The Hacker News
βœ”
152K subscribers
1.88K photos
10 videos
3 files
7.79K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
A new cyber campaign in the Middle East and North Africa is using modified AsyncRAT malware to target over 900 victims, including in oil, IT, and agriculture.

The attack spreads through social media ads and file-sharing platforms.

Learn how to protect your systems: https://thehackernews.com/2025/03/desert-dexter-targets-900-victims-using.html
πŸ‘10πŸ”₯4🀯2😁1
⚠️🚨 A new browser extension attack is mimicking legit add-ons to steal sensitive data.

By manipulating icons, popups, and disabling real extensions, attackers target all Chromium-based browsers, risking personal and financial info.

Get the full details here: https://thehackernews.com/2025/03/researchers-expose-new-polymorphic.html
🀯13πŸ‘5😱4πŸ”₯2
πŸ”΄ Google Workspace is a top collaboration tool, but its security risks are rising. Cybercriminals are outpacing patchwork defenses, exploiting vulnerabilities.

To secure Google Workspace, businesses need a unified solution that simplifies security and closes critical gaps.

Learn more here: https://thehackernews.com/2025/03/why-modern-google-workspace-needs.html
⚑19πŸ‘8
CISA added 5 critical vulnerabilities to its Known Exploited list, affecting Advantive VeraCore and Ivanti Endpoint Manager.

These flaws are actively being exploited, putting your systems at risk of remote access and credential theft.

Get the full details here: https://thehackernews.com/2025/03/cisa-adds-five-actively-exploited.html
πŸ‘13πŸ”₯2πŸ‘1😁1
⚠️ A critical flaw (CVE-2024-12297) in Moxa PT switches could let attackers bypass authentication, with a CVSS score of 9.2/10.

This could lead to unauthorized access or service disruptions.

Protect your systems now: https://thehackernews.com/2025/03/moxa-issues-fix-for-critical.html
πŸ‘9πŸ”₯6🀯1
SideWinder APT is still targeting high-profile sectors like maritime, nuclear energy, and consulting.

Their main tactic: spear-phishing emails with malicious documents about critical infrastructures.

Get the full details here: https://thehackernews.com/2025/03/sidewinder-apt-targets-maritime-nuclear.html
⚑8
Identity-based attacks are escalating, and traditional security isn’t sufficient.

Misconfigurations, excessive permissions, and stolen credentials in SaaS apps cause 61% of data breaches.

Learn to secure your SaaS environment here: https://thehackernews.com/expert-insights/2025/03/identity-attacksprevention-isnt-enough.html
πŸ”₯6πŸ‘2😁1
⚠️ A new botnet, Ballista, is exploiting unpatched TP-Link Archer routers through the CVE-2023-1389 vulnerability.

This critical flaw allows attackers to execute remote code, triggering widespread malware infections. Thousands of devices, including those in healthcare and manufacturing, are at risk.

Read the full analysis here: https://thehackernews.com/2025/03/ballista-botnet-exploits-unpatched-tp.html
😁10πŸ‘6πŸ”₯5πŸ‘3⚑1
Cybercriminals are hiding malware in images, making it nearly invisible to security tools.

A harmless landscape photo πŸ–ΌοΈ could be carrying a payload that steals data or takes over your system. Traditional security tools miss this, leaving you exposed.

Learn how to protect your systems: https://thehackernews.com/2025/03/steganography-explained-how-xworm-hides.html
πŸ”₯33😱5⚑2πŸ‘2🀯1
🚨 Apple just patched a zero-day under active attack!

CVE-2025-24201 lets hackers escape the WebKit sandboxβ€”Apple calls the exploit β€œextremely sophisticated.”

Targeted? Unknown
Duration? Unknown

But if you use an iPhone, Mac, or Vision Proβ€”update NOW.

πŸ“² Details: https://thehackernews.com/2025/03/apple-releases-patch-for-webkit-zero.html
πŸ”₯23πŸ‘8⚑4πŸ€”3😁2🀯1
⚑ Proactive security > Reactive fixes.

ASPM's "shift-left" approach empowers teams to prevent vulnerabilities BEFORE they spread. Don't miss out on how this could save you time and money.

πŸš€ Learn more in this expert webinar β€” https://thehacker.news/aspm-future-appsec
πŸ‘9
🚨 6,000+ fake Play Store pages exposed!

PlayPraetor Trojan malware is tricking users into downloading apps that steal banking info, intercept 2FA, and spy on you. CTM360 uncovered this global scam, where cybercriminals use realistic fake pages to hijack devices and steal data.

