The Hacker News
โœ”
152K subscribers
1.87K photos
10 videos
3 files
7.79K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: [email protected]

๐ŸŒ Website: https://thehackernews.com
Download Telegram
๐Ÿšจ Hackers are abusing WordPress mu-pluginsโ€”a hidden auto-run directoryโ€”to inject malware, hijack links, and redirect users to scam sites.

Also, add these to the list of 2024's major WordPress threats:
CVE-2024-27956 | SQL injection
CVE-2024-25600 | RCE in Bricks theme
CVE-2024-8353 | PHP injection
CVE-2024-4345 | Arbitrary file upload

If you run a WordPress site, check your mu-plugins folder NOW.

๐Ÿ›ก๏ธ Full story: https://thehackernews.com/2025/03/hackers-exploit-wordpress-mu-plugins-to.html
๐Ÿ‘14โšก3๐Ÿ”ฅ3
๐Ÿšจ A Russian group, Water Gamayun, is abusing a Windows zero-day (CVE-2025-26633) to drop two chilling backdoors: SilentPrism & DarkWisp.

Theyโ€™re hiding in plain sightโ€”using signed .msi files posing as legit apps like DingTalk & VooV to hijack systems.

๐Ÿ‘€ Targets? Your data, credentials, and even crypto wallets.

๐Ÿ’€ Techniques? Living-off-the-land, PowerShell implants, fake WinRAR sitesโ€”pure cyber espionage playbook.

๐Ÿ”— Learn more: https://thehackernews.com/2025/03/russian-hackers-exploit-cve-2025-26633.html
๐Ÿ‘22๐Ÿคฏ9โšก4๐Ÿค”4๐Ÿ˜ฑ3๐Ÿ˜2
๐Ÿ”ฅ Apple hit with โ‚ฌ150M fine for โ€œbiasedโ€ privacy rules.

France says Appleโ€™s App Tracking Transparency (ATT) gave itself a privacy passโ€”while forcing rivals through a double-consent maze.

Regulators call it unfair, confusing, and not truly neutral.

https://thehackernews.com/2025/04/apple-fined-150-million-by-french.html
๐Ÿ‘27๐Ÿ˜7๐Ÿ‘5๐Ÿ”ฅ3๐Ÿค”1
A China-linked hacking group, Earth Alux, is hitting key sectors in Asia-Pacific and Latin America with stealthy, advanced cyberattacks.

๐Ÿ›  Tools & Tactics:
โ€ข VARGEIT: A backdoor hidden in mspaint.exe, used for spying and data theft
โ€ข COBEACON (Cobalt Strike): Initial access
โ€ข MASQLOADER: Evades security detection
โ€ข Uses 10+ covert communication channels, including Microsoft Outlook drafts

๐Ÿ‘‰ Learn more: https://thehackernews.com/2025/04/china-linked-earth-alux-uses-vargeit.html

Stay alert. These attacks are live.
๐Ÿ‘21๐Ÿ”ฅ9๐Ÿค”1
๐Ÿ”ฅ 23,958 IPs. 10 days. One target: Palo Alto GlobalProtect.

A massive spike in login scans hints at coordinated reconโ€”and possible exploitation ahead.

If you run GlobalProtect, this is your early warning. Audit & harden exposed portals now.

๐Ÿ”— Full story: https://thehackernews.com/2025/04/nearly-24000-ips-target-pan-os.html
๐Ÿ‘15๐Ÿ”ฅ3
๐Ÿšจ Old iPhones, new threats. Apple just patched 3 exploited zero-daysโ€”and yes, even your dusty iPhone 6s is getting a fix.

๐Ÿ›ก๏ธ What's at stake?
โ€ข CVE-2025-24201 (CVSS 8.8): Malicious web content breaking free from Safariโ€™s sandbox
โ€ข CVE-2025-24085 (7.3): Apps hijacking system privileges
โ€ข CVE-2025-24200 (4.6): Bypassing USB Restricted Modeโ€”hello physical attacks

๐Ÿ”ฅ Why now? These bugs are being actively exploited in the wild.

๐Ÿ”— Full list + device breakdown: https://thehackernews.com/2025/04/apple-backports-critical-fixes-for-3.html
๐Ÿ‘21๐Ÿ”ฅ5๐Ÿ˜4๐Ÿ‘3๐Ÿค”2
๐Ÿ”ฅ Your CSRF tokens might already be leaking.

