The Hacker News
βœ”
151K subscribers
1.85K photos
10 videos
3 files
7.77K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
CrushFTP flaw (CVE-2025-31161, CVSS 9.8) is being actively exploited.

Full system takeover via authentication bypass (no login needed)

β€”First attacks seen March 30
β€”815 vulnerable servers
β€” Targets: marketing, retail, semiconductor sectors
β€” Malware used: MeshAgent, Telegram bots

FCEB agencies must patch by April 28. Exploit guide is public. Attackers are moving fast.

πŸ”— See details: https://thehackernews.com/2025/04/cisa-adds-crushftp-vulnerability-to-kev.html
πŸ‘13⚑2πŸ”₯2😁2
πŸ‘€ AI is coding fasterβ€”but leaking secrets faster too.

New GitGuardian data (2025):
πŸ”Ή Copilot repos leak secrets 40% more often.
πŸ”Ή 6.4% exposed credentials β€” 1,200+ cases.

As AI builds, non-human identities are explodingβ€”and attackers are watching.

CISOs must rethink security NOW.

Learn why βž” https://thehackernews.com/expert-insights/2025/04/the-new-frontier-of-security-risk-ai.html
πŸ‘9😁7πŸ‘6πŸ€”4
🚨 CERT-UA warns: Military, police, and local governments are targeted by phishing emails dropping two new threats:

πŸ› οΈ GIFTEDCROOK stealer (C/C++, browser data theft)
⚑ Reverse shell via PowerShell scripts from "PSSW100AVB" GitHub repo

Tools: PyRDP, RemoteApps β€” silent file theft, clipboard hijack.

πŸ‘‰ Full details: https://thehackernews.com/2025/04/uac-0226-deploys-giftedcrook-stealer.html
πŸ€”12πŸ‘6😁5⚑4πŸ”₯3🀯1
Security teams aren't drowning in threats. They're drowning in alerts.

πŸ‘€ Most "AI copilots" just sit there, waiting for instructions. Meanwhile, real attacks slip through.

⚑ Agentic AI flips the script:
β†’ Investigates autonomously
β†’ Prioritizes real risk
β†’ Cuts analyst burnout

The future is autonomous. See why β†’ https://thehackernews.com/2025/04/agentic-ai-in-soc-dawn-of-autonomous.html
😁12πŸ‘8
🚨 Hackers are abusing SourceForge to spread crypto miners & clipper malware disguised as Microsoft Office downloads.

➑️ 4,600+ users hit (Jan–Mar 2025)
➑️ 90% victims = Russian speakers
➑️ Attack chain uses Telegram API, fake URLs & Google Ads

πŸ”— Read: https://thehackernews.com/2025/04/cryptocurrency-miner-and-clipper.html
πŸ‘15πŸ”₯4πŸ€”2
🚨 Hackers could have owned your AWS serversβ€”easily.

A flaw in Amazon’s SSM Agent let attackers write scripts with root access by gaming plugin IDs (../).

If you haven’t updatedβ€”you're still at risk.

πŸ‘€ Read more: https://thehackernews.com/2025/04/amazon-ec2-ssm-agent-flaw-patched-after.html
πŸ‘24πŸ”₯6πŸ€”4⚑2😱2
🚨 Critical alert for Fortinet users! A 9.3 CVSS flaw (CVE-2024-48887) in FortiSwitch lets hackers remotely change admin passwords β€” no login needed.

πŸ”§ Fix it: Upgrade ASAP (7.6.1+, 7.4.5+, 7.2.9+, 7.0.11+, 6.4.15+)

⚑ No exploits yetβ€”but Fortinet bugs have been weaponized before.

πŸ‘‰ Full details: https://thehackernews.com/2025/04/fortinet-urges-fortiswitch-upgrades-to.html
⚑13πŸ‘8πŸ”₯5🀯5😁3😱1
🚨 Critical alert: 30 new security flaws found in Adobe ColdFusionβ€”11 rated Critical.

⚑ Top threats: arbitrary code execution, file system read, security bypass.

CVE-2025-24446 | CVSS 9.1
CVE-2025-24447 | CVSS 9.1
CVE-2025-30281 | CVSS 9.1
(and more)

No active exploits yetβ€”but don’t wait.

πŸ”— Update now or risk being the next headline: https://thehackernews.com/2025/04/adobe-patches-11-critical-coldfusion.html
πŸ‘13πŸ”₯5⚑2
πŸ”₯ Security teams are drowning in complexityβ€”and AI copilots aren't a future fix. They're already critical in 2025.

From instant policy answers to auto-summarizing risk reports, AI is reshaping how top teams stay ahead.

🧠 But AI isn’t magic. Humans still rule judgment.

How the smartest teams are striking the balance πŸ‘‰ https://thehackernews.com/expert-insights/2025/04/supercharging-security-compliance-with.html
πŸ‘10🀯6
Microsoft’s April update patches 126 flawsβ€”but CVE-2025-29824, already exploited in ransomware attacks, has no fix for Windows 10.

