The Hacker News
โœ”
151K subscribers
1.86K photos
10 videos
3 files
7.77K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: [email protected]

๐ŸŒ Website: https://thehackernews.com
Download Telegram
๐Ÿ›‘ Critical SAP Exploit Alert!

Hackers are abusing a flaw in SAP NetWeaver to drop JSP web shellsโ€”even fully patched systems are hit.

Likely tied to CVE-2025-31324 (CVSS 10.0) | Allows unauthenticated file uploads via /metadatauploader.

Details โ†’ https://thehackernews.com/2025/04/sap-confirms-critical-netweaver-flaw.html
๐Ÿ‘18โšก4๐Ÿ˜3๐Ÿ”ฅ2
๐Ÿ”ฅ Machines are talking. And they hold the keys.

70% of leaked secrets still work. NHIs outnumber humans 100:1 โ€” no MFA, no alerts, no control.

Most teams donโ€™t know where these secrets are, or whoโ€™s using them.

๐Ÿ‘€ Time to find the risks. Fix them. Before itโ€™s too late.

See how: https://thehackernews.com/2025/04/why-nhis-are-securitys-most-dangerous.html
๐Ÿ‘13๐Ÿค”4๐Ÿ˜ฑ3
๐Ÿ”ฅ Fake jobs, real danger.

North Korean hackers are posing as crypto firms to lure devs into malware traps.

๐Ÿ”น3 fronts: BlockNovas, Angeloper, SoftGlide
๐Ÿ”น3 Malware: BeaverTail, InvisibleFerret, OtterCookie ๐Ÿ”น3 Target: Your wallet, data & trust.

Read: https://thehackernews.com/2025/04/north-korean-hackers-spread-malware-via.html
๐Ÿ‘31๐Ÿคฏ10๐Ÿ˜3๐Ÿ‘2๐Ÿค”2
A stealthy hacker-for-hire ToyMaker is selling access to top targets โ€” leading straight to CACTUS ransomware attacks.

๐Ÿ’ฐ They scan, hack, and hand over.
๐Ÿ› ๏ธ Malware: LAGTOY

These brokers are speeding up ransomware ops. No espionage, just cash.

Learn more: https://thehackernews.com/2025/04/toymaker-uses-lagtoy-to-sell-access-to.html
๐Ÿคฏ27๐Ÿ‘14๐Ÿค”5๐Ÿ”ฅ3
๐Ÿ‘€ Hackers are mining crypto in the cloudโ€”on your dime.

Microsoft uncovered Storm-1977 targeting education sector cloud accounts via password spraying.

They used AzureChecker.exe, hijacked guest accounts, spun up 200+ containers, and ran illicit crypto mining.

โš ๏ธ Time to lock it down.

๐Ÿ‘‰ Learn more: https://thehackernews.com/2025/04/storm-1977-hits-education-clouds-with.html
๐Ÿ‘23๐Ÿ”ฅ10๐Ÿ˜7
๐Ÿšจ 13,000+ sites at risk.

Hackers are actively exploiting 2 zero-days in Craft CMS, hitting servers via image tools. One flaw scores 10.0 CVSSโ€”worst possible. Nearly 300 sites likely breached already.

Watch for POST hits to "/actions/assets/generate-transform"

๐Ÿ”— Details: https://thehackernews.com/2025/04/hackers-exploit-critical-craft-cms.html

๐Ÿ‘€ Patch now. Rotate keys. Check logs.
๐Ÿ‘15๐Ÿ˜ฑ11๐Ÿคฏ4
โš ๏ธ Think you're installing a security patch? Think again.

Hackers are luring WordPress site owners with fake WooCommerce alerts urging a โ€œcritical patchโ€ download โ€” but itโ€™s a trap. The download creates a hidden admin account, installs web shells, and gives attackers full control.

Full story โ€”https://thehackernews.com/2025/04/woocommerce-users-targeted-by-fake.html
๐Ÿ˜20๐Ÿคฏ8๐Ÿ‘7๐Ÿ˜ฑ4๐Ÿค”1
๐Ÿ‘€ New APT Earth Kurma is spying on Southeast Asiaโ€™s top sectorsโ€”hidden in plain sight.

