The Hacker News
βœ”
151K subscribers
1.86K photos
10 videos
3 files
7.77K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
⚑ New Malware Alert!

Chinese-linked ToddyCat exploited an ESET flaw (CVE-2024-11859) to drop new malware TCESB β€” bypassing defenses and hijacking devices.

Update now | Stay alert.

Details πŸ‘‰https://thehackernews.com/2025/04/new-tcesb-malware-found-in-active.html
😁11πŸ‘6πŸ€”3
πŸ”₯ Non-human identities (NHIs) are exploding β€” and leaking secrets faster than ever.

In 2024:
β€’ 23.77M secrets leaked on GitHub (+25%)
β€’ NHIs outnumber humans 45-to-1
β€’ 70% of leaked secrets still active
β€’ Private repos = 8x more leaks than public
β€’ Copilot = 40% more leaks
β€’ Docker Hub = 100K+ valid secrets exposed

The attack surface is out of control. Secrets management must evolveβ€”fast.

πŸ”Ž Full 2025 Report: https://thehackernews.com/2025/04/explosive-growth-of-non-human.html
πŸ‘11πŸ”₯2
πŸ”₯ AI scams just leveled up.

Lovable AI scored 1.8/10 on Guardio Labs' security testβ€”the easiest tool for cybercrooks to build phishing sites in minutes.

πŸ‘€ It auto-deploys fake Microsoft pages, steals credentials, and even sets up admin dashboards.

Learn more: https://thehackernews.com/2025/04/lovable-ai-found-most-vulnerable-to.html
πŸ‘20πŸ”₯5πŸ‘5
🚨 AkiraBot has attacked 420,000 domains, using OpenAI’s GPT-4o-mini to flood contact forms and chats with SEO spam β€” even beating CAPTCHA.

πŸ”₯ Targets include Shopify, Wix, GoDaddy, and Squarespace. Nobody's safe.

Learn more: https://thehackernews.com/2025/04/akirabot-targets-420000-sites-with.html
😁24πŸ‘10πŸ”₯7🀯1
🚨 Europol's Operation Endgame just busted 5+ SmokeLoader customers linked to ransomware, spyware, and crypto theft.

Meanwhile, new malware loaders like ModiLoader, GootLoader, and FakeUpdates are hitting users with phishing, fake installs, and drive-by attacks.

πŸ”— Full story: https://thehackernews.com/2025/04/europol-arrests-five-smokeloader.html
πŸ‘14😁4πŸ€”2πŸ‘1🀯1
πŸ”₯ Gamaredon (aka Shuckworm) hit a Western military mission in Ukraine with a new, stealthier GammaSteel malware, Symantec warns.

πŸ“‚ Infected USBs β†’ Hidden shortcut traps β†’ Live exfil via Telegram & Telegraph.

πŸ”— Full story: https://thehackernews.com/2025/04/gamaredon-uses-infected-removable.html
πŸ‘16😁5😱3
🎲 53% of #DevSecOps teams are gambling with open source security.

New 2025 report from ActiveState reveals:

β†’ Risky workflows
β†’ Sluggish MTTD/MTTR
β†’ Traditional tools are failing fast

Ready to fix fasterβ€”without falling behind?

πŸ”—Read now β†’ https://thn.news/vuln-management-2025
😁9πŸ€”4πŸ‘3πŸ”₯2
🚨 New npm malware alert: pdf-to-office targets Atomic and Exodus wallets.

➑️ Injects malicious code to hijack crypto transfers.
➑️ Malware persists even after uninstalling.
➑️ 334+ downloads so far.

Supply chain attacks are rising.

Full report: https://thehackernews.com/2025/04/malicious-npm-package-targets-atomic.html
πŸ‘9πŸ‘4⚑3🀯3
AI agents aren’t just "tools" anymore β€” they're your new workforce.

But behind every agent is a non-human identity (NHI) β€” and that's where real risks live.

πŸ”’ Machine-speed attacks
πŸ”’ Invisible backdoors (Shadow AI)
πŸ”’ Cross-system breaches

Learn how to secure AI at the source βž” https://thehackernews.com/2025/04/the-identities-behind-ai-agents-deep.html
πŸ‘9
CTM360 just uncovered 16,000+ malicious Android URLs tied to the evolving PlayPraetor campaign.

πŸ›‘οΈ 5 new variants (Phish, RAT, PWA, Phantom, Veil) now target banking, tech, and energy users globally.

The threat is expanding fast.

Read the full report: https://thehackernews.com/2025/04/playpraetor-reloaded-ctm360-uncovers.html
πŸ‘9πŸ‘1😁1
🚨 NVIDIA’s critical security fix failed!

NVIDIA’s patch for CVE-2024-0132 (CVSS 9.0) was incomplete β€” attackers can still escape containers and gain root access (CVE-2025-23359).

