The Hacker News
βœ”
151K subscribers
1.85K photos
10 videos
3 files
7.77K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
⚠️ Target: Russian Military!

Android.Spy.1292.origin spyware steals data via fake Alpine Quest apps.

β€” Spread via fake Telegram & Rus. app stores
β€” Steals loc., contacts, files
β€” Sends data to Telegram bot, runs hidden malware

Doctor Web says it mimics Alpine Quest Pro, widely used in military zones.

Read: https://thehackernews.com/2025/04/android-spyware-disguised-as-alpine.html

πŸ‘€ Kaspersky found a Windows backdoor in fake ViPNet updates targeting Russian government, finance, and industry.
πŸ‘21😁8🀯4πŸ€”2
πŸ’Ό Dream Job? Or Cyber Trap?

Iranian hackers UNC2428 lured Israelis with fake jobs at defense giant Rafael. Victims downloaded β€œRafaelConnect.exe” β€” a trap that secretly installed the MURKYTOUR backdoor, giving attackers full access.

Read now β†’ https://thehackernews.com/2025/04/iran-linked-hackers-target-israel-with.html
πŸ”₯27🀯7πŸ‘6😁5πŸ€”3πŸ‘1
DPRK hackers are inside Web3β€”stealing crypto to fund WMDs.

In 2023, $137M stolen in 1 day via phishing. In 2024, they used deepfakes to win real jobs & extort firms. 12 fake identities at one US firm alone.

Learn more: https://thehackernews.com/2025/04/dprk-hackers-steal-137m-from-tron-users.html
🀯19😁8πŸ‘4πŸ€”3πŸ‘2
πŸ”’ WhatsApp rolls out Advanced Chat Privacy!

πŸ”Έ Blocks chat exports, auto-downloads, & AI use in sensitive convos.
πŸ”Έ Still allows screenshots & manual media saves.
πŸ”Έ Available now for all users on the latest update.

Update to try it πŸ‘‰ https://thehackernews.com/2025/04/whatsapp-adds-advanced-chat-privacy-to.html
😁29πŸ‘12πŸ€”10🀯2πŸ‘1
πŸ”₯ Critical Exploit Alert!

A 9.0 CVSS flaw in Commvault Command Center lets hackers run code without logging in.

🎯 Targets versions 11.38.0–11.38.19
πŸ’₯ Pre-auth SSRF β†’ Remote Code Execution

Learn more about CVE-2025-34028 here: https://thehackernews.com/2025/04/critical-commvault-command-center-flaw.html
πŸ‘11🀯3😱1
πŸ‘€ 133M patient records breached in 2024. Now, hackers target devices that save livesβ€”not just data.

Zero Trust is mandatory. New HIPAA rules demand it.

Main Line Health secured their network with Armis + Elisityβ€”in hours, not months.

πŸ”’ See how microsegmentation protects both patients & systems: https://thehackernews.com/2025/04/automating-zero-trust-in-healthcare.html
πŸ‘8πŸ€”4😱4😁1
🚨 New Threat Alert: Phishing just got an AI upgrade.

Darcula PhaaS now uses GenAI to help anyone build phishing sites in minutes β€” no tech skills needed. Smishing attacks just leveled up.

Learn more: https://thehackernews.com/2025/04/darcula-adds-genai-to-phishing-toolkit.html
🀯13πŸ‘6😁2
πŸ‘€ New Linux Rootkit Exploits io_uring, Evades Detection

ARMO’s Curing rootkit uses io_uring to bypass system call monitoringβ€”Falco, Tetragon, and even Microsoft Defender can’t see it.

Attackers can run commands without triggering system calls.

Read β†’ https://thehackernews.com/2025/04/linux-iouring-poc-rootkit-bypasses.html
πŸ‘20πŸ€”3
⚠️ 159 Bugs Exploited in 90 Days!

1 in 4 breaches now starts with a CVE exploit. In Q1 2025, 159 flaws hit in the wildβ€”28% within 24 hours of disclosure.

Top targets: CMSes, edge devices, Windows.

πŸ”— Learn more: https://thehackernews.com/2025/04/159-cves-exploited-in-q1-2025-283.html
πŸ‘15⚑6
⚑ Lazarus Group strikes South Koreaβ€”again.

6 major industries breached via watering hole attacks + zero-days in Cross EX & Innorix Agent.
Malware used: ThreatNeedle & more.

πŸ‘€ Supply chains are the target.

Learn more πŸ‘‰ https://thehackernews.com/2025/04/lazarus-hits-6-south-korean-firms-via.html
πŸ”₯18😱8😁6πŸ‘3
The ActiveState team is heading to RSA 2025, and we’re kicking things off with a Zero-Vulnerability Happy Hour! 🍻

πŸ“… When: Tuesday, April 29th @ 6:00 PM
πŸ“ Where: Local Tap SF

Join us for great drinks, meaningful conversations, and networking with DevSecOps leaders. Let’s talk open source security, vulnerability management, and the future of secure software supply chains.

Spaces are limitedβ€”secure your spot today! πŸ‘‰ https://thn.news/zero-vulnerability-rsa-happy-hour

#RSAC2025 #DevSecOps #OpenSource #CyberSecurity #ZeroVulnerability
πŸ‘10πŸ”₯2πŸ‘1
🚨 New Ivanti ICS Attacks Detected!

