The Hacker News
โœ”
152K subscribers
1.88K photos
10 videos
3 files
7.79K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: [email protected]

๐ŸŒ Website: https://thehackernews.com
Download Telegram
๐Ÿšจ Microsoft Warns: Fake Booking[.]com Emails Deploying Malware!

Hackers are using a new social engineering trickโ€”ClickFixโ€”to target the hospitality sector. Victims unknowingly copy-paste a command that launches data-stealing malware.

โš ๏ธ How the scam works:
๐Ÿ”น Fake Booking[.]com email โ†’ "Bad review alert!"
๐Ÿ”น Clicks lead to a fake CAPTCHA
๐Ÿ”น Trick: Victim pastes a malicious command = Instant infection

๐Ÿ”Ž Whoโ€™s behind it? A cybercrime group Storm-1865โ€”now using the same tactics as Russian & Iranian hackers.

๐Ÿ”— More details: https://thehackernews.com/2025/03/microsoft-warns-of-clickfix-phishing.html
๐Ÿ”ฅ16๐Ÿ‘8๐Ÿ˜2๐Ÿค”1
๐Ÿšจ Backups are failing when it matters most.

๐Ÿ”น Only 40% of IT teams trust their backups
๐Ÿ”น Downtime costs $14K/min
๐Ÿ”น 60% think they can recover in a dayโ€”only 35% do
๐Ÿ”น 94% of ransomware victims have backups targeted

IT leaders must act now. See the State of Backup & Recovery 2025 for key risks & solutions.

Read now: https://thehackernews.com/2025/03/bcdr-2025-trends-and-challenges-for-msps-and-it-teams.html
๐Ÿ‘13๐Ÿ‘4๐Ÿคฏ1
๐Ÿšจ New Malware Alert | OBSCURE#BAT ๐Ÿฆ‡
Hackers are using fake CAPTCHA pages & Trojanized software (Tor, VoIP apps) to spread the r77 rootkitโ€”hiding files, evading antivirus, and persisting after reboot.

๐ŸŽญ Targets: ๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡จ๐Ÿ‡ฆ๐Ÿ‡ฌ๐Ÿ‡ง๐Ÿ‡ฉ๐Ÿ‡ช ๐Ÿ› ๏ธ Techniques: Obfuscated batch scripts, AMSI bypass, API hooking ๐Ÿ” Stealthy & dangerousโ€”already in the wild!

Read more: https://thehackernews.com/2025/03/obscurebat-malware-uses-fake-captcha.html
๐Ÿ‘17๐Ÿ”ฅ4๐Ÿค”4๐Ÿ˜3๐Ÿ‘1
๐Ÿดโ€โ˜ ๏ธ Pirates Beware!

Downloading cracked software? You might be installing MassJackerโ€”a new clipper malware hijacking crypto transactions.

๐Ÿ”น 778,531 attacker-controlled wallets
๐Ÿ”น $336,700 in stolen funds
๐Ÿ”น Hides inside pirated downloads from pesktop[.]com

Your clipboard isn't safe. Copy a wallet address? It swaps it with the hackerโ€™s.

๐Ÿ”— Full story: https://thehackernews.com/2025/03/new-massjacker-malware-targets-piracy.html
๐Ÿ‘15๐Ÿ˜ฑ8๐Ÿ”ฅ5๐Ÿ˜4๐Ÿค”2๐Ÿ‘1
๐Ÿ”’ GSMA is bringing end-to-end encryption (E2EE) to RCS messages between Android & iOS. That means private, secure chatsโ€”no matter the device.

This comes right after Apple agreed to support RCS in iOS 18. Until now, Google encrypted RCS in its Messages app, but cross-platform chats were left exposed.

๐Ÿ”— Read more: https://thehackernews.com/2025/03/gsma-confirms-end-to-end-encryption-for.html
๐Ÿค”15๐Ÿ‘8๐Ÿ”ฅ4๐Ÿ˜2๐Ÿ‘1๐Ÿคฏ1๐Ÿ˜ฑ1
๐Ÿšจ LockBit Dev Extradited to U.S.

Rostislav Panev, a 51-year-old dual Russian-Israeli national, is now in U.S. custodyโ€”charged for developing LockBit ransomware.

LockBit has hit 2,500+ victims in 120+ countries, raking in $500M+ in profits.

