A stealthy hacker-for-hire ToyMaker is selling access to top targets โ leading straight to CACTUS ransomware attacks.
๐ฐ They scan, hack, and hand over.
๐ ๏ธ Malware: LAGTOY
These brokers are speeding up ransomware ops. No espionage, just cash.
Learn more: https://thehackernews.com/2025/04/toymaker-uses-lagtoy-to-sell-access-to.html
๐ฐ They scan, hack, and hand over.
๐ ๏ธ Malware: LAGTOY
These brokers are speeding up ransomware ops. No espionage, just cash.
Learn more: https://thehackernews.com/2025/04/toymaker-uses-lagtoy-to-sell-access-to.html
๐คฏ27๐14๐ค5๐ฅ3
๐ Hackers are mining crypto in the cloudโon your dime.
Microsoft uncovered Storm-1977 targeting education sector cloud accounts via password spraying.
They used AzureChecker.exe, hijacked guest accounts, spun up 200+ containers, and ran illicit crypto mining.
โ ๏ธ Time to lock it down.
๐ Learn more: https://thehackernews.com/2025/04/storm-1977-hits-education-clouds-with.html
Microsoft uncovered Storm-1977 targeting education sector cloud accounts via password spraying.
They used AzureChecker.exe, hijacked guest accounts, spun up 200+ containers, and ran illicit crypto mining.
โ ๏ธ Time to lock it down.
๐ Learn more: https://thehackernews.com/2025/04/storm-1977-hits-education-clouds-with.html
๐23๐ฅ10๐7
๐จ 13,000+ sites at risk.
Hackers are actively exploiting 2 zero-days in Craft CMS, hitting servers via image tools. One flaw scores 10.0 CVSSโworst possible. Nearly 300 sites likely breached already.
Watch for POST hits to "/actions/assets/generate-transform"
๐ Details: https://thehackernews.com/2025/04/hackers-exploit-critical-craft-cms.html
๐ Patch now. Rotate keys. Check logs.
Hackers are actively exploiting 2 zero-days in Craft CMS, hitting servers via image tools. One flaw scores 10.0 CVSSโworst possible. Nearly 300 sites likely breached already.
Watch for POST hits to "/actions/assets/generate-transform"
๐ Details: https://thehackernews.com/2025/04/hackers-exploit-critical-craft-cms.html
๐ Patch now. Rotate keys. Check logs.
๐15๐ฑ11๐คฏ4
โ ๏ธ Think you're installing a security patch? Think again.
Hackers are luring WordPress site owners with fake WooCommerce alerts urging a โcritical patchโ download โ but itโs a trap. The download creates a hidden admin account, installs web shells, and gives attackers full control.
Full story โhttps://thehackernews.com/2025/04/woocommerce-users-targeted-by-fake.html
Hackers are luring WordPress site owners with fake WooCommerce alerts urging a โcritical patchโ download โ but itโs a trap. The download creates a hidden admin account, installs web shells, and gives attackers full control.
Full story โhttps://thehackernews.com/2025/04/woocommerce-users-targeted-by-fake.html
๐20๐คฏ8๐7๐ฑ4๐ค1
๐ New APT Earth Kurma is spying on Southeast Asiaโs top sectorsโhidden in plain sight.
Since June 2024, ๐ต๐ญ ๐ป๐ณ ๐น๐ญ ๐ฒ๐พ govts & telcos face custom malware, rootkits, & data theft via Dropbox/OneDrive.
Hackers use legit tools (LotL), making detection hard.
๐ Learn more: https://thehackernews.com/2025/04/earth-kurma-targets-southeast-asia-with.html
Since June 2024, ๐ต๐ญ ๐ป๐ณ ๐น๐ญ ๐ฒ๐พ govts & telcos face custom malware, rootkits, & data theft via Dropbox/OneDrive.
Hackers use legit tools (LotL), making detection hard.
๐ Learn more: https://thehackernews.com/2025/04/earth-kurma-targets-southeast-asia-with.html
๐16๐5๐3๐ค2๐คฏ1
๐ป Your weakest link could cost you everything!
Hackers donโt need big bugsโsmall oversights cause massive breaches.
Intruder found:
๐ธA 302 redirect = AWS key theft
๐ธAn exposed .git = DB takeover
๐ธMetadata flaw = Remote access
Scan before they strike โ https://thehackernews.com/2025/04/how-breaches-start-breaking-down-5-real.html
Hackers donโt need big bugsโsmall oversights cause massive breaches.
