๐จ Apple just patched a zero-day under active attack!
CVE-2025-24201 lets hackers escape the WebKit sandboxโApple calls the exploit โextremely sophisticated.โ
Targeted? Unknown
Duration? Unknown
But if you use an iPhone, Mac, or Vision Proโupdate NOW.
๐ฒ Details: https://thehackernews.com/2025/03/apple-releases-patch-for-webkit-zero.html
CVE-2025-24201 lets hackers escape the WebKit sandboxโApple calls the exploit โextremely sophisticated.โ
Targeted? Unknown
Duration? Unknown
But if you use an iPhone, Mac, or Vision Proโupdate NOW.
๐ฒ Details: https://thehackernews.com/2025/03/apple-releases-patch-for-webkit-zero.html
๐ฅ23๐8โก4๐ค3๐2๐คฏ1
โก Proactive security > Reactive fixes.
ASPM's "shift-left" approach empowers teams to prevent vulnerabilities BEFORE they spread. Don't miss out on how this could save you time and money.
๐ Learn more in this expert webinar โ https://thehacker.news/aspm-future-appsec
ASPM's "shift-left" approach empowers teams to prevent vulnerabilities BEFORE they spread. Don't miss out on how this could save you time and money.
๐ Learn more in this expert webinar โ https://thehacker.news/aspm-future-appsec
๐9
๐จ 6,000+ fake Play Store pages exposed!
PlayPraetor Trojan malware is tricking users into downloading apps that steal banking info, intercept 2FA, and spy on you. CTM360 uncovered this global scam, where cybercriminals use realistic fake pages to hijack devices and steal data.
Protect yourself:
โ Download from trusted stores only
โ Check reviews & permissions
โ Use mobile security tools
๐ Full report: https://thehackernews.com/expert-insights/2025/03/ctm360-uncovers-large-scale-fake-play.html
PlayPraetor Trojan malware is tricking users into downloading apps that steal banking info, intercept 2FA, and spy on you. CTM360 uncovered this global scam, where cybercriminals use realistic fake pages to hijack devices and steal data.
Protect yourself:
โ Download from trusted stores only
โ Check reviews & permissions
โ Use mobile security tools
๐ Full report: https://thehackernews.com/expert-insights/2025/03/ctm360-uncovers-large-scale-fake-play.html
๐16๐4๐คฏ1
๐จ UPDATE: Microsoft has uncovered major upgrades in the latest XCSSET variant:
โ ๏ธ New persistence method โ Uses dockutil to swap in a fake Launchpad app, ensuring the malware runs every time you open it.
โ ๏ธ Stronger obfuscation โ Harder to detect, harder to analyze.
โ ๏ธ Still spreading via Xcode projects โ Developers, your builds could be compromised.
This marks the first major XCSSET update since 2022โand it's more deceptive than ever. Inspect Xcode projects carefully.
๐ More details: https://thehackernews.com/2025/02/microsoft-uncovers-new-xcsset-macos.html
โ ๏ธ New persistence method โ Uses dockutil to swap in a fake Launchpad app, ensuring the malware runs every time you open it.
โ ๏ธ Stronger obfuscation โ Harder to detect, harder to analyze.
โ ๏ธ Still spreading via Xcode projects โ Developers, your builds could be compromised.
This marks the first major XCSSET update since 2022โand it's more deceptive than ever. Inspect Xcode projects carefully.
๐ More details: https://thehackernews.com/2025/02/microsoft-uncovers-new-xcsset-macos.html
๐8๐4๐ฑ2๐ค1
This media is not supported in your browser
VIEW IN TELEGRAM
๐ฅ Microsoft warns: 6 zero-days under active attack!
This monthโs Patch Tuesday fixes 57 security flaws, including 6 exploited zero-days that attackers are already using for privilege escalation, data theft, and remote code execution.
๐น Key threats:
CVE-2025-24985 & CVE-2025-24993 โ File system flaws allowing remote code execution
CVE-2025-24983 โ A Win32k zero-day used in the wild with PipeMagic malware
CVE-2025-26633 โ Security bypass flaw in Microsoft Management Console
CISA has mandated patches by April 1. Donโt waitโsecure your systems now!
๐ Full patch details: https://thehackernews.com/2025/03/urgent-microsoft-patches-57-security.html
This monthโs Patch Tuesday fixes 57 security flaws, including 6 exploited zero-days that attackers are already using for privilege escalation, data theft, and remote code execution.
๐น Key threats:
CVE-2025-24985 & CVE-2025-24993 โ File system flaws allowing remote code execution
CVE-2025-24983 โ A Win32k zero-day used in the wild with PipeMagic malware
CVE-2025-26633 โ Security bypass flaw in Microsoft Management Console
CISA has mandated patches by April 1. Donโt waitโsecure your systems now!
