CrushFTP flaw (CVE-2025-31161, CVSS 9.8) is being actively exploited.
Full system takeover via authentication bypass (no login needed)
βFirst attacks seen March 30
β815 vulnerable servers
β Targets: marketing, retail, semiconductor sectors
β Malware used: MeshAgent, Telegram bots
FCEB agencies must patch by April 28. Exploit guide is public. Attackers are moving fast.
π See details: https://thehackernews.com/2025/04/cisa-adds-crushftp-vulnerability-to-kev.html
Full system takeover via authentication bypass (no login needed)
βFirst attacks seen March 30
β815 vulnerable servers
β Targets: marketing, retail, semiconductor sectors
β Malware used: MeshAgent, Telegram bots
FCEB agencies must patch by April 28. Exploit guide is public. Attackers are moving fast.
π See details: https://thehackernews.com/2025/04/cisa-adds-crushftp-vulnerability-to-kev.html
π13β‘2π₯2π2
π AI is coding fasterβbut leaking secrets faster too.
New GitGuardian data (2025):
πΉ Copilot repos leak secrets 40% more often.
πΉ 6.4% exposed credentials β 1,200+ cases.
As AI builds, non-human identities are explodingβand attackers are watching.
CISOs must rethink security NOW.
Learn why β https://thehackernews.com/expert-insights/2025/04/the-new-frontier-of-security-risk-ai.html
New GitGuardian data (2025):
πΉ Copilot repos leak secrets 40% more often.
πΉ 6.4% exposed credentials β 1,200+ cases.
As AI builds, non-human identities are explodingβand attackers are watching.
CISOs must rethink security NOW.
Learn why β https://thehackernews.com/expert-insights/2025/04/the-new-frontier-of-security-risk-ai.html
π9π7π6π€4
π¨ CERT-UA warns: Military, police, and local governments are targeted by phishing emails dropping two new threats:
π οΈ GIFTEDCROOK stealer (C/C++, browser data theft)
β‘ Reverse shell via PowerShell scripts from "PSSW100AVB" GitHub repo
Tools: PyRDP, RemoteApps β silent file theft, clipboard hijack.
π Full details: https://thehackernews.com/2025/04/uac-0226-deploys-giftedcrook-stealer.html
π οΈ GIFTEDCROOK stealer (C/C++, browser data theft)
β‘ Reverse shell via PowerShell scripts from "PSSW100AVB" GitHub repo
Tools: PyRDP, RemoteApps β silent file theft, clipboard hijack.
π Full details: https://thehackernews.com/2025/04/uac-0226-deploys-giftedcrook-stealer.html
π€12π6π5β‘4π₯3π€―1
Security teams aren't drowning in threats. They're drowning in alerts.
π Most "AI copilots" just sit there, waiting for instructions. Meanwhile, real attacks slip through.
β‘ Agentic AI flips the script:
β Investigates autonomously
β Prioritizes real risk
β Cuts analyst burnout
The future is autonomous. See why β https://thehackernews.com/2025/04/agentic-ai-in-soc-dawn-of-autonomous.html
π Most "AI copilots" just sit there, waiting for instructions. Meanwhile, real attacks slip through.
β‘ Agentic AI flips the script:
β Investigates autonomously
β Prioritizes real risk
β Cuts analyst burnout
The future is autonomous. See why β https://thehackernews.com/2025/04/agentic-ai-in-soc-dawn-of-autonomous.html
π12π8
π¨ Hackers are abusing SourceForge to spread crypto miners & clipper malware disguised as Microsoft Office downloads.
β‘οΈ 4,600+ users hit (JanβMar 2025)
β‘οΈ 90% victims = Russian speakers
β‘οΈ Attack chain uses Telegram API, fake URLs & Google Ads
π Read: https://thehackernews.com/2025/04/cryptocurrency-miner-and-clipper.html
β‘οΈ 4,600+ users hit (JanβMar 2025)
β‘οΈ 90% victims = Russian speakers
β‘οΈ Attack chain uses Telegram API, fake URLs & Google Ads
π Read: https://thehackernews.com/2025/04/cryptocurrency-miner-and-clipper.html
π15π₯4π€2
π¨ Hackers could have owned your AWS serversβeasily.
A flaw in Amazonβs SSM Agent let attackers write scripts with root access by gaming plugin IDs (../).
If you havenβt updatedβyou're still at risk.
π Read more: https://thehackernews.com/2025/04/amazon-ec2-ssm-agent-flaw-patched-after.html
A flaw in Amazonβs SSM Agent let attackers write scripts with root access by gaming plugin IDs (../).
If you havenβt updatedβyou're still at risk.
π Read more: https://thehackernews.com/2025/04/amazon-ec2-ssm-agent-flaw-patched-after.html
π24π₯6π€4β‘2π±2
π¨ Critical alert for Fortinet users! A 9.3 CVSS flaw (CVE-2024-48887) in FortiSwitch lets hackers remotely change admin passwords β no login needed.
π§ Fix it: Upgrade ASAP (7.6.1+, 7.4.5+, 7.2.9+, 7.0.11+, 6.4.15+)
β‘ No exploits yetβbut Fortinet bugs have been weaponized before.
