The Hacker News
โœ”
152K subscribers
1.87K photos
10 videos
3 files
7.79K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: [email protected]

๐ŸŒ Website: https://thehackernews.com
Download Telegram
๐Ÿšจ China accused of cyber espionageโ€”again.

Czech Republic publicly blames APT31, a state-linked hacking group, for targeting its Foreign Ministry since 2022. The attack hit critical infrastructure.

๐Ÿ”— Read the full story: https://thehackernews.com/2025/05/czech-republic-blames-china-linked.html
๐Ÿ˜12๐Ÿค”7๐Ÿ‘4๐Ÿ˜ฑ3๐Ÿ”ฅ2๐Ÿคฏ1
๐Ÿšจ Iranian Hacker Pleads Guilty in U.S. Ransomware Case

Sina Gholinejad, 37, admitted to leading Robbinhood ransomware attacks that hit U.S. cities like Baltimore and Greenville between 2019โ€“2024.

๐Ÿ’ฅ $19M+ in damages
๐Ÿ’ฅ City services shut down for months
๐Ÿ’ฅ Used stolen access + vulnerable drivers to avoid detection
๐Ÿ’ฅ Laundered ransom through crypto mixers

He faces up to 30 years in prison.

๐Ÿ‘‰ Read the full story: https://thehackernews.com/2025/05/iranian-hacker-pleads-guilty-in-19.html
๐Ÿ˜23๐Ÿ˜ฑ12๐Ÿ”ฅ11๐Ÿ‘3๐Ÿ‘2โšก1๐Ÿคฏ1
๐Ÿšจ 0-day Alert: Unpatched flaw threatens 100K+ WordPress sites

A critical vulnerability (CVE-2025-47577, CVSS 10.0) in TI WooCommerce Wishlist lets unauthenticated attackers upload malicious files.

๐Ÿ”— Full details โ†’ https://thehackernews.com/2025/05/over-100000-wordpress-sites-at-risk.html
โšก9๐Ÿ‘6๐Ÿ”ฅ3
๐Ÿšจ Google Calendarโ€ฆ as malware C2? You read that right.

Chinese APT41 hackers hijacked a govt site to launch a stealth campaign using malware dubbed TOUGHPROGRESSโ€”leveraging Google Calendar events to send commands & exfiltrate data.

Find details here โ€” https://thehackernews.com/2025/05/chinese-apt41-exploits-google-calendar.html
๐Ÿคฏ25๐Ÿ”ฅ9๐Ÿ‘3
๐ŸŽญ Phishing scams are down 20%โ€”but donโ€™t celebrate yet.

Hackers are now using GenAI to launch hyper-targeted attacks on HR and finance teams. The game changed. Are your defenses ready for whatโ€™s coming next?

๐Ÿ›ก๏ธ Read the full 2025 report: https://thehackernews.com/expert-insights/2025/05/zscaler-threatlabz-2025-phishing-report.html
๐Ÿ˜9๐Ÿ‘4โšก2๐Ÿคฏ1
๐Ÿšจ UPDATE: 9,000 ASUS routers hijacked in silent global attack. Hackers gained persistent access using a known flawโ€”no malware, no alerts.

Linked to the same group behind the Cisco honeypot botnet.

The real plan? Itโ€™s just starting... ๐Ÿ‘€

Read: https://thehackernews.com/2025/05/vicioustrap-uses-cisco-flaw-to-build.html
๐Ÿคฏ10๐Ÿค”5๐Ÿ‘4โšก3๐Ÿ‘1
๐Ÿšจ Hackers hijacked a trusted IT tool to launch ransomware attacks across multiple companies in a supply chain breach.

๐Ÿ‘€ The twist? Another cyber gang may have quietly opened the door. The ransomware underworld is shifting.

Learn more: https://thehackernews.com/2025/05/dragonforce-exploits-simplehelp-flaws.html
๐Ÿ‘10๐Ÿ˜ฑ4โšก3
๐Ÿงฌ New Malware Alert: Hides Using Broken File Headers!

