The Hacker News
โœ”
152K subscribers
1.88K photos
10 videos
3 files
7.79K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: [email protected]

๐ŸŒ Website: https://thehackernews.com
Download Telegram
Cybercriminals are hiding malware in images, making it nearly invisible to security tools.

A harmless landscape photo ๐Ÿ–ผ๏ธ could be carrying a payload that steals data or takes over your system. Traditional security tools miss this, leaving you exposed.

Learn how to protect your systems: https://thehackernews.com/2025/03/steganography-explained-how-xworm-hides.html
๐Ÿ”ฅ33๐Ÿ˜ฑ5โšก2๐Ÿ‘2๐Ÿคฏ1
๐Ÿšจ Apple just patched a zero-day under active attack!

CVE-2025-24201 lets hackers escape the WebKit sandboxโ€”Apple calls the exploit โ€œextremely sophisticated.โ€

Targeted? Unknown
Duration? Unknown

But if you use an iPhone, Mac, or Vision Proโ€”update NOW.

๐Ÿ“ฒ Details: https://thehackernews.com/2025/03/apple-releases-patch-for-webkit-zero.html
๐Ÿ”ฅ23๐Ÿ‘8โšก4๐Ÿค”3๐Ÿ˜2๐Ÿคฏ1
โšก Proactive security > Reactive fixes.

ASPM's "shift-left" approach empowers teams to prevent vulnerabilities BEFORE they spread. Don't miss out on how this could save you time and money.

๐Ÿš€ Learn more in this expert webinar โ€” https://thehacker.news/aspm-future-appsec
๐Ÿ‘9
๐Ÿšจ 6,000+ fake Play Store pages exposed!

PlayPraetor Trojan malware is tricking users into downloading apps that steal banking info, intercept 2FA, and spy on you. CTM360 uncovered this global scam, where cybercriminals use realistic fake pages to hijack devices and steal data.

Protect yourself:
โœ… Download from trusted stores only
โœ… Check reviews & permissions
โœ… Use mobile security tools

๐Ÿ”— Full report: https://thehackernews.com/expert-insights/2025/03/ctm360-uncovers-large-scale-fake-play.html
๐Ÿ‘16๐Ÿ˜4๐Ÿคฏ1
๐Ÿšจ UPDATE: Microsoft has uncovered major upgrades in the latest XCSSET variant:

โš ๏ธ New persistence method โ€“ Uses dockutil to swap in a fake Launchpad app, ensuring the malware runs every time you open it.
โš ๏ธ Stronger obfuscation โ€“ Harder to detect, harder to analyze.
โš ๏ธ Still spreading via Xcode projects โ€“ Developers, your builds could be compromised.

This marks the first major XCSSET update since 2022โ€”and it's more deceptive than ever. Inspect Xcode projects carefully.

๐Ÿ”— More details: https://thehackernews.com/2025/02/microsoft-uncovers-new-xcsset-macos.html
๐Ÿ˜8๐Ÿ‘4๐Ÿ˜ฑ2๐Ÿค”1
This media is not supported in your browser
VIEW IN TELEGRAM
๐Ÿ”ฅ Microsoft warns: 6 zero-days under active attack!

This monthโ€™s Patch Tuesday fixes 57 security flaws, including 6 exploited zero-days that attackers are already using for privilege escalation, data theft, and remote code execution.

๐Ÿ”น Key threats:
CVE-2025-24985 & CVE-2025-24993 โ€“ File system flaws allowing remote code execution
CVE-2025-24983 โ€“ A Win32k zero-day used in the wild with PipeMagic malware
CVE-2025-26633 โ€“ Security bypass flaw in Microsoft Management Console

CISA has mandated patches by April 1. Donโ€™t waitโ€”secure your systems now!

๐Ÿ”— Full patch details: https://thehackernews.com/2025/03/urgent-microsoft-patches-57-security.html
๐Ÿ‘22๐Ÿ˜7๐Ÿ‘2๐Ÿคฏ1
Do you know how secure your software supply chain really is?

According to ActiveState's 2025 State of Vulnerability Management and Remediation Report, DevSecOps pros signaled a 54% YoY increase in high-risk vulnerabilitiesโ€”download the FREE report to learn how to stay ahead of the curve.

https://thn.news/vulnerability-report-2025
๐Ÿคฏ5๐Ÿ‘1๐Ÿ˜ฑ1
๐Ÿšจ Massive SSRF Attack Surge Detected ๐Ÿ‘€

GreyNoise warns of a coordinated wave of SSRF exploits hitting at least 400 IPsโ€”targeting U.S., Germany, Singapore, Israel, and more.