Since June 2024, ๐Ÿ‡ต๐Ÿ‡ญ ๐Ÿ‡ป๐Ÿ‡ณ ๐Ÿ‡น๐Ÿ‡ญ ๐Ÿ‡ฒ๐Ÿ‡พ govts & telcos face custom malware, rootkits, & data theft via Dropbox/OneDrive.

Hackers use legit tools (LotL), making detection hard.

๐Ÿ”— Learn more: https://thehackernews.com/2025/04/earth-kurma-targets-southeast-asia-with.html
๐Ÿ‘16๐Ÿ‘5๐Ÿ˜3๐Ÿค”2๐Ÿคฏ1
๐Ÿ’ป Your weakest link could cost you everything!

Hackers donโ€™t need big bugsโ€”small oversights cause massive breaches.

Intruder found:
๐Ÿ”ธA 302 redirect = AWS key theft
๐Ÿ”ธAn exposed .git = DB takeover
๐Ÿ”ธMetadata flaw = Remote access

Scan before they strike โ†’ https://thehackernews.com/2025/04/how-breaches-start-breaking-down-5-real.html
๐Ÿ‘12๐Ÿ‘3๐Ÿ˜2
โšก What keeps CISOs awake at night this week?

๐Ÿ”ธ 0-days exploited before patches hit.
๐Ÿ”ธ AI turning low-skill attackers into high-impact threats.
๐Ÿ”ธ Identity systems being used against us โ€” again.

Security today demands strategic clarity.
Every vulnerability is an opportunity for attackers.
Every delay? A risk.

We have summarized last weekโ€™s top threats.

Read โ€” https://thehackernews.com/2025/04/weekly-recap-critical-sap-exploit-ai.html
๐Ÿ‘8โšก7๐Ÿ”ฅ5๐Ÿ˜3๐Ÿค”1
๐Ÿšจ CISA Alert: Two critical flaws โ€” in Broadcom Fabric OS (CVE-2025-1976) and Commvault Web Server (CVE-2025-3928) โ€” are now on the Known Exploited Vulnerabilities (KEV) list.

๐Ÿ”น Both bugs are actively exploited.
๐Ÿ”น Admin access can lead to full system compromise.
๐Ÿ”น Patching deadlines: May 17โ€“19, 2025.

๐Ÿ‘‰ Details: https://thehackernews.com/2025/04/cisa-adds-actively-exploited-broadcom.html
๐Ÿ‘19
๐Ÿ”ฅ New Cyber Attack Alert!

Senior members of the World Uyghur Congress were targeted by malware hidden in a fake UyghurEdit++ app, Citizen Lab reports (Mar 2025).

โ€” Custom-made spyware
โ€” Links to China
โ€” Started as early as May 2024

Learn more: https://thehackernews.com/2025/04/malware-attack-targets-world-uyghur.html
๐Ÿ‘15๐Ÿค”9๐Ÿ˜3๐Ÿคฏ2
๐Ÿ”’ Still trusting VPNs to secure remote access?

Recent critical flaws exposed thousands. Every open port and IP address is now a target, not a tool.

Legacy network security can't keep up with AI-driven attacks.

Zero Trust isnโ€™t optional anymore โ€” itโ€™s survival.

Learn why it matters โ†’ https://thehackernews.com/expert-insights/2025/04/its-time-to-rethink-your-security-for.html
๐Ÿ‘15๐Ÿค”7๐Ÿ˜ฑ5
๐Ÿ”ฅ 75 zero-day exploits hit in 2024 | 44% aimed at enterprise tools.

While browser & mobile attacks fell sharply, threat actors shifted focus โ€” hitting Ivanti, Palo Alto, Cisco & others.

๐Ÿ“Š Top targets: Microsoft (26), Google (11), Ivanti (7), Apple (5)
๐ŸŽฏ 20 zero-days hit security appliances
๐Ÿ•ต๏ธโ€โ™‚๏ธ State hackers, spyware firms & cybercrime crews all involved

Read the full story โ†’ https://thehackernews.com/2025/04/google-reports-75-zero-days-exploited.html
๐Ÿ‘10๐Ÿ˜2๐Ÿค”1
โšก Your AI Copilot could leak your secrets โ€” without you even knowing.

