๐ AI is attacking AI โ and it just got real.
A new worm, Morris II, is targeting AI apps + email assistants.
But hereโs the key: AI can defend us too.
๐ก๏ธ Zero Trust stops spread
๐ Smart vuln management cuts real risk
โก AI vs AI is the new norm
Donโt wait. AI attacks move fast.
Fight AI with AI โ or fall behind ๐ https://thehackernews.com/expert-insights/2025/03/what-it-means-to-fight-ai-with-ai-using.html
A new worm, Morris II, is targeting AI apps + email assistants.
But hereโs the key: AI can defend us too.
๐ก๏ธ Zero Trust stops spread
๐ Smart vuln management cuts real risk
โก AI vs AI is the new norm
Donโt wait. AI attacks move fast.
Fight AI with AI โ or fall behind ๐ https://thehackernews.com/expert-insights/2025/03/what-it-means-to-fight-ai-with-ai-using.html
๐17โก5๐4๐คฏ4๐ค3
๐จ A new wave of stealth malware loaders is hereโmodular, evasive, and cloud-integrated.
๐งฌ Hijack Loader: API spoofing, anti-VM, Avast evasion
๐ป SHELBY: GitHub as C2โpayloads & commands via commits
๐งช SmokeLoader: .NET Reactor obfuscation + 7-Zip phishing
๐ Read the full report: https://thehackernews.com/2025/04/new-malware-loaders-use-call-stack.html
๐งฌ Hijack Loader: API spoofing, anti-VM, Avast evasion
๐ป SHELBY: GitHub as C2โpayloads & commands via commits
๐งช SmokeLoader: .NET Reactor obfuscation + 7-Zip phishing
๐ Read the full report: https://thehackernews.com/2025/04/new-malware-loaders-use-call-stack.html
๐ฑ8๐4โก2๐2
๐จ Theyโre back. Russian threat group FIN7 is using Anubisโa lightweight Python backdoor that grants full remote access to Windows machines without leaving detectable files.
It runs entirely in memory, evades most defenses, and can steal passwords, take screenshots, and exfiltrate dataโall masked with Base64 and hosted on compromised SharePoint sites.
๐ Full analysis: https://thehackernews.com/2025/04/fin7-deploys-anubis-backdoor-to-hijack.html
It runs entirely in memory, evades most defenses, and can steal passwords, take screenshots, and exfiltrate dataโall masked with Base64 and hosted on compromised SharePoint sites.
๐ Full analysis: https://thehackernews.com/2025/04/fin7-deploys-anubis-backdoor-to-hijack.html
๐คฏ14๐ฅ10๐8โก5๐4
๐ฅ New Linux botnet ALERT!
Outlawโa Romanian-linked groupโis actively hijacking SSH servers to mine crypto via auto-spreading malware.
โ Targets servers with weak SSH creds
โ Uses BLITZ to self-propagate
โ Installs SHELLBOT for remote control, DDoS, and data theft
โ Exploits old bugs like Dirty COW (CVE-2016-5195)
๐ Full report: https://thehackernews.com/2025/04/outlaw-group-uses-ssh-brute-force-to.html
Outlawโa Romanian-linked groupโis actively hijacking SSH servers to mine crypto via auto-spreading malware.
โ Targets servers with weak SSH creds
โ Uses BLITZ to self-propagate
โ Installs SHELLBOT for remote control, DDoS, and data theft
โ Exploits old bugs like Dirty COW (CVE-2016-5195)
๐ Full report: https://thehackernews.com/2025/04/outlaw-group-uses-ssh-brute-force-to.html
๐ฅ12๐4๐ค3
53.5% of websites have weak SSL.
Not firewalls. Not zero-days. Just bad encryption setups.
๐ Thatโs how attackers walk in the front door.
SSL misconfigs = MITM attacks, eavesdropping & breaches.
๐ฅ Your attack surface is growing. Fix it before it spreads.
๐ Learn more: https://thehackernews.com/2025/04/how-ssl-misconfigurations-impact-your.html
Not firewalls. Not zero-days. Just bad encryption setups.
๐ Thatโs how attackers walk in the front door.
SSL misconfigs = MITM attacks, eavesdropping & breaches.
