The Hacker News
โœ”
152K subscribers
1.87K photos
10 videos
3 files
7.79K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: [email protected]

๐ŸŒ Website: https://thehackernews.com
Download Telegram
๐Ÿšจ Iranian Hacker Pleads Guilty in U.S. Ransomware Case

Sina Gholinejad, 37, admitted to leading Robbinhood ransomware attacks that hit U.S. cities like Baltimore and Greenville between 2019โ€“2024.

๐Ÿ’ฅ $19M+ in damages
๐Ÿ’ฅ City services shut down for months
๐Ÿ’ฅ Used stolen access + vulnerable drivers to avoid detection
๐Ÿ’ฅ Laundered ransom through crypto mixers

He faces up to 30 years in prison.

๐Ÿ‘‰ Read the full story: https://thehackernews.com/2025/05/iranian-hacker-pleads-guilty-in-19.html
๐Ÿ˜23๐Ÿ˜ฑ12๐Ÿ”ฅ11๐Ÿ‘3๐Ÿ‘2โšก1๐Ÿคฏ1
๐Ÿšจ 0-day Alert: Unpatched flaw threatens 100K+ WordPress sites

A critical vulnerability (CVE-2025-47577, CVSS 10.0) in TI WooCommerce Wishlist lets unauthenticated attackers upload malicious files.

๐Ÿ”— Full details โ†’ https://thehackernews.com/2025/05/over-100000-wordpress-sites-at-risk.html
โšก9๐Ÿ‘6๐Ÿ”ฅ3
๐Ÿšจ Google Calendarโ€ฆ as malware C2? You read that right.

Chinese APT41 hackers hijacked a govt site to launch a stealth campaign using malware dubbed TOUGHPROGRESSโ€”leveraging Google Calendar events to send commands & exfiltrate data.

Find details here โ€” https://thehackernews.com/2025/05/chinese-apt41-exploits-google-calendar.html
๐Ÿคฏ25๐Ÿ”ฅ9๐Ÿ‘3
๐ŸŽญ Phishing scams are down 20%โ€”but donโ€™t celebrate yet.

Hackers are now using GenAI to launch hyper-targeted attacks on HR and finance teams. The game changed. Are your defenses ready for whatโ€™s coming next?

๐Ÿ›ก๏ธ Read the full 2025 report: https://thehackernews.com/expert-insights/2025/05/zscaler-threatlabz-2025-phishing-report.html
๐Ÿ˜9๐Ÿ‘4โšก2๐Ÿคฏ1
๐Ÿšจ UPDATE: 9,000 ASUS routers hijacked in silent global attack. Hackers gained persistent access using a known flawโ€”no malware, no alerts.

Linked to the same group behind the Cisco honeypot botnet.

The real plan? Itโ€™s just starting... ๐Ÿ‘€

Read: https://thehackernews.com/2025/05/vicioustrap-uses-cisco-flaw-to-build.html
๐Ÿคฏ10๐Ÿค”5๐Ÿ‘4โšก3๐Ÿ‘1
๐Ÿšจ Hackers hijacked a trusted IT tool to launch ransomware attacks across multiple companies in a supply chain breach.

๐Ÿ‘€ The twist? Another cyber gang may have quietly opened the door. The ransomware underworld is shifting.

Learn more: https://thehackernews.com/2025/05/dragonforce-exploits-simplehelp-flaws.html
๐Ÿ‘10๐Ÿ˜ฑ4โšก3
๐Ÿงฌ New Malware Alert: Hides Using Broken File Headers!

Fortinet just uncovered a remote access trojan (RAT) that ran unnoticed for weeksโ€”using corrupted DOS & PE headers to avoid detection.

๐Ÿ–ฅ๏ธ Turns your PC into a remote access hub
๐Ÿ” Supports multiple attacker sessions
๐Ÿ” Uses TLS to stay stealthy

๐Ÿ”— Read the full story: https://thehackernews.com/2025/05/new-windows-rat-evades-detection-for.html
๐Ÿค”11๐Ÿ‘5๐Ÿ”ฅ4โšก2๐Ÿ˜2
At Georgetown, gain the tactical skills to plan for and respond to information security threats. Attend our June 12 webinar.