DslogdRAT malware used in real-world attacks after hackers exploited CVE-2025-0282 (zero-day).

First hit Japan πŸ‡―πŸ‡΅ in Dec 2024 β€” now global scanning surges 9X in 24 hrs.

πŸ”Ή 270+ IPs scanning Ivanti
πŸ”Ή 255 confirmed malicious
πŸ”Ή Top targets: US, Germany, Netherlands

Details: https://thehackernews.com/2025/04/dslogdrat-malware-deployed-via-ivanti.html
😁16πŸ‘3πŸ‘1πŸ€”1
πŸ‘€ Hackers could be one path away from your sensitive files!

🚨 New CVEs expose major flaws in Rack & Infodraw systems:

πŸ”Ή CVE-2025-27610 lets attackers read config files & credentials via path traversal.

πŸ”Ή Infodraw CVE-2025-43928 allows any file to be read or deletedβ€”no login needed.

Learn more: https://thehackernews.com/2025/04/researchers-identify-rackstatic.html

πŸ”₯ Exploits are trivial & patches missing. Systems in Belgium & Luxembourg already hit. Update now or go offline!
πŸ”₯17πŸ‘5πŸ€”1😱1
πŸ›‘ Critical SAP Exploit Alert!

Hackers are abusing a flaw in SAP NetWeaver to drop JSP web shellsβ€”even fully patched systems are hit.

Likely tied to CVE-2025-31324 (CVSS 10.0) | Allows unauthenticated file uploads via /metadatauploader.

Details β†’ https://thehackernews.com/2025/04/sap-confirms-critical-netweaver-flaw.html
πŸ‘18⚑4😁3πŸ”₯2
πŸ”₯ Machines are talking. And they hold the keys.

70% of leaked secrets still work. NHIs outnumber humans 100:1 β€” no MFA, no alerts, no control.

Most teams don’t know where these secrets are, or who’s using them.

πŸ‘€ Time to find the risks. Fix them. Before it’s too late.

See how: https://thehackernews.com/2025/04/why-nhis-are-securitys-most-dangerous.html
πŸ‘13πŸ€”4😱3
πŸ”₯ Fake jobs, real danger.

North Korean hackers are posing as crypto firms to lure devs into malware traps.

πŸ”Ή3 fronts: BlockNovas, Angeloper, SoftGlide
πŸ”Ή3 Malware: BeaverTail, InvisibleFerret, OtterCookie πŸ”Ή3 Target: Your wallet, data & trust.

Read: https://thehackernews.com/2025/04/north-korean-hackers-spread-malware-via.html
πŸ‘31🀯10😁3πŸ‘2πŸ€”2
A stealthy hacker-for-hire ToyMaker is selling access to top targets β€” leading straight to CACTUS ransomware attacks.

πŸ’° They scan, hack, and hand over.
πŸ› οΈ Malware: LAGTOY

These brokers are speeding up ransomware ops. No espionage, just cash.

Learn more: https://thehackernews.com/2025/04/toymaker-uses-lagtoy-to-sell-access-to.html
🀯27πŸ‘14πŸ€”5πŸ”₯3
πŸ‘€ Hackers are mining crypto in the cloudβ€”on your dime.

Microsoft uncovered Storm-1977 targeting education sector cloud accounts via password spraying.

They used AzureChecker.exe, hijacked guest accounts, spun up 200+ containers, and ran illicit crypto mining.

⚠️ Time to lock it down.

πŸ‘‰ Learn more: https://thehackernews.com/2025/04/storm-1977-hits-education-clouds-with.html
πŸ‘23πŸ”₯10😁7
🚨 13,000+ sites at risk.

Hackers are actively exploiting 2 zero-days in Craft CMS, hitting servers via image tools. One flaw scores 10.0 CVSSβ€”worst possible. Nearly 300 sites likely breached already.

Watch for POST hits to "/actions/assets/generate-transform"

πŸ”— Details: https://thehackernews.com/2025/04/hackers-exploit-critical-craft-cms.html

πŸ‘€ Patch now. Rotate keys. Check logs.
πŸ‘15😱11🀯4
⚠️ Think you're installing a security patch? Think again.

Hackers are luring WordPress site owners with fake WooCommerce alerts urging a β€œcritical patch” download β€” but it’s a trap. The download creates a hidden admin account, installs web shells, and gives attackers full control.

Full story β€”https://thehackernews.com/2025/04/woocommerce-users-targeted-by-fake.html
😁20🀯8πŸ‘7😱4πŸ€”1
πŸ‘€ New APT Earth Kurma is spying on Southeast Asia’s top sectorsβ€”hidden in plain sight.

Since June 2024, πŸ‡΅πŸ‡­ πŸ‡»πŸ‡³ πŸ‡ΉπŸ‡­ πŸ‡²πŸ‡Ύ govts & telcos face custom malware, rootkits, & data theft via Dropbox/OneDrive.

Hackers use legit tools (LotL), making detection hard.

πŸ”— Learn more: https://thehackernews.com/2025/04/earth-kurma-targets-southeast-asia-with.html
πŸ‘16πŸ‘5😁3πŸ€”2🀯1