The Hacker News
βœ”
152K subscribers
1.88K photos
10 videos
3 files
7.79K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
🚨 Microsoft has issued high-severity security updates for Bing (CVE-2025-21355) and Power Pages (CVE-2025-24989), addressing two serious flaws.

One of these vulnerabilities is already being exploited in the wild.

Read more: https://thehackernews.com/2025/02/microsoft-patches-actively-exploited.html
πŸ”₯13πŸ‘6πŸ€”5😁4
Citrix has patched a severe flaw in NetScaler Console & Agent (CVE-2024-12284) with a CVSS score of 8.8.

This privilege escalation bug could allow authenticated attackers to execute unauthorized actions.

UPDATE immediately to the latest versions.

Read: https://thehackernews.com/2025/02/citrix-releases-security-fix-for.html
⚑9πŸ‘6πŸ€”2πŸ”₯1
πŸ›‘ UPDATE: Researchers reveal tech details on credential coercion vulnerabilities (CVE-2024-13159-13161, 10811) in Ivanti EPM. Attackers could compromise servers via relay attacks.

⚑ Patch urgently if you haven’t done so alreadyβ€”PoC exploit now in the wild.

https://thehackernews.com/2025/01/researcher-uncovers-critical-flaws-in.html
😁12πŸ€”6πŸ‘3πŸ‘2
πŸ“… Mark your calendars!

Microsoft Exchange 2016 and 2019 support ends on October 14, 2025. This means no more security patches or technical support.

πŸ” Without updates, these versions will be prime targets for cybercriminals.

Get the full details on your migration options in the article: https://thehackernews.com/2025/02/microsoft-end-of-support-for-exchange-2016-and-exchange-2019.html
πŸ‘18πŸ”₯5😁2πŸ‘1πŸ€”1
Cybercriminals are using the Eclipse Foundation’s jarsigner tool to distribute XLoader malware, exploiting DLL side-loading techniques.

The malware now employs complex encryption at runtime, making signature-based defenses less effective.

Read more: https://thehackernews.com/2025/02/cybercriminals-use-eclipse-jarsigner-to.html
😱10πŸ‘4πŸ€”2😁1
πŸ›‘ The Green Nailao campaign deployed NailaoLocker ransomware, locking files and demanding Bitcoin payments.

Attackers exploited a Check Point flaw to steal credentials and escalate via RDP.

πŸ‘‰ Learn more: https://thehackernews.com/2025/02/chinese-linked-attackers-exploit-check.html
πŸ”₯12😁3πŸ‘2πŸ€”1🀯1
By March 31, 2025, all businesses handling cardholder data must implement PCI DSS 4.0 DMARC β€” No exceptions.

Failure to comply could cost you $5K-$100K in penaltiesβ€”and that’s just the start.

Read the full article now: https://thehackernews.com/2025/02/pci-dss-40-mandates-dmarc-by-31st-march.html
πŸ‘11πŸ”₯6😁5πŸ€”1😱1
🚨 Freelance developers are under attack.

North Korean hackers use fake job interviews on Upwork and GitHub to infect crypto developers with BeaverTail and InvisibleFerret malware, stealing credentials and funds.

πŸ‘‰ Get the full story: https://thehackernews.com/2025/02/north-korean-hackers-target-freelance.html
😁23😱11⚑9πŸ‘6πŸ€”3πŸ”₯1
The CISA has flagged a critical vulnerability in Craft CMS, prompting urgent action.

CVE-2025-23209 carries a high CVSS score of 8.1β€”indicating significant risk to any organization still using outdated versions.

This code injection flaw opens the door to remote code execution, potentially exposing sensitive user security keys.

Learn more: https://thehackernews.com/2025/02/cisa-flags-craft-cms-vulnerability-cve.html
πŸ‘12πŸ€”5😁3πŸ‘1
A Chinese threat group, Salt Typhoon, has infiltrated major U.S. telecoms by exploiting CVE-2018-0171, a critical security flaw.