A global retailer dodged a $3.9M breach and GDPR fines up to โ‚ฌ20Mโ€”all due to one misconfigured Facebook Pixel exposing CSRF tokens.

The kicker? This wasnโ€™t malware. It was human errorโ€”undetectable by blockers.

Protect your site before regulators come knocking.

๐Ÿ”— Learn what to fix โ†’ https://thehackernews.com/2025/04/new-case-study-global-retailer.html
๐Ÿ˜6๐Ÿ‘3
๐Ÿšจ Think SMS phishing is old news? Think again.

A new PhaaS platform called Lucid is hijacking iMessage & Android RCS to dodge filters and hit 169 targets in 88 countries.

๐Ÿ’ณ Goal? Steal credit cards + PII, at scale.

๐Ÿ”— Learn more: https://thehackernews.com/2025/04/lucid-phaas-hits-169-targets-in-88.html
๐Ÿ˜13๐Ÿ”ฅ6๐Ÿค”2๐Ÿ‘1
This media is not supported in your browser
VIEW IN TELEGRAM
๐Ÿ”ฅ On its 21st birthday, Google rolls out built-in end-to-end encryption for enterprise Gmail usersโ€”no extensions, no certificate swaps.

๐Ÿ”’ Just click, send, secure. Powered by client-side encryption.

๐Ÿ› ๏ธ Admins hold the keys | Google canโ€™t see a thing.

๐Ÿ‘‰ See how it works: https://thehackernews.com/2025/04/enterprise-gmail-users-can-now-send-end.html
๐Ÿ˜24๐Ÿ‘5๐Ÿค”4๐Ÿ‘2๐Ÿ˜ฑ2
๐Ÿ”ฅ 1,500+ PostgreSQL servers hacked for crypto mining.

A threat group tracked as JINX-0126 is exploiting publicly exposed PostgreSQL instances with weak passwords.

Whatโ€™s happening:
โ€ข Malware: PG_MEM (fileless, evasive)
โ€ข Goal: Deploy XMRig miner
โ€ข Victims: Over 1,500 servers, 3 wallets, ~550 miners each

๐Ÿ”— Full story: https://thehackernews.com/2025/04/over-1500-postgresql-servers.html
๐Ÿ”ฅ26๐Ÿ‘7๐Ÿค”5
๐Ÿ‘€ AI is attacking AI โ€” and it just got real.

A new worm, Morris II, is targeting AI apps + email assistants.

But hereโ€™s the key: AI can defend us too.
๐Ÿ›ก๏ธ Zero Trust stops spread
๐Ÿ” Smart vuln management cuts real risk
โšก AI vs AI is the new norm

Donโ€™t wait. AI attacks move fast.

Fight AI with AI โ€” or fall behind ๐Ÿ‘‰ https://thehackernews.com/expert-insights/2025/03/what-it-means-to-fight-ai-with-ai-using.html
๐Ÿ˜17โšก5๐Ÿ‘4๐Ÿคฏ4๐Ÿค”3
๐Ÿšจ A new wave of stealth malware loaders is hereโ€”modular, evasive, and cloud-integrated.

๐Ÿงฌ Hijack Loader: API spoofing, anti-VM, Avast evasion
๐Ÿ’ป SHELBY: GitHub as C2โ€”payloads & commands via commits
๐Ÿงช SmokeLoader: .NET Reactor obfuscation + 7-Zip phishing

๐Ÿ”— Read the full report: https://thehackernews.com/2025/04/new-malware-loaders-use-call-stack.html
๐Ÿ˜ฑ8๐Ÿ‘4โšก2๐Ÿ‘2
๐Ÿšจ Theyโ€™re back. Russian threat group FIN7 is using Anubisโ€”a lightweight Python backdoor that grants full remote access to Windows machines without leaving detectable files.

It runs entirely in memory, evades most defenses, and can steal passwords, take screenshots, and exfiltrate dataโ€”all masked with Base64 and hosted on compromised SharePoint sites.

๐Ÿ”— Full analysis: https://thehackernews.com/2025/04/fin7-deploys-anubis-backdoor-to-hijack.html
๐Ÿคฏ14๐Ÿ”ฅ10๐Ÿ‘8โšก5๐Ÿ˜4
๐Ÿ”ฅ New Linux botnet ALERT!