๐Ÿ”ด Exploiting multiple CVEs at once, including:
โ€ข CVE-2020-7796 (Zimbra, CVSS 9.8)
โ€ข CVE-2021-22175 (GitLab, CVSS 9.8)
โ€ข CVE-2023-5830 (ColumbiaSoft, CVSS 9.8)

๐Ÿš€ Automated? Pre-compromise recon? Either wayโ€”patch now, restrict outbound traffic, and monitor logs.

Details: https://thehackernews.com/2025/03/over-400-ips-exploiting-multiple-ssrf.html
๐Ÿคฏ9๐Ÿ”ฅ5๐Ÿ‘3โšก2๐Ÿค”2
With a Georgetown master's you'll gain the tactical skills to plan for, respond to, and mitigate cyber security threats.


View event: https://thn.news/cyber-risk-webinar-2025-li
๐Ÿ‘6๐Ÿ˜3๐Ÿค”2
๐Ÿšจ China-backed hackers are hitting routersโ€”undetected.

UNC3886 is targeting Juniper Networks routers, deploying stealthy TinyShell-based backdoors to control critical infrastructure. These implants evade security, disable logs, and hijack SSH credsโ€”all in silence. ๐Ÿ‘€

Mandiant warns: "Long-term persistence, minimal detection."

Why does this matter? Routers are now the frontline. If theyโ€™re compromised, so is everything behind them.

๐Ÿ”— Details on the latest cyber espionage:
https://thehackernews.com/2025/03/chinese-hackers-breach-juniper-networks.html
๐Ÿ‘19๐Ÿ˜5โšก4๐Ÿ”ฅ4๐Ÿ˜ฑ4
๐Ÿšจ UPDATE: Garantex Co-Founder ARRESTED in India!

Besciokov was caught in Thiruvananthapuram while trying to flee after a U.S. extradition request (March 10). He was vacationing in Varkala when Indiaโ€™s CBI moved in.

More: https://thehackernews.com/2025/03/us-secret-service-seizes-russian.html
๐Ÿ˜ฑ11๐Ÿ˜4๐Ÿ‘3
๐Ÿšจ Firefox Warning: Update Before March 14.

A critical root certificate will expire on March 14, 2025. If youโ€™re using an old Firefox version (before 128 or ESR 115.13+), your add-ons may stop working, DRM media could break, and security features may fail.

๐Ÿ“ข Fix it now: Update to Firefox 128+ (or ESR 115.13+) to avoid issues.

๐Ÿ”— Read: https://thehackernews.com/2025/03/warning-expiring-root-certificate-may.html
๐Ÿ‘23๐Ÿ”ฅ8๐Ÿ˜3๐Ÿค”2
๐Ÿšจ Critical Alert: A severe vulnerability (CVE-2025-27363) in the FreeType font library, used by millions, is being actively exploited.

This flaw allows RCE, risking numerous systems. Affected platforms include Linux distributions, Android, and iOS.

Read: https://thehackernews.com/2025/03/meta-warns-of-freetype-vulnerability.html

Update to FreeType version 2.13.3 immediately to protect your devices. Act now!
๐Ÿ”ฅ20๐Ÿคฏ9๐Ÿ‘2๐Ÿ˜ฑ2โšก1
๐Ÿ”ด ruby-saml Flaws Open SAML Auth to Hijacking

GitHub Security Lab found CVE-2025-25291 & CVE-2025-25292 (CVSS 8.8) in ruby-saml, allowing attackers to bypass authentication using a valid signature.

๐Ÿ”— Read: https://thehackernews.com/2025/03/github-uncovers-new-ruby-saml.html

๐Ÿ”‘ Update now or risk account takeover.
๐Ÿคฏ9๐Ÿ‘4โšก1๐Ÿ”ฅ1
What are the top priorities for security teams in 2025? And what's threatening to derail them?

IDC asked 900+ security leaders across the US, Europe, and Australia. In a webinar on March 26, Voice of Security 2025 sponsors Tines and AWS will unpack the results.

Join them to uncover:
๐Ÿ”ธ How AI and automation are transforming security strategies
๐Ÿ”ธ The biggest challenges leaders face - and whatโ€™s holding them back
๐Ÿ”ธ What drives job satisfaction (and frustration) in security leadership
๐Ÿ”ธ Where tooling helps vs. where itโ€™s adding to the pain
๐Ÿ”ธ What leaders look for when hiring security analysts

Sign up for a deep dive into the data: https://thn.news/voice-of-security-2025-x
๐Ÿ‘7๐Ÿ‘1
๐Ÿšจ A never-before-seen Android spyware KoSpy is targeting Korean & English usersโ€”stealing texts, calls, files & more.