The attackers maintained access for over three years, showcasing their patience and sophistication.

Read more to learn: https://thehackernews.com/2025/02/cisco-confirms-salt-typhoon-exploited.html
πŸ‘19😱9πŸ”₯4πŸ‘3😁2πŸ€”2⚑1🀯1
AI-powered algorithms are changing the way we consume news, creating digital echo chambers.

One in five Americans now get their news from social media, fueling polarized viewpoints.

Read the full article to explore the rise of AI-driven misinformation: https://thehackernews.com/2025/02/ai-powered-deception-is-menace-to-our.html
πŸ”₯7πŸ‘3πŸ‘2πŸ€”1😱1
Darcula v3 enables fraudsters to clone any website’s landing page with easeβ€”no technical expertise required.

In just 10 minutes, attackers can create a phishing site with a brand’s exact look and feel, targeting unsuspecting users.

Read this article: https://thehackernews.com/2025/02/cybercriminals-can-now-clone-any-brands.html
πŸ”₯12πŸ‘7😁2πŸ€”1
Weak identity security is a major threat to your business in 2025. If your strategy isn’t evolving, it might already be too late.

Watch this webinar for actionable strategies to defend against modern cyber threats: https://thehackernews.com/2025/02/webinar-learn-how-to-identify-high-risk.html
πŸ‘13πŸ€”2
A leaked data cache from Chinese cybersecurity firm TopSec reveals shocking details about its censorship-as-a-service offerings.

The leak reveals a "Cloud Monitoring Service" contract to detect and remove politically sensitive content.

Read: https://thehackernews.com/2025/02/data-leak-exposes-topsecs-role-in.html
πŸ‘16🀯8πŸ”₯5πŸ€”1
Apple removes Advanced Data Protection (ADP) for iCloud in the U.K. following pressure from the government to build a backdoor into encrypted data.

This undermines end-to-end encryption and could set a dangerous precedent globally.

Read more: https://thehackernews.com/2025/02/apple-drops-iclouds-advanced-data.html
🀯73😁13πŸ”₯11😱9πŸ‘6πŸ€”2⚑1
OpenAI has taken action against a network using ChatGPT to develop an AI-powered surveillance tool targeting anti-China protests.

The tool, believed to be linked to Chinese authorities, analyzes social media content from platforms like X, Facebook, and Reddit to gather real-time data.

Read the full article: https://thehackernews.com/2025/02/openai-bans-accounts-misusing-chatgpt.html
πŸ”₯22😁15πŸ‘4⚑3πŸ‘2πŸ€”2🀯2
Over $1.46 billion worth of cryptocurrency was stolen from Bybit's Ethereum cold wallet in the largest crypto heist to date, reportedly orchestrated by the Lazarus Group.

The attack masked the signing interface, tricking the wallet into transferring funds to an unknown address.

Learn more: https://thehackernews.com/2025/02/bybit-confirms-record-breaking-146.html
😱86πŸ‘20πŸ”₯18😁15πŸ€”5⚑4
Australia has banned Kaspersky software due to national security risks. The Australian government cites threats like foreign interference and espionage as reasons for the ban.

Read the full article: https://thehackernews.com/2025/02/australia-bans-kaspersky-software-over.html
😁49πŸ‘25πŸ”₯8😱6πŸ€”5⚑3🀯3πŸ‘2
Get hands-on tips on optimizing your SOC at a webinar on Feb 26, 3:00 PM GMT

Experts will demonstrate best practices for faster and more effective triage, incident response, and threat hunting.

Don't miss it: https://thn.news/better-soc-malware-sandbox-tg
⚑10πŸ‘5πŸ‘4πŸ€”1
Google Cloud introduces quantum-safe digital signatures in Cloud KMS, setting the stage for a future-proof encryption strategy.

This update addresses the quantum risk, aligning with NIST's post-quantum cryptography standards.

Read: https://thehackernews.com/2025/02/google-cloud-kms-adds-quantum-safe.html
πŸ‘24πŸ€”10⚑5πŸ”₯5😁5