The Hacker News
151K subscribers
1.85K photos
10 videos
3 files
7.77K links
Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

📨 Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
🚨 China-linked hackers just targeted Tibetans with fake documents tied to the Dalai Lama & WPCT.

Behind it? Mustang Panda’s new malware chain: Claimloader → PUBLOAD → Pubshell (reverse shell access).

The twist? It spreads via Google Drive links & even USB worms.

Learn more → https://thehackernews.com/2025/06/pubload-and-pubshell-malware-used-in.html
👏10😱8🔥4👍1🤯1
🚨 1,000+ hacked home & office devices turned into a covert spying network for Chinese ops.

Worse? The malware mimics the LAPD—and it’s still growing quietly across the US + Asia.

Details on “LapDogs” & the backdoor behind it → https://thehackernews.com/2025/06/over-1000-soho-devices-hacked-in-china.html
👏13🔥6😁6🤯6👍1🤔1
🚨 Facebook now asks to upload your phone photos—even unposted ones—to generate AI recaps, collages, and story ideas.

Say yes, and Meta can scan faces, locations, and more.

Full story → https://thehackernews.com/2025/06/facebooks-new-ai-tool-requests-photo.html
🤯34😁13😱12🤔4👍3
🚨 A Ukrainian military phishing campaign just escalated.

GIFTEDCROOK malware now steals not just browser data—but sensitive documents, emails, and VPN configs.

It hides in fake Excel files, exfiltrates via Telegram, and wipes its tracks.

The goal? Targeted intelligence ops.

Full report → https://thehackernews.com/2025/06/giftedcrook-malware-evolves-from.html
🤯27🔥9👍2
🚨 Scattered Spider is now targeting airlines, FBI warns.

Their method? Impersonate staff, trick help desks, bypass MFA—no malware needed.

Why it matters: Even C-level accounts are being hijacked with just a phone call.

Details here → https://thehackernews.com/2025/06/fbi-warns-of-scattered-spiders.html
🤯354👍4🔥1
🚨 83% of attacks now involve stolen credentials—and machines outnumber humans 50 to 1.

The real threat? Leaked API keys & orphaned tokens silently granting access across your stack.

GitGuardian just launched a smarter way to track every secret & secure your non-human identities.

Details here → https://thehackernews.com/2025/06/leveraging-credentials-as-unique.html
🔥7👍1
🚨 Blind Eagle is back—now using Russian bulletproof hosting (Proton66) to launch phishing attacks on Colombian banks.

They’re hiding malware in fake login pages & encrypted scripts.

The RATs they use are open-source—and still effective.

Full story → https://thehackernews.com/2025/06/blind-eagle-uses-proton66-hosting-for.html
🤯5👍3🤔2
🚨 A global crypto fraud ring just got busted—€460M laundered, 5,000+ victims worldwide.

The twist? It’s tied to scam compounds using forced labor and AI-powered romance baiting.

This is industrialized cybercrime.

Full story ↓ https://thehackernews.com/2025/06/europol-dismantles-540-million.html
👏8🤯6
🚨 U.S. agencies warn: Iranian-linked hackers may strike soon.

Targets? Defense firms tied to Israel. Tactics? Password cracking, phishing, OT access.

The threat is rising—even amid ceasefire talks.

Full details + mitigations → https://thehackernews.com/2025/06/us-agencies-warn-of-rising-iranian.html
🔥226👏4🤔3😁2😱2
🚨 Microsoft is killing password support in its Authenticator app by August 2025.

Autofill dies in July.
Saved logins? Only accessible in Edge—if it’s your default autofill.

Don’t export in time? You lose them.

What to know + what to do ↓ https://thehackernews.com/2025/07/microsoft-removes-password-management.html
😁20😱11👍6🤔5
🚨 North Korea infiltrated 100+ U.S. companies using fake remote workers—stealing data, crypto & defense tech.

They even used AI to forge voices, documents & LinkedIn profiles.