๐ Full patch details: https://thehackernews.com/2025/03/urgent-microsoft-patches-57-security.html
๐22๐7๐2๐คฏ1
Do you know how secure your software supply chain really is?
According to ActiveState's 2025 State of Vulnerability Management and Remediation Report, DevSecOps pros signaled a 54% YoY increase in high-risk vulnerabilitiesโdownload the FREE report to learn how to stay ahead of the curve.
https://thn.news/vulnerability-report-2025
According to ActiveState's 2025 State of Vulnerability Management and Remediation Report, DevSecOps pros signaled a 54% YoY increase in high-risk vulnerabilitiesโdownload the FREE report to learn how to stay ahead of the curve.
https://thn.news/vulnerability-report-2025
๐คฏ5๐1๐ฑ1
๐จ Massive SSRF Attack Surge Detected ๐
GreyNoise warns of a coordinated wave of SSRF exploits hitting at least 400 IPsโtargeting U.S., Germany, Singapore, Israel, and more.
๐ด Exploiting multiple CVEs at once, including:
โข CVE-2020-7796 (Zimbra, CVSS 9.8)
โข CVE-2021-22175 (GitLab, CVSS 9.8)
โข CVE-2023-5830 (ColumbiaSoft, CVSS 9.8)
๐ Automated? Pre-compromise recon? Either wayโpatch now, restrict outbound traffic, and monitor logs.
Details: https://thehackernews.com/2025/03/over-400-ips-exploiting-multiple-ssrf.html
GreyNoise warns of a coordinated wave of SSRF exploits hitting at least 400 IPsโtargeting U.S., Germany, Singapore, Israel, and more.
๐ด Exploiting multiple CVEs at once, including:
โข CVE-2020-7796 (Zimbra, CVSS 9.8)
โข CVE-2021-22175 (GitLab, CVSS 9.8)
โข CVE-2023-5830 (ColumbiaSoft, CVSS 9.8)
๐ Automated? Pre-compromise recon? Either wayโpatch now, restrict outbound traffic, and monitor logs.
Details: https://thehackernews.com/2025/03/over-400-ips-exploiting-multiple-ssrf.html
๐คฏ9๐ฅ5๐3โก2๐ค2
With a Georgetown master's you'll gain the tactical skills to plan for, respond to, and mitigate cyber security threats.
View event: https://thn.news/cyber-risk-webinar-2025-li
View event: https://thn.news/cyber-risk-webinar-2025-li
๐6๐3๐ค2
๐จ China-backed hackers are hitting routersโundetected.
UNC3886 is targeting Juniper Networks routers, deploying stealthy TinyShell-based backdoors to control critical infrastructure. These implants evade security, disable logs, and hijack SSH credsโall in silence. ๐
Mandiant warns: "Long-term persistence, minimal detection."
Why does this matter? Routers are now the frontline. If theyโre compromised, so is everything behind them.
๐ Details on the latest cyber espionage:
https://thehackernews.com/2025/03/chinese-hackers-breach-juniper-networks.html
UNC3886 is targeting Juniper Networks routers, deploying stealthy TinyShell-based backdoors to control critical infrastructure. These implants evade security, disable logs, and hijack SSH credsโall in silence. ๐
Mandiant warns: "Long-term persistence, minimal detection."
Why does this matter? Routers are now the frontline. If theyโre compromised, so is everything behind them.
๐ Details on the latest cyber espionage:
https://thehackernews.com/2025/03/chinese-hackers-breach-juniper-networks.html
๐19๐5โก4๐ฅ4๐ฑ4
๐จ UPDATE: Garantex Co-Founder ARRESTED in India!
Besciokov was caught in Thiruvananthapuram while trying to flee after a U.S. extradition request (March 10). He was vacationing in Varkala when Indiaโs CBI moved in.
More: https://thehackernews.com/2025/03/us-secret-service-seizes-russian.html
Besciokov was caught in Thiruvananthapuram while trying to flee after a U.S. extradition request (March 10). He was vacationing in Varkala when Indiaโs CBI moved in.
More: https://thehackernews.com/2025/03/us-secret-service-seizes-russian.html
๐ฑ11๐4๐3
๐จ Firefox Warning: Update Before March 14.
A critical root certificate will expire on March 14, 2025. If youโre using an old Firefox version (before 128 or ESR 115.13+), your add-ons may stop working, DRM media could break, and security features may fail.
๐ข Fix it now: Update to Firefox 128+ (or ESR 115.13+) to avoid issues.
๐ Read: https://thehackernews.com/2025/03/warning-expiring-root-certificate-may.html
A critical root certificate will expire on March 14, 2025. If youโre using an old Firefox version (before 128 or ESR 115.13+), your add-ons may stop working, DRM media could break, and security features may fail.
