The Hacker News
βœ”
151K subscribers
1.86K photos
10 videos
3 files
7.77K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
πŸ‘€ Microsoft Credits EncryptHub β€” the Hacker Behind 618+ Breaches β€” for Disclosing Windows Flaws. πŸ‘€

In March 2025, EncryptHub reported 2 critical bugs (CVE-2025-24061 & CVE-2025-24071).

Weeks later, he exploited a zero-day (CVE-2025-26633), hitting hundreds of targets using ChatGPT-built malware.

πŸ”— Full story: https://thehackernews.com/2025/04/microsoft-credits-encrypthub-hacker.html
πŸ‘19πŸ”₯11😁10πŸ‘5⚑3
🚨 PoisonSeed ALERT: Hackers are hijacking CRM platforms like Mailchimp, SendGrid, Hubspot to steal crypto wallets β€” by sending fake seed phrases in mass spam attacks.

Once inside? They create API keys for stealthy, long-term control β€” even if passwords are reset.

Learn more βž” https://thehackernews.com/2025/04/poisonseed-exploits-crm-accounts-to.html
😁12πŸ”₯7πŸ‘6⚑1
πŸ”Ž Vanity metrics β‰  security

Fortune 500s still chase patch counts and scan ratesβ€”but real threats slip through.

Real security = measuring impact, not activity.

Gartner predicts CTEM will cut breaches by 66% by 2026.

πŸ‘‰ Learn more: https://thehackernews.com/2025/04/security-theater-vanity-metrics-keep.html
πŸ”₯7πŸ‘6
⚑ Threats are moving faster than patches.

This week in THN: VPN exploits, supply chain hacks, insider threats, fake job scams, and malware-laced phones.

Stay ahead β€” full recap here ➑️ https://thehackernews.com/2025/04/weekly-recap-vpn-exploits-oracles.html
πŸ‘15πŸ€”4😁3πŸ”₯1
🚨 ALERT: Fast Flux networks are backβ€”and more dangerous than ever.

CISA, NSA, FBI + allies (πŸ‡¦πŸ‡ΊπŸ‡¨πŸ‡¦πŸ‡³πŸ‡Ώ) warn: hackers like Gamaredon & Raspberry Robin are rapidly rotating domains to evade takedowns and launch malware attacks.

Block, filter, sinkhole, monitor β€” or risk exposure.

πŸ”— Read the full advisory: https://thehackernews.com/2025/04/cisa-and-fbi-warn-fast-flux-is-powering.html
⚑17πŸ‘12🀯7πŸ€”4πŸ”₯1πŸ‘1
πŸ”₯ Google patches 62 security flaws β€” but 2 were already exploited in the wild.

One (CVE-2024-53197) helped hackers break into a Serbian activist’s phone in Dec 2024.

πŸ‘€ Zero user interaction. Remote takeover.

Full story β†’ https://thehackernews.com/2025/04/google-releases-android-update-to-patch.html
πŸ‘18🀯9😱7πŸ€”3πŸ”₯2
CrushFTP flaw (CVE-2025-31161, CVSS 9.8) is being actively exploited.

Full system takeover via authentication bypass (no login needed)

β€”First attacks seen March 30
β€”815 vulnerable servers
β€” Targets: marketing, retail, semiconductor sectors
β€” Malware used: MeshAgent, Telegram bots

FCEB agencies must patch by April 28. Exploit guide is public. Attackers are moving fast.

πŸ”— See details: https://thehackernews.com/2025/04/cisa-adds-crushftp-vulnerability-to-kev.html
πŸ‘13⚑2πŸ”₯2😁2
πŸ‘€ AI is coding fasterβ€”but leaking secrets faster too.

New GitGuardian data (2025):
πŸ”Ή Copilot repos leak secrets 40% more often.
πŸ”Ή 6.4% exposed credentials β€” 1,200+ cases.

As AI builds, non-human identities are explodingβ€”and attackers are watching.

CISOs must rethink security NOW.

Learn why βž” https://thehackernews.com/expert-insights/2025/04/the-new-frontier-of-security-risk-ai.html
πŸ‘9😁7πŸ‘6πŸ€”4
🚨 CERT-UA warns: Military, police, and local governments are targeted by phishing emails dropping two new threats:

πŸ› οΈ GIFTEDCROOK stealer (C/C++, browser data theft)
⚑ Reverse shell via PowerShell scripts from "PSSW100AVB" GitHub repo

Tools: PyRDP, RemoteApps β€” silent file theft, clipboard hijack.

πŸ‘‰ Full details: https://thehackernews.com/2025/04/uac-0226-deploys-giftedcrook-stealer.html
πŸ€”12πŸ‘6😁5⚑4πŸ”₯3🀯1
Security teams aren't drowning in threats. They're drowning in alerts.

πŸ‘€ Most "AI copilots" just sit there, waiting for instructions. Meanwhile, real attacks slip through.

⚑ Agentic AI flips the script:
β†’ Investigates autonomously
β†’ Prioritizes real risk
β†’ Cuts analyst burnout

The future is autonomous. See why β†’ https://thehackernews.com/2025/04/agentic-ai-in-soc-dawn-of-autonomous.html
😁12πŸ‘8
🚨 Hackers are abusing SourceForge to spread crypto miners & clipper malware disguised as Microsoft Office downloads.

