The Hacker News
βœ”
151K subscribers
1.86K photos
10 videos
3 files
7.77K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
πŸ‘€ $0 GitHub Action βž” $B security nightmare.

In Nov 2024, a SpotBugs maintainer accidentally leaked a GitHub access token.

⚑ Attackers exploited itβ€”moving from SpotBugs βž” reviewdog βž” poisoning tj-actions/changed-filesβ€”before striking Coinbase in March 2025.

➑️ Details here: https://thehackernews.com/2025/04/spotbugs-access-token-theft-identified.html
πŸ‘13😱9πŸ‘5
DDoS attacks are rising β€” and gaps in protection are being exposed. πŸ“ˆ

In 2024, Cloudflare reported 25M+ DDoS attacks, a 53% YoY increase.

Even basic attacks can bypass defenses due to hidden vulnerabilities in security policies β€” not vendor failures.

Continuous validation is now essential to stay resilient.

Learn more πŸ‘‰ https://thehackernews.com/expert-insights/2025/03/the-surprising-gap-in-ddos-protections.html
πŸ‘15😁3πŸ”₯2
🚨 Malicious Python packages on PyPI steal data from 34,000+ users!

Fake libraries (bitcoinlibdbfix, bitcoinlib-dev, disgrasya) hid malware to exfiltrate databases and test stolen credit cards.

πŸ‘€ Attackers even joined GitHub discussions to trick users.

πŸ”— Read: https://thehackernews.com/2025/04/malicious-python-packages-on-pypi.html
🀯24πŸ‘11πŸ‘2
πŸ‘‰ North Korean hackers are hunting developersβ€”right now.

New malware-laced npm packages (5,600+ downloads) are spreading BeaverTail and a new RAT loader, hidden as fake utilities.

πŸ‘€ Targets? Your code. Your system. Your data.

Read: https://thehackernews.com/2025/04/north-korean-hackers-deploy-beavertail.html
😁13πŸ”₯11πŸ‘5πŸ€”4😱3
πŸ‘€ Microsoft Credits EncryptHub β€” the Hacker Behind 618+ Breaches β€” for Disclosing Windows Flaws. πŸ‘€

In March 2025, EncryptHub reported 2 critical bugs (CVE-2025-24061 & CVE-2025-24071).

Weeks later, he exploited a zero-day (CVE-2025-26633), hitting hundreds of targets using ChatGPT-built malware.

πŸ”— Full story: https://thehackernews.com/2025/04/microsoft-credits-encrypthub-hacker.html
πŸ‘19πŸ”₯11😁10πŸ‘5⚑3
🚨 PoisonSeed ALERT: Hackers are hijacking CRM platforms like Mailchimp, SendGrid, Hubspot to steal crypto wallets β€” by sending fake seed phrases in mass spam attacks.

Once inside? They create API keys for stealthy, long-term control β€” even if passwords are reset.

Learn more βž” https://thehackernews.com/2025/04/poisonseed-exploits-crm-accounts-to.html
😁12πŸ”₯7πŸ‘6⚑1
πŸ”Ž Vanity metrics β‰  security

Fortune 500s still chase patch counts and scan ratesβ€”but real threats slip through.

Real security = measuring impact, not activity.

Gartner predicts CTEM will cut breaches by 66% by 2026.

πŸ‘‰ Learn more: https://thehackernews.com/2025/04/security-theater-vanity-metrics-keep.html
πŸ”₯7πŸ‘6
⚑ Threats are moving faster than patches.

This week in THN: VPN exploits, supply chain hacks, insider threats, fake job scams, and malware-laced phones.

Stay ahead β€” full recap here ➑️ https://thehackernews.com/2025/04/weekly-recap-vpn-exploits-oracles.html
πŸ‘15πŸ€”4😁3πŸ”₯1
🚨 ALERT: Fast Flux networks are backβ€”and more dangerous than ever.

CISA, NSA, FBI + allies (πŸ‡¦πŸ‡ΊπŸ‡¨πŸ‡¦πŸ‡³πŸ‡Ώ) warn: hackers like Gamaredon & Raspberry Robin are rapidly rotating domains to evade takedowns and launch malware attacks.

Block, filter, sinkhole, monitor β€” or risk exposure.

πŸ”— Read the full advisory: https://thehackernews.com/2025/04/cisa-and-fbi-warn-fast-flux-is-powering.html
⚑17πŸ‘12🀯7πŸ€”4πŸ”₯1πŸ‘1
πŸ”₯ Google patches 62 security flaws β€” but 2 were already exploited in the wild.

One (CVE-2024-53197) helped hackers break into a Serbian activist’s phone in Dec 2024.

πŸ‘€ Zero user interaction. Remote takeover.

Full story β†’ https://thehackernews.com/2025/04/google-releases-android-update-to-patch.html
πŸ‘18🀯9😱7πŸ€”3πŸ”₯2
CrushFTP flaw (CVE-2025-31161, CVSS 9.8) is being actively exploited.

Full system takeover via authentication bypass (no login needed)

β€”First attacks seen March 30
β€”815 vulnerable servers
β€” Targets: marketing, retail, semiconductor sectors
β€” Malware used: MeshAgent, Telegram bots

FCEB agencies must patch by April 28. Exploit guide is public. Attackers are moving fast.