๐ฅ Your attack surface is growing. Fix it before it spreads.
๐ Learn more: https://thehackernews.com/2025/04/how-ssl-misconfigurations-impact-your.html
๐8๐5โก4๐ฑ4
๐ฅ 93% of service providers struggle with cybersecurity compliance.
Only 2% feel confident. Thatโs a problemโand an opportunity.
This guide breaks down NIST compliance into clear, doable steps for MSPs & MSSPs.
โ Find gaps
โ Automate tasks
โ Build client trust
โ Cut manual work by 70%
Start here โ https://thehackernews.com/2025/04/helping-your-clients-achieve-nist.html
Only 2% feel confident. Thatโs a problemโand an opportunity.
This guide breaks down NIST compliance into clear, doable steps for MSPs & MSSPs.
โ Find gaps
โ Automate tasks
โ Build client trust
โ Cut manual work by 70%
Start here โ https://thehackernews.com/2025/04/helping-your-clients-achieve-nist.html
๐7๐2
This media is not supported in your browser
VIEW IN TELEGRAM
๐ New Google Cloud vulnerability exposed private containersโnow patched.
A flaw in Google Cloud Run (ImageRunner) let attackers with limited access pull private images and inject malicious code.
Attackers could exploit this to steal secrets or run malicious containers.
๐ Learn more: https://thehackernews.com/2025/04/google-fixed-cloud-run-vulnerability.html
A flaw in Google Cloud Run (ImageRunner) let attackers with limited access pull private images and inject malicious code.
Attackers could exploit this to steal secrets or run malicious containers.
๐ Learn more: https://thehackernews.com/2025/04/google-fixed-cloud-run-vulnerability.html
๐9๐6๐2
๐จ Kidflix Taken Down!
The largest CSAM platformโ1.8M users, 91K videosโhas been dismantled in a global sting across 38 countries.
โก Operation Stream seized 72,000 files on March 11. Crypto. Tokens. Gamified abuse.
Real kids. Real crimes.
๐ Read: https://thehackernews.com/2025/04/europol-dismantles-kidflix-with-72000.html
The largest CSAM platformโ1.8M users, 91K videosโhas been dismantled in a global sting across 38 countries.
โก Operation Stream seized 72,000 files on March 11. Crypto. Tokens. Gamified abuse.
Real kids. Real crimes.
๐ Read: https://thehackernews.com/2025/04/europol-dismantles-kidflix-with-72000.html
๐32๐ฅ13๐12๐1
๐จ New web skimming campaign abuses old Stripe API to steal real credit cards
๐ณ 49+ sites hit. Real Stripe screen, fake iframe. Cloned buttons.
Targets: WooCommerce, WordPress, PrestaShop.
๐ Details โ https://thehackernews.com/2025/04/legacy-stripe-api-exploited-to-validate.html
๐ณ 49+ sites hit. Real Stripe screen, fake iframe. Cloned buttons.
Targets: WooCommerce, WordPress, PrestaShop.
๐ Details โ https://thehackernews.com/2025/04/legacy-stripe-api-exploited-to-validate.html
๐16๐8
๐ Think that cheap Android phone is a bargain? It might come loaded with Triadaโa powerful malware pre-installed on counterfeit devices.
๐ 2,600+ victims hit in just two weeks; and hackers stole ๐ฐ $270K+ in crypto.
๐ Learn more: https://thehackernews.com/2025/04/triada-malware-preloaded-on-counterfeit.html
๐ 2,600+ victims hit in just two weeks; and hackers stole ๐ฐ $270K+ in crypto.
๐ Learn more: https://thehackernews.com/2025/04/triada-malware-preloaded-on-counterfeit.html
๐9๐5๐ค5๐ฅ4๐1
๐จ New Google Quick Share flaw exposed.
๐ CVE-2024-10668
Attackers could crash your PC or send files to it without approval via Quick Share for Windows.
๐ Learn more: https://thehackernews.com/2025/04/google-patches-quick-share.html
๐ CVE-2024-10668
Attackers could crash your PC or send files to it without approval via Quick Share for Windows.
