The Hacker News
โœ”
152K subscribers
1.87K photos
10 videos
3 files
7.79K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: [email protected]

๐ŸŒ Website: https://thehackernews.com
Download Telegram
Apple blocked $9B+ in App Store fraud.

In 2024 alone:
๐Ÿ”ฅ $2B in fake transactions stopped
๐Ÿšซ 139K shady devs rejected
๐Ÿ‘ค 129M bogus accounts banned

From malware to manipulated reviewsโ€”fraud is evolving fast.

๐Ÿ‘‰ See whatโ€™s under the hood: https://thehackernews.com/2025/05/apple-blocks-9-billion-in-fraud-over-5.html
๐Ÿ˜17๐Ÿ‘9๐Ÿคฏ8๐Ÿ‘3๐Ÿ”ฅ3
๐Ÿšจ One Day. 251 IPs. 75 Targets.

Experts detected a wave of Japan-based, Amazon-hosted IPs scanning 75 exposure points in hours.

CVEs hit: ColdFusion (CVE-2018-15961), Struts (CVE-2017-5638), Elasticsearch (CVE-2015-1427)

See what was targeted โ†’ https://thehackernews.com/2025/05/251-amazon-hosted-ips-used-in-exploit.html
๐Ÿ‘16
๐Ÿšจ A new zero-day is under attack โ€” and itโ€™s making money off your CMS.

Hackers are hijacking Craft CMS via a fresh zero-day to mine crypto and sell your bandwidth โ€” all with stealthy new tools. One odd Python trick might help you spot them.

Learn more: https://thehackernews.com/2025/05/mimo-hackers-exploit-cve-2025-32432-in.html
๐Ÿ‘7๐Ÿค”4
โš ๏ธ You passed MFA. But your session didnโ€™t.

A new attack, Browser-in-the-Middle, tricks users into typing passwords on a hackerโ€™s browserโ€”without knowing it.

Itโ€™s fast, invisible, and bypasses MFA.

Learn how it worksโ€”and how to stop it before it hits you. ๐Ÿ‘‡ https://thehackernews.com/2025/05/how-browser-in-middle-attacks-steal.html
๐Ÿ˜15๐Ÿคฏ8๐Ÿค”4๐Ÿ‘3๐Ÿ˜ฑ1
๐Ÿšจ A new botnet is quietly hijacking Linux-based IoT devices.

PumaBot is targeting embedded Linux IoT devicesโ€”brute-forcing SSH, mining crypto, and hijacking credentials.

It impersonates Redis, evades honeypots, and survives reboots using systemd persistence.

๐Ÿ”— Read: https://thehackernews.com/2025/05/new-pumabot-botnet-targets-linux-iot.html
๐Ÿ‘11๐Ÿคฏ4
๐Ÿšจ Session hijacking just replaced password theft.

Attackers now buy live access to Microsoft 365, AWS, Slackโ€”no passwords, no MFA needed.

Flare analyzed 20M+ stealer logs. What they found changes everything.

๐Ÿ‘‰ How fast it happensโ€”and how to stop it: https://thehackernews.com/2025/05/from-infection-to-access-24-hour.html
๐Ÿ‘12โšก3๐Ÿ˜3
๐Ÿšจ WARNING โ†’

Apps like ChatGPT and Trello can access your entire OneDrive cloud via Microsoftโ€™s File Pickerโ€”even if you upload just one file.

๐Ÿ”“ Overly broad permissions, vague prompts. No fix yet.

๐Ÿ”— See whatโ€™s at risk โ†’ https://thehackernews.com/2025/05/microsoft-onedrive-file-picker-flaw.html
๐Ÿ‘23๐Ÿ˜ฑ18๐Ÿ˜7๐Ÿคฏ5
๐Ÿšจ China accused of cyber espionageโ€”again.

Czech Republic publicly blames APT31, a state-linked hacking group, for targeting its Foreign Ministry since 2022. The attack hit critical infrastructure.

๐Ÿ”— Read the full story: https://thehackernews.com/2025/05/czech-republic-blames-china-linked.html
๐Ÿ˜12๐Ÿค”7๐Ÿ‘4๐Ÿ˜ฑ3๐Ÿ”ฅ2๐Ÿคฏ1
๐Ÿšจ Iranian Hacker Pleads Guilty in U.S. Ransomware Case

Sina Gholinejad, 37, admitted to leading Robbinhood ransomware attacks that hit U.S. cities like Baltimore and Greenville between 2019โ€“2024.

๐Ÿ’ฅ $19M+ in damages
๐Ÿ’ฅ City services shut down for months
๐Ÿ’ฅ Used stolen access + vulnerable drivers to avoid detection
๐Ÿ’ฅ Laundered ransom through crypto mixers

He faces up to 30 years in prison.

๐Ÿ‘‰ Read the full story: https://thehackernews.com/2025/05/iranian-hacker-pleads-guilty-in-19.html
๐Ÿ˜23๐Ÿ˜ฑ12๐Ÿ”ฅ11๐Ÿ‘3๐Ÿ‘2โšก1๐Ÿคฏ1
๐Ÿšจ 0-day Alert: Unpatched flaw threatens 100K+ WordPress sites

A critical vulnerability (CVE-2025-47577, CVSS 10.0) in TI WooCommerce Wishlist lets unauthenticated attackers upload malicious files.