π Full details: https://thehackernews.com/2025/04/fortinet-urges-fortiswitch-upgrades-to.html
π§ Fix it: Upgrade ASAP (7.6.1+, 7.4.5+, 7.2.9+, 7.0.11+, 6.4.15+)
β‘ No exploits yetβbut Fortinet bugs have been weaponized before.
π Full details: https://thehackernews.com/2025/04/fortinet-urges-fortiswitch-upgrades-to.html
β‘13π8π₯5π€―5π3π±1
π¨ Critical alert: 30 new security flaws found in Adobe ColdFusionβ11 rated Critical.
β‘ Top threats: arbitrary code execution, file system read, security bypass.
CVE-2025-24446 | CVSS 9.1
CVE-2025-24447 | CVSS 9.1
CVE-2025-30281 | CVSS 9.1
(and more)
No active exploits yetβbut donβt wait.
π Update now or risk being the next headline: https://thehackernews.com/2025/04/adobe-patches-11-critical-coldfusion.html
β‘ Top threats: arbitrary code execution, file system read, security bypass.
CVE-2025-24446 | CVSS 9.1
CVE-2025-24447 | CVSS 9.1
CVE-2025-30281 | CVSS 9.1
(and more)
No active exploits yetβbut donβt wait.
π Update now or risk being the next headline: https://thehackernews.com/2025/04/adobe-patches-11-critical-coldfusion.html
π13π₯5β‘2
π₯ Security teams are drowning in complexityβand AI copilots aren't a future fix. They're already critical in 2025.
From instant policy answers to auto-summarizing risk reports, AI is reshaping how top teams stay ahead.
π§ But AI isnβt magic. Humans still rule judgment.
How the smartest teams are striking the balance π https://thehackernews.com/expert-insights/2025/04/supercharging-security-compliance-with.html
From instant policy answers to auto-summarizing risk reports, AI is reshaping how top teams stay ahead.
π§ But AI isnβt magic. Humans still rule judgment.
How the smartest teams are striking the balance π https://thehackernews.com/expert-insights/2025/04/supercharging-security-compliance-with.html
π10π€―6
Microsoftβs April update patches 126 flawsβbut CVE-2025-29824, already exploited in ransomware attacks, has no fix for Windows 10.
π More details: https://thehackernews.com/2025/04/microsoft-patches-126-flaws-including.html
CISA demands federal agencies patch by April 29.
π More details: https://thehackernews.com/2025/04/microsoft-patches-126-flaws-including.html
CISA demands federal agencies patch by April 29.
π€―16π8π₯6π€2
π¨ New Windows zero-day (CVE-2025-29824) exploited in ransomware attacks!
β‘ Attackers used PipeMagic malware, hidden in MSBuild files, and hijacked legit sites to spread payloads. Linked to RansomEXX gang.
Full report π https://thehackernews.com/2025/04/pipemagic-trojan-exploits-windows-clfs.html
π Patch ASAP if you haven't!
β‘ Attackers used PipeMagic malware, hidden in MSBuild files, and hijacked legit sites to spread payloads. Linked to RansomEXX gang.
Full report π https://thehackernews.com/2025/04/pipemagic-trojan-exploits-windows-clfs.html
π Patch ASAP if you haven't!
π₯19π6π±5π1π€1
π¨ New CISA Alert!
Gladinet CentreStack flaw (CVE-2025-30406, CVSS 9.0) is actively exploited.
βΆοΈ Hard-coded machineKey enables remote code execution.
βΆοΈ Exploited as a zero-day in March 2025.
π Details: https://thehackernews.com/2025/04/cisa-warns-of-centrestacks-hard-coded.html
Patch or rotate keys now.
Gladinet CentreStack flaw (CVE-2025-30406, CVSS 9.0) is actively exploited.
βΆοΈ Hard-coded machineKey enables remote code execution.
βΆοΈ Exploited as a zero-day in March 2025.
π Details: https://thehackernews.com/2025/04/cisa-warns-of-centrestacks-hard-coded.html
Patch or rotate keys now.
π10π€5
β‘ New Malware Alert!
Chinese-linked ToddyCat exploited an ESET flaw (CVE-2024-11859) to drop new malware TCESB β bypassing defenses and hijacking devices.
Update now | Stay alert.
Details πhttps://thehackernews.com/2025/04/new-tcesb-malware-found-in-active.html
Chinese-linked ToddyCat exploited an ESET flaw (CVE-2024-11859) to drop new malware TCESB β bypassing defenses and hijacking devices.
Update now | Stay alert.
Details πhttps://thehackernews.com/2025/04/new-tcesb-malware-found-in-active.html
π11π6π€3
π₯ Non-human identities (NHIs) are exploding β and leaking secrets faster than ever.
In 2024:
β’ 23.77M secrets leaked on GitHub (+25%)
β’ NHIs outnumber humans 45-to-1
β’ 70% of leaked secrets still active
β’ Private repos = 8x more leaks than public
β’ Copilot = 40% more leaks
β’ Docker Hub = 100K+ valid secrets exposed
The attack surface is out of control. Secrets management must evolveβfast.
