The Hacker News
โœ”
151K subscribers
1.86K photos
10 videos
3 files
7.77K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: [email protected]

๐ŸŒ Website: https://thehackernews.com
Download Telegram
๐Ÿšจ Forgotten domains are becoming cybercriminals' secret weapon to bypass email security!

Hackers are reviving decades-old domains that lack basic security measures to send phishing emails. These tactics fool even advanced systems like SPF and DMARC.

Learn more: https://thehackernews.com/2025/01/neglected-domains-used-in-malspam-to.html
๐Ÿ‘18๐Ÿ”ฅ3
๐Ÿ”ฎ What does the future hold for SaaS security in 2025?

Here are some predictions for the year ahead, including:

๐Ÿ“ˆ Increased SaaS-based attacks
โ˜๏ธ Zero Trust will be non-negotiable
โš”๏ธ Identity management as the key battleground

See what else is in store for the year ahead: https://thn.news/saas-security-predictions-li
โšก10๐Ÿ‘5
๐Ÿ”ฅ Critical Ivanti Flaw Under Attack!

Hackers are actively targeting CVE-2025-0282โ€”a buffer overflow flaw (CVSS 9.0)โ€”in Ivanti Connect Secure, Policy Secure, and ZTA Gateways.

Mandiant links this to China-linked actors (UNC5337) using novel tools like DRYHOOK for credential theft.

โคท Federal agencies must patch by January 15, 2025.
โคท Organizations worldwide are at risk of breaches.

๐Ÿ‘‰ Learn more here: https://thehackernews.com/2025/01/ivanti-flaw-cve-2025-0282-actively.html
๐Ÿ˜11๐Ÿ‘4๐Ÿคฏ1๐Ÿ˜ฑ1
๐Ÿ˜„๐Ÿ˜„ For the first time ever, the European Commission has been fined (Just โ‚ฌ400) for violating its own data privacy laws.

The breach involved sending an EU citizen's dataโ€”including IP address and browser metadataโ€”to Meta's servers in the U.S. via "Sign in with Facebook."

Learn more: https://thehackernews.com/2025/01/eu-commission-fined-for-transferring.html
๐Ÿ˜67๐Ÿ˜ฑ8๐Ÿ‘7๐Ÿ‘6โšก5
โš ๏ธ Warning: Over 23,800 GFI KerioControl firewalls are vulnerable to a 1-click RCE flaw (CVE-2024-52875) that gives attackers root access.

๐Ÿ›ก๏ธ Update to v9.4.5 Patch 1 and audit your firewall access points immediately.

๐Ÿ‘‰ Full details here: https://thehackernews.com/2025/01/critical-rce-flaw-in-gfi-keriocontrol.html
โšก10๐Ÿ‘5๐Ÿ˜4
๐Ÿ›‘ China-linked MirrorFace has targeted Japanโ€™s security and tech sectors in over 4 years of persistent attacks, says NPA & NCSC.

These attackers use spear-phishing, exploit device vulnerabilities, and evade antivirus detection by operating in Windows Sandboxโ€”leaving no trace behind.

๐Ÿ”— Learn the tactics attackers use and how to counter them: https://thehackernews.com/2025/01/mirrorface-leverages-anel-and-noopdoor.html
๐Ÿ”ฅ10๐Ÿ˜5โšก4๐Ÿ‘2๐Ÿ‘2
Advance your skills in strategic security design with Georgetownโ€™s Online Certificate in Cybersecurity Strategy.

Learn more: https://thn.news/cybersecurity-strategy-ig
๐Ÿ”ฅ16๐Ÿ‘5๐Ÿ˜1
๐Ÿšจ New Threat Alert: Banshee Stealer!

The latest variant targets macOS users and hides its tracks using Apple-inspired encryption.

๐Ÿ’ป Targets victims via phishing websites disguised as Google Chrome & Telegram
๐Ÿ’ธ Offered to hackers for $3,000/month under a Malware-as-a-Service model

๐Ÿ”— Read more: https://thehackernews.com/2025/01/new-banshee-stealer-variant-bypasses.html
๐Ÿ‘16โšก4๐Ÿ˜4
๐Ÿšจ Critical flaws found in major platforms:

โคท SonicWall: SSLVPN bypass (CVSS 8.2) & privilege escalation.
โคท Palo Alto Networks: SQL injection exposes passwords & API keys (CVSS 7.8).
โคท Aviatrix: Max severity flaw (CVSS 10.0) allows remote code execution.

๐Ÿ‘‰ Full details: https://thehackernews.com/2025/01/major-vulnerabilities-patched-in.html

Patch systems to secure your organization.
๐Ÿ‘22โšก4๐Ÿ”ฅ4๐Ÿค”2๐Ÿคฏ2
โš ๏ธ Hackers are impersonating cybersecurity giant CrowdStrike, tricking victims into downloading a cryptominer disguised as a recruitment tool.

๐Ÿ›‘ In a separate campaign, cybercriminals are targeting researchers with a fake PoC for the LDAPNightmare vulnerability (CVE-2024-49113).