๐Ÿ”— Full story: https://thehackernews.com/2025/03/alleged-israeli-lockbit-developer.html
๐Ÿ‘16๐Ÿ‘7๐Ÿ˜5๐Ÿ”ฅ1๐Ÿคฏ1
๐Ÿšจ Most microsegmentation projects fail before startingโ€”too complex, slow, and disruptive.

But Andelyn Biosciences succeeded.

โœ… 2,700 security policies enforced
โœ… No hardware changes needed
โœ… Full segmentation in weeks, not years

They replaced legacy VLANs and firewalls with Elisity's identity-based microsegmentation.

๐Ÿ” Learn how and get lessons for your Zero Trust journey: https://thehackernews.com/2025/03/why-most-microsegmentation-projects.html
๐Ÿ‘9๐Ÿ‘3๐Ÿ˜ฑ1
๐Ÿšจ 2025 is the year of cyberattacks.

๐Ÿ”น Phishing is getting smarter.
๐Ÿ”น MFA isnโ€™t stopping breaches.
๐Ÿ”น AppSec tools are still missing the mark.

๐Ÿ”— Join these webinars to fix security for good: https://www.linkedin.com/pulse/phishing-mfa-bypass-appsec-failuresfix-them-webinars-thehackernews-t1oee/
๐Ÿ˜16๐Ÿ‘12โšก2๐Ÿ”ฅ2๐Ÿ‘1
๐Ÿšจ Hackers are poisoning PyPI again. Devs, check your dependencies NOW!

Cybercriminals planted 20 fake Python packages on PyPIโ€”stealing cloud access tokens from AWS, Alibaba Cloud, and Tencent Cloud. These packages, disguised as "time" utilities, racked up 14,100+ downloads before removal.

๐Ÿ‘€ One even snuck into a GitHub project with 519 stars and 42 forks.

๐Ÿ”— Read more: https://thehackernews.com/2025/03/malicious-pypi-packages-stole-cloud.html
๐Ÿ‘19๐Ÿ˜11๐Ÿ”ฅ10๐Ÿคฏ8๐Ÿ‘7โšก3๐Ÿค”1
๐Ÿšจ WARNING: A supply chain attack hit tj-actions/changed-files, a GitHub Action used by 23,000+ reposโ€”exposing AWS keys, PATs, and RSA keys in CI/CD logs.

๐Ÿ‘€ Affected? Update to v46.0.1 NOW and Audit workflows for leaks.

๐Ÿ”— Read more: https://thehackernews.com/2025/03/github-action-compromise-puts-cicd.html
๐Ÿ‘12๐Ÿคฏ3๐Ÿค”2๐Ÿ”ฅ1
๐Ÿ‘€ Your email client might be leaking more than you think...

Hackers are exploiting CSS to bypass spam filters and track users without JavaScript.

๐Ÿšจ Cisco Talos warns that attackers use CSS properties like media, text-indent, and opacity to hide phishing content and fingerprint victims.

Stay aheadโ€”learn how at https://thehackernews.com/2025/03/cybercriminals-exploit-css-to-evade.html.
๐Ÿ”ฅ17๐Ÿ‘4๐Ÿ˜4๐Ÿค”1
๐Ÿšจ Cloud ransomware is evolvingโ€”your security settings wonโ€™t save you.

66% of cloud storage buckets hold sensitive data. Attackers now exploit legit AWS & Azure features to lock you out.

๐Ÿ”น Block risky encryption methods
๐Ÿ”น Enable backups & versioning (not default!)
๐Ÿ”น Lock down IAM policies

The cloud wonโ€™t save youโ€”take action now.

๐ŸŽฅ Read & Watch: https://thehackernews.com/2025/03/sans-institute-warns-of-novel-cloud.html
๐Ÿ‘15
๐Ÿšจ Old Cameras, New Threats ๐Ÿ”ฅ

A critical flaw (CVE-2025-1316, CVSS 9.3) in Edimax IC-7100 cameras is under active attackโ€”turning unpatched devices into Mirai botnet soldiers for massive DDoS strikes.

Default creds (admin:1234) = easy pickings for attackers

๐Ÿ”— Details: https://thehackernews.com/2025/03/unpatched-edimax-camera-flaw-exploited.html
๐Ÿ”ฅ18๐Ÿ‘4
๐Ÿšจ Last Week in Cybersecurity...