Protect yourself:
βœ… Download from trusted stores only
βœ… Check reviews & permissions
βœ… Use mobile security tools

πŸ”— Full report: https://thehackernews.com/expert-insights/2025/03/ctm360-uncovers-large-scale-fake-play.html
πŸ‘16😁4🀯1
🚨 UPDATE: Microsoft has uncovered major upgrades in the latest XCSSET variant:

⚠️ New persistence method – Uses dockutil to swap in a fake Launchpad app, ensuring the malware runs every time you open it.
⚠️ Stronger obfuscation – Harder to detect, harder to analyze.
⚠️ Still spreading via Xcode projects – Developers, your builds could be compromised.

This marks the first major XCSSET update since 2022β€”and it's more deceptive than ever. Inspect Xcode projects carefully.

πŸ”— More details: https://thehackernews.com/2025/02/microsoft-uncovers-new-xcsset-macos.html
😁8πŸ‘4😱2πŸ€”1
This media is not supported in your browser
VIEW IN TELEGRAM
πŸ”₯ Microsoft warns: 6 zero-days under active attack!

This month’s Patch Tuesday fixes 57 security flaws, including 6 exploited zero-days that attackers are already using for privilege escalation, data theft, and remote code execution.

πŸ”Ή Key threats:
CVE-2025-24985 & CVE-2025-24993 – File system flaws allowing remote code execution
CVE-2025-24983 – A Win32k zero-day used in the wild with PipeMagic malware
CVE-2025-26633 – Security bypass flaw in Microsoft Management Console

CISA has mandated patches by April 1. Don’t waitβ€”secure your systems now!

πŸ”— Full patch details: https://thehackernews.com/2025/03/urgent-microsoft-patches-57-security.html
πŸ‘22😁7πŸ‘2🀯1
Do you know how secure your software supply chain really is?

According to ActiveState's 2025 State of Vulnerability Management and Remediation Report, DevSecOps pros signaled a 54% YoY increase in high-risk vulnerabilitiesβ€”download the FREE report to learn how to stay ahead of the curve.

https://thn.news/vulnerability-report-2025
🀯5πŸ‘1😱1
🚨 Massive SSRF Attack Surge Detected πŸ‘€

GreyNoise warns of a coordinated wave of SSRF exploits hitting at least 400 IPsβ€”targeting U.S., Germany, Singapore, Israel, and more.

πŸ”΄ Exploiting multiple CVEs at once, including:
β€’ CVE-2020-7796 (Zimbra, CVSS 9.8)
β€’ CVE-2021-22175 (GitLab, CVSS 9.8)
β€’ CVE-2023-5830 (ColumbiaSoft, CVSS 9.8)

πŸš€ Automated? Pre-compromise recon? Either wayβ€”patch now, restrict outbound traffic, and monitor logs.

Details: https://thehackernews.com/2025/03/over-400-ips-exploiting-multiple-ssrf.html
🀯9πŸ”₯5πŸ‘3⚑2πŸ€”2
With a Georgetown master's you'll gain the tactical skills to plan for, respond to, and mitigate cyber security threats.


View event: https://thn.news/cyber-risk-webinar-2025-li
πŸ‘6😁3πŸ€”2
🚨 China-backed hackers are hitting routersβ€”undetected.

UNC3886 is targeting Juniper Networks routers, deploying stealthy TinyShell-based backdoors to control critical infrastructure. These implants evade security, disable logs, and hijack SSH credsβ€”all in silence. πŸ‘€

Mandiant warns: "Long-term persistence, minimal detection."

Why does this matter? Routers are now the frontline. If they’re compromised, so is everything behind them.

πŸ”— Details on the latest cyber espionage:
https://thehackernews.com/2025/03/chinese-hackers-breach-juniper-networks.html
πŸ‘19😁5⚑4πŸ”₯4😱4
🚨 UPDATE: Garantex Co-Founder ARRESTED in India!

Besciokov was caught in Thiruvananthapuram while trying to flee after a U.S. extradition request (March 10). He was vacationing in Varkala when India’s CBI moved in.

More: https://thehackernews.com/2025/03/us-secret-service-seizes-russian.html
😱11😁4πŸ‘3
🚨 Firefox Warning: Update Before March 14.

A critical root certificate will expire on March 14, 2025. If you’re using an old Firefox version (before 128 or ESR 115.13+), your add-ons may stop working, DRM media could break, and security features may fail.

πŸ“’ Fix it now: Update to Firefox 128+ (or ESR 115.13+) to avoid issues.

πŸ”— Read: https://thehackernews.com/2025/03/warning-expiring-root-certificate-may.html
πŸ‘23πŸ”₯8😁3πŸ€”2