The Hacker News
โœ”
152K subscribers
1.87K photos
10 videos
3 files
7.79K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: [email protected]

๐ŸŒ Website: https://thehackernews.com
Download Telegram
๐Ÿšจ CI/CD pipelines move fastโ€”but security often lags behind.

Misconfigs, weak containers, and unchecked code can open real attack paths.

Wazuh spots what others missโ€”and stops it cold.

๐Ÿ” See the risks + how to fix them โ†’ https://thehackernews.com/2025/05/securing-cicd-workflows-with-wazuh.html
๐Ÿ‘7๐Ÿ˜ฑ5
๐Ÿšจ From Inbox to Full Compromise:

Hackers are hitting Russian businesses with phishing emails disguised as docs, delivering PureRAT malware for full-system access, password theft & crypto hijacking.

๐ŸŽฏ Attacks have quadrupled in early 2025.

๐Ÿ”— Details: https://thehackernews.com/2025/05/purerat-malware-spikes-4x-in-2025.html
๐Ÿ”ฅ8๐Ÿ˜ฑ3๐Ÿค”2
โš ๏ธ Russiaโ€™s cyber war isnโ€™t just on the battlefieldโ€”itโ€™s hitting inboxes across the West.

APT28 (Fancy Bear) is targeting logistics, defense & IT firms in 14 countries to track aid to Ukraine.

Outlook, Roundcube, VPNsโ€”even border cameras compromised.

๐Ÿ”— Learn more: https://thehackernews.com/2025/05/russian-hackers-exploit-email-and-vpn.html
๐Ÿ‘21๐Ÿ”ฅ14๐Ÿ˜7๐Ÿค”6๐Ÿคฏ2
๐Ÿ”ฅ Biggest Info-Stealer Takedown of 2025!

๐Ÿšจ 2,300+ domains seized | 10M+ infections cut off.

Lumma Stealerโ€”the worldโ€™s top info-stealerโ€”just got dismantled by a global strike led by Microsoft, FBI, and Europol.

๐Ÿ”— Read this story โ†’ https://thehackernews.com/2025/05/fbi-and-europol-disrupt-lumma-stealer.html
๐Ÿคฏ11๐Ÿ‘8๐Ÿ‘6๐Ÿ”ฅ1
Most companies think their identity security is under controlโ€”Itโ€™s not.

๐Ÿšจ <4% have fully automated ID workflows
๐Ÿ”‘ 89% depend on users to manually enable MFA
๐Ÿ“‰ 52% faced breaches from manual ID tasks

Read latest 2025 report โ†’ https://thehackernews.com/2025/05/identity-security-has-automation.html
๐Ÿ‘10๐Ÿ”ฅ1๐Ÿ‘1๐Ÿ˜1
๐Ÿšจ 3 Critical Flaws. 1 Exploit Chain. No Fix.

Versa Concerto's SD-WAN platform has 3 severe CVEsโ€”one rated 10.0โ€”that can let attackers bypass auth, escalate privileges & gain full system control via reverse shell.

๐Ÿ”— Read this story โ†’ https://thehackernews.com/2025/05/unpatched-versa-concerto-flaws-let.html
๐Ÿค”6๐Ÿ”ฅ3๐Ÿ‘3๐Ÿ˜2๐Ÿ‘1
๐Ÿšจ China-linked UNC5221 hackers exploited Ivanti EPMM zero-days (CVE-2025-4427 & 4428) immediately after disclosure, targeting mobile endpoints in defense, healthcare, and finance sectors.

Full report โ†’ https://thehackernews.com/2025/05/chinese-hackers-exploit-ivanti-epmm.html
๐Ÿ‘7๐Ÿ”ฅ3๐Ÿ‘2
โšก Webinar ALERT!

Cybersecurity isn't enoughโ€”you must prove it.

Courts, regulators, and insurers demand "reasonable" programs, and vague efforts won't suffice. Learn what this means and how to comply.

๐Ÿ“… Register for this free session now โ†’ https://thehackernews.com/2025/05/webinar-learn-how-to-build-reasonable.html
๐Ÿค”6๐Ÿ‘1๐Ÿ‘1
๐Ÿ›‘ WARNING โ€” Any user to Domain Admin?

Akamai researchers demoed BadSuccessor, an attack abusing the new dMSA featureโ€”enabled by defaultโ€”to escalate privileges in Active Directory.

โœ… Works in 91% of orgs.
โŒ No patch yet

Details here โ†’ https://thehackernews.com/2025/05/critical-windows-server-2025-dmsa.html
๐Ÿ˜ฑ12๐Ÿ˜2๐Ÿ‘1
โš ๏ธ A Chinese-speaking threat actor quietly breached U.S. local gov systems via a critical flaw in Cityworks.

They didnโ€™t just break inโ€”they stayedโ€”deploying Cobalt Strike & VShell via Rust-based TetraLoader.

Full report โ†’ https://thehackernews.com/2025/05/chinese-hackers-exploit-trimble.html
๐Ÿคฏ16๐Ÿ‘9๐Ÿ‘7๐Ÿ”ฅ4๐Ÿ˜3๐Ÿค”2๐Ÿ˜ฑ1
๐Ÿ’ฅ Hidden code. Stolen secrets. Weaponized AI.