➑️ 4,600+ users hit (Jan–Mar 2025)
➑️ 90% victims = Russian speakers
➑️ Attack chain uses Telegram API, fake URLs & Google Ads

πŸ”— Read: https://thehackernews.com/2025/04/cryptocurrency-miner-and-clipper.html
πŸ‘15πŸ”₯4πŸ€”2
🚨 Hackers could have owned your AWS serversβ€”easily.

A flaw in Amazon’s SSM Agent let attackers write scripts with root access by gaming plugin IDs (../).

If you haven’t updatedβ€”you're still at risk.

πŸ‘€ Read more: https://thehackernews.com/2025/04/amazon-ec2-ssm-agent-flaw-patched-after.html
πŸ‘24πŸ”₯6πŸ€”4⚑2😱2
🚨 Critical alert for Fortinet users! A 9.3 CVSS flaw (CVE-2024-48887) in FortiSwitch lets hackers remotely change admin passwords β€” no login needed.

πŸ”§ Fix it: Upgrade ASAP (7.6.1+, 7.4.5+, 7.2.9+, 7.0.11+, 6.4.15+)

⚑ No exploits yetβ€”but Fortinet bugs have been weaponized before.

πŸ‘‰ Full details: https://thehackernews.com/2025/04/fortinet-urges-fortiswitch-upgrades-to.html
⚑13πŸ‘8πŸ”₯5🀯5😁3😱1
🚨 Critical alert: 30 new security flaws found in Adobe ColdFusionβ€”11 rated Critical.

⚑ Top threats: arbitrary code execution, file system read, security bypass.

CVE-2025-24446 | CVSS 9.1
CVE-2025-24447 | CVSS 9.1
CVE-2025-30281 | CVSS 9.1
(and more)

No active exploits yetβ€”but don’t wait.

πŸ”— Update now or risk being the next headline: https://thehackernews.com/2025/04/adobe-patches-11-critical-coldfusion.html
πŸ‘13πŸ”₯5⚑2
πŸ”₯ Security teams are drowning in complexityβ€”and AI copilots aren't a future fix. They're already critical in 2025.

From instant policy answers to auto-summarizing risk reports, AI is reshaping how top teams stay ahead.

🧠 But AI isn’t magic. Humans still rule judgment.

How the smartest teams are striking the balance πŸ‘‰ https://thehackernews.com/expert-insights/2025/04/supercharging-security-compliance-with.html
πŸ‘10🀯6
Microsoft’s April update patches 126 flawsβ€”but CVE-2025-29824, already exploited in ransomware attacks, has no fix for Windows 10.

πŸ”— More details: https://thehackernews.com/2025/04/microsoft-patches-126-flaws-including.html

CISA demands federal agencies patch by April 29.
🀯16πŸ‘8πŸ”₯6πŸ€”2
🚨 New Windows zero-day (CVE-2025-29824) exploited in ransomware attacks!

⚑ Attackers used PipeMagic malware, hidden in MSBuild files, and hijacked legit sites to spread payloads. Linked to RansomEXX gang.

Full report πŸ‘‰ https://thehackernews.com/2025/04/pipemagic-trojan-exploits-windows-clfs.html

πŸ”’ Patch ASAP if you haven't!
πŸ”₯19πŸ‘6😱5😁1πŸ€”1
🚨 New CISA Alert!

Gladinet CentreStack flaw (CVE-2025-30406, CVSS 9.0) is actively exploited.

▢️ Hard-coded machineKey enables remote code execution.
▢️ Exploited as a zero-day in March 2025.

πŸ”— Details: https://thehackernews.com/2025/04/cisa-warns-of-centrestacks-hard-coded.html

Patch or rotate keys now.
πŸ‘10πŸ€”5
⚑ New Malware Alert!

Chinese-linked ToddyCat exploited an ESET flaw (CVE-2024-11859) to drop new malware TCESB β€” bypassing defenses and hijacking devices.

Update now | Stay alert.

Details πŸ‘‰https://thehackernews.com/2025/04/new-tcesb-malware-found-in-active.html
😁11πŸ‘6πŸ€”3
πŸ”₯ Non-human identities (NHIs) are exploding β€” and leaking secrets faster than ever.

In 2024:
β€’ 23.77M secrets leaked on GitHub (+25%)
β€’ NHIs outnumber humans 45-to-1
β€’ 70% of leaked secrets still active
β€’ Private repos = 8x more leaks than public
β€’ Copilot = 40% more leaks
β€’ Docker Hub = 100K+ valid secrets exposed

The attack surface is out of control. Secrets management must evolveβ€”fast.

πŸ”Ž Full 2025 Report: https://thehackernews.com/2025/04/explosive-growth-of-non-human.html
πŸ‘11πŸ”₯2
πŸ”₯ AI scams just leveled up.

Lovable AI scored 1.8/10 on Guardio Labs' security testβ€”the easiest tool for cybercrooks to build phishing sites in minutes.

πŸ‘€ It auto-deploys fake Microsoft pages, steals credentials, and even sets up admin dashboards.

Learn more: https://thehackernews.com/2025/04/lovable-ai-found-most-vulnerable-to.html
πŸ‘20πŸ”₯5πŸ‘5