The Hacker News
βœ”
152K subscribers
1.87K photos
10 videos
3 files
7.79K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
53.5% of websites have weak SSL.

Not firewalls. Not zero-days. Just bad encryption setups.

πŸ‘€ That’s how attackers walk in the front door.
SSL misconfigs = MITM attacks, eavesdropping & breaches.

πŸ”₯ Your attack surface is growing. Fix it before it spreads.

πŸ”— Learn more: https://thehackernews.com/2025/04/how-ssl-misconfigurations-impact-your.html
😁8πŸ‘5⚑4😱4
πŸ”₯ 93% of service providers struggle with cybersecurity compliance.

Only 2% feel confident. That’s a problemβ€”and an opportunity.

This guide breaks down NIST compliance into clear, doable steps for MSPs & MSSPs.

βœ… Find gaps
βœ… Automate tasks
βœ… Build client trust
βœ… Cut manual work by 70%

Start here β†’ https://thehackernews.com/2025/04/helping-your-clients-achieve-nist.html
πŸ‘7πŸ‘2
This media is not supported in your browser
VIEW IN TELEGRAM
πŸ‘€ New Google Cloud vulnerability exposed private containersβ€”now patched.

A flaw in Google Cloud Run (ImageRunner) let attackers with limited access pull private images and inject malicious code.

Attackers could exploit this to steal secrets or run malicious containers.

πŸ”— Learn more: https://thehackernews.com/2025/04/google-fixed-cloud-run-vulnerability.html
πŸ‘9πŸ‘6😁2
🚨 Kidflix Taken Down!

The largest CSAM platformβ€”1.8M users, 91K videosβ€”has been dismantled in a global sting across 38 countries.

⚑ Operation Stream seized 72,000 files on March 11. Crypto. Tokens. Gamified abuse.
Real kids. Real crimes.

πŸ”— Read: https://thehackernews.com/2025/04/europol-dismantles-kidflix-with-72000.html
πŸ‘32πŸ”₯13πŸ‘12😁1
🚨 New web skimming campaign abuses old Stripe API to steal real credit cards

πŸ’³ 49+ sites hit. Real Stripe screen, fake iframe. Cloned buttons.

Targets: WooCommerce, WordPress, PrestaShop.

πŸ”Ž Details β†’ https://thehackernews.com/2025/04/legacy-stripe-api-exploited-to-validate.html
😁16πŸ‘8
πŸ›‘ Think that cheap Android phone is a bargain? It might come loaded with Triadaβ€”a powerful malware pre-installed on counterfeit devices.

πŸ‘€ 2,600+ victims hit in just two weeks; and hackers stole πŸ’° $270K+ in crypto.

πŸ”— Learn more: https://thehackernews.com/2025/04/triada-malware-preloaded-on-counterfeit.html
πŸ‘9😁5πŸ€”5πŸ”₯4πŸ‘1
🚨 New Google Quick Share flaw exposed.
πŸ“Œ CVE-2024-10668

Attackers could crash your PC or send files to it without approval via Quick Share for Windows.

πŸ”— Learn more: https://thehackernews.com/2025/04/google-patches-quick-share.html
😁16πŸ‘4πŸ”₯3πŸ‘1🀯1
🚨 AI isn’t waiting for your compliance checklist.

CISOs want faster, smarter SOCsβ€”but GRC teams hit pause. Result? Missed threats. Wasted time. Rising risk.

βœ… The fix: Practical AI governance.

πŸ‘‰ Break the deadlock now. Read the guide: https://thehackernews.com/2025/04/ai-adoption-in-enterprise-breaking.html
😱5πŸ‘4
πŸ”₯ North Korea’s Lazarus Group is backβ€”with a new twist on fake job scams.

They’re using ClickFix tricks to infect crypto job seekers with GolangGhost, a stealthy Go-based backdoor hitting Windows & macOS.

Now expanding fast in Europeβ€”with IT workers faking identities to infiltrate companies in πŸ‡©πŸ‡ͺGermany, πŸ‡΅πŸ‡ΉPortugal & πŸ‡¬πŸ‡§UK.

πŸ”— Full story: https://thehackernews.com/2025/04/lazarus-group-targets-job-seekers-with.html
πŸ‘16πŸ”₯6😁6πŸ€”2
🚨 Cybercriminals just got smarter. Did your defenses?

AI isn't just a tool for goodβ€”it’s a weapon in the wrong hands. Deepfake phishing, AI-powered exploits, invisible breachesβ€”they’re already here.

If your security hasn’t adapted, you’re already behind. But there’s a way forward.

πŸ‘€ Join us for our next WEBINAR
πŸŽ™οΈ Featuring expert from @Zscaler
πŸ’‘ Learn how to outsmart AI-powered threats

Watch now β†’ https://thehackernews.com/2025/04/ai-threats-are-evolving-fast-learn.html
😁14πŸ‘6
Stop patching blindly. Start defending smart.

Threat-Led Vulnerability Management (TLVM) helps you focus on what attackers are actually exploitingβ€”not just what’s labeled β€œcritical.”