๐ Learn more: https://thehackernews.com/2025/04/google-patches-quick-share.html
๐16๐4๐ฅ3๐1๐คฏ1
๐จ AI isnโt waiting for your compliance checklist.
CISOs want faster, smarter SOCsโbut GRC teams hit pause. Result? Missed threats. Wasted time. Rising risk.
โ The fix: Practical AI governance.
๐ Break the deadlock now. Read the guide: https://thehackernews.com/2025/04/ai-adoption-in-enterprise-breaking.html
CISOs want faster, smarter SOCsโbut GRC teams hit pause. Result? Missed threats. Wasted time. Rising risk.
โ The fix: Practical AI governance.
๐ Break the deadlock now. Read the guide: https://thehackernews.com/2025/04/ai-adoption-in-enterprise-breaking.html
๐ฑ5๐4
๐ฅ North Koreaโs Lazarus Group is backโwith a new twist on fake job scams.
Theyโre using ClickFix tricks to infect crypto job seekers with GolangGhost, a stealthy Go-based backdoor hitting Windows & macOS.
Now expanding fast in Europeโwith IT workers faking identities to infiltrate companies in ๐ฉ๐ชGermany, ๐ต๐นPortugal & ๐ฌ๐งUK.
๐ Full story: https://thehackernews.com/2025/04/lazarus-group-targets-job-seekers-with.html
Theyโre using ClickFix tricks to infect crypto job seekers with GolangGhost, a stealthy Go-based backdoor hitting Windows & macOS.
Now expanding fast in Europeโwith IT workers faking identities to infiltrate companies in ๐ฉ๐ชGermany, ๐ต๐นPortugal & ๐ฌ๐งUK.
๐ Full story: https://thehackernews.com/2025/04/lazarus-group-targets-job-seekers-with.html
๐16๐ฅ6๐6๐ค2
๐จ Cybercriminals just got smarter. Did your defenses?
AI isn't just a tool for goodโitโs a weapon in the wrong hands. Deepfake phishing, AI-powered exploits, invisible breachesโtheyโre already here.
If your security hasnโt adapted, youโre already behind. But thereโs a way forward.
๐ Join us for our next WEBINAR
๐๏ธ Featuring expert from @Zscaler
๐ก Learn how to outsmart AI-powered threats
Watch now โ https://thehackernews.com/2025/04/ai-threats-are-evolving-fast-learn.html
AI isn't just a tool for goodโitโs a weapon in the wrong hands. Deepfake phishing, AI-powered exploits, invisible breachesโtheyโre already here.
If your security hasnโt adapted, youโre already behind. But thereโs a way forward.
๐ Join us for our next WEBINAR
๐๏ธ Featuring expert from @Zscaler
๐ก Learn how to outsmart AI-powered threats
Watch now โ https://thehackernews.com/2025/04/ai-threats-are-evolving-fast-learn.html
๐14๐6
Stop patching blindly. Start defending smart.
Threat-Led Vulnerability Management (TLVM) helps you focus on what attackers are actually exploitingโnot just whatโs labeled โcritical.โ
In todayโs AI-fueled threat landscape, context > CVSS.
๐ฏ Prioritize real risks.
๐ก๏ธ Strengthen your defenses.
โฑ๏ธ Act before attackers do.
Learn how: https://thehackernews.com/expert-insights/2025/03/why-now-is-time-to-adopt-threat-led.html
Threat-Led Vulnerability Management (TLVM) helps you focus on what attackers are actually exploitingโnot just whatโs labeled โcritical.โ
In todayโs AI-fueled threat landscape, context > CVSS.
๐ฏ Prioritize real risks.
๐ก๏ธ Strengthen your defenses.
โฑ๏ธ Act before attackers do.
Learn how: https://thehackernews.com/expert-insights/2025/03/why-now-is-time-to-adopt-threat-led.html
๐9
๐จ Microsoft Alert: New tax-season phishing wave hits 2,300+ U.S. Companies!
Hackers are using PDFs, QR codes, and fake DocuSign pages to steal passwords and install malware like Latrodectus and Brute Ratel.