Intruder found:
๐ธA 302 redirect = AWS key theft
๐ธAn exposed .git = DB takeover
๐ธMetadata flaw = Remote access
Scan before they strike โ https://thehackernews.com/2025/04/how-breaches-start-breaking-down-5-real.html
๐12๐3๐2
โก What keeps CISOs awake at night this week?
๐ธ 0-days exploited before patches hit.
๐ธ AI turning low-skill attackers into high-impact threats.
๐ธ Identity systems being used against us โ again.
Security today demands strategic clarity.
Every vulnerability is an opportunity for attackers.
Every delay? A risk.
We have summarized last weekโs top threats.
Read โ https://thehackernews.com/2025/04/weekly-recap-critical-sap-exploit-ai.html
๐ธ 0-days exploited before patches hit.
๐ธ AI turning low-skill attackers into high-impact threats.
๐ธ Identity systems being used against us โ again.
Security today demands strategic clarity.
Every vulnerability is an opportunity for attackers.
Every delay? A risk.
We have summarized last weekโs top threats.
Read โ https://thehackernews.com/2025/04/weekly-recap-critical-sap-exploit-ai.html
๐8โก7๐ฅ5๐3๐ค1
๐จ CISA Alert: Two critical flaws โ in Broadcom Fabric OS (CVE-2025-1976) and Commvault Web Server (CVE-2025-3928) โ are now on the Known Exploited Vulnerabilities (KEV) list.
๐น Both bugs are actively exploited.
๐น Admin access can lead to full system compromise.
๐น Patching deadlines: May 17โ19, 2025.
๐ Details: https://thehackernews.com/2025/04/cisa-adds-actively-exploited-broadcom.html
๐น Both bugs are actively exploited.
๐น Admin access can lead to full system compromise.
๐น Patching deadlines: May 17โ19, 2025.
๐ Details: https://thehackernews.com/2025/04/cisa-adds-actively-exploited-broadcom.html
๐19
๐ฅ New Cyber Attack Alert!
Senior members of the World Uyghur Congress were targeted by malware hidden in a fake UyghurEdit++ app, Citizen Lab reports (Mar 2025).
โ Custom-made spyware
โ Links to China
โ Started as early as May 2024
Learn more: https://thehackernews.com/2025/04/malware-attack-targets-world-uyghur.html
Senior members of the World Uyghur Congress were targeted by malware hidden in a fake UyghurEdit++ app, Citizen Lab reports (Mar 2025).
โ Custom-made spyware
โ Links to China
โ Started as early as May 2024
Learn more: https://thehackernews.com/2025/04/malware-attack-targets-world-uyghur.html
๐15๐ค9๐3๐คฏ2
๐ Still trusting VPNs to secure remote access?
Recent critical flaws exposed thousands. Every open port and IP address is now a target, not a tool.
Legacy network security can't keep up with AI-driven attacks.
Zero Trust isnโt optional anymore โ itโs survival.
Learn why it matters โ https://thehackernews.com/expert-insights/2025/04/its-time-to-rethink-your-security-for.html
Recent critical flaws exposed thousands. Every open port and IP address is now a target, not a tool.
Legacy network security can't keep up with AI-driven attacks.
Zero Trust isnโt optional anymore โ itโs survival.
Learn why it matters โ https://thehackernews.com/expert-insights/2025/04/its-time-to-rethink-your-security-for.html
๐15๐ค7๐ฑ5
๐ฅ 75 zero-day exploits hit in 2024 | 44% aimed at enterprise tools.
While browser & mobile attacks fell sharply, threat actors shifted focus โ hitting Ivanti, Palo Alto, Cisco & others.
๐ Top targets: Microsoft (26), Google (11), Ivanti (7), Apple (5)
๐ฏ 20 zero-days hit security appliances
๐ต๏ธโโ๏ธ State hackers, spyware firms & cybercrime crews all involved
Read the full story โ https://thehackernews.com/2025/04/google-reports-75-zero-days-exploited.html
While browser & mobile attacks fell sharply, threat actors shifted focus โ hitting Ivanti, Palo Alto, Cisco & others.