Sign up now: https://thn.news/cyber-risk-2025-ig
๐Ÿ‘8๐Ÿ”ฅ2
๐Ÿšจ AI tools are the new bait!

Fake ChatGPT & InVideo AI installers are spreading ransomware & destructive malware like CyberLock, Lucky_Gh0$t, and Numero.

Hackers are weaponizing AI hype. Don't trust free tools from shady links.

๐Ÿ”—Details: https://thehackernews.com/2025/05/cybercriminals-target-ai-users-with.html
๐Ÿ˜12๐Ÿคฏ5โšก4๐Ÿ‘4๐Ÿ”ฅ2๐Ÿค”1
๐Ÿšจ Fake News, Real Threats!

Meta just shut down 3 secret influence ops from Iran, China, and Romania using fake accounts, AI, and hashtags to sway public opinion.

๐Ÿ‘โ€๐Ÿ—จ 658 fake Facebook accounts.
๐ŸŽญ AI-generated profiles.

One Iranian campaign tied to Storm-2035 even misused ChatGPT to spread polarizing propaganda.

๐Ÿ”— Read details โ€” https://thehackernews.com/2025/05/meta-disrupts-influence-ops-targeting.html
๐Ÿ˜15๐Ÿ‘8๐Ÿค”2
๐Ÿšจ ConnectWise confirms a targeted cyberattack on its environmentโ€”likely tied to a nation-state actor.

Just weeks after patching CVE-2025-3935, suspicious activity hit a small group of customers.

Stay ALERT | Read details: https://thehackernews.com/2025/05/connectwise-hit-by-cyberattack-nation.html
๐Ÿ‘7๐Ÿ‘2๐Ÿค”1
๐Ÿšจ The U.S. Treasury has sanctioned Funnull, a Philippines-based firm powering thousands of crypto scamsโ€”causing over $200M in U.S. losses.

The twist? They used AWS and Azure to host fake sites at scale.

๐Ÿ”น 332K+ domains
๐Ÿ”น 548 spoofed brands
๐Ÿ”น Avg. victim loss: $150K+

Donโ€™t get played: https://thehackernews.com/2025/05/us-sanctions-funnull-for-200m-romance.html
๐Ÿ”ฅ12๐Ÿ˜3๐Ÿ‘1
UPDATE โ€” Two PoC exploits for the BadSuccessor flaw in Windows Server 2025 are now public.

โš ๏ธ One enables stealthy privilege escalation with just a Kerberos ticket
โš ๏ธ SharpSuccessor lets low-priv users gain domain admin via CreateChild rights

Read: https://thehackernews.com/2025/05/critical-windows-server-2025-dmsa.html
๐Ÿ˜5๐Ÿคฏ4๐Ÿ‘3
๐Ÿ”ฅ China-backed hackers are on the move.

Earth Lamia is hitting govts, IT firms & universities in ๐Ÿ‡ฎ๐Ÿ‡ณ ๐Ÿ‡ง๐Ÿ‡ท ๐Ÿ‡ป๐Ÿ‡ณ ๐Ÿ‡ต๐Ÿ‡ญ ๐Ÿ‡น๐Ÿ‡ญ using 9 exploitsโ€”incl. SAP NetWeaver & TeamCity.

โš ๏ธ SQL injections
โš ๏ธ Custom malware
โš ๏ธ Ransomwareโ€ฆ then delete it?

Full story ๐Ÿ‘‰ https://thehackernews.com/2025/05/china-linked-hackers-exploit-sap-and.html
๐Ÿ˜14๐Ÿ”ฅ5๐Ÿค”3๐Ÿ˜ฑ3๐Ÿ‘1
๐Ÿ‘€ โ€œWe never drop tools. We use yours.โ€ โ€” BlackBasta ransomware.