Outlawโ€”a Romanian-linked groupโ€”is actively hijacking SSH servers to mine crypto via auto-spreading malware.

โ€“ Targets servers with weak SSH creds
โ€“ Uses BLITZ to self-propagate
โ€“ Installs SHELLBOT for remote control, DDoS, and data theft
โ€“ Exploits old bugs like Dirty COW (CVE-2016-5195)

๐Ÿ”— Full report: https://thehackernews.com/2025/04/outlaw-group-uses-ssh-brute-force-to.html
๐Ÿ”ฅ12๐Ÿ‘4๐Ÿค”3
53.5% of websites have weak SSL.

Not firewalls. Not zero-days. Just bad encryption setups.

๐Ÿ‘€ Thatโ€™s how attackers walk in the front door.
SSL misconfigs = MITM attacks, eavesdropping & breaches.

๐Ÿ”ฅ Your attack surface is growing. Fix it before it spreads.

๐Ÿ”— Learn more: https://thehackernews.com/2025/04/how-ssl-misconfigurations-impact-your.html
๐Ÿ˜8๐Ÿ‘5โšก4๐Ÿ˜ฑ4
๐Ÿ”ฅ 93% of service providers struggle with cybersecurity compliance.

Only 2% feel confident. Thatโ€™s a problemโ€”and an opportunity.

This guide breaks down NIST compliance into clear, doable steps for MSPs & MSSPs.

โœ… Find gaps
โœ… Automate tasks
โœ… Build client trust
โœ… Cut manual work by 70%

Start here โ†’ https://thehackernews.com/2025/04/helping-your-clients-achieve-nist.html
๐Ÿ‘7๐Ÿ‘2
This media is not supported in your browser
VIEW IN TELEGRAM
๐Ÿ‘€ New Google Cloud vulnerability exposed private containersโ€”now patched.

A flaw in Google Cloud Run (ImageRunner) let attackers with limited access pull private images and inject malicious code.

Attackers could exploit this to steal secrets or run malicious containers.

๐Ÿ”— Learn more: https://thehackernews.com/2025/04/google-fixed-cloud-run-vulnerability.html
๐Ÿ‘9๐Ÿ‘6๐Ÿ˜2
๐Ÿšจ Kidflix Taken Down!

The largest CSAM platformโ€”1.8M users, 91K videosโ€”has been dismantled in a global sting across 38 countries.

โšก Operation Stream seized 72,000 files on March 11. Crypto. Tokens. Gamified abuse.
Real kids. Real crimes.

๐Ÿ”— Read: https://thehackernews.com/2025/04/europol-dismantles-kidflix-with-72000.html
๐Ÿ‘32๐Ÿ”ฅ13๐Ÿ‘12๐Ÿ˜1
๐Ÿšจ New web skimming campaign abuses old Stripe API to steal real credit cards

๐Ÿ’ณ 49+ sites hit. Real Stripe screen, fake iframe. Cloned buttons.

Targets: WooCommerce, WordPress, PrestaShop.

๐Ÿ”Ž Details โ†’ https://thehackernews.com/2025/04/legacy-stripe-api-exploited-to-validate.html
๐Ÿ˜16๐Ÿ‘8
๐Ÿ›‘ Think that cheap Android phone is a bargain? It might come loaded with Triadaโ€”a powerful malware pre-installed on counterfeit devices.

๐Ÿ‘€ 2,600+ victims hit in just two weeks; and hackers stole ๐Ÿ’ฐ $270K+ in crypto.

๐Ÿ”— Learn more: https://thehackernews.com/2025/04/triada-malware-preloaded-on-counterfeit.html
๐Ÿ‘9๐Ÿ˜5๐Ÿค”5๐Ÿ”ฅ4๐Ÿ‘1
๐Ÿšจ New Google Quick Share flaw exposed.
๐Ÿ“Œ CVE-2024-10668

Attackers could crash your PC or send files to it without approval via Quick Share for Windows.

๐Ÿ”— Learn more: https://thehackernews.com/2025/04/google-patches-quick-share.html
๐Ÿ˜16๐Ÿ‘4๐Ÿ”ฅ3๐Ÿ‘1๐Ÿคฏ1