๐ฅ Hackers got hacked.
BlackLock, a top ransomware gang in 2025, just got ownedโby threat hunters who found a fatal flaw in their infrastructure.
exposing...
โก๏ธ Real IPs behind their hidden servers
โก๏ธ Command history showing OPSEC fails
โก๏ธ Credentials, configs, and MEGA storage accounts used for exfil
๐ Turns out, DragonForceโanother ransomware crewโalso hacked BlackLockโs site last week, leaking internal chats and configs.
Read: https://thehackernews.com/2025/03/blacklock-ransomware-exposed-after.html
BlackLock, a top ransomware gang in 2025, just got ownedโby threat hunters who found a fatal flaw in their infrastructure.
exposing...
โก๏ธ Real IPs behind their hidden servers
โก๏ธ Command history showing OPSEC fails
โก๏ธ Credentials, configs, and MEGA storage accounts used for exfil
๐ Turns out, DragonForceโanother ransomware crewโalso hacked BlackLockโs site last week, leaking internal chats and configs.
Read: https://thehackernews.com/2025/03/blacklock-ransomware-exposed-after.html
๐45๐19๐5โก4๐ค1
๐จ New Android threat spotted: Crocodilus malware is targeting users in Spain and Turkey, posing as Google Chrome to hijack phones.
โข Bypasses Android 13+ protections
โข Abuses Accessibility to steal credentials
โข Records screen & key actions
โข Remotely controls the device
โข Hides with black screen overlays
๐ฑ Targets banks + crypto wallets
๐ Learn how it works: https://thehackernews.com/2025/03/new-android-trojan-crocodilus-abuses.html
โข Bypasses Android 13+ protections
โข Abuses Accessibility to steal credentials
โข Records screen & key actions
โข Remotely controls the device
โข Hides with black screen overlays
๐ฑ Targets banks + crypto wallets
๐ Learn how it works: https://thehackernews.com/2025/03/new-android-trojan-crocodilus-abuses.html
๐21๐คฏ8๐ฅ5๐3๐ค3โก1
๐จ New Malware: RESURGE
China-linked hackers are exploiting Ivanti VPNs via CVE-2025-0282.
๐ ๏ธ RESURGE = rootkit + bootkit + web shell
๐ฏ Hits critical infrastructure
๐ Linked to UNC5337 & Silk Typhoon
Patch now | Ivanti <22.7R2.5 is vulnerable
Full CISA alert: https://thehackernews.com/2025/03/resurge-malware-exploits-ivanti-flaw.html
China-linked hackers are exploiting Ivanti VPNs via CVE-2025-0282.
๐ ๏ธ RESURGE = rootkit + bootkit + web shell
๐ฏ Hits critical infrastructure
๐ Linked to UNC5337 & Silk Typhoon
Patch now | Ivanti <22.7R2.5 is vulnerable
Full CISA alert: https://thehackernews.com/2025/03/resurge-malware-exploits-ivanti-flaw.html
๐16๐ฅ4โก2๐ค1
๐จ Russia-linked hackers Gamaredon are using fake war docs to drop Remcos RAT on Ukrainian systems.
๐ชค ZIP โ LNK โ PowerShell โ DLL side-loading โ full access
Meanwhile, another phishing op is posing as the CIA to trick pro-Ukraine Russians into handing over personal info via Google Forms.
Two fronts. One strategy.
Learn more: https://thehackernews.com/2025/03/russia-linked-gamaredon-uses-troop.html
๐ชค ZIP โ LNK โ PowerShell โ DLL side-loading โ full access
Meanwhile, another phishing op is posing as the CIA to trick pro-Ukraine Russians into handing over personal info via Google Forms.
Two fronts. One strategy.
Learn more: https://thehackernews.com/2025/03/russia-linked-gamaredon-uses-troop.html
๐คฏ20๐13๐ฅ5๐5๐4โก3๐ฑ2
โก THN Weekly Recap โ This Week in Cyber:
โ Chrome 0-Day exploited in the wild
โ Kubernetes RCE nightmare exposed
โ Solar inverters at risk of blackouts
โ Rclone-powered leak site breached
โ DNS-based phishing just got stealthier
๐ฉ Catch up now: https://thehackernews.com/2025/03/weekly-recap-chrome-0-day.html
โ Chrome 0-Day exploited in the wild
โ Kubernetes RCE nightmare exposed
โ Solar inverters at risk of blackouts
โ Rclone-powered leak site breached
โ DNS-based phishing just got stealthier
๐ฉ Catch up now: https://thehackernews.com/2025/03/weekly-recap-chrome-0-day.html
๐ฅ10๐3
๐จ AWS doesn't secure your cloudโyou do. Most cloud breaches happen because customers miss what's theirs to protect.