Microsoft 365 Copilot boosts productivity, but opens the door to massive data risks. Reco spots risky prompts, flags hidden attacks, and locks down your SaaS ecosystem.

Learn how: https://thehackernews.com/2025/04/product-walkthrough-securing-microsoft.html
โšก16๐Ÿ‘6๐Ÿ˜ฑ3
๐Ÿšจ Cybersecurity firms are under attack!

๐Ÿ‡จ๐Ÿ‡ณ Chinaโ€™s PurpleHaze hackers targeted SentinelOneโ€™s systems and high-value customers.

๐ŸŽญ 360+ fake North Korean IT workers tried to infiltrate the company.

๐Ÿ‡ท๐Ÿ‡บ Russian ransomware gangs are buying real security products to beat defenses.

Read ๐Ÿ‘‰https://thehackernews.com/2025/04/sentinelone-uncovers-chinese-espionage.html
๐Ÿ˜16๐Ÿ‘6๐Ÿ”ฅ5๐Ÿ‘3
๐Ÿšจ New jailbreaks ("Inception", "Do-Not-Reply"), memory hacks, tool poisoning, unsafe model upgrades โ€” CERT, METR, and others warn:

โšก ChatGPT, Claude, Copilot, Gemini, Grok, Meta AI can leak code, malware, data.
โšก GPT-4.1 is 3X riskier than before.
โšก MCP protocols, Chrome extensions now exploited.

The AI arms race is outpacing safety.

Read: https://thehackernews.com/2025/04/new-reports-uncover-jailbreaks-unsafe.html
๐Ÿ‘16โšก2
๐Ÿ”ฅ Privacy vs AI?

WhatsApp just dropped Private Processingโ€”letting you use AI features like message summaries without Meta (or anyone) seeing your chats.

๐Ÿ›ก๏ธ Encrypted. Auditable. Anonymous.

โ€” Confidential Virtual Machine
โ€” Oblivious HTTP
โ€” Forward Security

๐Ÿ”— Learn how it works: https://thehackernews.com/2025/04/whatsapp-launches-private-processing-to.html
๐Ÿค”23๐Ÿ‘11๐Ÿ˜9โšก1
๐Ÿšจ Proton Mail faces nationwide ban in India ๐Ÿ‡ฎ๐Ÿ‡ณ

Karnataka High Court has ordered the govโ€™t to block the encrypted email provider after a legal complaint tied to AI deepfakes and obscene messages sent via the platform.

๐Ÿ”’ Still accessibleโ€”for now.

Read: https://thehackernews.com/2025/04/indian-court-orders-action-to-block.html
๐Ÿ˜33๐Ÿ˜ฑ19๐Ÿ‘6๐Ÿค”5๐Ÿ‘3๐Ÿคฏ3
๐Ÿ”ฅ Meta just dropped a firewall for AI.

LlamaFirewall is open-sourceโ€”and built to stop jailbreaks, prompt injections, and insecure code in real time.

Itโ€™s modular. Itโ€™s fast. Itโ€™s made for the LLM era.

๐Ÿ›ก๏ธ Also out:
๐Ÿ”น CyberSecEval 4 with AutoPatchBench to test AI-powered vuln fixes
๐Ÿ”น Llama for Defenders to help fight scams, fraud & phishing
๐Ÿ”น Private Processing to run AI features without leaking user data

๐Ÿ”— Full details here: https://thehackernews.com/2025/04/meta-launches-llamafirewall-framework.html
๐Ÿ‘27๐Ÿ”ฅ7๐Ÿ˜5๐Ÿค”4๐Ÿ‘3๐Ÿ˜ฑ1
๐Ÿšจ RansomHub's empire just vanished.

After stealing data from 200+ victims, its dark web site mysteriously went offline on April 1, 2025โ€”triggering panic among affiliates.

Qilin's leaks doubled. DragonForce claims a takeover.

๐Ÿ”— Read More: https://thehackernews.com/2025/04/ransomhub-went-dark-april-1-affiliates.html
๐Ÿ‘11๐Ÿ˜5