The Hacker News
โœ”
152K subscribers
1.88K photos
10 videos
3 files
7.79K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: [email protected]

๐ŸŒ Website: https://thehackernews.com
Download Telegram
This media is not supported in your browser
VIEW IN TELEGRAM
๐Ÿ’€ New Malware Alert โ€” Microsoft warns of StilachiRAT, a stealthy remote access trojan that:

๐Ÿ”น Steals browser passwords & clipboard data
๐Ÿ”น Targets crypto wallets
๐Ÿ”น Executes remote commands & monitors RDP sessions
๐Ÿ”น Evades detection by clearing event logs

Read: https://thehackernews.com/2025/03/microsoft-warns-of-stilachirat-stealthy.html

๐Ÿ•ต๏ธโ€โ™‚๏ธ No known actor yet, but itโ€™s spreading. Protect your assets NOW.
๐Ÿ‘21๐Ÿค”7๐Ÿ˜ฑ6
โš ๏ธ Your Device Might Be Part of the Largest CTV Botnet Ever!

Cybercriminals are exploiting cheap Android devices to build a massive botnet for:

๐Ÿ”น Ad fraud & fake clicks
๐Ÿ”น Residential proxy abuse
๐Ÿ”น DDoS attacks & account takeovers
๐Ÿ”น Hidden malware pre-installed in devices

Learn more: https://thehackernews.com/2025/03/badbox-20-botnet-infects-1-million.html

๐Ÿ’€ 1M+ devices infected worldwide, mostly in Brazil, US, & Mexico. Google removed 24 malicious apps, but the operation is still evolving.
๐Ÿ˜16๐Ÿ‘5
๐Ÿšจ China-linked MirrorFace just carried out a stealthy attack on a European diplomatic groupโ€”using:

๐Ÿ”น ANEL backdoorโ€”revived after 6 years
๐Ÿ”น AsyncRAT & HiddenFace malware
๐Ÿ”น Stealthy access via VS Code Remote Tunnels

Learn more: https://thehackernews.com/2025/03/china-linked-mirrorface-deploys-anel.html
๐Ÿค”16๐Ÿ˜7๐Ÿ‘5๐Ÿ”ฅ3โšก1๐Ÿ‘1
What are the essential skills security analysts need to succeed?

IDC's latest survey of 900+ security leaders reveals the top five.

Uncover these and more findings in a live webinar with sponsors Tines and AWS.

Sign up to attend: https://thn.news/voice-of-security-2025-tw
๐Ÿ‘11๐Ÿ‘2๐Ÿ˜2๐Ÿค”2
๐Ÿšจ 331 Malicious Android Google Play Apps, 60 Million+ Downloads!

The Vapor scam used:
๐Ÿ”น Full-screen adsโ€”locking devices
๐Ÿ”น Phishing attacksโ€”stealing credentials & credit cards
๐Ÿ”น Hidden icons & impersonationโ€”evading detection
๐Ÿ”น Versioning tricksโ€”turning clean apps malicious later

โš ๏ธ Check your phone NOW. Delete suspicious apps!

๐Ÿ”— Full details โ€” https://thehackernews.com/2025/03/new-ad-fraud-campaign-exploits-331-apps.html
๐Ÿค”12๐Ÿ”ฅ6๐Ÿ‘4๐Ÿ˜3โšก1
๐Ÿšจ Critical AMI BMC Vulnerability (CVE-2024-54085) โ€“ CVSS 10.0!

A severe authentication bypass flaw allows attackers to:

๐Ÿ”น Remotely control servers & deploy malware
๐Ÿ”น Tamper with firmware, brick motherboards & cause reboot loops
๐Ÿ”น Potentially damage hardware

โš ๏ธ Affected: HPE, ASUS, ASRockRack & more

๐Ÿ”— Read more: https://thehackernews.com/2025/03/new-critical-ami-bmc-vulnerability.html

๐Ÿ“ข Admins: Patch ASAP! Patches released (March 11, 2025), OEM updates required.
๐Ÿ‘9๐Ÿ˜5๐Ÿคฏ3
๐Ÿšจ WARNING: Windows Zero-Day!