πŸ”— More details: https://thehackernews.com/2025/04/microsoft-patches-126-flaws-including.html

CISA demands federal agencies patch by April 29.
🀯16πŸ‘8πŸ”₯6πŸ€”2
🚨 New Windows zero-day (CVE-2025-29824) exploited in ransomware attacks!

⚑ Attackers used PipeMagic malware, hidden in MSBuild files, and hijacked legit sites to spread payloads. Linked to RansomEXX gang.

Full report πŸ‘‰ https://thehackernews.com/2025/04/pipemagic-trojan-exploits-windows-clfs.html

πŸ”’ Patch ASAP if you haven't!
πŸ”₯19πŸ‘6😱5😁1πŸ€”1
🚨 New CISA Alert!

Gladinet CentreStack flaw (CVE-2025-30406, CVSS 9.0) is actively exploited.

▢️ Hard-coded machineKey enables remote code execution.
▢️ Exploited as a zero-day in March 2025.

πŸ”— Details: https://thehackernews.com/2025/04/cisa-warns-of-centrestacks-hard-coded.html

Patch or rotate keys now.
πŸ‘10πŸ€”5
⚑ New Malware Alert!

Chinese-linked ToddyCat exploited an ESET flaw (CVE-2024-11859) to drop new malware TCESB β€” bypassing defenses and hijacking devices.

Update now | Stay alert.

Details πŸ‘‰https://thehackernews.com/2025/04/new-tcesb-malware-found-in-active.html
😁11πŸ‘6πŸ€”3
πŸ”₯ Non-human identities (NHIs) are exploding β€” and leaking secrets faster than ever.

In 2024:
β€’ 23.77M secrets leaked on GitHub (+25%)
β€’ NHIs outnumber humans 45-to-1
β€’ 70% of leaked secrets still active
β€’ Private repos = 8x more leaks than public
β€’ Copilot = 40% more leaks
β€’ Docker Hub = 100K+ valid secrets exposed

The attack surface is out of control. Secrets management must evolveβ€”fast.

πŸ”Ž Full 2025 Report: https://thehackernews.com/2025/04/explosive-growth-of-non-human.html
πŸ‘11πŸ”₯2
πŸ”₯ AI scams just leveled up.

Lovable AI scored 1.8/10 on Guardio Labs' security testβ€”the easiest tool for cybercrooks to build phishing sites in minutes.

πŸ‘€ It auto-deploys fake Microsoft pages, steals credentials, and even sets up admin dashboards.

Learn more: https://thehackernews.com/2025/04/lovable-ai-found-most-vulnerable-to.html
πŸ‘20πŸ”₯5πŸ‘5
🚨 AkiraBot has attacked 420,000 domains, using OpenAI’s GPT-4o-mini to flood contact forms and chats with SEO spam β€” even beating CAPTCHA.

πŸ”₯ Targets include Shopify, Wix, GoDaddy, and Squarespace. Nobody's safe.

Learn more: https://thehackernews.com/2025/04/akirabot-targets-420000-sites-with.html
😁24πŸ‘10πŸ”₯7🀯1
🚨 Europol's Operation Endgame just busted 5+ SmokeLoader customers linked to ransomware, spyware, and crypto theft.

Meanwhile, new malware loaders like ModiLoader, GootLoader, and FakeUpdates are hitting users with phishing, fake installs, and drive-by attacks.

πŸ”— Full story: https://thehackernews.com/2025/04/europol-arrests-five-smokeloader.html
πŸ‘14😁4πŸ€”2πŸ‘1🀯1
πŸ”₯ Gamaredon (aka Shuckworm) hit a Western military mission in Ukraine with a new, stealthier GammaSteel malware, Symantec warns.

πŸ“‚ Infected USBs β†’ Hidden shortcut traps β†’ Live exfil via Telegram & Telegraph.

πŸ”— Full story: https://thehackernews.com/2025/04/gamaredon-uses-infected-removable.html
πŸ‘16😁5😱3
🎲 53% of #DevSecOps teams are gambling with open source security.

New 2025 report from ActiveState reveals:

β†’ Risky workflows
β†’ Sluggish MTTD/MTTR
β†’ Traditional tools are failing fast

Ready to fix fasterβ€”without falling behind?

πŸ”—Read now β†’ https://thn.news/vuln-management-2025
😁9πŸ€”4πŸ‘3πŸ”₯2
🚨 New npm malware alert: pdf-to-office targets Atomic and Exodus wallets.

➑️ Injects malicious code to hijack crypto transfers.
➑️ Malware persists even after uninstalling.
➑️ 334+ downloads so far.

Supply chain attacks are rising.

Full report: https://thehackernews.com/2025/04/malicious-npm-package-targets-atomic.html
πŸ‘9πŸ‘4⚑3🀯3
AI agents aren’t just "tools" anymore β€” they're your new workforce.

But behind every agent is a non-human identity (NHI) β€” and that's where real risks live.

πŸ”’ Machine-speed attacks
πŸ”’ Invisible backdoors (Shadow AI)
πŸ”’ Cross-system breaches

Learn how to secure AI at the source βž” https://thehackernews.com/2025/04/the-identities-behind-ai-agents-deep.html
πŸ‘9