5 silent risks you're likely exposed to:
โข SSRF attacks
โข Leaky S3 buckets
โข Over-permissive IAM
โข Unpatched EC2
โข Public-facing services
AWS secures the foundation. You secure the rest.
๐ Start scanning in minutes โ https://thehackernews.com/2025/03/5-impactful-aws-vulnerabilities-youre.html
5 silent risks you're likely exposed to:
โข SSRF attacks
โข Leaky S3 buckets
โข Over-permissive IAM
โข Unpatched EC2
โข Public-facing services
AWS secures the foundation. You secure the rest.
๐ Start scanning in minutes โ https://thehackernews.com/2025/03/5-impactful-aws-vulnerabilities-youre.html
๐13โก4
๐จ Hackers are abusing WordPress mu-pluginsโa hidden auto-run directoryโto inject malware, hijack links, and redirect users to scam sites.
Also, add these to the list of 2024's major WordPress threats:
CVE-2024-27956 | SQL injection
CVE-2024-25600 | RCE in Bricks theme
CVE-2024-8353 | PHP injection
CVE-2024-4345 | Arbitrary file upload
If you run a WordPress site, check your mu-plugins folder NOW.
๐ก๏ธ Full story: https://thehackernews.com/2025/03/hackers-exploit-wordpress-mu-plugins-to.html
Also, add these to the list of 2024's major WordPress threats:
CVE-2024-27956 | SQL injection
CVE-2024-25600 | RCE in Bricks theme
CVE-2024-8353 | PHP injection
CVE-2024-4345 | Arbitrary file upload
If you run a WordPress site, check your mu-plugins folder NOW.
๐ก๏ธ Full story: https://thehackernews.com/2025/03/hackers-exploit-wordpress-mu-plugins-to.html
๐14โก3๐ฅ3
๐จ A Russian group, Water Gamayun, is abusing a Windows zero-day (CVE-2025-26633) to drop two chilling backdoors: SilentPrism & DarkWisp.
Theyโre hiding in plain sightโusing signed .msi files posing as legit apps like DingTalk & VooV to hijack systems.
๐ Targets? Your data, credentials, and even crypto wallets.
๐ Techniques? Living-off-the-land, PowerShell implants, fake WinRAR sitesโpure cyber espionage playbook.
๐ Learn more: https://thehackernews.com/2025/03/russian-hackers-exploit-cve-2025-26633.html
Theyโre hiding in plain sightโusing signed .msi files posing as legit apps like DingTalk & VooV to hijack systems.
๐ Targets? Your data, credentials, and even crypto wallets.
๐ Techniques? Living-off-the-land, PowerShell implants, fake WinRAR sitesโpure cyber espionage playbook.
๐ Learn more: https://thehackernews.com/2025/03/russian-hackers-exploit-cve-2025-26633.html
๐22๐คฏ9โก4๐ค4๐ฑ3๐2
๐ฅ Apple hit with โฌ150M fine for โbiasedโ privacy rules.
France says Appleโs App Tracking Transparency (ATT) gave itself a privacy passโwhile forcing rivals through a double-consent maze.
Regulators call it unfair, confusing, and not truly neutral.
https://thehackernews.com/2025/04/apple-fined-150-million-by-french.html
France says Appleโs App Tracking Transparency (ATT) gave itself a privacy passโwhile forcing rivals through a double-consent maze.
Regulators call it unfair, confusing, and not truly neutral.
https://thehackernews.com/2025/04/apple-fined-150-million-by-french.html
๐27๐7๐5๐ฅ3๐ค1
A China-linked hacking group, Earth Alux, is hitting key sectors in Asia-Pacific and Latin America with stealthy, advanced cyberattacks.
๐ Tools & Tactics:
โข VARGEIT: A backdoor hidden in mspaint.exe, used for spying and data theft
โข COBEACON (Cobalt Strike): Initial access
โข MASQLOADER: Evades security detection
โข Uses 10+ covert communication channels, including Microsoft Outlook drafts
๐ Learn more: https://thehackernews.com/2025/04/china-linked-earth-alux-uses-vargeit.html
Stay alert. These attacks are live.
๐ Tools & Tactics:
โข VARGEIT: A backdoor hidden in mspaint.exe, used for spying and data theft
โข COBEACON (Cobalt Strike): Initial access
โข MASQLOADER: Evades security detection
โข Uses 10+ covert communication channels, including Microsoft Outlook drafts
๐ Learn more: https://thehackernews.com/2025/04/china-linked-earth-alux-uses-vargeit.html
Stay alert. These attacks are live.
๐21๐ฅ9๐ค1
๐ฅ 23,958 IPs. 10 days. One target: Palo Alto GlobalProtect.
