The Hacker News
โœ”
152K subscribers
1.87K photos
10 videos
3 files
7.78K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: [email protected]

๐ŸŒ Website: https://thehackernews.com
Download Telegram
Most companies think their identity security is under controlโ€”Itโ€™s not.

๐Ÿšจ <4% have fully automated ID workflows
๐Ÿ”‘ 89% depend on users to manually enable MFA
๐Ÿ“‰ 52% faced breaches from manual ID tasks

Read latest 2025 report โ†’ https://thehackernews.com/2025/05/identity-security-has-automation.html
๐Ÿ‘10๐Ÿ”ฅ1๐Ÿ‘1๐Ÿ˜1
๐Ÿšจ 3 Critical Flaws. 1 Exploit Chain. No Fix.

Versa Concerto's SD-WAN platform has 3 severe CVEsโ€”one rated 10.0โ€”that can let attackers bypass auth, escalate privileges & gain full system control via reverse shell.

๐Ÿ”— Read this story โ†’ https://thehackernews.com/2025/05/unpatched-versa-concerto-flaws-let.html
๐Ÿค”6๐Ÿ”ฅ3๐Ÿ‘3๐Ÿ˜2๐Ÿ‘1
๐Ÿšจ China-linked UNC5221 hackers exploited Ivanti EPMM zero-days (CVE-2025-4427 & 4428) immediately after disclosure, targeting mobile endpoints in defense, healthcare, and finance sectors.

Full report โ†’ https://thehackernews.com/2025/05/chinese-hackers-exploit-ivanti-epmm.html
๐Ÿ‘7๐Ÿ”ฅ3๐Ÿ‘2
โšก Webinar ALERT!

Cybersecurity isn't enoughโ€”you must prove it.

Courts, regulators, and insurers demand "reasonable" programs, and vague efforts won't suffice. Learn what this means and how to comply.

๐Ÿ“… Register for this free session now โ†’ https://thehackernews.com/2025/05/webinar-learn-how-to-build-reasonable.html
๐Ÿค”6๐Ÿ‘1๐Ÿ‘1
๐Ÿ›‘ WARNING โ€” Any user to Domain Admin?

Akamai researchers demoed BadSuccessor, an attack abusing the new dMSA featureโ€”enabled by defaultโ€”to escalate privileges in Active Directory.

โœ… Works in 91% of orgs.
โŒ No patch yet

Details here โ†’ https://thehackernews.com/2025/05/critical-windows-server-2025-dmsa.html
๐Ÿ˜ฑ12๐Ÿ˜2๐Ÿ‘1
โš ๏ธ A Chinese-speaking threat actor quietly breached U.S. local gov systems via a critical flaw in Cityworks.

They didnโ€™t just break inโ€”they stayedโ€”deploying Cobalt Strike & VShell via Rust-based TetraLoader.

Full report โ†’ https://thehackernews.com/2025/05/chinese-hackers-exploit-trimble.html
๐Ÿคฏ16๐Ÿ‘9๐Ÿ‘7๐Ÿ”ฅ4๐Ÿ˜3๐Ÿค”2๐Ÿ˜ฑ1
๐Ÿ’ฅ Hidden code. Stolen secrets. Weaponized AI.

GitLabโ€™s AI assistant Duo was vulnerable to indirect prompt injectionโ€”letting attackers quietly steal source code, embed malicious links, and exfiltrate zero-days.

Learn more: https://thehackernews.com/2025/05/gitlab-duo-vulnerability-enabled.html
โšก12๐Ÿ‘10๐Ÿ˜1
๐Ÿšจ New CISA Alert: Hackers exploited CVE-2025-3928 in Commvaultโ€™s Metallic SaaS, compromising M365 credentials.

This isnโ€™t an isolated caseโ€”itโ€™s part of a broader campaign targeting SaaS apps with default configs and excessive permissions.

๐Ÿ” Details: https://thehackernews.com/2025/05/cisa-warns-of-suspected-broader-saas.html
๐Ÿ”ฅ9๐Ÿ‘5
๐Ÿ”ฅ The DoJ has dismantled DanaBotโ€”a Russian-controlled malware that infected 300K+ devices and caused $50M+ in global losses.

16 charged. Servers seized.

Some hackers unmasked after accidentally infecting themselves.

Read more: https://thehackernews.com/2025/05/us-dismantles-danabot-malware-network.html
๐Ÿ˜19๐Ÿค”6โšก4๐Ÿ”ฅ4๐Ÿ‘3
๐Ÿ”ฅ Europol just dropped the hammer: 300 servers taken down, โ‚ฌ3.5M in crypto seized, and 20 international arrest warrants issuedโ€”key QakBot and TrickBot operatives named.

At the same time, Operation RapTor arrested 270 dark web vendors across 10 countries, seizing โ‚ฌ184M in cash and crypto, 2 tons of drugs, and 180 firearms.

๐Ÿ”— Learn more โ†’ https://thehackernews.com/2025/05/300-servers-and-35m-seized-as-europol.html
๐Ÿ”ฅ22๐Ÿ˜ฑ7๐Ÿ‘6๐Ÿ˜4๐Ÿคฏ2
๐Ÿ›ก๏ธ 99.45% detection. 0.07% false positives.