Fortinet just uncovered a remote access trojan (RAT) that ran unnoticed for weeksโ€”using corrupted DOS & PE headers to avoid detection.

๐Ÿ–ฅ๏ธ Turns your PC into a remote access hub
๐Ÿ” Supports multiple attacker sessions
๐Ÿ” Uses TLS to stay stealthy

๐Ÿ”— Read the full story: https://thehackernews.com/2025/05/new-windows-rat-evades-detection-for.html
๐Ÿค”11๐Ÿ‘5๐Ÿ”ฅ4โšก2๐Ÿ˜2
At Georgetown, gain the tactical skills to plan for and respond to information security threats. Attend our June 12 webinar.

Sign up now: https://thn.news/cyber-risk-2025-ig
๐Ÿ‘8๐Ÿ”ฅ2
๐Ÿšจ AI tools are the new bait!

Fake ChatGPT & InVideo AI installers are spreading ransomware & destructive malware like CyberLock, Lucky_Gh0$t, and Numero.

Hackers are weaponizing AI hype. Don't trust free tools from shady links.

๐Ÿ”—Details: https://thehackernews.com/2025/05/cybercriminals-target-ai-users-with.html
๐Ÿ˜12๐Ÿคฏ5โšก4๐Ÿ‘4๐Ÿ”ฅ2๐Ÿค”1
๐Ÿšจ Fake News, Real Threats!

Meta just shut down 3 secret influence ops from Iran, China, and Romania using fake accounts, AI, and hashtags to sway public opinion.

๐Ÿ‘โ€๐Ÿ—จ 658 fake Facebook accounts.
๐ŸŽญ AI-generated profiles.

One Iranian campaign tied to Storm-2035 even misused ChatGPT to spread polarizing propaganda.

๐Ÿ”— Read details โ€” https://thehackernews.com/2025/05/meta-disrupts-influence-ops-targeting.html
๐Ÿ˜15๐Ÿ‘8๐Ÿค”2
๐Ÿšจ ConnectWise confirms a targeted cyberattack on its environmentโ€”likely tied to a nation-state actor.

Just weeks after patching CVE-2025-3935, suspicious activity hit a small group of customers.

Stay ALERT | Read details: https://thehackernews.com/2025/05/connectwise-hit-by-cyberattack-nation.html
๐Ÿ‘7๐Ÿ‘2๐Ÿค”1
๐Ÿšจ The U.S. Treasury has sanctioned Funnull, a Philippines-based firm powering thousands of crypto scamsโ€”causing over $200M in U.S. losses.

The twist? They used AWS and Azure to host fake sites at scale.

๐Ÿ”น 332K+ domains
๐Ÿ”น 548 spoofed brands
๐Ÿ”น Avg. victim loss: $150K+

Donโ€™t get played: https://thehackernews.com/2025/05/us-sanctions-funnull-for-200m-romance.html
๐Ÿ”ฅ12๐Ÿ˜3๐Ÿ‘1
UPDATE โ€” Two PoC exploits for the BadSuccessor flaw in Windows Server 2025 are now public.

โš ๏ธ One enables stealthy privilege escalation with just a Kerberos ticket
โš ๏ธ SharpSuccessor lets low-priv users gain domain admin via CreateChild rights

Read: https://thehackernews.com/2025/05/critical-windows-server-2025-dmsa.html
๐Ÿ˜5๐Ÿคฏ4๐Ÿ‘3
๐Ÿ”ฅ China-backed hackers are on the move.

Earth Lamia is hitting govts, IT firms & universities in ๐Ÿ‡ฎ๐Ÿ‡ณ ๐Ÿ‡ง๐Ÿ‡ท ๐Ÿ‡ป๐Ÿ‡ณ ๐Ÿ‡ต๐Ÿ‡ญ ๐Ÿ‡น๐Ÿ‡ญ using 9 exploitsโ€”incl. SAP NetWeaver & TeamCity.