Masquerading as legit apps on Google Play, KoSpy operated undetected for 2 years (2022-2024). Now linked to APT27 & Kimsuky.

Meanwhile, North Korean hackers are also infiltrating npm packages & crypto walletsโ€”deploying RustDoor, BeaverTail & Koi Stealer.

Find out here: https://thehackernews.com/2025/03/north-koreas-scarcruft-deploys-kospy.html
๐Ÿค”15๐Ÿ˜5๐Ÿ‘3๐Ÿ‘2๐Ÿ˜ฑ2โšก1
๐Ÿšจ Microsoft Warns: Fake Booking[.]com Emails Deploying Malware!

Hackers are using a new social engineering trickโ€”ClickFixโ€”to target the hospitality sector. Victims unknowingly copy-paste a command that launches data-stealing malware.

โš ๏ธ How the scam works:
๐Ÿ”น Fake Booking[.]com email โ†’ "Bad review alert!"
๐Ÿ”น Clicks lead to a fake CAPTCHA
๐Ÿ”น Trick: Victim pastes a malicious command = Instant infection

๐Ÿ”Ž Whoโ€™s behind it? A cybercrime group Storm-1865โ€”now using the same tactics as Russian & Iranian hackers.

๐Ÿ”— More details: https://thehackernews.com/2025/03/microsoft-warns-of-clickfix-phishing.html
๐Ÿ”ฅ16๐Ÿ‘8๐Ÿ˜2๐Ÿค”1
๐Ÿšจ Backups are failing when it matters most.

๐Ÿ”น Only 40% of IT teams trust their backups
๐Ÿ”น Downtime costs $14K/min
๐Ÿ”น 60% think they can recover in a dayโ€”only 35% do
๐Ÿ”น 94% of ransomware victims have backups targeted

IT leaders must act now. See the State of Backup & Recovery 2025 for key risks & solutions.

Read now: https://thehackernews.com/2025/03/bcdr-2025-trends-and-challenges-for-msps-and-it-teams.html
๐Ÿ‘13๐Ÿ‘4๐Ÿคฏ1
๐Ÿšจ New Malware Alert | OBSCURE#BAT ๐Ÿฆ‡
Hackers are using fake CAPTCHA pages & Trojanized software (Tor, VoIP apps) to spread the r77 rootkitโ€”hiding files, evading antivirus, and persisting after reboot.

๐ŸŽญ Targets: ๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡จ๐Ÿ‡ฆ๐Ÿ‡ฌ๐Ÿ‡ง๐Ÿ‡ฉ๐Ÿ‡ช ๐Ÿ› ๏ธ Techniques: Obfuscated batch scripts, AMSI bypass, API hooking ๐Ÿ” Stealthy & dangerousโ€”already in the wild!

Read more: https://thehackernews.com/2025/03/obscurebat-malware-uses-fake-captcha.html
๐Ÿ‘17๐Ÿ”ฅ4๐Ÿค”4๐Ÿ˜3๐Ÿ‘1
๐Ÿดโ€โ˜ ๏ธ Pirates Beware!

Downloading cracked software? You might be installing MassJackerโ€”a new clipper malware hijacking crypto transactions.

๐Ÿ”น 778,531 attacker-controlled wallets
๐Ÿ”น $336,700 in stolen funds
๐Ÿ”น Hides inside pirated downloads from pesktop[.]com

Your clipboard isn't safe. Copy a wallet address? It swaps it with the hackerโ€™s.

๐Ÿ”— Full story: https://thehackernews.com/2025/03/new-massjacker-malware-targets-piracy.html
๐Ÿ‘15๐Ÿ˜ฑ8๐Ÿ”ฅ5๐Ÿ˜4๐Ÿค”2๐Ÿ‘1
๐Ÿ”’ GSMA is bringing end-to-end encryption (E2EE) to RCS messages between Android & iOS. That means private, secure chatsโ€”no matter the device.

This comes right after Apple agreed to support RCS in iOS 18. Until now, Google encrypted RCS in its Messages app, but cross-platform chats were left exposed.

๐Ÿ”— Read more: https://thehackernews.com/2025/03/gsma-confirms-end-to-end-encryption-for.html
๐Ÿค”15๐Ÿ‘8๐Ÿ”ฅ4๐Ÿ˜2๐Ÿ‘1๐Ÿคฏ1๐Ÿ˜ฑ1