A massive spike in login scans hints at coordinated reconโand possible exploitation ahead.
If you run GlobalProtect, this is your early warning. Audit & harden exposed portals now.
๐ Full story: https://thehackernews.com/2025/04/nearly-24000-ips-target-pan-os.html
A massive spike in login scans hints at coordinated reconโand possible exploitation ahead.
If you run GlobalProtect, this is your early warning. Audit & harden exposed portals now.
๐ Full story: https://thehackernews.com/2025/04/nearly-24000-ips-target-pan-os.html
๐15๐ฅ3
๐จ Old iPhones, new threats. Apple just patched 3 exploited zero-daysโand yes, even your dusty iPhone 6s is getting a fix.
๐ก๏ธ What's at stake?
โข CVE-2025-24201 (CVSS 8.8): Malicious web content breaking free from Safariโs sandbox
โข CVE-2025-24085 (7.3): Apps hijacking system privileges
โข CVE-2025-24200 (4.6): Bypassing USB Restricted Modeโhello physical attacks
๐ฅ Why now? These bugs are being actively exploited in the wild.
๐ Full list + device breakdown: https://thehackernews.com/2025/04/apple-backports-critical-fixes-for-3.html
๐ก๏ธ What's at stake?
โข CVE-2025-24201 (CVSS 8.8): Malicious web content breaking free from Safariโs sandbox
โข CVE-2025-24085 (7.3): Apps hijacking system privileges
โข CVE-2025-24200 (4.6): Bypassing USB Restricted Modeโhello physical attacks
๐ฅ Why now? These bugs are being actively exploited in the wild.
๐ Full list + device breakdown: https://thehackernews.com/2025/04/apple-backports-critical-fixes-for-3.html
๐21๐ฅ5๐4๐3๐ค2
๐ฅ Your CSRF tokens might already be leaking.
A global retailer dodged a $3.9M breach and GDPR fines up to โฌ20Mโall due to one misconfigured Facebook Pixel exposing CSRF tokens.
The kicker? This wasnโt malware. It was human errorโundetectable by blockers.
Protect your site before regulators come knocking.
๐ Learn what to fix โ https://thehackernews.com/2025/04/new-case-study-global-retailer.html
A global retailer dodged a $3.9M breach and GDPR fines up to โฌ20Mโall due to one misconfigured Facebook Pixel exposing CSRF tokens.
The kicker? This wasnโt malware. It was human errorโundetectable by blockers.
Protect your site before regulators come knocking.
๐ Learn what to fix โ https://thehackernews.com/2025/04/new-case-study-global-retailer.html
๐6๐3
๐จ Think SMS phishing is old news? Think again.
A new PhaaS platform called Lucid is hijacking iMessage & Android RCS to dodge filters and hit 169 targets in 88 countries.
๐ณ Goal? Steal credit cards + PII, at scale.
๐ Learn more: https://thehackernews.com/2025/04/lucid-phaas-hits-169-targets-in-88.html
A new PhaaS platform called Lucid is hijacking iMessage & Android RCS to dodge filters and hit 169 targets in 88 countries.
๐ณ Goal? Steal credit cards + PII, at scale.
๐ Learn more: https://thehackernews.com/2025/04/lucid-phaas-hits-169-targets-in-88.html
๐13๐ฅ6๐ค2๐1
This media is not supported in your browser
VIEW IN TELEGRAM
๐ฅ On its 21st birthday, Google rolls out built-in end-to-end encryption for enterprise Gmail usersโno extensions, no certificate swaps.
๐ Just click, send, secure. Powered by client-side encryption.
๐ ๏ธ Admins hold the keys | Google canโt see a thing.
๐ See how it works: https://thehackernews.com/2025/04/enterprise-gmail-users-can-now-send-end.html
๐ Just click, send, secure. Powered by client-side encryption.
๐ ๏ธ Admins hold the keys | Google canโt see a thing.
๐ See how it works: https://thehackernews.com/2025/04/enterprise-gmail-users-can-now-send-end.html
๐24๐5๐ค4๐2๐ฑ2
๐ฅ 1,500+ PostgreSQL servers hacked for crypto mining.
A threat group tracked as JINX-0126 is exploiting publicly exposed PostgreSQL instances with weak passwords.
Whatโs happening:
โข Malware: PG_MEM (fileless, evasive)
โข Goal: Deploy XMRig miner
โข Victims: Over 1,500 servers, 3 wallets, ~550 miners each
๐ Full story: https://thehackernews.com/2025/04/over-1500-postgresql-servers.html
A threat group tracked as JINX-0126 is exploiting publicly exposed PostgreSQL instances with weak passwords.
