The Hacker News
βœ”
151K subscribers
1.85K photos
10 videos
3 files
7.77K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
πŸ”₯ Security teams are drowning in complexityβ€”and AI copilots aren't a future fix. They're already critical in 2025.

From instant policy answers to auto-summarizing risk reports, AI is reshaping how top teams stay ahead.

🧠 But AI isn’t magic. Humans still rule judgment.

How the smartest teams are striking the balance πŸ‘‰ https://thehackernews.com/expert-insights/2025/04/supercharging-security-compliance-with.html
πŸ‘10🀯6
Microsoft’s April update patches 126 flawsβ€”but CVE-2025-29824, already exploited in ransomware attacks, has no fix for Windows 10.

πŸ”— More details: https://thehackernews.com/2025/04/microsoft-patches-126-flaws-including.html

CISA demands federal agencies patch by April 29.
🀯16πŸ‘8πŸ”₯6πŸ€”2
🚨 New Windows zero-day (CVE-2025-29824) exploited in ransomware attacks!

⚑ Attackers used PipeMagic malware, hidden in MSBuild files, and hijacked legit sites to spread payloads. Linked to RansomEXX gang.

Full report πŸ‘‰ https://thehackernews.com/2025/04/pipemagic-trojan-exploits-windows-clfs.html

πŸ”’ Patch ASAP if you haven't!
πŸ”₯19πŸ‘6😱5😁1πŸ€”1
🚨 New CISA Alert!

Gladinet CentreStack flaw (CVE-2025-30406, CVSS 9.0) is actively exploited.

▢️ Hard-coded machineKey enables remote code execution.
▢️ Exploited as a zero-day in March 2025.

πŸ”— Details: https://thehackernews.com/2025/04/cisa-warns-of-centrestacks-hard-coded.html

Patch or rotate keys now.
πŸ‘10πŸ€”5
⚑ New Malware Alert!

Chinese-linked ToddyCat exploited an ESET flaw (CVE-2024-11859) to drop new malware TCESB β€” bypassing defenses and hijacking devices.

Update now | Stay alert.

Details πŸ‘‰https://thehackernews.com/2025/04/new-tcesb-malware-found-in-active.html
😁11πŸ‘6πŸ€”3
πŸ”₯ Non-human identities (NHIs) are exploding β€” and leaking secrets faster than ever.

In 2024:
β€’ 23.77M secrets leaked on GitHub (+25%)
β€’ NHIs outnumber humans 45-to-1
β€’ 70% of leaked secrets still active
β€’ Private repos = 8x more leaks than public
β€’ Copilot = 40% more leaks
β€’ Docker Hub = 100K+ valid secrets exposed

The attack surface is out of control. Secrets management must evolveβ€”fast.

πŸ”Ž Full 2025 Report: https://thehackernews.com/2025/04/explosive-growth-of-non-human.html
πŸ‘11πŸ”₯2
πŸ”₯ AI scams just leveled up.

Lovable AI scored 1.8/10 on Guardio Labs' security testβ€”the easiest tool for cybercrooks to build phishing sites in minutes.

πŸ‘€ It auto-deploys fake Microsoft pages, steals credentials, and even sets up admin dashboards.

Learn more: https://thehackernews.com/2025/04/lovable-ai-found-most-vulnerable-to.html
πŸ‘20πŸ”₯5πŸ‘5
🚨 AkiraBot has attacked 420,000 domains, using OpenAI’s GPT-4o-mini to flood contact forms and chats with SEO spam β€” even beating CAPTCHA.

πŸ”₯ Targets include Shopify, Wix, GoDaddy, and Squarespace. Nobody's safe.

Learn more: https://thehackernews.com/2025/04/akirabot-targets-420000-sites-with.html
😁24πŸ‘10πŸ”₯7🀯1
🚨 Europol's Operation Endgame just busted 5+ SmokeLoader customers linked to ransomware, spyware, and crypto theft.

Meanwhile, new malware loaders like ModiLoader, GootLoader, and FakeUpdates are hitting users with phishing, fake installs, and drive-by attacks.

πŸ”— Full story: https://thehackernews.com/2025/04/europol-arrests-five-smokeloader.html
πŸ‘14😁4πŸ€”2πŸ‘1🀯1
πŸ”₯ Gamaredon (aka Shuckworm) hit a Western military mission in Ukraine with a new, stealthier GammaSteel malware, Symantec warns.

πŸ“‚ Infected USBs β†’ Hidden shortcut traps β†’ Live exfil via Telegram & Telegraph.

πŸ”— Full story: https://thehackernews.com/2025/04/gamaredon-uses-infected-removable.html
πŸ‘16😁5😱3
🎲 53% of #DevSecOps teams are gambling with open source security.

New 2025 report from ActiveState reveals:

β†’ Risky workflows
β†’ Sluggish MTTD/MTTR
β†’ Traditional tools are failing fast

Ready to fix fasterβ€”without falling behind?