A still-unpatched flaw (ZDI-CAN-25373) in Windows has been actively exploited since 2017 by state-backed hackers from China, Russia, Iran & North Korea for cyber espionage & data theft.

๐Ÿ”น 1,000+ malicious .LNK files discovered
๐Ÿ”น Targets: Governments, banks, telecoms, defense sectors

Learn more: https://thehackernews.com/2025/03/unpatched-windows-zero-day-flaw.html

Microsoft wonโ€™t release a patch, citing โ€œlow severityโ€
๐Ÿคฏ20๐Ÿ˜8โšก4๐Ÿ‘3๐Ÿ‘3
๐Ÿ”ฅ Breaking: Google is acquiring cloud security firm Wiz for $32 Billionโ€”its largest deal in history.

๐Ÿ’ฐ Largest acquisition in Googleโ€™s history
๐Ÿ›ก๏ธ Boosts AI-powered cloud security
๐ŸŒ Wiz remains independent, still working with AWS, Azure, Oracle

https://thehackernews.com/2025/03/google-acquires-wiz-for-32-billion-in.html
๐Ÿ˜ฑ22๐Ÿ”ฅ9๐Ÿ‘6โšก2
๐Ÿšจ Android Threat Hunters, Your Job Just Got Easier!

ANY.RUN has just released a brand-new OS designed for real-time Android threat analysis inside a secure sandbox environment.

Now, businesses and security teams can:
โœ… Detect Android threats faster
๐Ÿ” Investigate APK behavior in real time
โšก Speed up incident response
๐Ÿ’ฐ Reduce cybersecurity costs

Best part? Itโ€™s available for all plansโ€”even FREE users!

๐Ÿ‘‰ Try now: https://thn.news/malware-sandbox-android-tg
๐Ÿ‘21๐Ÿ”ฅ13๐Ÿ˜ฑ3
๐Ÿšจ Is Your Okta Environment Secure? Even with best practices, misconfigurations and identity sprawl can leave your system exposed.

โš ๏ธ Key risks:
โž Inactive admin accounts & weak MFA
โž Misconfigured security settings
โž Forgotten API tokens granting access
โž Lingering access for ex-employees

๐Ÿ”— Learn how to protect your identity infrastructure: https://thehackernews.com/2025/03/how-to-improve-okta-security-in-four.html
๐Ÿ‘9
๐Ÿ›‘ New Rules File Backdoor attack lets hackers poison AI-powered tools like GitHub Copilot & Cursor, injecting hidden malicious code into projects.

๐Ÿ”น Invisible backdoors via Unicode tricks
๐Ÿ”น Supply chain riskโ€”spreads across repos
๐Ÿ”น No alertsโ€”developers unknowingly ship compromised code

Review AI-generated code carefullyโ€”your โ€œtrusted assistantโ€ might be compromised.

๐Ÿ”— Learn more: https://thehackernews.com/2025/03/new-rules-file-backdoor-attack-lets.html
๐Ÿ‘16๐Ÿ˜1๐Ÿคฏ1
๐Ÿšจ GitHub Actions are under attack!

A supply chain attack hit tj-actions/changed-files, leaking AWS keys, GitHub PATs & more. CISA confirms active exploitation.

๐Ÿ”น CVE-2025-30066 (CVSS 8.6)
๐Ÿ”น Attack spread via another compromised Action
๐Ÿ”น Sensitive secrets exposed via logs

Details: https://thehackernews.com/2025/03/cisa-warns-of-active-exploitation-in.html

โš ๏ธ Rotate secrets, audit workflows, pin actions to commitsโ€”this wonโ€™t be the last attack.
๐Ÿคฏ18๐Ÿ”ฅ7๐Ÿ‘3๐Ÿ˜3
๐Ÿšจ Critical SCADA Flaws โ€” Researchers uncovered 2 critical vulnerabilities (CVSS 9.3) in mySCADA myPRO, allowing attackers to execute system commands & hijack operations.

๐Ÿ”น CVE-2025-20014 & CVE-2025-20061
๐Ÿ”น Full Industrial Network Compromise Possible

Details here: https://thehackernews.com/2025/03/critical-myscada-mypro-flaws-could-let.html
๐Ÿ‘17๐Ÿคฏ4โšก2๐Ÿ”ฅ1๐Ÿค”1
๐Ÿšจ ClearFake Malware Spreading Fast!

