The Hacker News
βœ”
152K subscribers
1.88K photos
10 videos
3 files
7.79K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
New macOS malware alert: FrigidStealer is targeting users outside North America through fake updates to steal sensitive data.

This threat is linked to the elusive TA2727 group, which also spreads malware like Lumma Stealer and Marcher via web injects.

https://thehackernews.com/2025/02/new-frigidstealer-malware-targets-macos.html
😁12πŸ‘6πŸ”₯2πŸ€”2😱1
πŸ’» 93% of malware still relies on the Top 10 MITRE ATT&CK techniques.

πŸ›‘οΈ Focus on proven TTPs like credential theft and process injection to defend against the threats that matter today.

πŸ”— Explore the full insights in the Picus Red Report 2025: https://thehackernews.com/2025/02/debunking-ai-hype-inside-real-hacker.html
😁8πŸ‘5πŸ€”2⚑1
🐼 Mustang Panda, a Chinese state-backed group, has evolved its attack methods by using Microsoft’s MAVInject.exe to inject malware into external processes, bypassing antivirus detection and remaining undetected.

Read more about the attack chain: https://thehackernews.com/2025/02/chinese-hackers-exploit-mavinjectexe-to.html
πŸ‘19πŸ”₯4πŸ€”4
πŸ”΄ Two new vulnerabilities found in OpenSSH – one allowing active Man-in-the-Middle (MitM) attacks and the other leading to Denial-of-Service (DoS).

Get the details on CVE-2025-26465 and CVE-2025-26466: https://thehackernews.com/2025/02/new-openssh-flaws-enable-man-in-middle.html
πŸ”₯30😱15πŸ‘3⚑1πŸ€”1🀯1
🚨 Two critical vulnerabilities in Palo Alto Networks PAN-OS and SonicWall SonicOS SSLVPN are actively exploited, now added to CISA's KEV catalog.

CVE-2025-0108 allows unauthenticated attackers to bypass PAN-OS security, while CVE-2024-53704 compromises SSLVPN authentication.

Exploitation is escalating, with attack traffic spiking 10x in a week. Act now!

Read More: https://thehackernews.com/2025/02/cisa-adds-palo-alto-networks-and.html
πŸ‘16😁8πŸ‘1πŸ€”1
🚨ALERT: A global cryptocurrency miner campaign is targeting gamers.

Cybercriminals are using popular games like BeamNG-drive and Garry's Mod to deliver malicious software, secretly mining cryptocurrency on infected gaming rigs.

Learn more: https://thehackernews.com/2025/02/trojanized-game-installers-deploy.html
🀯13πŸ€”6πŸ‘4😁1
⚠️ Exposed or forgotten assets are prime hacker targets. In 2024, over 60% of breaches started with small, overlooked assets like old subdomains.

Learn how Attack Surface Management (ASM) helps you detect changes in real time and secure vulnerable assets.

Read: https://thehackernews.com/expert-insights/2025/02/how-hackers-exploit-your-attack-surface.html
πŸ‘17πŸ€”5
Looking to grow your cybersecurity business? vCISO services are the key to capturing the growing demand for strategic leadership.

This Ultimate Guide breaks down actionable steps for MSPs and MSSPs to build a profitable vCISO practice.

Check out: https://thehackernews.com/2025/02/the-ultimate-msp-guide-to-structuring.html
πŸ€”7πŸ‘1🀯1
A new Snake Keylogger variant is targeting Windows users in China, Turkey, Indonesia, Taiwan, and Spain, with over 280 million infection attempts blocked in a year.

Delivered via phishing emails, it logs keystrokes, steals credentials, and monitors clipboards from browsers like Chrome and Firefox.

Read more: https://thehackernews.com/2025/02/new-snake-keylogger-variant-leverages.html
πŸ”₯17πŸ€”5⚑4πŸ‘4😁3😱2πŸ‘1
Russian-aligned threat actors are using malicious QR codes to hijack Signal accounts via the app’s legitimate β€œlinked devices” feature.

Once compromised, threat actors gain real-time access to victim messages, enabling persistent surveillance.