๐ Top targets: Microsoft (26), Google (11), Ivanti (7), Apple (5)
๐ฏ 20 zero-days hit security appliances
๐ต๏ธโโ๏ธ State hackers, spyware firms & cybercrime crews all involved
Read the full story โ https://thehackernews.com/2025/04/google-reports-75-zero-days-exploited.html
๐10๐2๐ค1
โก Your AI Copilot could leak your secrets โ without you even knowing.
Microsoft 365 Copilot boosts productivity, but opens the door to massive data risks. Reco spots risky prompts, flags hidden attacks, and locks down your SaaS ecosystem.
Learn how: https://thehackernews.com/2025/04/product-walkthrough-securing-microsoft.html
Microsoft 365 Copilot boosts productivity, but opens the door to massive data risks. Reco spots risky prompts, flags hidden attacks, and locks down your SaaS ecosystem.
Learn how: https://thehackernews.com/2025/04/product-walkthrough-securing-microsoft.html
โก16๐6๐ฑ3
๐จ Cybersecurity firms are under attack!
๐จ๐ณ Chinaโs PurpleHaze hackers targeted SentinelOneโs systems and high-value customers.
๐ญ 360+ fake North Korean IT workers tried to infiltrate the company.
๐ท๐บ Russian ransomware gangs are buying real security products to beat defenses.
Read ๐https://thehackernews.com/2025/04/sentinelone-uncovers-chinese-espionage.html
๐จ๐ณ Chinaโs PurpleHaze hackers targeted SentinelOneโs systems and high-value customers.
๐ญ 360+ fake North Korean IT workers tried to infiltrate the company.
๐ท๐บ Russian ransomware gangs are buying real security products to beat defenses.
Read ๐https://thehackernews.com/2025/04/sentinelone-uncovers-chinese-espionage.html
๐16๐6๐ฅ5๐3
๐จ New jailbreaks ("Inception", "Do-Not-Reply"), memory hacks, tool poisoning, unsafe model upgrades โ CERT, METR, and others warn:
โก ChatGPT, Claude, Copilot, Gemini, Grok, Meta AI can leak code, malware, data.
โก GPT-4.1 is 3X riskier than before.
โก MCP protocols, Chrome extensions now exploited.
The AI arms race is outpacing safety.
Read: https://thehackernews.com/2025/04/new-reports-uncover-jailbreaks-unsafe.html
โก ChatGPT, Claude, Copilot, Gemini, Grok, Meta AI can leak code, malware, data.
โก GPT-4.1 is 3X riskier than before.
โก MCP protocols, Chrome extensions now exploited.
The AI arms race is outpacing safety.
Read: https://thehackernews.com/2025/04/new-reports-uncover-jailbreaks-unsafe.html
๐16โก2
๐ฅ Privacy vs AI?
WhatsApp just dropped Private Processingโletting you use AI features like message summaries without Meta (or anyone) seeing your chats.
๐ก๏ธ Encrypted. Auditable. Anonymous.
โ Confidential Virtual Machine
โ Oblivious HTTP
โ Forward Security
๐ Learn how it works: https://thehackernews.com/2025/04/whatsapp-launches-private-processing-to.html
WhatsApp just dropped Private Processingโletting you use AI features like message summaries without Meta (or anyone) seeing your chats.
๐ก๏ธ Encrypted. Auditable. Anonymous.
โ Confidential Virtual Machine
โ Oblivious HTTP
โ Forward Security
๐ Learn how it works: https://thehackernews.com/2025/04/whatsapp-launches-private-processing-to.html
๐ค23๐11๐9โก1
๐จ Proton Mail faces nationwide ban in India ๐ฎ๐ณ
Karnataka High Court has ordered the govโt to block the encrypted email provider after a legal complaint tied to AI deepfakes and obscene messages sent via the platform.
๐ Still accessibleโfor now.
Read: https://thehackernews.com/2025/04/indian-court-orders-action-to-block.html
Karnataka High Court has ordered the govโt to block the encrypted email provider after a legal complaint tied to AI deepfakes and obscene messages sent via the platform.
๐ Still accessibleโfor now.
Read: https://thehackernews.com/2025/04/indian-court-orders-action-to-block.html
๐33๐ฑ19๐6๐ค5๐3๐คฏ3
๐ฅ Meta just dropped a firewall for AI.
LlamaFirewall is open-sourceโand built to stop jailbreaks, prompt injections, and insecure code in real time.
Itโs modular. Itโs fast. Itโs made for the LLM era.