SafeLine is now the top open-source WAF on GitHub (16.4K+ โญ) โ€” built for teams needing full control, zero-day defense, and advanced bot protection.

๐Ÿ‘‰ See why itโ€™s outpacing cloud WAFs โ†’ https://thehackernews.com/2025/05/safeline-waf-open-source-web.html
๐Ÿค”14๐Ÿ‘10๐Ÿคฏ4๐Ÿ˜ฑ4๐Ÿ‘1
๐Ÿšจ 5,300 routers hijackedโ€”not to attack, but to spy.

A shadowy group dubbed ViciousTrap is turning Cisco routers across 84 countries into a massive honeypot-style networkโ€”not to attack, but to silently watch.

๐Ÿ” Exploiting CVE-2023-20118
๐Ÿ‘ป Dropping a script called NetGhost

Read: https://thehackernews.com/2025/05/vicioustrap-uses-cisco-flaw-to-build.html
๐Ÿ˜ฑ14๐Ÿ”ฅ12๐Ÿ‘4๐Ÿค”3๐Ÿคฏ1
Hackers are turning TikTok into a malware delivery tool.

From ClickFix to fake Spotify "boosts"โ€”hackers are now using AI-generated TikToks to trick users into running malicious commands. One video got 500K views before takedown.

See full report โ†’ https://thehackernews.com/2025/05/hackers-use-tiktok-videos-to-distribute.html
๐Ÿ˜40๐Ÿ‘23๐Ÿ˜ฑ21๐Ÿคฏ7
๐Ÿšจ Fake installers, real threat โ€” Malware hidden in trojanized QQ Browser & LetsVPN setups drops Winos 4.0, a stealthy RAT built for memory-only attacks.

Signed with expired certs. Linked to Chinese-speaking targets & APT Silver Fox.

๐Ÿ‘€ Full scoop โ†’ https://thehackernews.com/2025/05/hackers-use-fake-vpn-and-browser-nsis.html
๐Ÿ”ฅ26๐Ÿ‘6๐Ÿคฏ1
70% of top sites drop tracking cookies even after users say no.

Thatโ€™s a lawsuit waiting to happen.

This guide shows CISOs how to catch hidden privacy failures before they cost you millions.

โ†’ Fix it now: https://thehackernews.com/2025/05/cisos-guide-to-web-privacy-validation.html
๐Ÿ‘10๐Ÿ˜9๐Ÿ˜ฑ3
๐Ÿšจ Malware is hiding in your dev tools. 70+ npm & VS Code packages were caught stealing data, wiping files, even triggering shutdowns.

Hackers used trusted names to slip through.

Your next install could be a trap.
โ†’ Audit often.
โ†’ Trust less.

๐Ÿ”—Read: https://thehackernews.com/2025/05/over-70-malicious-npm-and-vs-code.html
๐Ÿ˜14๐Ÿ‘10๐Ÿ”ฅ6๐Ÿคฏ5
โšก New this week in cybersecurity RECAP:

โ€“ Chrome extensions hijacking sessions
โ€“ AI assistants leaking code
โ€“ State actors exploiting SaaS
โ€“ 20+ critical CVEs

You can't protect what you ignore.

Read the recap now โ†’ https://thehackernews.com/2025/05/weekly-recap-apt-campaigns-browser.html
๐Ÿ‘25๐Ÿ˜1
๐Ÿšจ Russia-linked TAG-110 is now hitting Tajikistan with macro-laced Word docsโ€”ditching old methods for stealthier new ones.

Aimed at gov and research orgs, this shift signals bigger moves ahead.

New tactics. Same goal. Learn more: https://thehackernews.com/2025/05/russia-linked-hackers-target-tajikistan.html
๐Ÿ˜10๐Ÿ‘5๐Ÿค”3๐Ÿคฏ2๐Ÿ”ฅ1
๐Ÿšจ Law firms are under attack.

A stealthy group known as Luna Moth is using fake IT callsโ€”not malwareโ€”to quietly breach systems and steal sensitive data.

No clicks neededโ€”just trust abused.

Learn why itโ€™s workingโ€”and how to stop it: https://thehackernews.com/2025/05/hackers-are-calling-your-office-fbi.html
๐Ÿ‘15๐Ÿ˜5โšก2
Drive your SOC forward with solutions trusted by 15,000 businesses worldwide

โœ… Get bonus licenses for ANYRUN's Interactive Sandbox
โœ… Double your cyber threat investigations quota with TI Lookup

Just 4 days left ๐Ÿ‘‰ https://thn.news/anyrun-plans-spring-tg
๐Ÿ‘9๐Ÿ‘2
๐Ÿšจ AI agents are leaking secretsโ€”and no one's watching.

Enterprises now manage 45+ machine identities per userโ€”from chatbots to CI/CD bots. In 2024 alone, 23.7M secrets leaked on GitHub. AI tools like Copilot worsened this by 40%.

NHIs donโ€™t rotate keys. Donโ€™t log off. Donโ€™t forget.

๐Ÿ”’ Learn how to lock down AI agents โ†’ https://thehackernews.com/2025/05/ai-agents-and-nonhuman-identity-crisis.html
๐Ÿ”ฅ14๐Ÿ‘7๐Ÿ˜4๐Ÿ‘3