๐ฏ Targeted: IT, consulting, and engineering firms
๐ฆ Malware: Remcos, AHKBot, GuLoader, more
๐ Full story here: https://thehackernews.com/2025/04/microsoft-warns-of-tax-themed-email.html
Hackers are using PDFs, QR codes, and fake DocuSign pages to steal passwords and install malware like Latrodectus and Brute Ratel.
๐ฏ Targeted: IT, consulting, and engineering firms
๐ฆ Malware: Remcos, AHKBot, GuLoader, more
๐ Full story here: https://thehackernews.com/2025/04/microsoft-warns-of-tax-themed-email.html
๐11๐ฅ5๐ฑ1
๐จ Massive new risk for data systems!
CVE-2025-30065 | Apache Parquet Java lib flaw (CVSS 10.0) lets attackers execute arbitrary code via poisoned files.
If your pipelines touch untrusted Parquet files, patch NOW.
Read: https://thehackernews.com/2025/04/critical-flaw-in-apache-parquet-allows.html
CVE-2025-30065 | Apache Parquet Java lib flaw (CVSS 10.0) lets attackers execute arbitrary code via poisoned files.
If your pipelines touch untrusted Parquet files, patch NOW.
Read: https://thehackernews.com/2025/04/critical-flaw-in-apache-parquet-allows.html
๐ฑ7๐คฏ5๐1๐ฅ1๐1
๐ The cloud never slows down โ neither do the threats.
Wiz, now part of Googleโs biggest acquisition ever, can show you in 15 mins how to secure everything from code to runtimeโwithout adding friction.
๐ See how it works: https://thehackernews.com/videos/2025/03/wiz-15-minute-demo-secure-everything.html
Wiz, now part of Googleโs biggest acquisition ever, can show you in 15 mins how to secure everything from code to runtimeโwithout adding friction.
๐ See how it works: https://thehackernews.com/videos/2025/03/wiz-15-minute-demo-secure-everything.html
๐7๐คฏ3๐1
โก CERT-UA confirms 3+ attacks on Ukraineโs government and critical systems since Fall 2024 using phishing links (DropMeFiles, Google Drive) to deploy WRECKSTEEL malware.
Cyber threats are escalating.
Read more โ https://thehackernews.com/2025/04/cert-ua-reports-cyberattacks-targeting.html
Cyber threats are escalating.
Read more โ https://thehackernews.com/2025/04/cert-ua-reports-cyberattacks-targeting.html
๐11๐ค6๐4๐2
๐ฅ New Ivanti ZERO-DAY exploited in the wild โ China-linked UNC5221 hits Connect Secure (CVE-2025-22457, CVSS 9.0).
๐ฃ Exploits spotted mid-March by Mandiant.
๐ต๏ธโโ๏ธMalware: TRAILBLAZE, BRUSHFIRE, SPAWN.
๐ฏ Persistence. Credential theft. Data exfiltration.
โก Patch now | See full story + urgent guidance: https://thehackernews.com/2025/04/critical-ivanti-flaw-actively-exploited.html
๐ฃ Exploits spotted mid-March by Mandiant.
๐ต๏ธโโ๏ธMalware: TRAILBLAZE, BRUSHFIRE, SPAWN.
๐ฏ Persistence. Credential theft. Data exfiltration.
โก Patch now | See full story + urgent guidance: https://thehackernews.com/2025/04/critical-ivanti-flaw-actively-exploited.html
๐8๐4๐ค4๐2
๐จ Hackers arenโt hiding in basements anymore โ theyโre students with business plans.
A 19-year-old, Coquettte, used Russian bulletproof hosting to spread malware disguised as antivirus software.
An OPSEC mistake exposed ties to Horrid, a cybercrime group training new hackers.
๐ Learn more: https://thehackernews.com/2025/04/opsec-failure-exposes-coquetttes.html
A 19-year-old, Coquettte, used Russian bulletproof hosting to spread malware disguised as antivirus software.
An OPSEC mistake exposed ties to Horrid, a cybercrime group training new hackers.
๐ Learn more: https://thehackernews.com/2025/04/opsec-failure-exposes-coquetttes.html
๐ฅ27๐8๐4๐2