๐ก๏ธ Also out:
๐น CyberSecEval 4 with AutoPatchBench to test AI-powered vuln fixes
๐น Llama for Defenders to help fight scams, fraud & phishing
๐น Private Processing to run AI features without leaking user data
๐ Full details here: https://thehackernews.com/2025/04/meta-launches-llamafirewall-framework.html
LlamaFirewall is open-sourceโand built to stop jailbreaks, prompt injections, and insecure code in real time.
Itโs modular. Itโs fast. Itโs made for the LLM era.
๐ก๏ธ Also out:
๐น CyberSecEval 4 with AutoPatchBench to test AI-powered vuln fixes
๐น Llama for Defenders to help fight scams, fraud & phishing
๐น Private Processing to run AI features without leaking user data
๐ Full details here: https://thehackernews.com/2025/04/meta-launches-llamafirewall-framework.html
๐27๐ฅ7๐5๐ค4๐3๐ฑ1
๐จ RansomHub's empire just vanished.
After stealing data from 200+ victims, its dark web site mysteriously went offline on April 1, 2025โtriggering panic among affiliates.
Qilin's leaks doubled. DragonForce claims a takeover.
๐ Read More: https://thehackernews.com/2025/04/ransomhub-went-dark-april-1-affiliates.html
After stealing data from 200+ victims, its dark web site mysteriously went offline on April 1, 2025โtriggering panic among affiliates.
Qilin's leaks doubled. DragonForce claims a takeover.
๐ Read More: https://thehackernews.com/2025/04/ransomhub-went-dark-april-1-affiliates.html
๐11๐5
๐จ China-linked APT โTheWizardsโ caught hijacking trusted Chinese apps to deploy malware updates.
Uses IPv6/DNS to turn Sogou Pinyin & Tencent QQ into WizardNet backdoor delivery for users in ๐จ๐ณ๐ญ๐ฐ๐ฐ๐ญ๐ต๐ญ๐ฆ๐ช.
๐ Their tool Spellbinder quietly captures traffic, reroutes updates to attacker servers.
๐ Full story: https://thehackernews.com/2025/04/chinese-hackers-abuse-ipv6-slaac-for.html
Uses IPv6/DNS to turn Sogou Pinyin & Tencent QQ into WizardNet backdoor delivery for users in ๐จ๐ณ๐ญ๐ฐ๐ฐ๐ญ๐ต๐ญ๐ฆ๐ช.
๐ Their tool Spellbinder quietly captures traffic, reroutes updates to attacker servers.
๐ Full story: https://thehackernews.com/2025/04/chinese-hackers-abuse-ipv6-slaac-for.html
๐ฅ8๐5๐4
๐ โAll my shows were in Spanish. I didnโt change anything.โ
Thatโs not a glitchโitโs an account takeover.
๐ 100K+ accounts/mo exposed on major platforms.
๐ฎ Streaming, gaming, SaaS vulnerable.
๐ง MFA fails vs. stolen session cookies.
Act now: Monitor infostealers. Reset risk. Rebuild trust.
๐ ReadfFull story + Flareโs ATO report: https://thehackernews.com/2025/04/customer-account-takeovers-multi.html
Thatโs not a glitchโitโs an account takeover.
๐ 100K+ accounts/mo exposed on major platforms.
๐ฎ Streaming, gaming, SaaS vulnerable.
๐ง MFA fails vs. stolen session cookies.
Act now: Monitor infostealers. Reset risk. Rebuild trust.
๐ ReadfFull story + Flareโs ATO report: https://thehackernews.com/2025/04/customer-account-takeovers-multi.html
๐7๐คฏ3
๐จ New Espionage Alert!
A Russian-speaking APT group, Nebulous Mantis, is deploying the stealthy RomCom RAT to target NATO-linked entities, gov agencies, and critical infra โ using bulletproof hosting, IPFS, and over 40 remote commands.
๐ See how it works, whoโs behind it, and why it matters now: https://thehackernews.com/2025/04/nebulous-mantis-targets-nato-linked.html
A Russian-speaking APT group, Nebulous Mantis, is deploying the stealthy RomCom RAT to target NATO-linked entities, gov agencies, and critical infra โ using bulletproof hosting, IPFS, and over 40 remote commands.
๐ See how it works, whoโs behind it, and why it matters now: https://thehackernews.com/2025/04/nebulous-mantis-targets-nato-linked.html
๐14๐6