โš ๏ธ SQL injections
โš ๏ธ Custom malware
โš ๏ธ Ransomwareโ€ฆ then delete it?

Full story ๐Ÿ‘‰ https://thehackernews.com/2025/05/china-linked-hackers-exploit-sap-and.html
๐Ÿ˜14๐Ÿ”ฅ5๐Ÿค”3๐Ÿ˜ฑ3๐Ÿ‘1
๐Ÿ‘€ โ€œWe never drop tools. We use yours.โ€ โ€” BlackBasta ransomware.

A new Bitdefender analysis of 700,000 incidents reveals this chilling truth: 84% of major cyberattacks use Living Off the Land tools like netsh.exe, powershell.exe, wmic.exe.

๐Ÿ”— Read the report: https://thehackernews.com/expert-insights/2025/05/living-off-land-what-we-learned-from.html
๐Ÿ‘16๐Ÿค”6๐Ÿ”ฅ2
โ€œHealthcare loves to walk backwards into the future.โ€ โ€“ Jason Elrod, CISO, MultiCare Health System.

Legacy IT nearly broke care delivery. But with identity-based microsegmentation, Elrod flipped the script:
โœ… 30K staff
โœ… 14 hospitals
โœ… Zero downtime
โœ… 238% ROI

Security shouldn't be a roadblockโ€”it should be a bridge.

See how MultiCare did it โ†’ https://thehackernews.com/2025/05/from-department-of-no-to-culture-of-yes.html
โšก8๐Ÿ‘5
๐Ÿšจ โ€œProve you're not a robotโ€ โ€” turns into full system breach!

Hackers are using fake CAPTCHA checks to deploy a stealthy new Rust malware, EDDIESTEALER, via ClickFixโ€”a social engineering trick abusing PowerShell on Windows.

๐ŸŽฏ Targets: Passwords, crypto wallets, cookies, and more.

๐Ÿ”— Full report: https://thehackernews.com/2025/05/eddiestealer-malware-uses-clickfix.html
๐Ÿคฏ25๐Ÿ˜19๐Ÿ”ฅ4๐Ÿ‘4๐Ÿค”3โšก1
๐Ÿšจ Global cybercrime tool taken down.

On May 27, 2025, U.S., Dutch, and Finnish authorities seized domains like AvCheck[.]net, used by hackers to hide malware from antivirus tools.

๐Ÿ‘€ The twist? These โ€œsecurity checkersโ€ claimed to detect threatsโ€”but were secretly helping cybercriminals stay invisible.

๐Ÿ”— Details: https://thehackernews.com/2025/05/us-doj-seizes-4-domains-supporting.html
๐Ÿ‘26๐Ÿ”ฅ8๐Ÿ‘4๐Ÿ˜4๐Ÿคฏ3โšก1
๐Ÿ” Two Linux flaws let local attackers steal secrets from crash dumps โ€” including password hashes.

Found in Ubuntu, RHEL & Fedora, the bugs (CVE-2025-5054 & CVE-2025-4598) exploit SUID crash handling.

A simple raceโ€”triggered at just the right timeโ€”can leak /etc/shadow data.

PoC is public. Mitigations exist.

Read: https://thehackernews.com/2025/05/new-linux-flaws-allow-password-hash.html
๐Ÿค”16๐Ÿ˜ฑ10๐Ÿ‘7๐Ÿ”ฅ7๐Ÿ‘7๐Ÿคฏ7๐Ÿ˜4โšก3
๐Ÿ‘€ โ€œStrategic Opportunityโ€ or Silent Backdoor?

CFOs across Europe, Africa, & Asia are being hunted in a stealth phishing op impersonating Rothschild recruiters. Victims solve a CAPTCHAโ€”then unknowingly install NetBird & OpenSSH, giving attackers remote access.

Itโ€™s legit software. Weaponized.

Learn more: https://thehackernews.com/2025/06/fake-recruiter-emails-target-cfos-using.html
๐Ÿ”ฅ29๐Ÿ‘10โšก1