🎉 Share Your 2025 Year-End Summary & Win $10,000 Sharing Rewards!
Reflect on your year with Gate and share your report on Square for a chance to win $10,000!
👇 How to Join:
1️⃣ Click to check your Year-End Summary: https://www.gate.com/competition/your-year-in-review-2025
2️⃣ After viewing, share it on social media or Gate Square using the "Share" button
3️⃣ Invite friends to like, comment, and share. More interactions, higher chances of winning!
🎁 Generous Prizes:
1️⃣ Daily Lucky Winner: 1 winner per day gets $30 GT, a branded hoodie, and a Gate × Red Bull tumbler
2️⃣ Lucky Share Draw: 10
Blackmail of PornHub premium users, SantaStealer cryptocurrency drainers, and other cybersecurity events - ForkLog: cryptocurrencies, AI, singularity, the future
We have compiled the most important cybersecurity news of the week.
Vulnerability in a JavaScript library was exploited to steal cryptocurrencies
Recently, there has been an increase in cases of malware loading to drain crypto wallets. It infiltrates websites through a vulnerability in a popular JavaScript library for creating user interfaces React, reports Cointelegraph.
On December 3, the React team announced that white-hat hacker Laklan Davidson discovered a vulnerability allowing remote code execution without authentication. The same day, an update was released.
According to the non-profit cybersecurity organization Security Alliance (SEAL), malicious actors are using this vulnerability to covertly add drainer code to cryptocurrency sites.
SEAL emphasized that not only Web3 protocols are at risk but all websites in general. Users are advised to exercise extreme caution when signing any transactions or permissions.
Hackers threatened to reveal premium user data from Pornhub
Users of the adult platform Pornhub were extorted by the hacking group ShinyHunters. This was reported by the company’s management.
The letter states that the platform was compromised due to a breach of a third-party analytics provider, Mixpanel. The incident occurred on November 8, 2025, after a spear-phishing attack.
According to BleepingComputer, Pornhub has not worked with Mixpanel since 2021, indicating the timing of the incident.
The contractor confirmed that the breach affected a “limited number” of clients, previously including OpenAI and CoinTracker.
In a comment to BleepingComputer, representatives stated they do not consider their system the source of the leak:
BleepingComputer learned that ShinyHunters began blackmailing Mixpanel clients last week, sending emails demanding ransom.
In an ultimatum sent to Pornhub, hackers claimed to have stolen 94 GB of data containing over 200 million records of personal inf