Routers hacked, malicious PyPI packages detected, new ransomware decryptors released, and major threats uncovered.

Read: https://thehackernews.com/2025/03/thn-weekly-recap-router-hacks-pypi.html

Stay informedโ€”stay secure. #THNWeeklyRecap
๐Ÿ˜14โšก8๐Ÿ‘4
๐Ÿšจ Apache Tomcat Under Attack.

Hackers are actively exploiting CVE-2025-24813 just 30 hours after disclosure.

๐Ÿ”น RCE & Info Disclosure Risk
๐Ÿ”น No Authentication Needed
๐Ÿ”น Attackers Upload & Execute Malicious Files

โš ๏ธ Delaying could mean backdoors, config tampering & full compromise.

Read: https://thehackernews.com/2025/03/apache-tomcat-vulnerability-comes-under.html

Donโ€™t waitโ€”secure your systems NOW
๐Ÿ˜25๐Ÿ”ฅ15๐Ÿ‘11๐Ÿคฏ4๐Ÿ‘1๐Ÿค”1
This media is not supported in your browser
VIEW IN TELEGRAM
๐Ÿ’€ New Malware Alert โ€” Microsoft warns of StilachiRAT, a stealthy remote access trojan that:

๐Ÿ”น Steals browser passwords & clipboard data
๐Ÿ”น Targets crypto wallets
๐Ÿ”น Executes remote commands & monitors RDP sessions
๐Ÿ”น Evades detection by clearing event logs

Read: https://thehackernews.com/2025/03/microsoft-warns-of-stilachirat-stealthy.html

๐Ÿ•ต๏ธโ€โ™‚๏ธ No known actor yet, but itโ€™s spreading. Protect your assets NOW.
๐Ÿ‘21๐Ÿค”7๐Ÿ˜ฑ6
โš ๏ธ Your Device Might Be Part of the Largest CTV Botnet Ever!

Cybercriminals are exploiting cheap Android devices to build a massive botnet for:

๐Ÿ”น Ad fraud & fake clicks
๐Ÿ”น Residential proxy abuse
๐Ÿ”น DDoS attacks & account takeovers
๐Ÿ”น Hidden malware pre-installed in devices

Learn more: https://thehackernews.com/2025/03/badbox-20-botnet-infects-1-million.html

๐Ÿ’€ 1M+ devices infected worldwide, mostly in Brazil, US, & Mexico. Google removed 24 malicious apps, but the operation is still evolving.
๐Ÿ˜16๐Ÿ‘5
๐Ÿšจ China-linked MirrorFace just carried out a stealthy attack on a European diplomatic groupโ€”using:

๐Ÿ”น ANEL backdoorโ€”revived after 6 years
๐Ÿ”น AsyncRAT & HiddenFace malware
๐Ÿ”น Stealthy access via VS Code Remote Tunnels

Learn more: https://thehackernews.com/2025/03/china-linked-mirrorface-deploys-anel.html
๐Ÿค”16๐Ÿ˜7๐Ÿ‘5๐Ÿ”ฅ3โšก1๐Ÿ‘1
What are the essential skills security analysts need to succeed?

IDC's latest survey of 900+ security leaders reveals the top five.

Uncover these and more findings in a live webinar with sponsors Tines and AWS.

Sign up to attend: https://thn.news/voice-of-security-2025-tw
๐Ÿ‘11๐Ÿ‘2๐Ÿ˜2๐Ÿค”2
๐Ÿšจ 331 Malicious Android Google Play Apps, 60 Million+ Downloads!

The Vapor scam used:
๐Ÿ”น Full-screen adsโ€”locking devices
๐Ÿ”น Phishing attacksโ€”stealing credentials & credit cards
๐Ÿ”น Hidden icons & impersonationโ€”evading detection
๐Ÿ”น Versioning tricksโ€”turning clean apps malicious later

โš ๏ธ Check your phone NOW. Delete suspicious apps!

๐Ÿ”— Full details โ€” https://thehackernews.com/2025/03/new-ad-fraud-campaign-exploits-331-apps.html
๐Ÿค”12๐Ÿ”ฅ6๐Ÿ‘4๐Ÿ˜3โšก1