Whatโs happening:
โข Malware: PG_MEM (fileless, evasive)
โข Goal: Deploy XMRig miner
โข Victims: Over 1,500 servers, 3 wallets, ~550 miners each
๐ Full story: https://thehackernews.com/2025/04/over-1500-postgresql-servers.html
๐ฅ26๐7๐ค5
๐ AI is attacking AI โ and it just got real.
A new worm, Morris II, is targeting AI apps + email assistants.
But hereโs the key: AI can defend us too.
๐ก๏ธ Zero Trust stops spread
๐ Smart vuln management cuts real risk
โก AI vs AI is the new norm
Donโt wait. AI attacks move fast.
Fight AI with AI โ or fall behind ๐ https://thehackernews.com/expert-insights/2025/03/what-it-means-to-fight-ai-with-ai-using.html
A new worm, Morris II, is targeting AI apps + email assistants.
But hereโs the key: AI can defend us too.
๐ก๏ธ Zero Trust stops spread
๐ Smart vuln management cuts real risk
โก AI vs AI is the new norm
Donโt wait. AI attacks move fast.
Fight AI with AI โ or fall behind ๐ https://thehackernews.com/expert-insights/2025/03/what-it-means-to-fight-ai-with-ai-using.html
๐17โก5๐4๐คฏ4๐ค3
๐จ A new wave of stealth malware loaders is hereโmodular, evasive, and cloud-integrated.
๐งฌ Hijack Loader: API spoofing, anti-VM, Avast evasion
๐ป SHELBY: GitHub as C2โpayloads & commands via commits
๐งช SmokeLoader: .NET Reactor obfuscation + 7-Zip phishing
๐ Read the full report: https://thehackernews.com/2025/04/new-malware-loaders-use-call-stack.html
๐งฌ Hijack Loader: API spoofing, anti-VM, Avast evasion
๐ป SHELBY: GitHub as C2โpayloads & commands via commits
๐งช SmokeLoader: .NET Reactor obfuscation + 7-Zip phishing
๐ Read the full report: https://thehackernews.com/2025/04/new-malware-loaders-use-call-stack.html
๐ฑ8๐4โก2๐2
๐จ Theyโre back. Russian threat group FIN7 is using Anubisโa lightweight Python backdoor that grants full remote access to Windows machines without leaving detectable files.
It runs entirely in memory, evades most defenses, and can steal passwords, take screenshots, and exfiltrate dataโall masked with Base64 and hosted on compromised SharePoint sites.
๐ Full analysis: https://thehackernews.com/2025/04/fin7-deploys-anubis-backdoor-to-hijack.html
It runs entirely in memory, evades most defenses, and can steal passwords, take screenshots, and exfiltrate dataโall masked with Base64 and hosted on compromised SharePoint sites.
๐ Full analysis: https://thehackernews.com/2025/04/fin7-deploys-anubis-backdoor-to-hijack.html
๐คฏ14๐ฅ10๐8โก5๐4
๐ฅ New Linux botnet ALERT!
Outlawโa Romanian-linked groupโis actively hijacking SSH servers to mine crypto via auto-spreading malware.
โ Targets servers with weak SSH creds
โ Uses BLITZ to self-propagate
โ Installs SHELLBOT for remote control, DDoS, and data theft
โ Exploits old bugs like Dirty COW (CVE-2016-5195)
๐ Full report: https://thehackernews.com/2025/04/outlaw-group-uses-ssh-brute-force-to.html
Outlawโa Romanian-linked groupโis actively hijacking SSH servers to mine crypto via auto-spreading malware.
โ Targets servers with weak SSH creds
โ Uses BLITZ to self-propagate
โ Installs SHELLBOT for remote control, DDoS, and data theft
โ Exploits old bugs like Dirty COW (CVE-2016-5195)
๐ Full report: https://thehackernews.com/2025/04/outlaw-group-uses-ssh-brute-force-to.html
๐ฅ12๐4๐ค3
53.5% of websites have weak SSL.
Not firewalls. Not zero-days. Just bad encryption setups.
๐ Thatโs how attackers walk in the front door.
SSL misconfigs = MITM attacks, eavesdropping & breaches.
๐ฅ Your attack surface is growing. Fix it before it spreads.
๐ Learn more: https://thehackernews.com/2025/04/how-ssl-misconfigurations-impact-your.html
Not firewalls. Not zero-days. Just bad encryption setups.
๐ Thatโs how attackers walk in the front door.
SSL misconfigs = MITM attacks, eavesdropping & breaches.
๐ฅ Your attack surface is growing. Fix it before it spreads.
๐ Learn more: https://thehackernews.com/2025/04/how-ssl-misconfigurations-impact-your.html
๐8๐5โก4๐ฑ4