πŸ”— See details: https://thehackernews.com/2025/04/cisa-adds-crushftp-vulnerability-to-kev.html
πŸ‘13⚑2πŸ”₯2😁2
πŸ‘€ AI is coding fasterβ€”but leaking secrets faster too.

New GitGuardian data (2025):
πŸ”Ή Copilot repos leak secrets 40% more often.
πŸ”Ή 6.4% exposed credentials β€” 1,200+ cases.

As AI builds, non-human identities are explodingβ€”and attackers are watching.

CISOs must rethink security NOW.

Learn why βž” https://thehackernews.com/expert-insights/2025/04/the-new-frontier-of-security-risk-ai.html
πŸ‘9😁7πŸ‘6πŸ€”4
🚨 CERT-UA warns: Military, police, and local governments are targeted by phishing emails dropping two new threats:

πŸ› οΈ GIFTEDCROOK stealer (C/C++, browser data theft)
⚑ Reverse shell via PowerShell scripts from "PSSW100AVB" GitHub repo

Tools: PyRDP, RemoteApps β€” silent file theft, clipboard hijack.

πŸ‘‰ Full details: https://thehackernews.com/2025/04/uac-0226-deploys-giftedcrook-stealer.html
πŸ€”12πŸ‘6😁5⚑4πŸ”₯3🀯1
Security teams aren't drowning in threats. They're drowning in alerts.

πŸ‘€ Most "AI copilots" just sit there, waiting for instructions. Meanwhile, real attacks slip through.

⚑ Agentic AI flips the script:
β†’ Investigates autonomously
β†’ Prioritizes real risk
β†’ Cuts analyst burnout

The future is autonomous. See why β†’ https://thehackernews.com/2025/04/agentic-ai-in-soc-dawn-of-autonomous.html
😁12πŸ‘8
🚨 Hackers are abusing SourceForge to spread crypto miners & clipper malware disguised as Microsoft Office downloads.

➑️ 4,600+ users hit (Jan–Mar 2025)
➑️ 90% victims = Russian speakers
➑️ Attack chain uses Telegram API, fake URLs & Google Ads

πŸ”— Read: https://thehackernews.com/2025/04/cryptocurrency-miner-and-clipper.html
πŸ‘15πŸ”₯4πŸ€”2
🚨 Hackers could have owned your AWS serversβ€”easily.

A flaw in Amazon’s SSM Agent let attackers write scripts with root access by gaming plugin IDs (../).

If you haven’t updatedβ€”you're still at risk.

πŸ‘€ Read more: https://thehackernews.com/2025/04/amazon-ec2-ssm-agent-flaw-patched-after.html
πŸ‘24πŸ”₯6πŸ€”4⚑2😱2
🚨 Critical alert for Fortinet users! A 9.3 CVSS flaw (CVE-2024-48887) in FortiSwitch lets hackers remotely change admin passwords β€” no login needed.

πŸ”§ Fix it: Upgrade ASAP (7.6.1+, 7.4.5+, 7.2.9+, 7.0.11+, 6.4.15+)

⚑ No exploits yetβ€”but Fortinet bugs have been weaponized before.

πŸ‘‰ Full details: https://thehackernews.com/2025/04/fortinet-urges-fortiswitch-upgrades-to.html
⚑13πŸ‘8πŸ”₯5🀯5😁3😱1
🚨 Critical alert: 30 new security flaws found in Adobe ColdFusionβ€”11 rated Critical.

⚑ Top threats: arbitrary code execution, file system read, security bypass.

CVE-2025-24446 | CVSS 9.1
CVE-2025-24447 | CVSS 9.1
CVE-2025-30281 | CVSS 9.1
(and more)

No active exploits yetβ€”but don’t wait.

πŸ”— Update now or risk being the next headline: https://thehackernews.com/2025/04/adobe-patches-11-critical-coldfusion.html
πŸ‘13πŸ”₯5⚑2
πŸ”₯ Security teams are drowning in complexityβ€”and AI copilots aren't a future fix. They're already critical in 2025.

From instant policy answers to auto-summarizing risk reports, AI is reshaping how top teams stay ahead.

🧠 But AI isn’t magic. Humans still rule judgment.

How the smartest teams are striking the balance πŸ‘‰ https://thehackernews.com/expert-insights/2025/04/supercharging-security-compliance-with.html
πŸ‘10🀯6
Microsoft’s April update patches 126 flawsβ€”but CVE-2025-29824, already exploited in ransomware attacks, has no fix for Windows 10.

πŸ”— More details: https://thehackernews.com/2025/04/microsoft-patches-126-flaws-including.html

CISA demands federal agencies patch by April 29.
🀯16πŸ‘8πŸ”₯6πŸ€”2
🚨 New Windows zero-day (CVE-2025-29824) exploited in ransomware attacks!

⚑ Attackers used PipeMagic malware, hidden in MSBuild files, and hijacked legit sites to spread payloads. Linked to RansomEXX gang.

Full report πŸ‘‰ https://thehackernews.com/2025/04/pipemagic-trojan-exploits-windows-clfs.html

πŸ”’ Patch ASAP if you haven't!
πŸ”₯19πŸ‘6😱5😁1πŸ€”1