GitLabโ€™s AI assistant Duo was vulnerable to indirect prompt injectionโ€”letting attackers quietly steal source code, embed malicious links, and exfiltrate zero-days.

Learn more: https://thehackernews.com/2025/05/gitlab-duo-vulnerability-enabled.html
โšก12๐Ÿ‘10๐Ÿ˜1
๐Ÿšจ New CISA Alert: Hackers exploited CVE-2025-3928 in Commvaultโ€™s Metallic SaaS, compromising M365 credentials.

This isnโ€™t an isolated caseโ€”itโ€™s part of a broader campaign targeting SaaS apps with default configs and excessive permissions.

๐Ÿ” Details: https://thehackernews.com/2025/05/cisa-warns-of-suspected-broader-saas.html
๐Ÿ”ฅ9๐Ÿ‘5
๐Ÿ”ฅ The DoJ has dismantled DanaBotโ€”a Russian-controlled malware that infected 300K+ devices and caused $50M+ in global losses.

16 charged. Servers seized.

Some hackers unmasked after accidentally infecting themselves.

Read more: https://thehackernews.com/2025/05/us-dismantles-danabot-malware-network.html
๐Ÿ˜19๐Ÿค”6โšก4๐Ÿ”ฅ4๐Ÿ‘3
๐Ÿ”ฅ Europol just dropped the hammer: 300 servers taken down, โ‚ฌ3.5M in crypto seized, and 20 international arrest warrants issuedโ€”key QakBot and TrickBot operatives named.

At the same time, Operation RapTor arrested 270 dark web vendors across 10 countries, seizing โ‚ฌ184M in cash and crypto, 2 tons of drugs, and 180 firearms.

๐Ÿ”— Learn more โ†’ https://thehackernews.com/2025/05/300-servers-and-35m-seized-as-europol.html
๐Ÿ”ฅ22๐Ÿ˜ฑ7๐Ÿ‘6๐Ÿ˜4๐Ÿคฏ2
๐Ÿ›ก๏ธ 99.45% detection. 0.07% false positives.

SafeLine is now the top open-source WAF on GitHub (16.4K+ โญ) โ€” built for teams needing full control, zero-day defense, and advanced bot protection.

๐Ÿ‘‰ See why itโ€™s outpacing cloud WAFs โ†’ https://thehackernews.com/2025/05/safeline-waf-open-source-web.html
๐Ÿค”14๐Ÿ‘10๐Ÿคฏ4๐Ÿ˜ฑ4๐Ÿ‘1
๐Ÿšจ 5,300 routers hijackedโ€”not to attack, but to spy.

A shadowy group dubbed ViciousTrap is turning Cisco routers across 84 countries into a massive honeypot-style networkโ€”not to attack, but to silently watch.

๐Ÿ” Exploiting CVE-2023-20118
๐Ÿ‘ป Dropping a script called NetGhost

Read: https://thehackernews.com/2025/05/vicioustrap-uses-cisco-flaw-to-build.html
๐Ÿ˜ฑ14๐Ÿ”ฅ12๐Ÿ‘4๐Ÿค”3๐Ÿคฏ1
Hackers are turning TikTok into a malware delivery tool.

From ClickFix to fake Spotify "boosts"โ€”hackers are now using AI-generated TikToks to trick users into running malicious commands. One video got 500K views before takedown.

See full report โ†’ https://thehackernews.com/2025/05/hackers-use-tiktok-videos-to-distribute.html
๐Ÿ˜40๐Ÿ‘23๐Ÿ˜ฑ21๐Ÿคฏ7
๐Ÿšจ Fake installers, real threat โ€” Malware hidden in trojanized QQ Browser & LetsVPN setups drops Winos 4.0, a stealthy RAT built for memory-only attacks.

Signed with expired certs. Linked to Chinese-speaking targets & APT Silver Fox.

๐Ÿ‘€ Full scoop โ†’ https://thehackernews.com/2025/05/hackers-use-fake-vpn-and-browser-nsis.html
๐Ÿ”ฅ26๐Ÿ‘6๐Ÿคฏ1
70% of top sites drop tracking cookies even after users say no.

Thatโ€™s a lawsuit waiting to happen.

This guide shows CISOs how to catch hidden privacy failures before they cost you millions.

โ†’ Fix it now: https://thehackernews.com/2025/05/cisos-guide-to-web-privacy-validation.html
๐Ÿ‘10๐Ÿ˜9๐Ÿ˜ฑ3
๐Ÿšจ Malware is hiding in your dev tools. 70+ npm & VS Code packages were caught stealing data, wiping files, even triggering shutdowns.

Hackers used trusted names to slip through.

Your next install could be a trap.
โ†’ Audit often.
โ†’ Trust less.

๐Ÿ”—Read: https://thehackernews.com/2025/05/over-70-malicious-npm-and-vs-code.html
๐Ÿ˜14๐Ÿ‘10๐Ÿ”ฅ6๐Ÿคฏ5
โšก New this week in cybersecurity RECAP:

โ€“ Chrome extensions hijacking sessions
โ€“ AI assistants leaking code
โ€“ State actors exploiting SaaS
โ€“ 20+ critical CVEs

You can't protect what you ignore.

Read the recap now โ†’ https://thehackernews.com/2025/05/weekly-recap-apt-campaigns-browser.html
๐Ÿ‘25๐Ÿ˜1