The worst part? Some were praised as top talent.

Full story → https://thehackernews.com/2025/07/us-arrests-key-facilitator-in-north.html
🤯15👏108😁3
🚨 A new Chrome zero-day is already being exploited in the wild.

Discovered by Google TAG on June 25, CVE-2025-6554 lets attackers run malicious code via a crafted web page.

It targets Chrome’s V8 engine—again.

Update now → https://thehackernews.com/2025/07/google-patches-critical-zero-day-flaw.html
🤯13😁5👍4🔥2👏2
🚨 Compliance ≠ Trust.

Join Vanta and Matt Johansen, Founder & Security Researcher at Vulnerable U, on July 23 to unpack the new Trust Maturity Report and explore what real security trust looks like—at every stage of growth.

Don’t miss the session: Security, AI, and Trust: Reviewing Vanta’s Trust Maturity Report → https://thn.news/trust-ai-security-webinar
🔥8
🚨 85% of work now happens in the browser—yet most orgs still can’t see what’s pasted into ChatGPT.

A new guide exposes how GenAI, BYOD, and rogue extensions turned the browser into the #1 blind spot in enterprise security.

Get the fix → https://thehackernews.com/2025/07/a-new-maturity-model-for-browser.html
😱13👍3
🚨 Verified? Think again.

Malicious extensions can pose as trusted in VS Code, IntelliJ, Visual Studio & #Cursor—bypassing checks and running OS commands.

The “verified” badge isn’t protection. Even Microsoft’s filters missed it.

Full details → https://thehackernews.com/2025/07/new-flaw-in-ides-like-visual-studio.html
🤯20🤔14👍5😁2😱1
🚨 Russia-linked hackers are now blurring the line between cybercrime and espionage.

TA829 & UNK_GreenSec are using identical tactics—fake job lures, IPFS malware, REM Proxies—to drop ransomware and spy tools.

Read details → https://thehackernews.com/2025/07/ta829-and-unkgreensec-share-tactics-and.html
😁17👍3🤔3
🚨 Critical RCE flaw hits Anthropic’s AI dev tool.

Just visiting a malicious site could let hackers run code on your machine.

It targets localhost—using a 19-year-old browser bug.

MCP Inspector < v0.14.1 is at risk.

Patch now → https://thehackernews.com/2025/07/critical-vulnerability-in-anthropics.html
👏9👍3🔥2
🚨 Hackers are now using AI tools like Vercel's v0 to spin up fake login pages—just from text prompts.

They’re cloning trusted brands, hosting on legit platforms, and bypassing old phishing methods.

The AI phishing era is here.

Read details here → https://thehackernews.com/2025/07/vercels-v0-ai-tool-weaponized-by.html
👍14👏8🔥5😱1
🚨 AI agents are leaking sensitive enterprise data — and most orgs don’t even know it.

GenAI tools often connect to S3, SharePoint, Google Drive… without proper controls.

The risk? Silent breaches.

Join the webinar on July 7 to learn how to secure your AI workflows ↓ https://thehacker.news/securing-ai-agents-workflows?source=social
😁9👍1👏1
🚨 U.S. sanctions Russian hosting firm Aeza Group for fueling ransomware, data theft & drug trade.

Its CEO ran dark web drug markets. Its servers powered RomCom, RedLine, and Doppelganger ops.

This wasn't just hosting—it was cybercrime infrastructure.

READ → https://thehackernews.com/2025/07/us-sanctions-russian-bulletproof.html
🤔9👍5🤯5
🚨 Hackers now talk you into getting hacked.

PDF phishing emails impersonate Microsoft, PayPal, DocuSign—urging you to call fake support lines.

On the call, they steal your info or install malware.

FBI, Cisco, and Varonis warn: it’s rising fast.

Read how it works → https://thehackernews.com/2025/07/hackers-using-pdfs-to-impersonate.html
😁13🤔4🤯42