The Hacker News
βœ”
152K subscribers
1.87K photos
10 videos
3 files
7.79K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
🚨 Zero-click AI exploit in Microsoft 365 Copilot (CVE-2025-32711, CVSS 9.3) lets attackers steal sensitive data silently via emailβ€”no user interaction needed.

Details ↓ https://thehackernews.com/2025/06/zero-click-ai-vulnerability-exposes.html

Already patched, but shows serious AI security risks ahead.
😁16⚑10πŸ‘4πŸ€”4
✨ Webinar Alert! Artificial Intelligence isn’t just transforming tech β€” it’s creating invisible, unchecked identities hackers exploit to breach your systems silently.

Traditional security can’t see or stop them.

If you use AI, you’re at risk.

LEARN out how to secure these hidden non-human identities ↓ https://thehackernews.com/2025/06/ai-agents-run-on-secret-accounts-learn.html
😁9🀯4😱2
⚠️ New TokenBreak ATTACK lets attackers bypass AI content filters by tweaking just one letterβ€”making harmful prompts slip past unnoticed.

It fools many text classifiers while keeping meaning clear to humans and AI, enabling prompt injections.

Read more ↓ https://thehackernews.com/2025/06/new-tokenbreak-attack-bypasses-ai.html
πŸ‘5😁4πŸ€”3🀯1
VexTrio’s cybercrime network hijacks hundreds of thousands of websites to spread scams & malware through fake ads and push alerts.

Even after a setback in late 2024, they keep running using clever DNS tricks & Russian servers.

What;s really going on ↓ https://thehackernews.com/2025/06/wordpress-sites-turned-weapon-how.html
🀯12πŸ”₯5πŸ‘3😁1πŸ€”1😱1
This media is not supported in your browser
VIEW IN TELEGRAM
🚨 WARNING: Apple just confirmed a serious zero-click flaw in Messages was actively exploited to spy on journalists using Israeli spyware Paragon Graphite β€” no user action needed.

Details here ↓ https://thehackernews.com/2025/06/apple-zero-click-flaw-in-messages.html
🀯31πŸ€”8πŸ”₯6😁3😱2πŸ‘1
🚨 Ransomware gangs are exploiting unpatched SimpleHelp flaws to hit utility billing customers with double extortion attacks β€” since Jan 2025.

CISA warns: patch now or risk serious breaches.

Read β†’ https://thehackernews.com/2025/06/ransomware-gangs-exploit-unpatched.html

Meanwhile, new Fog ransomware uses legit employee monitoring software to stay hidden and persistent for weeks.
πŸ‘14πŸ”₯2
Security teams drown in alertsβ€”but real risks slip through unnoticed.

Continuous Threat Exposure Management (CTEM) shifts focus from alerts to actual attack paths, prioritizing prevention over reaction.

Stop chasing every alert. Start managing risk with purpose.

Read more ↓ https://thehackernews.com/2025/06/ctem-is-new-soc-shifting-from.html
πŸ‘7πŸ‘1
🚨 Over 269,000 legit websites hijacked with hidden JavaScript redirecting search engine visitors to malware and scams.

Using a stealthy JSFireTruck obfuscation, attackers fingerprint devices to serve fake CAPTCHAs, tech support scams, and malwareβ€”evading detection at scale.

Learn how this massive campaign works ↓ https://thehackernews.com/2025/06/over-269000-websites-infected-with.html
🀯9πŸ‘5
Discord invite links are being hijacked to deliver malware that steals crypto wallets and personal data.

Attackers reuse expired/deleted invites, redirecting to fake servers, tricking users into running malicious PowerShell scripts disguised as verification.

Full details here ↓ https://thehackernews.com/2025/06/discord-invite-link-hijacking-delivers.html

This Multi-stage attack uses Pastebin & GitHub to evade security tools.
πŸ‘35πŸ€”12πŸ‘8πŸ”₯3😁3
⚠️ A fake Python package just stole AWS tokens, Jamf data & CI/CD secrets β€” from devs at Grab.

The malware posed as a legit helper for ML workflows, hid a multi-stage info-stealer, and targeted macOS too.

Details here β†’ https://thehackernews.com/2025/06/malicious-pypi-package-masquerades-as.html
😱19πŸ”₯12πŸ‘10⚑5πŸ‘2😁2
🚨 Most cybersecurity providers are leaving money on the table.