πŸ”—Read now β†’ https://thn.news/vuln-management-2025
😁9πŸ€”4πŸ‘3πŸ”₯2
🚨 New npm malware alert: pdf-to-office targets Atomic and Exodus wallets.

➑️ Injects malicious code to hijack crypto transfers.
➑️ Malware persists even after uninstalling.
➑️ 334+ downloads so far.

Supply chain attacks are rising.

Full report: https://thehackernews.com/2025/04/malicious-npm-package-targets-atomic.html
πŸ‘9πŸ‘4⚑3🀯3
AI agents aren’t just "tools" anymore β€” they're your new workforce.

But behind every agent is a non-human identity (NHI) β€” and that's where real risks live.

πŸ”’ Machine-speed attacks
πŸ”’ Invisible backdoors (Shadow AI)
πŸ”’ Cross-system breaches

Learn how to secure AI at the source βž” https://thehackernews.com/2025/04/the-identities-behind-ai-agents-deep.html
πŸ‘9
CTM360 just uncovered 16,000+ malicious Android URLs tied to the evolving PlayPraetor campaign.

πŸ›‘οΈ 5 new variants (Phish, RAT, PWA, Phantom, Veil) now target banking, tech, and energy users globally.

The threat is expanding fast.

Read the full report: https://thehackernews.com/2025/04/playpraetor-reloaded-ctm360-uncovers.html
πŸ‘9πŸ‘1😁1
🚨 NVIDIA’s critical security fix failed!

NVIDIA’s patch for CVE-2024-0132 (CVSS 9.0) was incomplete β€” attackers can still escape containers and gain root access (CVE-2025-23359).

πŸ‘€ Admins: Threat actors are watching...
βœ… Patch now
βœ… Audit your containers
βœ… Lock down Docker APIs

Full report βž” https://thehackernews.com/2025/04/incomplete-patch-in-nvidia-toolkit.html
😱23πŸ‘6πŸ”₯6🀯6πŸ€”4
ALERT β€” A critical OttoKit plugin flaw (CVE-2025-3102) is under active attack: 100K+ WordPress sites at risk.

Hackers can create admin accounts and fully take over vulnerable sites.

Check admin users β†’ Remove any suspicious accounts.

πŸ‘‰ Full details: https://thehackernews.com/2025/04/ottokit-wordpress-plugin-admin-creation.html

If you use OttoKit, update to v1.0.79 NOW.
πŸ€”11πŸ‘6🀯3
⚑ Mobile Malware Alert β€” Cybersecurity researchers warn of rising threats from SpyNote, BadBazaar, and MOONSHINE malware.

➑️ SpyNote exploits fake Google Play pages to hijack Android devices β€” stealing data, mic, and camera access.

➑️ BadBazaar and MOONSHINE target Tibetan, Uyghur, and Taiwanese communities β€” tied to Chinese APT groups.

πŸ”— Full report: https://thehackernews.com/2025/04/spynote-badbazaar-moonshine-malware.html
πŸ‘7πŸ€”4
🚨 23,958 IPs. 5 countries. 1 target.

Palo Alto Networks' GlobalProtect portals are under coordinated brute-force login attacksβ€”no vulnerability yet, but the threat is real.

Urgent:
βœ… Update PAN-OS
βœ… Enforce MFA
βœ… Harden your portals

πŸ”— Full story: https://thehackernews.com/2025/04/palo-alto-networks-warns-of-brute-force.html
πŸ”₯10πŸ‘3😁2😱2
πŸ”₯ Cyberattacks are scaling like startups β€” thanks to Initial Access Brokers (IABs).

πŸ”Ή In 2024, 58% of hacked access sells for under $1K.
πŸ”Ή Target sectors are widening β€” no one’s safe.
πŸ”Ή USA, Brazil, France top the hit list.

Cheaper access = faster, wider cyberattacks.

Details + defense tips πŸ‘‰ https://thehackernews.com/2025/04/initial-access-brokers-shift-tactics.html
πŸ‘19😁3
🚨 Paper Werewolf (aka GOFFEE) is hitting Russian government, energy, and media sectors with a stealthy new weapon β†’ PowerModul.

It hijacks systems via fake Word/PDF files β†’ deploys PowerShell malware β†’ pivots with Mythic agents.

Read: https://thehackernews.com/2025/04/paper-werewolf-deploys-powermodul.html
πŸ€”19πŸ‘6⚑4😱3😁1
⚑ Even patching won't save you.

Fortinet confirms attackers kept read-only access to FortiGate devices after patching old flaws (CVE-2022-42475, CVE-2023-27997, CVE-2024-21762) via hidden symlink in SSL-VPN.

Full details πŸ‘‰ https://thehackernews.com/2025/04/fortinet-warns-attackers-retain.html
😁29πŸ‘16🀯15πŸ”₯6πŸ‘5⚑2