A new Bitdefender analysis of 700,000 incidents reveals this chilling truth: 84% of major cyberattacks use Living Off the Land tools like netsh.exe, powershell.exe, wmic.exe.

๐Ÿ”— Read the report: https://thehackernews.com/expert-insights/2025/05/living-off-land-what-we-learned-from.html
๐Ÿ‘16๐Ÿค”6๐Ÿ”ฅ2
โ€œHealthcare loves to walk backwards into the future.โ€ โ€“ Jason Elrod, CISO, MultiCare Health System.

Legacy IT nearly broke care delivery. But with identity-based microsegmentation, Elrod flipped the script:
โœ… 30K staff
โœ… 14 hospitals
โœ… Zero downtime
โœ… 238% ROI

Security shouldn't be a roadblockโ€”it should be a bridge.

See how MultiCare did it โ†’ https://thehackernews.com/2025/05/from-department-of-no-to-culture-of-yes.html
โšก8๐Ÿ‘5
๐Ÿšจ โ€œProve you're not a robotโ€ โ€” turns into full system breach!

Hackers are using fake CAPTCHA checks to deploy a stealthy new Rust malware, EDDIESTEALER, via ClickFixโ€”a social engineering trick abusing PowerShell on Windows.

๐ŸŽฏ Targets: Passwords, crypto wallets, cookies, and more.

๐Ÿ”— Full report: https://thehackernews.com/2025/05/eddiestealer-malware-uses-clickfix.html
๐Ÿคฏ25๐Ÿ˜19๐Ÿ”ฅ4๐Ÿ‘4๐Ÿค”3โšก1
๐Ÿšจ Global cybercrime tool taken down.

On May 27, 2025, U.S., Dutch, and Finnish authorities seized domains like AvCheck[.]net, used by hackers to hide malware from antivirus tools.

๐Ÿ‘€ The twist? These โ€œsecurity checkersโ€ claimed to detect threatsโ€”but were secretly helping cybercriminals stay invisible.

๐Ÿ”— Details: https://thehackernews.com/2025/05/us-doj-seizes-4-domains-supporting.html
๐Ÿ‘26๐Ÿ”ฅ8๐Ÿ‘4๐Ÿ˜4๐Ÿคฏ3โšก1
๐Ÿ” Two Linux flaws let local attackers steal secrets from crash dumps โ€” including password hashes.

Found in Ubuntu, RHEL & Fedora, the bugs (CVE-2025-5054 & CVE-2025-4598) exploit SUID crash handling.

A simple raceโ€”triggered at just the right timeโ€”can leak /etc/shadow data.

PoC is public. Mitigations exist.

Read: https://thehackernews.com/2025/05/new-linux-flaws-allow-password-hash.html
๐Ÿค”16๐Ÿ˜ฑ10๐Ÿ‘7๐Ÿ”ฅ7๐Ÿ‘7๐Ÿคฏ7๐Ÿ˜4โšก3
๐Ÿ‘€ โ€œStrategic Opportunityโ€ or Silent Backdoor?

CFOs across Europe, Africa, & Asia are being hunted in a stealth phishing op impersonating Rothschild recruiters. Victims solve a CAPTCHAโ€”then unknowingly install NetBird & OpenSSH, giving attackers remote access.

Itโ€™s legit software. Weaponized.

Learn more: https://thehackernews.com/2025/06/fake-recruiter-emails-target-cfos-using.html
๐Ÿ”ฅ29๐Ÿ‘10โšก1
Cyberattacks are getting smarterโ€”not louder.

APTs, AI malware, and browser hijacks are slipping in through trusted tools.

Weโ€™ve cut through the noiseโ€”here are the key exploits, CVEs, and tactics to know.

๐Ÿ”— Read latest weekly recap: https://thehackernews.com/2025/06/weekly-recap-apt-intrusions-ai-malware.html
๐Ÿ”ฅ21๐Ÿ˜6๐Ÿ‘3๐Ÿ‘2๐Ÿค”1