The Hacker News
βœ”
152K subscribers
1.87K photos
10 videos
3 files
7.79K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
⚠️ New Mirai Botnet Variant Aquabot Targets CVE-2024-41710 in Mitel Phones for DDoS Attacks.

The flaw affects Mitel 6800, 6900, 6900w phones and Mitel 6970 Conference Units. Attackers have been exploiting CVE-2024-41710 since January 2025.

Attackers are using Telegram to sell DDoS servicesβ€”this threat is already commercialized.

Learn more: https://thehackernews.com/2025/01/new-aquabot-botnet-exploits-cve-2024.html
πŸ‘19😁4πŸ€”3πŸ‘2
🚨 Security Flaws Discovered in Voyager PHP Package.

Attackers can exploit these UNPATCHED flaws with just one clickβ€”allowing them to execute arbitrary code remotely.

Click here to learn more: https://thehackernews.com/2025/01/unpatched-php-voyager-flaws-leave.html
πŸ”₯11πŸ‘6😁1🀯1
🚨 AI Startup #DeepSeek Exposes Sensitive Data!

A ClickHouse database was exposed on the internet, allowing anyone to access internal secrets, chat logs, API secrets, and moreβ€”all unprotected.

Read more: https://thehackernews.com/2025/01/deepseek-ai-database-exposed-over-1.html
😁39😱20πŸ”₯9πŸ‘5πŸ‘5
⚑ SOC Analysts Are Burning Out!

Manual tasks, false positives, and tool overloadβ€”AI is the solution SOC teams need NOW.

AI enables faster research, quicker analysis, and smarter responses to emerging threats.

Learn more: https://thehackernews.com/2025/01/soc-analysts-reimagining-their-role.html
😁13πŸ‘7πŸ€”6⚑4🀯4😱3
⚠️ Warning: Critical Flaw Discovered in Lightning AI Studio!

The vulnerability allowed attackers to run commands with root privileges, potentially compromising entire AI projects.

Get the full analysis: https://thehackernews.com/2025/01/lightning-ai-studio-vulnerability.html
πŸ”₯13πŸ‘7πŸ‘2😁2⚑1
πŸ”’ International law enforcement has dismantled infamous cybercrime hubs linked to platforms like Cracked, Nulled, StarkRDP and Sellix.

These platforms sold malware, hack tools, and personal data.

πŸ”— Read more about the "Operation Talent" β€” https://thehackernews.com/2025/01/authorities-seize-domains-of-popular.html
😁14πŸ‘9🀯6⚑4😱1
🚨 ALERT: Over 57 threat actors from China, Iran, North Korea, and Russia are now using Google's Gemini AI to power their malicious cyber operations.

From researching vulnerabilities to crafting phishing campaigns, they’re leveraging GenAI for faster, more efficient cybercrime.

Learn more: https://thehackernews.com/2025/01/google-over-57-nation-state-threat.html
😁30πŸ‘16😱14🀯7⚑3πŸ€”3πŸ”₯2
🚨 High-Risk VMware Vulnerabilities Discovered – Update ASAP!

5 major flaws have been found in VMware Aria Operations & Aria Operations for Logs, with CVSS scores ranging from 4.3 to 8.5. Attackers could escalate privileges, steal credentials, or inject malicious scripts.

πŸ”— Read more: https://thehackernews.com/2025/01/broadcom-patches-vmware-aria-flaws.html
πŸ”₯15😱7πŸ‘6😁3πŸ‘2🀯2⚑1
🚨 Google Blocks 2.36 Million Harmful Android Apps in 2024. Over 158,000 bad developer accounts banned.

Even apps outside the official store are being scrutinizedβ€”your device’s defense is constantly evolving.

πŸ‘‰ Learn more: https://thehackernews.com/2025/01/google-bans-158000-malicious-android.html
πŸ‘21πŸ‘10πŸ”₯4
⚠️ Italy Bans DeepSeek AI Service Over Questionable Data Practices and Privacy Concerns!

Meanwhile, malicious hackers are exploiting DeepSeek's AI models to generate dangerous content.

πŸ”— Read the full story: https://thehackernews.com/2025/01/italy-bans-chinese-deepseek-ai-over.html
😁48πŸ‘21🀯11⚑7πŸ€”6😱5πŸ”₯3πŸ‘3
🚨 AI is changing the game of social engineeringβ€”forever.