๐Ÿ”— Full details โ†’ https://thehackernews.com/2025/05/over-100000-wordpress-sites-at-risk.html
โšก9๐Ÿ‘6๐Ÿ”ฅ3
๐Ÿšจ Google Calendarโ€ฆ as malware C2? You read that right.

Chinese APT41 hackers hijacked a govt site to launch a stealth campaign using malware dubbed TOUGHPROGRESSโ€”leveraging Google Calendar events to send commands & exfiltrate data.

Find details here โ€” https://thehackernews.com/2025/05/chinese-apt41-exploits-google-calendar.html
๐Ÿคฏ25๐Ÿ”ฅ9๐Ÿ‘3
๐ŸŽญ Phishing scams are down 20%โ€”but donโ€™t celebrate yet.

Hackers are now using GenAI to launch hyper-targeted attacks on HR and finance teams. The game changed. Are your defenses ready for whatโ€™s coming next?

๐Ÿ›ก๏ธ Read the full 2025 report: https://thehackernews.com/expert-insights/2025/05/zscaler-threatlabz-2025-phishing-report.html
๐Ÿ˜9๐Ÿ‘4โšก2๐Ÿคฏ1
๐Ÿšจ UPDATE: 9,000 ASUS routers hijacked in silent global attack. Hackers gained persistent access using a known flawโ€”no malware, no alerts.

Linked to the same group behind the Cisco honeypot botnet.

The real plan? Itโ€™s just starting... ๐Ÿ‘€

Read: https://thehackernews.com/2025/05/vicioustrap-uses-cisco-flaw-to-build.html
๐Ÿคฏ10๐Ÿค”5๐Ÿ‘4โšก3๐Ÿ‘1
๐Ÿšจ Hackers hijacked a trusted IT tool to launch ransomware attacks across multiple companies in a supply chain breach.

๐Ÿ‘€ The twist? Another cyber gang may have quietly opened the door. The ransomware underworld is shifting.

Learn more: https://thehackernews.com/2025/05/dragonforce-exploits-simplehelp-flaws.html
๐Ÿ‘10๐Ÿ˜ฑ4โšก3
๐Ÿงฌ New Malware Alert: Hides Using Broken File Headers!

Fortinet just uncovered a remote access trojan (RAT) that ran unnoticed for weeksโ€”using corrupted DOS & PE headers to avoid detection.

๐Ÿ–ฅ๏ธ Turns your PC into a remote access hub
๐Ÿ” Supports multiple attacker sessions
๐Ÿ” Uses TLS to stay stealthy

๐Ÿ”— Read the full story: https://thehackernews.com/2025/05/new-windows-rat-evades-detection-for.html
๐Ÿค”11๐Ÿ‘5๐Ÿ”ฅ4โšก2๐Ÿ˜2
At Georgetown, gain the tactical skills to plan for and respond to information security threats. Attend our June 12 webinar.

Sign up now: https://thn.news/cyber-risk-2025-ig
๐Ÿ‘8๐Ÿ”ฅ2
๐Ÿšจ AI tools are the new bait!

Fake ChatGPT & InVideo AI installers are spreading ransomware & destructive malware like CyberLock, Lucky_Gh0$t, and Numero.

Hackers are weaponizing AI hype. Don't trust free tools from shady links.

๐Ÿ”—Details: https://thehackernews.com/2025/05/cybercriminals-target-ai-users-with.html
๐Ÿ˜12๐Ÿคฏ5โšก4๐Ÿ‘4๐Ÿ”ฅ2๐Ÿค”1
๐Ÿšจ Fake News, Real Threats!

Meta just shut down 3 secret influence ops from Iran, China, and Romania using fake accounts, AI, and hashtags to sway public opinion.

๐Ÿ‘โ€๐Ÿ—จ 658 fake Facebook accounts.
๐ŸŽญ AI-generated profiles.

One Iranian campaign tied to Storm-2035 even misused ChatGPT to spread polarizing propaganda.

๐Ÿ”— Read details โ€” https://thehackernews.com/2025/05/meta-disrupts-influence-ops-targeting.html
๐Ÿ˜15๐Ÿ‘8๐Ÿค”2
๐Ÿšจ ConnectWise confirms a targeted cyberattack on its environmentโ€”likely tied to a nation-state actor.

Just weeks after patching CVE-2025-3935, suspicious activity hit a small group of customers.

Stay ALERT | Read details: https://thehackernews.com/2025/05/connectwise-hit-by-cyberattack-nation.html
๐Ÿ‘7๐Ÿ‘2๐Ÿค”1
๐Ÿšจ The U.S. Treasury has sanctioned Funnull, a Philippines-based firm powering thousands of crypto scamsโ€”causing over $200M in U.S. losses.

The twist? They used AWS and Azure to host fake sites at scale.

๐Ÿ”น 332K+ domains
๐Ÿ”น 548 spoofed brands
๐Ÿ”น Avg. victim loss: $150K+

Donโ€™t get played: https://thehackernews.com/2025/05/us-sanctions-funnull-for-200m-romance.html
๐Ÿ”ฅ12๐Ÿ˜3๐Ÿ‘1
UPDATE โ€” Two PoC exploits for the BadSuccessor flaw in Windows Server 2025 are now public.

โš ๏ธ One enables stealthy privilege escalation with just a Kerberos ticket
โš ๏ธ SharpSuccessor lets low-priv users gain domain admin via CreateChild rights

Read: https://thehackernews.com/2025/05/critical-windows-server-2025-dmsa.html
๐Ÿ˜5๐Ÿคฏ4๐Ÿ‘3