Safely with Community-Maintained Tools
26
Nov
2025

Learn to Spot Risks and Patch Safely with Community-Maintained Tools

Nov 26, 2025The Hacker NewsSoftware Security / Patch Management If you’re using community tools like Chocolatey or Winget to keep…

Can your SOC Save You?
26
Nov
2025

Can your SOC Save You?

Enterprises today are expected to have at least 6-8 detection tools, as detection is considered a standard investment and the…

Chrome Extension Caught Injecting Hidden Solana Transfer Fees Into Raydium Swaps
26
Nov
2025

Chrome Extension Caught Injecting Hidden Solana Transfer Fees Into Raydium Swaps

Nov 26, 2025Ravie LakshmananBrowser Security / Cryptocurrency Cybersecurity researchers have discovered a new malicious extension on the Chrome Web Store…

RomCom Uses SocGholish Fake Update Attacks to Deliver Mythic Agent Malware
26
Nov
2025

RomCom Uses SocGholish Fake Update Attacks to Deliver Mythic Agent Malware

Nov 26, 2025Ravie LakshmananMalware / Cyber Espionage The threat actors behind a malware family known as RomCom targeted a U.S.-based…

FBI Reports $262M in ATO Fraud as Researchers Cite Growing AI Phishing and Holiday Scams
26
Nov
2025

FBI Reports $262M in ATO Fraud as Researchers Cite Growing AI Phishing and Holiday Scams

The U.S. Federal Bureau of Investigation (FBI) has warned that cybercriminals are impersonating financial institutions with an aim to steal…

Years of JSONFormatter and CodeBeautify Leaks Expose Thousands of Passwords and API Keys
25
Nov
2025

Years of JSONFormatter and CodeBeautify Leaks Expose Thousands of Passwords and API Keys

Nov 25, 2025Ravie LakshmananData Exposure / Cloud Security New research has found that organizations in various sensitive sectors, including governments,…

JackFix Uses Fake Windows Update Pop-Ups on Adult Sites to Deliver Multiple Stealers
25
Nov
2025

JackFix Uses Fake Windows Update Pop-Ups on Adult Sites to Deliver Multiple Stealers

Cybersecurity researchers are calling attention to a new campaign that’s leveraging a combination of ClickFix lures and fake adult websites…

ToddyCat's New Hacking Tools Steal Outlook Emails and Microsoft 365 Access Tokens
25
Nov
2025

ToddyCat’s New Hacking Tools Steal Outlook Emails and Microsoft 365 Access Tokens

Nov 25, 2025Ravie LakshmananMalware / Vulnerability The threat actor known as ToddyCat has been observed adopting new methods to obtain…