The Hacker News
โœ”
152K subscribers
1.87K photos
10 videos
3 files
7.78K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: [email protected]

๐ŸŒ Website: https://thehackernews.com
Download Telegram
๐Ÿ‘€ Meta vs. Europeโ€”Round 2

Starting May 27, Meta plans to train its AI using Facebook & Instagram user data across the E.U.โ€”without asking for consent.

Privacy watchdog noyb says itโ€™s illegal. A class action may be coming.

Full story: https://thehackernews.com/2025/05/meta-to-train-ai-on-eu-user-data-from.html
๐Ÿ˜15๐Ÿ‘9๐Ÿคฏ5๐Ÿค”3
๐Ÿšซ Your firewall isn't brokenโ€”it's just outdated.

AI-powered attacks are faster than ever. Still exposing your network with public IPs? You're playing defense with a blindfold.

Zscaler's Zero Trust model flips the scriptโ€”no public IPs, no easy targets. It's not magic. It's strategy.

๐Ÿ‘€ The most secure network is the one they can't see.

๐Ÿ”Ž Discover how it works โ†’ https://thehackernews.com/expert-insights/2025/05/eliminating-public-ips-case-for-zero.html
๐Ÿ‘13๐Ÿ”ฅ3๐Ÿค”3
๐Ÿ’ป Spectre Isnโ€™t Dead. Itโ€™s Mutating! New CPU flaw hits ALL modern Intel chips.

๐Ÿ›  Researchers at ETH Zurich and VUSec uncovered Spectre-style Intel CPU flaws (CVE-2024-45332, CVE-2024-28956, CVE-2025-24495) that leak memory across users, guests, and hostsโ€”at rates up to 17KB/sec.

Read details โ†’ https://thehackernews.com/2025/05/researchers-expose-new-intel-cpu-flaws.html

Patches are out. But is this just another Band-Aid?
โšก15๐Ÿ‘7๐Ÿ”ฅ3๐Ÿ‘3
๐Ÿšจ A new Windows-based botnetโ€”HTTPBotโ€”is quietly choking login and payment systems across Chinaโ€™s gaming and tech sectors.

๐Ÿ”ฅ Over 200 targeted attacks since April 2025
๐Ÿง  Mimics real users with Chrome, cookies & HTTP/2

Learn more about this: https://thehackernews.com/2025/05/new-httpbot-botnet-launches-200.html
๐Ÿค”11๐Ÿ˜5๐Ÿคฏ4๐Ÿ‘3๐Ÿ‘2
๐Ÿ”’ What if your most sensitive data is already exposedโ€”and no one knows yet?

AI-powered DLP, zero trust, browser isolation, and cloud posture control are reshaping data defense.

Learn 10 must-do strategies now โ†’ https://thehackernews.com/2025/05/top-10-best-practices-for-effective.html
๐Ÿ‘28๐Ÿคฏ5๐Ÿ˜2๐Ÿ˜ฑ1
๐Ÿ›‘ 2 critical Firefox zero-days โ€” CVE-2025-4918 & CVE-2025-4919 โ€” proven exploitable.

Attackers can read/write sensitive data or trigger remote code execution.

Affects all versions before: โ€ข Firefox 138.0.4 โ€ข ESR 128.10.1 / 115.23.1
๐Ÿ”— Patch now. Full story: https://thehackernews.com/2025/05/firefox-patches-2-zero-days-exploited.html
๐Ÿ˜30๐Ÿ‘15๐Ÿคฏ9๐Ÿ˜ฑ2๐Ÿค”1
โ€œWe never drop tools on machines.โ€

84% of major cyberattacks now use built-in system tools like PowerShell & netsh.exe โ€” not malware.

๐Ÿ‘€ Bitdefender analyzed 700,000 incidents: attackers are hiding in plain sight using legit admin utilities.

Living Off the Land isnโ€™t just stealthโ€”itโ€™s standard.

โ†’ See how PHASR flips the script: smart blocking, zero disruption.

๐Ÿ”— Read: https://thehackernews.com/expert-insights/2025/05/living-off-land-what-we-learned-from.html
๐Ÿ‘23๐Ÿ˜ฑ2
โšก Weekly Recap: Zero-days are just the tip. This weekโ€™s threat activity points to a deeper shift in how attackers operate.

Read now, recalibrate faster โ†’ https://thehackernews.com/2025/05/weekly-recap-zero-day-exploits-insider.html
๐Ÿ˜6๐Ÿ‘4
๐Ÿšจ New favorite toy of ransomware gangs? A stealthy malware called Skitnetโ€”now seen in live attacks.

First sold on dark forums in 2024, it's now powering phishing campaigns from groups like Black Basta in 2025.

โ†’ Reverse shell via DNS
โ†’ Evades AV using GetProcAddress
โ†’ Deploys legit tools like AnyDesk
โ†’ Modular, stealthy, persistent

Learn how it works: https://thehackernews.com/2025/05/ransomware-gangs-use-skitnet-malware.html
๐Ÿค”15๐Ÿ‘7โšก1๐Ÿ”ฅ1
๐Ÿ”ฅ CTEM is the new must-have for cybersecurity leaders.

Forget yearly audits. This is about always-on risk testing โ€” and itโ€™s working.

CTEM uses attack simulations, real-time testing & exposure tracking to stay ahead.

Why are top CISOs making the switch?