π Full 2025 Report: https://thehackernews.com/2025/04/explosive-growth-of-non-human.html
In 2024:
β’ 23.77M secrets leaked on GitHub (+25%)
β’ NHIs outnumber humans 45-to-1
β’ 70% of leaked secrets still active
β’ Private repos = 8x more leaks than public
β’ Copilot = 40% more leaks
β’ Docker Hub = 100K+ valid secrets exposed
The attack surface is out of control. Secrets management must evolveβfast.
π Full 2025 Report: https://thehackernews.com/2025/04/explosive-growth-of-non-human.html
π11π₯2
π₯ AI scams just leveled up.
Lovable AI scored 1.8/10 on Guardio Labs' security testβthe easiest tool for cybercrooks to build phishing sites in minutes.
π It auto-deploys fake Microsoft pages, steals credentials, and even sets up admin dashboards.
Learn more: https://thehackernews.com/2025/04/lovable-ai-found-most-vulnerable-to.html
Lovable AI scored 1.8/10 on Guardio Labs' security testβthe easiest tool for cybercrooks to build phishing sites in minutes.
π It auto-deploys fake Microsoft pages, steals credentials, and even sets up admin dashboards.
Learn more: https://thehackernews.com/2025/04/lovable-ai-found-most-vulnerable-to.html
π20π₯5π5
π¨ AkiraBot has attacked 420,000 domains, using OpenAIβs GPT-4o-mini to flood contact forms and chats with SEO spam β even beating CAPTCHA.
π₯ Targets include Shopify, Wix, GoDaddy, and Squarespace. Nobody's safe.
Learn more: https://thehackernews.com/2025/04/akirabot-targets-420000-sites-with.html
π₯ Targets include Shopify, Wix, GoDaddy, and Squarespace. Nobody's safe.
Learn more: https://thehackernews.com/2025/04/akirabot-targets-420000-sites-with.html
π24π10π₯7π€―1
π¨ Europol's Operation Endgame just busted 5+ SmokeLoader customers linked to ransomware, spyware, and crypto theft.
Meanwhile, new malware loaders like ModiLoader, GootLoader, and FakeUpdates are hitting users with phishing, fake installs, and drive-by attacks.
π Full story: https://thehackernews.com/2025/04/europol-arrests-five-smokeloader.html
Meanwhile, new malware loaders like ModiLoader, GootLoader, and FakeUpdates are hitting users with phishing, fake installs, and drive-by attacks.
π Full story: https://thehackernews.com/2025/04/europol-arrests-five-smokeloader.html
π14π4π€2π1π€―1
π₯ Gamaredon (aka Shuckworm) hit a Western military mission in Ukraine with a new, stealthier GammaSteel malware, Symantec warns.
π Infected USBs β Hidden shortcut traps β Live exfil via Telegram & Telegraph.
π Full story: https://thehackernews.com/2025/04/gamaredon-uses-infected-removable.html
π Infected USBs β Hidden shortcut traps β Live exfil via Telegram & Telegraph.
π Full story: https://thehackernews.com/2025/04/gamaredon-uses-infected-removable.html
π16π5π±3
π² 53% of #DevSecOps teams are gambling with open source security.
New 2025 report from ActiveState reveals:
β Risky workflows
β Sluggish MTTD/MTTR
β Traditional tools are failing fast
Ready to fix fasterβwithout falling behind?
πRead now β https://thn.news/vuln-management-2025
New 2025 report from ActiveState reveals:
β Risky workflows
β Sluggish MTTD/MTTR
β Traditional tools are failing fast
Ready to fix fasterβwithout falling behind?
πRead now β https://thn.news/vuln-management-2025
π9π€4π3π₯2
π¨ New npm malware alert: pdf-to-office targets Atomic and Exodus wallets.
β‘οΈ Injects malicious code to hijack crypto transfers.
β‘οΈ Malware persists even after uninstalling.
β‘οΈ 334+ downloads so far.
Supply chain attacks are rising.
Full report: https://thehackernews.com/2025/04/malicious-npm-package-targets-atomic.html
β‘οΈ Injects malicious code to hijack crypto transfers.
β‘οΈ Malware persists even after uninstalling.
β‘οΈ 334+ downloads so far.
Supply chain attacks are rising.
Full report: https://thehackernews.com/2025/04/malicious-npm-package-targets-atomic.html
π9π4β‘3π€―3
AI agents arenβt just "tools" anymore β they're your new workforce.
But behind every agent is a non-human identity (NHI) β and that's where real risks live.
π Machine-speed attacks
π Invisible backdoors (Shadow AI)
π Cross-system breaches
Learn how to secure AI at the source β https://thehackernews.com/2025/04/the-identities-behind-ai-agents-deep.html
But behind every agent is a non-human identity (NHI) β and that's where real risks live.
π Machine-speed attacks
π Invisible backdoors (Shadow AI)
π Cross-system breaches
Learn how to secure AI at the source β https://thehackernews.com/2025/04/the-identities-behind-ai-agents-deep.html
π9