๐ข Fix it now: Update to Firefox 128+ (or ESR 115.13+) to avoid issues.
๐ Read: https://thehackernews.com/2025/03/warning-expiring-root-certificate-may.html
๐23๐ฅ8๐3๐ค2
๐จ Critical Alert: A severe vulnerability (CVE-2025-27363) in the FreeType font library, used by millions, is being actively exploited.
This flaw allows RCE, risking numerous systems. Affected platforms include Linux distributions, Android, and iOS.
Read: https://thehackernews.com/2025/03/meta-warns-of-freetype-vulnerability.html
Update to FreeType version 2.13.3 immediately to protect your devices. Act now!
This flaw allows RCE, risking numerous systems. Affected platforms include Linux distributions, Android, and iOS.
Read: https://thehackernews.com/2025/03/meta-warns-of-freetype-vulnerability.html
Update to FreeType version 2.13.3 immediately to protect your devices. Act now!
๐ฅ20๐คฏ9๐2๐ฑ2โก1
๐ด ruby-saml Flaws Open SAML Auth to Hijacking
GitHub Security Lab found CVE-2025-25291 & CVE-2025-25292 (CVSS 8.8) in ruby-saml, allowing attackers to bypass authentication using a valid signature.
๐ Read: https://thehackernews.com/2025/03/github-uncovers-new-ruby-saml.html
๐ Update now or risk account takeover.
GitHub Security Lab found CVE-2025-25291 & CVE-2025-25292 (CVSS 8.8) in ruby-saml, allowing attackers to bypass authentication using a valid signature.
๐ Read: https://thehackernews.com/2025/03/github-uncovers-new-ruby-saml.html
๐ Update now or risk account takeover.
๐คฏ9๐4โก1๐ฅ1
What are the top priorities for security teams in 2025? And what's threatening to derail them?
IDC asked 900+ security leaders across the US, Europe, and Australia. In a webinar on March 26, Voice of Security 2025 sponsors Tines and AWS will unpack the results.
Join them to uncover:
๐ธ How AI and automation are transforming security strategies
๐ธ The biggest challenges leaders face - and whatโs holding them back
๐ธ What drives job satisfaction (and frustration) in security leadership
๐ธ Where tooling helps vs. where itโs adding to the pain
๐ธ What leaders look for when hiring security analysts
Sign up for a deep dive into the data: https://thn.news/voice-of-security-2025-x
IDC asked 900+ security leaders across the US, Europe, and Australia. In a webinar on March 26, Voice of Security 2025 sponsors Tines and AWS will unpack the results.
Join them to uncover:
๐ธ How AI and automation are transforming security strategies
๐ธ The biggest challenges leaders face - and whatโs holding them back
๐ธ What drives job satisfaction (and frustration) in security leadership
๐ธ Where tooling helps vs. where itโs adding to the pain
๐ธ What leaders look for when hiring security analysts
Sign up for a deep dive into the data: https://thn.news/voice-of-security-2025-x
Tines
Voice of Security 2025 - Essential insights from 900 security leaders | Tines
Mar 26 2025, 11:00 AM โข US Eastern Time โข Learn what 900+ security leaders think about people, processes, and technologies this year, and uncover how to build a more resilient security strategy with your team in 2025 and beyond.
๐7๐1
๐จ A never-before-seen Android spyware KoSpy is targeting Korean & English usersโstealing texts, calls, files & more.
Masquerading as legit apps on Google Play, KoSpy operated undetected for 2 years (2022-2024). Now linked to APT27 & Kimsuky.
Meanwhile, North Korean hackers are also infiltrating npm packages & crypto walletsโdeploying RustDoor, BeaverTail & Koi Stealer.
Find out here: https://thehackernews.com/2025/03/north-koreas-scarcruft-deploys-kospy.html
Masquerading as legit apps on Google Play, KoSpy operated undetected for 2 years (2022-2024). Now linked to APT27 & Kimsuky.
Meanwhile, North Korean hackers are also infiltrating npm packages & crypto walletsโdeploying RustDoor, BeaverTail & Koi Stealer.
Find out here: https://thehackernews.com/2025/03/north-koreas-scarcruft-deploys-kospy.html
๐ค15๐5๐3๐2๐ฑ2โก1
๐จ Microsoft Warns: Fake Booking[.]com Emails Deploying Malware!
Hackers are using a new social engineering trickโClickFixโto target the hospitality sector. Victims unknowingly copy-paste a command that launches data-stealing malware.
โ ๏ธ How the scam works:
๐น Fake Booking[.]com email โ "Bad review alert!"