Hackers use fake reCAPTCHA & Cloudflare checks to deploy Lumma & Vidar Stealer malware.

๐Ÿ”น 9,300+ infected sites
๐Ÿ”น 200,000+ users exposed (July 2024)
๐Ÿ”น Now using Binance Smart Chain for stealth

Learn more: https://thehackernews.com/2025/03/clearfake-infects-9300-sites-uses-fake.html
โšก12๐Ÿ‘9๐Ÿค”8
๐Ÿ›ก Top 7 AI Risk Mitigation Strategies

AI security secrets? Discover the 7 essential concepts, techniques, and mitigation strategies for securing your AI pipelines.

Learn more: https://thn.news/genai-security-cheat-sheet
๐Ÿ”ฅ7๐Ÿ‘4โšก2
โš ๏ธ SaaS identity attacks are exploding!

Hackers are stealing credentials, hijacking logins, and abusing privilegesโ€”yet most security tools overlook SaaS identity threats.

๐Ÿ›ก๏ธ The Fix? Identity Threat Detection & Response (ITDR)

๐Ÿ”— Secure SaaS now โ†’ https://thehackernews.com/2025/03/5-identity-threat-detection-response.html
๐Ÿ˜8๐Ÿ‘6๐Ÿ˜ฑ4๐Ÿ‘1
๐Ÿ”ฅ Russiaโ€™s Role in Cybercrime Just Got Exposed!

200,000+ leaked messages expose direct ties between the ransomware gang & Russian officials.

๐Ÿ”น AI-powered fraud & malware dev
๐Ÿ”น Leader escaped via a "green corridor"

Read the full story ๐Ÿ‘‡ https://thehackernews.com/2025/03/leaked-black-basta-chats-suggest.html
๐Ÿ‘16๐Ÿ˜11โšก8๐Ÿ”ฅ5๐Ÿค”1
๐Ÿšจ Severe PHP Flaw Under Attack.

Hackers are exploiting CVE-2024-4577 to deploy crypto miners โ›๏ธ & Quasar RAT on Windows servers.

๐Ÿ”น 54% of attacks target Taiwan
๐Ÿ”น 5% deploy XMRig miner
๐Ÿ”น PHP CGI mode at risk

Patch NOW before your servers become a battleground.

๐Ÿ”— Learn more: https://thehackernews.com/2025/03/hackers-exploit-severe-php-flaw-to.html
๐Ÿ”ฅ17๐Ÿ‘3โšก2๐Ÿ‘2๐Ÿ˜1
๐Ÿšจ Hackers are hijacking compromised Signal accounts to spread Dark Crystal RAT malwareโ€”targeting Ukraineโ€™s military & defense industry.

๐Ÿ”น Fake meeting minutes ๐Ÿ“„
๐Ÿ”น Hidden malware inside archives ๐Ÿฆ 
๐Ÿ”น Remote control & data theft

Read more: https://thehackernews.com/2025/03/cert-ua-warns-dark-crystal-rat-targets.html
๐Ÿค”13๐Ÿ‘8๐Ÿ”ฅ5โšก4๐Ÿ˜1
๐Ÿ’€ CISA just flagged this backup flaw as actively exploited!

CVE-2024-48248 | Unauthenticated file read in NAKIVO Backup & Replication exposes sensitive data & credentials.

๐Ÿ”น Exploit already public
๐Ÿ”น Update before itโ€™s too late

Details: https://thehackernews.com/2025/03/cisa-adds-nakivo-vulnerability-to-kev.html
๐Ÿ‘11๐Ÿ”ฅ7
๐Ÿšจ Spyware Alert!

Citizen Lab reports Australia, Canada, Denmark & more may be using Paragon's Graphite spywareโ€”the same tool used to target journalists & activists via WhatsApp.

โš ๏ธ 90+ journalists targeted
โš ๏ธ iPhones & Androids hacked

๐Ÿ”— Full story: https://thehackernews.com/2025/03/six-governments-likely-use-israeli.html
๐Ÿ˜ฑ14๐Ÿ‘9๐Ÿ”ฅ4๐Ÿ˜3๐Ÿ‘1๐Ÿคฏ1