Learn how these attacks work: https://thehackernews.com/2025/02/hackers-exploit-signals-linked-devices.html
πŸ”₯23😁11🀯11πŸ‘3⚑2πŸ€”2πŸ‘1
🚨 Microsoft has issued high-severity security updates for Bing (CVE-2025-21355) and Power Pages (CVE-2025-24989), addressing two serious flaws.

One of these vulnerabilities is already being exploited in the wild.

Read more: https://thehackernews.com/2025/02/microsoft-patches-actively-exploited.html
πŸ”₯13πŸ‘6πŸ€”5😁4
Citrix has patched a severe flaw in NetScaler Console & Agent (CVE-2024-12284) with a CVSS score of 8.8.

This privilege escalation bug could allow authenticated attackers to execute unauthorized actions.

UPDATE immediately to the latest versions.

Read: https://thehackernews.com/2025/02/citrix-releases-security-fix-for.html
⚑9πŸ‘6πŸ€”2πŸ”₯1
πŸ›‘ UPDATE: Researchers reveal tech details on credential coercion vulnerabilities (CVE-2024-13159-13161, 10811) in Ivanti EPM. Attackers could compromise servers via relay attacks.

⚑ Patch urgently if you haven’t done so alreadyβ€”PoC exploit now in the wild.

https://thehackernews.com/2025/01/researcher-uncovers-critical-flaws-in.html
😁12πŸ€”6πŸ‘3πŸ‘2
πŸ“… Mark your calendars!

Microsoft Exchange 2016 and 2019 support ends on October 14, 2025. This means no more security patches or technical support.

πŸ” Without updates, these versions will be prime targets for cybercriminals.

Get the full details on your migration options in the article: https://thehackernews.com/2025/02/microsoft-end-of-support-for-exchange-2016-and-exchange-2019.html
πŸ‘18πŸ”₯5😁2πŸ‘1πŸ€”1
Cybercriminals are using the Eclipse Foundation’s jarsigner tool to distribute XLoader malware, exploiting DLL side-loading techniques.

The malware now employs complex encryption at runtime, making signature-based defenses less effective.

Read more: https://thehackernews.com/2025/02/cybercriminals-use-eclipse-jarsigner-to.html
😱10πŸ‘4πŸ€”2😁1
πŸ›‘ The Green Nailao campaign deployed NailaoLocker ransomware, locking files and demanding Bitcoin payments.

Attackers exploited a Check Point flaw to steal credentials and escalate via RDP.

πŸ‘‰ Learn more: https://thehackernews.com/2025/02/chinese-linked-attackers-exploit-check.html
πŸ”₯12😁3πŸ‘2πŸ€”1🀯1
By March 31, 2025, all businesses handling cardholder data must implement PCI DSS 4.0 DMARC β€” No exceptions.

Failure to comply could cost you $5K-$100K in penaltiesβ€”and that’s just the start.

Read the full article now: https://thehackernews.com/2025/02/pci-dss-40-mandates-dmarc-by-31st-march.html
πŸ‘11πŸ”₯6😁5πŸ€”1😱1
🚨 Freelance developers are under attack.

North Korean hackers use fake job interviews on Upwork and GitHub to infect crypto developers with BeaverTail and InvisibleFerret malware, stealing credentials and funds.

πŸ‘‰ Get the full story: https://thehackernews.com/2025/02/north-korean-hackers-target-freelance.html
😁23😱11⚑9πŸ‘6πŸ€”3πŸ”₯1
The CISA has flagged a critical vulnerability in Craft CMS, prompting urgent action.

CVE-2025-23209 carries a high CVSS score of 8.1β€”indicating significant risk to any organization still using outdated versions.

This code injection flaw opens the door to remote code execution, potentially exposing sensitive user security keys.

Learn more: https://thehackernews.com/2025/02/cisa-flags-craft-cms-vulnerability-cve.html
πŸ‘12πŸ€”5😁3πŸ‘1
A Chinese threat group, Salt Typhoon, has infiltrated major U.S. telecoms by exploiting CVE-2018-0171, a critical security flaw.

The attackers maintained access for over three years, showcasing their patience and sophistication.

Read more to learn: https://thehackernews.com/2025/02/cisco-confirms-salt-typhoon-exploited.html
πŸ‘19😱9πŸ”₯4πŸ‘3😁2πŸ€”2⚑1🀯1