๐น Clicks lead to a fake CAPTCHA
๐น Trick: Victim pastes a malicious command = Instant infection
๐ Whoโs behind it? A cybercrime group Storm-1865โnow using the same tactics as Russian & Iranian hackers.
๐ More details: https://thehackernews.com/2025/03/microsoft-warns-of-clickfix-phishing.html
Hackers are using a new social engineering trickโClickFixโto target the hospitality sector. Victims unknowingly copy-paste a command that launches data-stealing malware.
โ ๏ธ How the scam works:
๐น Fake Booking[.]com email โ "Bad review alert!"
๐น Clicks lead to a fake CAPTCHA
๐น Trick: Victim pastes a malicious command = Instant infection
๐ Whoโs behind it? A cybercrime group Storm-1865โnow using the same tactics as Russian & Iranian hackers.
๐ More details: https://thehackernews.com/2025/03/microsoft-warns-of-clickfix-phishing.html
๐ฅ16๐8๐2๐ค1
๐จ Backups are failing when it matters most.
๐น Only 40% of IT teams trust their backups
๐น Downtime costs $14K/min
๐น 60% think they can recover in a dayโonly 35% do
๐น 94% of ransomware victims have backups targeted
IT leaders must act now. See the State of Backup & Recovery 2025 for key risks & solutions.
Read now: https://thehackernews.com/2025/03/bcdr-2025-trends-and-challenges-for-msps-and-it-teams.html
๐น Only 40% of IT teams trust their backups
๐น Downtime costs $14K/min
๐น 60% think they can recover in a dayโonly 35% do
๐น 94% of ransomware victims have backups targeted
IT leaders must act now. See the State of Backup & Recovery 2025 for key risks & solutions.
Read now: https://thehackernews.com/2025/03/bcdr-2025-trends-and-challenges-for-msps-and-it-teams.html
๐13๐4๐คฏ1
๐จ New Malware Alert | OBSCURE#BAT ๐ฆ
Hackers are using fake CAPTCHA pages & Trojanized software (Tor, VoIP apps) to spread the r77 rootkitโhiding files, evading antivirus, and persisting after reboot.
๐ญ Targets: ๐บ๐ธ๐จ๐ฆ๐ฌ๐ง๐ฉ๐ช ๐ ๏ธ Techniques: Obfuscated batch scripts, AMSI bypass, API hooking ๐ Stealthy & dangerousโalready in the wild!
Read more: https://thehackernews.com/2025/03/obscurebat-malware-uses-fake-captcha.html
Hackers are using fake CAPTCHA pages & Trojanized software (Tor, VoIP apps) to spread the r77 rootkitโhiding files, evading antivirus, and persisting after reboot.
๐ญ Targets: ๐บ๐ธ๐จ๐ฆ๐ฌ๐ง๐ฉ๐ช ๐ ๏ธ Techniques: Obfuscated batch scripts, AMSI bypass, API hooking ๐ Stealthy & dangerousโalready in the wild!
Read more: https://thehackernews.com/2025/03/obscurebat-malware-uses-fake-captcha.html
๐17๐ฅ4๐ค4๐3๐1
๐ดโโ ๏ธ Pirates Beware!
Downloading cracked software? You might be installing MassJackerโa new clipper malware hijacking crypto transactions.
๐น 778,531 attacker-controlled wallets
๐น $336,700 in stolen funds
๐น Hides inside pirated downloads from pesktop[.]com
Your clipboard isn't safe. Copy a wallet address? It swaps it with the hackerโs.
๐ Full story: https://thehackernews.com/2025/03/new-massjacker-malware-targets-piracy.html
Downloading cracked software? You might be installing MassJackerโa new clipper malware hijacking crypto transactions.
๐น 778,531 attacker-controlled wallets
๐น $336,700 in stolen funds
๐น Hides inside pirated downloads from pesktop[.]com
Your clipboard isn't safe. Copy a wallet address? It swaps it with the hackerโs.
๐ Full story: https://thehackernews.com/2025/03/new-massjacker-malware-targets-piracy.html
๐15๐ฑ8๐ฅ5๐4๐ค2๐1
๐ GSMA is bringing end-to-end encryption (E2EE) to RCS messages between Android & iOS. That means private, secure chatsโno matter the device.
This comes right after Apple agreed to support RCS in iOS 18. Until now, Google encrypted RCS in its Messages app, but cross-platform chats were left exposed.
๐ Read more: https://thehackernews.com/2025/03/gsma-confirms-end-to-end-encryption-for.html
This comes right after Apple agreed to support RCS in iOS 18. Until now, Google encrypted RCS in its Messages app, but cross-platform chats were left exposed.
๐ Read more: https://thehackernews.com/2025/03/gsma-confirms-end-to-end-encryption-for.html
๐ค15๐8๐ฅ4๐2๐1๐คฏ1๐ฑ1