πŸ‘€ Admins: Threat actors are watching...
βœ… Patch now
βœ… Audit your containers
βœ… Lock down Docker APIs

Full report βž” https://thehackernews.com/2025/04/incomplete-patch-in-nvidia-toolkit.html
😱23πŸ‘6πŸ”₯6🀯6πŸ€”4
ALERT β€” A critical OttoKit plugin flaw (CVE-2025-3102) is under active attack: 100K+ WordPress sites at risk.

Hackers can create admin accounts and fully take over vulnerable sites.

Check admin users β†’ Remove any suspicious accounts.

πŸ‘‰ Full details: https://thehackernews.com/2025/04/ottokit-wordpress-plugin-admin-creation.html

If you use OttoKit, update to v1.0.79 NOW.
πŸ€”11πŸ‘6🀯3
⚑ Mobile Malware Alert β€” Cybersecurity researchers warn of rising threats from SpyNote, BadBazaar, and MOONSHINE malware.

➑️ SpyNote exploits fake Google Play pages to hijack Android devices β€” stealing data, mic, and camera access.

➑️ BadBazaar and MOONSHINE target Tibetan, Uyghur, and Taiwanese communities β€” tied to Chinese APT groups.

πŸ”— Full report: https://thehackernews.com/2025/04/spynote-badbazaar-moonshine-malware.html
πŸ‘7πŸ€”4
🚨 23,958 IPs. 5 countries. 1 target.

Palo Alto Networks' GlobalProtect portals are under coordinated brute-force login attacksβ€”no vulnerability yet, but the threat is real.

Urgent:
βœ… Update PAN-OS
βœ… Enforce MFA
βœ… Harden your portals

πŸ”— Full story: https://thehackernews.com/2025/04/palo-alto-networks-warns-of-brute-force.html
πŸ”₯10πŸ‘3😁2😱2
πŸ”₯ Cyberattacks are scaling like startups β€” thanks to Initial Access Brokers (IABs).

πŸ”Ή In 2024, 58% of hacked access sells for under $1K.
πŸ”Ή Target sectors are widening β€” no one’s safe.
πŸ”Ή USA, Brazil, France top the hit list.

Cheaper access = faster, wider cyberattacks.

Details + defense tips πŸ‘‰ https://thehackernews.com/2025/04/initial-access-brokers-shift-tactics.html
πŸ‘19😁3
🚨 Paper Werewolf (aka GOFFEE) is hitting Russian government, energy, and media sectors with a stealthy new weapon β†’ PowerModul.

It hijacks systems via fake Word/PDF files β†’ deploys PowerShell malware β†’ pivots with Mythic agents.

Read: https://thehackernews.com/2025/04/paper-werewolf-deploys-powermodul.html
πŸ€”19πŸ‘6⚑4😱3😁1
⚑ Even patching won't save you.

Fortinet confirms attackers kept read-only access to FortiGate devices after patching old flaws (CVE-2022-42475, CVE-2023-27997, CVE-2024-21762) via hidden symlink in SSL-VPN.

Full details πŸ‘‰ https://thehackernews.com/2025/04/fortinet-warns-attackers-retain.html
😁29πŸ‘16🀯15πŸ”₯6πŸ‘5⚑2
🚨 New cyber threat alert!

Pakistan-linked hackers are ramping up attacks on India's oil, railways, and external affairs sectors using Xeno RAT, Spark RAT, and new malware CurlBack RAT.

They're now using MSI packagesβ€”ditching old methodsβ€”to steal browser data, files, and credentials across Windows & Linux.

Find details here: https://thehackernews.com/2025/04/pakistan-linked-hackers-expand-targets.html
😁19πŸ”₯10πŸ‘7πŸ€”4πŸ‘1
AI is already rewriting cybersecurityβ€”and most defenders are unprepared.

Hackers are using AI to automate attacks in minutes, while security teams still react manually.

The new arms race isn’t humans vs. humans.

It’s AI vs. AI.

Learn more β†’ https://thehackernews.com/2025/04/cybersecurity-in-ai-era-evolve-faster.html
πŸ‘25🀯10😁8πŸ”₯7
πŸ”₯ Defenses can fail. Trusted tools can turn.

This week's newsletter covers how breaches happen before you even know they're possible.

⚑ Read and prepare β†’ https://thehackernews.com/2025/04/weekly-recap-windows-0-day-vpn-exploits.html
πŸ”₯14πŸ‘7
🚨 Precision-targeted attacks are validating emails in real-time before stealing credentials.

πŸ” Only verified, high-value accounts see fake login screens. No email? You’re redirected to Wikipedia to dodge detection.

Learn more: https://thehackernews.com/2025/04/phishing-campaigns-use-real-time-checks.html
πŸ‘23😁6😱1