๐Ÿ‘‰ Learn how it works: https://thehackernews.com/2025/05/why-ctem-is-winning-bet-for-cisos-in.html
๐Ÿ˜6๐Ÿ‘3
๐Ÿ›‘ WARNING: Popular VMware tool RVTools was hacked to spread Bumblebee malware via its official site.

The site is now offline โ€” but โš ๏ธ do not download from unofficial sources either.

Meanwhile, Procolored printer software was found carrying a Delphi backdoor and a $974K crypto clipper named SnipVex, which infects .exe files to hijack Bitcoin transactions.

๐Ÿ”Ž Full details here: https://thehackernews.com/2025/05/rvtools-official-site-hacked-to-deliver.html
โšก16๐Ÿ‘14๐Ÿคฏ7๐Ÿค”5๐Ÿ˜1
๐Ÿ‘€ Devs, you're being hunted.

3 Python packages quietly turned stolen emails into verified TikTok & Instagram targets. Another posed as a dev toolโ€”actually a stealth backdoor.

๐Ÿ”— Full story โ†’ https://thehackernews.com/2025/05/malicious-pypi-packages-exploit.html
๐Ÿคฏ16๐Ÿ‘9๐Ÿ”ฅ7๐Ÿ˜3๐Ÿ˜ฑ1
๐Ÿšจ RedisRaider is hereโ€”and it's hunting Linux servers.

A new cryptojacking campaign is weaponizing Redis config commands to silently hijack Linux systems and mine Monero.

๐Ÿ”— Learn more: https://thehackernews.com/2025/05/go-based-malware-deploys-xmrig-miner-on.html
๐Ÿ‘7๐Ÿ”ฅ7๐Ÿคฏ4๐Ÿ‘1
๐Ÿšจ New Chinese APT uncovered!

ESET reveals MarsSnake, a stealth backdoor used in a multi-year campaign targeting a Saudi org via fake flight emails.

The threat actor? UnsolicitedBookerโ€”and itโ€™s not working alone.

๐Ÿ‘€ More tactics, ties, and twists โ†’ https://thehackernews.com/2025/05/chinese-hackers-deploy-marssnake.html
๐Ÿ‘10๐Ÿคฏ7๐Ÿ”ฅ1
๐Ÿ’€ Most breaches begin with identity.

Issue isnโ€™t firewallโ€”it's login. You invest in EDR, NDR, ITDR, but attackers use valid credentials.

๐Ÿ”ฅ ITP stops attacks pre-access.

๐Ÿ‘‰ Learn more: https://thehackernews.com/expert-insights/2025/05/breach-fatalism-is-over-why-identity.html
๐Ÿ‘11๐Ÿ˜3
๐Ÿ’ฅ 75 security tools, 2,000+ alerts/week โ€” Still breached.

This new "2025 State of Pentesting" report reveals whatโ€™s really working (and whatโ€™s not) in modern security testing.

๐Ÿ”— Get the key insights: https://thehackernews.com/2025/05/the-crowded-battle-key-insights-from.html
๐Ÿ‘9
๐Ÿšจ One default IAM role can expose your entire AWS account.

Experts found overly permissive roles in AWS services like SageMaker & Glueโ€”granting attackers wide access, including full S3 control.

Itโ€™s not just misconfigโ€”it's a silent backdoor.

Details: https://thehackernews.com/2025/05/aws-default-iam-roles-found-to-enable.html
โšก9๐Ÿ‘8
โš ๏ธ Old flawsโ€”new threat!

A new SideWinder campaign hit govโ€™t agencies in ๐Ÿ‡ฑ๐Ÿ‡ฐ Sri Lanka, ๐Ÿ‡ง๐Ÿ‡ฉ Bangladesh & ๐Ÿ‡ต๐Ÿ‡ฐ Pakistan using geofenced malware and old MS Office flaws.

๐Ÿ”— Details just dropped: https://thehackernews.com/2025/05/south-asian-ministries-hit-by.html
๐Ÿ‘20
๐Ÿšจ Over 100 malicious Chrome extensions slipped through Googleโ€™s radar since Feb 2024.

They looked legitโ€”VPNs, AI tools, banking appsโ€”but secretly stole data, hijacked sessions, and redirected traffic.

๐Ÿ‘€ Even bad reviews were filtered.

๐Ÿ”— Read: https://thehackernews.com/2025/05/100-fake-chrome-extensions-found.html
๐Ÿ‘15๐Ÿ˜ฑ5๐Ÿค”4๐Ÿ”ฅ2
โš ๏ธ Trusted domains. Abandoned cloud assets. Hijacked by a ghost.

A threat actor called Hazy Hawk is hijacking unused domains from big names like CDC & PwCโ€”turning trusted URLs into malware traps via DNS misconfig.

See how it works โž https://thehackernews.com/2025/05/hazy-hawk-exploits-dns-records-to.html
๐Ÿ‘19๐Ÿ‘1๐Ÿค”1
This media is not supported in your browser
VIEW IN TELEGRAM
๐Ÿ”ฅ Google Chrome just got SMARTER!!!

It now auto-changes compromised passwordsโ€”in one click.

๐Ÿ” Detects hacked passwords
๐Ÿค– Auto-generates a strong password
โšก Instantly updates them

See it in action: https://thehackernews.com/2025/05/google-chrome-can-now-auto-change.html
๐Ÿ”ฅ24๐Ÿ‘11๐Ÿ˜7๐Ÿค”6๐Ÿ‘3