In today’s AI-fueled threat landscape, context > CVSS.
🎯 Prioritize real risks.
πŸ›‘οΈ Strengthen your defenses.
⏱️ Act before attackers do.

Learn how: https://thehackernews.com/expert-insights/2025/03/why-now-is-time-to-adopt-threat-led.html
πŸ‘9
🚨 Microsoft Alert: New tax-season phishing wave hits 2,300+ U.S. Companies!

Hackers are using PDFs, QR codes, and fake DocuSign pages to steal passwords and install malware like Latrodectus and Brute Ratel.

🎯 Targeted: IT, consulting, and engineering firms
πŸ“¦ Malware: Remcos, AHKBot, GuLoader, more

πŸ”— Full story here: https://thehackernews.com/2025/04/microsoft-warns-of-tax-themed-email.html
πŸ‘11πŸ”₯5😱1
🚨 Massive new risk for data systems!

CVE-2025-30065 | Apache Parquet Java lib flaw (CVSS 10.0) lets attackers execute arbitrary code via poisoned files.

If your pipelines touch untrusted Parquet files, patch NOW.

Read: https://thehackernews.com/2025/04/critical-flaw-in-apache-parquet-allows.html
😱7🀯5πŸ‘1πŸ”₯1πŸ‘1
πŸ‘€ The cloud never slows down β€” neither do the threats.

Wiz, now part of Google’s biggest acquisition ever, can show you in 15 mins how to secure everything from code to runtimeβ€”without adding friction.

πŸ‘‰ See how it works: https://thehackernews.com/videos/2025/03/wiz-15-minute-demo-secure-everything.html
😁7🀯3πŸ‘1
⚑ CERT-UA confirms 3+ attacks on Ukraine’s government and critical systems since Fall 2024 using phishing links (DropMeFiles, Google Drive) to deploy WRECKSTEEL malware.

Cyber threats are escalating.

Read more βž” https://thehackernews.com/2025/04/cert-ua-reports-cyberattacks-targeting.html
πŸ‘11πŸ€”6😁4πŸ‘2
πŸ”₯ New Ivanti ZERO-DAY exploited in the wild β€” China-linked UNC5221 hits Connect Secure (CVE-2025-22457, CVSS 9.0).

πŸ’£ Exploits spotted mid-March by Mandiant.
πŸ•΅οΈβ€β™‚οΈMalware: TRAILBLAZE, BRUSHFIRE, SPAWN.
🎯 Persistence. Credential theft. Data exfiltration.

⚑ Patch now | See full story + urgent guidance: https://thehackernews.com/2025/04/critical-ivanti-flaw-actively-exploited.html
😁8πŸ‘4πŸ€”4πŸ‘2
🚨 Hackers aren’t hiding in basements anymore β€” they’re students with business plans.

A 19-year-old, Coquettte, used Russian bulletproof hosting to spread malware disguised as antivirus software.

An OPSEC mistake exposed ties to Horrid, a cybercrime group training new hackers.

πŸ‘€ Learn more: https://thehackernews.com/2025/04/opsec-failure-exposes-coquetttes.html
πŸ”₯27πŸ‘8πŸ‘4😁2
πŸ”₯ 10 years ago, Docker changed how we build software.

Today, Chainguard OS changes how we deliver it.

Chainguard OS:
βœ… Secure upstream sources
βœ… Daily updates
βœ… Smaller, safer, faster

Containers evolved. Now software delivery has too.

πŸ‘‰ What’s next: https://thehackernews.com/2025/04/have-we-reached-distroless-tipping-point.html
😁8πŸ‘6😱4πŸ‘2πŸ€”2
πŸ‘€ $0 GitHub Action βž” $B security nightmare.

In Nov 2024, a SpotBugs maintainer accidentally leaked a GitHub access token.

⚑ Attackers exploited itβ€”moving from SpotBugs βž” reviewdog βž” poisoning tj-actions/changed-filesβ€”before striking Coinbase in March 2025.

➑️ Details here: https://thehackernews.com/2025/04/spotbugs-access-token-theft-identified.html
πŸ‘13😱9πŸ‘5
DDoS attacks are rising β€” and gaps in protection are being exposed. πŸ“ˆ

In 2024, Cloudflare reported 25M+ DDoS attacks, a 53% YoY increase.

Even basic attacks can bypass defenses due to hidden vulnerabilities in security policies β€” not vendor failures.

Continuous validation is now essential to stay resilient.

Learn more πŸ‘‰ https://thehackernews.com/expert-insights/2025/03/the-surprising-gap-in-ddos-protections.html
πŸ‘15😁3πŸ”₯2
🚨 Malicious Python packages on PyPI steal data from 34,000+ users!

Fake libraries (bitcoinlibdbfix, bitcoinlib-dev, disgrasya) hid malware to exfiltrate databases and test stolen credit cards.

πŸ‘€ Attackers even joined GitHub discussions to trick users.

πŸ”— Read: https://thehackernews.com/2025/04/malicious-python-packages-on-pypi.html
🀯24πŸ‘11πŸ‘2