Still selling one-off audits or patch jobs? You're missing the shift.

Strategic services like vCISO programs aren’t just higher valueβ€”they’re recurring revenue machines.

How to evolve your offering ↓ https://thehackernews.com/2025/06/playbook-transforming-your.html
πŸ‘7πŸ”₯3πŸ‘3
🚨 New ransomware β€œAnubis” can encrypt your filesβ€”and then erase them forever.

Even if you pay, recovery is impossible. Victims span healthcare, hospitality & more.

This rare dual-threat ups the pressure to pay.

Details here β†’ https://thehackernews.com/2025/06/anubis-ransomware-encrypts-and-wipes.html
🀯19πŸ”₯10😱7⚑3πŸ‘2
🚨 U.S. seizes $7.7M linked to North Korean IT worker scam targeting crypto firms.

Fake identities, AI tools, and Zoom hacks helped funnel millions to fund Pyongyang’s weapons program.

Here’s how deep the deception goes ↓ https://thehackernews.com/2025/06/us-seizes-774m-in-crypto-tied-to-north.html
😁18πŸ€”8🀯7πŸ‘6⚑5
🚨 WhatsApp ads are finally hereβ€”inside your Status updates.

Meta says it’s privacy-friendly, but it’s tapping your location, device data, and even Facebook activity to target you.

Here’s what’s changing ↓ https://thehackernews.com/2025/06/meta-starts-showing-ads-on-whatsapp.html
😱25😁16🀯14πŸ‘5⚑3πŸ€”2πŸ”₯1πŸ‘1
🚨 VPNs are now a business risk β€” not just a security hole.

Hackers are using AI to scan for flaws 24/7. One bug in your VPN, and it’s open season.

The fix? Stop trusting the network. Start securing access.

Details here β†’ https://thehackernews.com/expert-insights/2025/04/its-time-to-rethink-your-security-for.html
πŸ‘18πŸ”₯3πŸ‘1🀯1
🚨 CISA just flagged a live exploit in TP-Link routers (CVE-2023-33538, CVSS 8.8) β€” attackers can run system commands remotely.

Worse? Many affected models may be end-of-life, with no fix coming.

Here’s what you need to know ↓ https://thehackernews.com/2025/06/tp-link-router-flaw-cve-2023-33538.html
😱17πŸ‘5πŸ”₯1
🚨 Langflow flaw (CVSS 9.8) now exploited in the wild β€” installs new Flodrix botnet

No login needed. One HTTP request = full remote control.

Targets AI servers for encrypted DDoS via TOR.

Details here β†’ https://thehackernews.com/2025/06/new-flodrix-botnet-variant-exploits.html
πŸ‘11πŸ”₯4πŸ‘1
🚨 Sitecore flaw gives hackers full access β€” with a single-character password.

A default login of β€œb” can be chained to remote code execution. It works pre-auth.

Used by banks, airlines, global firms. The blast radius is huge.

Here’s what you need to know ↓ https://thehackernews.com/2025/06/hard-coded-b-password-in-sitecore-xp.html
😁11πŸ”₯4πŸ‘2😱1
🚨 Ransomware is now destroying your backups first.

Hackers are targeting snapshots, wiping cloud copies, and deleting recovery paths β€” before locking your systems.

The worst part? Many orgs don’t realize it until it’s too late.

Here’s how to bulletproof your backups ↓ https://thehackernews.com/2025/06/how-to-protect-your-backups-from-ransomware-attacks.html
🀯13😁7πŸ‘4πŸ”₯3πŸ‘2😱1
🚨 24 million secrets exposed on GitHubβ€”and AI is making it worse.

Repos using Copilot are 40% more likely to leak credentials.

Think API keys, SSH tokens… the stuff attackers love.
The worst part? Most devs don’t even know they’re leaking them.

Here’s how to fix it ↓ https://thehackernews.com/expert-insights/2025/06/exposed-developer-secrets-are-big.html
😁15😱4πŸ‘3πŸ”₯2
πŸ•·οΈ Scattered Spider is now hitting U.S. insurance giants β€” not just retailers.

⚠️ They’re bypassing MFA, tricking help desks, and breaching entire IT ecosystems.

Here’s how they do it β€” and how to stop them ↓ https://thehackernews.com/2025/06/google-warns-of-scattered-spider.html
🀯7πŸ‘5πŸ”₯1πŸ‘1