Hackers now manipulate trust & emotions to launch attacks at scale. AI lets hackers replicate voices, faces, and even your colleagues.

πŸ‘‰ Read the full story: https://thehackernews.com/2025/01/top-5-ai-powered-social-engineering.html
πŸ”₯19πŸ‘8😁2πŸ‘1πŸ€”1🀯1
πŸ›‘ CISA and FDA have just issued urgent warnings about critical flaws in Contec CMS8000 and Epsimed MN-120 patient monitors.

Hackers could exploit these flaws to gain remote access to devices, overwrite files & even steal sensitive patient data.

Read: https://thehackernews.com/2025/01/cisa-and-fda-warn-of-critical-backdoor.html
πŸ‘22🀯12πŸ”₯7😱1
🚨 Attack Alert: Cybercriminals are using bogus Google ads to direct Microsoft advertisers to phishing pages designed to capture login details and 2FA codes.

Over 630 phishing pages detected, with domains mostly hosted in Brazil.

Read the full report: https://thehackernews.com/2025/02/malvertising-scam-uses-fake-google-ads.html
😱21πŸ”₯9😁4πŸ‘3⚑1
🚨 WARNING: WhatsApp uncovers major spyware campaign targeting journalists!

➀ 90+ victims were attacked by Israeli firm Paragon Solutions.
➀ Zero-click spyware deployed via a PDF fileβ€”no action from the user needed

πŸ‘‰ Full story: https://thehackernews.com/2025/02/meta-confirms-zero-click-whatsapp.html
πŸ”₯15🀯12πŸ‘6😁4😱3⚑2
πŸ” BeyondTrust’s breach compromised 17 Remote Support SaaS customers, caused by a compromised API key.

Attackers exploited a zero-day vulnerability in a third-party app to reset application passwords.

Federal agencies, including the U.S. Treasury, were affected by this breach.

Read the full report: https://thehackernews.com/2025/02/beyondtrust-zero-day-breach-exposes-17.html
⚑13πŸ”₯9πŸ‘4😁3
πŸ”₯ BUSTED β€” 39 Cybercrime Domains Shut Down in Massive Global Takedown.

U.S. and Dutch law enforcement have just crippled a major fraud network responsible for over $3 million in scams, selling phishing kits, scam pages, and fraud tools.

Learn more: https://thehackernews.com/2025/02/us-and-dutch-authorities-dismantle-39.html
😁28πŸ‘18πŸ”₯16
πŸ›‘ Cybercrime Alert: Crazy Evil Steals Millions!

A Russian-speaking cybercriminal gang has stolen over $5M using targeted social media scams.

They hijack Windows and macOS users with malware like StealC and AMOS to steal cryptocurrencies.

Learn more: https://thehackernews.com/2025/02/crazy-evil-gang-targets-crypto-with.html
🀯17πŸ‘13😁6😱5⚑2
⚠️ A new wave of attacks is hitting Brazilian Windows users with the Coyote Banking Trojan.

This malware targets over 1,000 financial sites and can steal your credentials, log your keystrokes, and even capture screenshots.

πŸ‘‰ Learn how Coyote works: https://thehackernews.com/2025/02/coyote-malware-expands-reach-now.html
πŸ”₯18😁9πŸ‘5🀯4
🚨 Attack surfaces are growing faster than your security team can keep up. Attackers are always looking for new weak spotsβ€”often hidden until it’s too late.

Learn how Attack Surface Management (ASM) tools like Intruder give you visibility into your risks: https://thehackernews.com/2025/02/what-is-attack-surface-management.html
😁13πŸ‘4πŸ‘4🀯2
πŸ”’ PyPI Introduces Archiving for Projects!

PyPI now lets developers archive projects, signaling they won’t receive future updates.

This helps prevent the spread of outdated or vulnerable packages--huge win for supply chain security.

Full details: https://thehackernews.com/2025/02/pypi-introduces-archival-status-to.html
πŸ‘16😁13πŸ”₯5⚑1
🚨 768 vulnerabilities exploited in 2024β€”a shocking 20% increase from last year!

These vulnerabilities are being weaponized faster than ever, with nearly 1 in 4 exploited on the same day they were disclosed.

Read the full report: https://thehackernews.com/2025/02/768-cves-exploited-in-2024-reflecting.html
πŸ”₯18πŸ‘11πŸ€”3⚑2🀯1