๐Ÿ”— Stay informed and learn more: https://thehackernews.com/2025/01/crowdstrike-warns-of-phishing-scam.html
โšก8๐Ÿ˜5๐Ÿ‘4
๐Ÿšจ China-linked RedDelta hackers are targeting Southeast Asia, Mongolia & Taiwan with custom PlugX backdoors in a series of espionage attacks.

โคท New tactic: Using Cloudflare CDN to mask malicious traffic
โคท Spyware deployed: Custom PlugX backdoor

Read: https://thehackernews.com/2025/01/reddelta-deploys-plugx-malware-to.html
๐Ÿ‘15โšก5๐Ÿ˜3๐Ÿค”2
โš ๏ธ A high-severity vulnerability in Samsung's Monkey's Audio decoder (CVE-2024-49415) is putting millions of devices at risk.

๐Ÿ”ด No user interaction needed โ€“ attackers can exploit this flaw remotely, allowing them to execute arbitrary code on your phone.

Update your Samsung device immediately to patch this flaw.

Read details here: https://thehackernews.com/2025/01/google-project-zero-researcher-uncovers.html
๐Ÿ”ฅ14๐Ÿ‘6โšก5๐Ÿคฏ3๐Ÿ˜ฑ2
This media is not supported in your browser
VIEW IN TELEGRAM
๐Ÿšจ Shadow AI is hereโ€”and itโ€™s putting your company at risk as employees secretly use AI tools like ChatGPT, transcription apps, and customer support bots.

Identify which apps and AI tools are in use across your organization with Recoโ€™s detection solutionโ€”before they lead to a security incident.

Start securing your apps now: https://thehackernews.com/2025/01/product-review-how-reco-discovers.html
๐Ÿ‘12โšก5
โšก FunkSec, a rising ransomware group, has already hit 85+ victims, demanding ransoms as low as $10,000. Whatโ€™s worse? Theyโ€™re leveraging AI to rapidly evolve their attacks.

With targets like the U.S. and India, FunkSec's motives go beyond moneyโ€”they are blurring the lines between hacktivism and cybercrime.

๐Ÿ‘‰ Learn more: https://thehackernews.com/2025/01/ai-driven-ransomware-funksec-targets-85.html
โšก11๐Ÿ‘8๐Ÿ”ฅ5
Kick off 2025 with a game plan to grow your MSPโ€™s revenue and deliver outstanding value to your clients.

Join us on January 15 to "10x Your MSP Profits in 2025 with Automated Network Pentesting" and discover how vPenTest can help you set the tone for a successful year.

Save your spot: https://thn.news/webinar-automated-pentesting-2025
๐Ÿ‘6๐Ÿ”ฅ5โšก3๐Ÿ‘2๐Ÿ˜1
๐Ÿ“Š Reporting is broken! Is YOUR cybersecurity reporting still a โ€œcheck the boxโ€ task?

Clients donโ€™t want to hear about firewall logsโ€”they want to understand how YOU are safeguarding their business.

Find out how to improve it here: https://thehackernews.com/2025/01/taking-pain-out-of-cybersecurity.html
โšก7๐Ÿ”ฅ4๐Ÿ˜ฑ3๐Ÿ˜2๐Ÿ‘1
๐Ÿ’ฐ How One U.S. Health System Cut Security Costs by 76% ...

๐Ÿ‘‰ The system deployed Elisity with just 2 staff members per site, compared to 14 for traditional segmentation.

โšก Elisity is a seamless, lightweight solution that integrates with existing switches and works with Cisco, Juniper, and Arista devices, taking less than 30 minutes to deploy without any network downtime.

Get the full details here: https://thehackernews.com/2025/01/hands-on-walkthrough-microsegmentation.html
โšก11๐Ÿ‘7๐Ÿ”ฅ5๐Ÿ˜5๐Ÿค”5
๐Ÿ›‘ U.S. Justice Department indicts 3 Russian nationals involved in laundering millions through cryptocurrency mixers Blender`io and Sinbad`io.

Full details inside: https://thehackernews.com/2025/01/doj-indicts-three-russians-for.html
โšก19๐Ÿ‘10๐Ÿ˜ฑ6๐Ÿ”ฅ3
๐Ÿ”ฅ Microsoft has taken legal action against hackers using stolen Azure credentials to exploit AI services like OpenAI and DALL-E for malicious purposes.

Read the full story: https://thehackernews.com/2025/01/microsoft-sues-hacking-group-exploiting.html
๐Ÿ˜44๐Ÿ‘25๐Ÿ”ฅ13๐Ÿค”7โšก1๐Ÿคฏ1
๐Ÿ‘€ Over 4,000 web backdoors hijackedโ€”by registering abandoned domains for as little as $20.

๐Ÿ”‘ Researchers gained control of backdoors targeting government & academic networks in Bangladesh, China, Nigeria, South Korea, and more!

Read now: https://thehackernews.com/2025/01/expired-domains-allowed-control-over.html
๐Ÿ˜24๐Ÿ‘12โšก8๐Ÿ”ฅ8