The Hacker News
βœ”
152K subscribers
1.88K photos
10 videos
3 files
7.79K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
A China-linked hacking group, Earth Alux, is hitting key sectors in Asia-Pacific and Latin America with stealthy, advanced cyberattacks.

πŸ›  Tools & Tactics:
β€’ VARGEIT: A backdoor hidden in mspaint.exe, used for spying and data theft
β€’ COBEACON (Cobalt Strike): Initial access
β€’ MASQLOADER: Evades security detection
β€’ Uses 10+ covert communication channels, including Microsoft Outlook drafts

πŸ‘‰ Learn more: https://thehackernews.com/2025/04/china-linked-earth-alux-uses-vargeit.html

Stay alert. These attacks are live.
πŸ‘21πŸ”₯9πŸ€”1
πŸ”₯ 23,958 IPs. 10 days. One target: Palo Alto GlobalProtect.

A massive spike in login scans hints at coordinated reconβ€”and possible exploitation ahead.

If you run GlobalProtect, this is your early warning. Audit & harden exposed portals now.

πŸ”— Full story: https://thehackernews.com/2025/04/nearly-24000-ips-target-pan-os.html
πŸ‘15πŸ”₯3
🚨 Old iPhones, new threats. Apple just patched 3 exploited zero-daysβ€”and yes, even your dusty iPhone 6s is getting a fix.

πŸ›‘οΈ What's at stake?
β€’ CVE-2025-24201 (CVSS 8.8): Malicious web content breaking free from Safari’s sandbox
β€’ CVE-2025-24085 (7.3): Apps hijacking system privileges
β€’ CVE-2025-24200 (4.6): Bypassing USB Restricted Modeβ€”hello physical attacks

πŸ”₯ Why now? These bugs are being actively exploited in the wild.

πŸ”— Full list + device breakdown: https://thehackernews.com/2025/04/apple-backports-critical-fixes-for-3.html
πŸ‘21πŸ”₯5😁4πŸ‘3πŸ€”2
πŸ”₯ Your CSRF tokens might already be leaking.

A global retailer dodged a $3.9M breach and GDPR fines up to €20Mβ€”all due to one misconfigured Facebook Pixel exposing CSRF tokens.

The kicker? This wasn’t malware. It was human errorβ€”undetectable by blockers.

Protect your site before regulators come knocking.

πŸ”— Learn what to fix β†’ https://thehackernews.com/2025/04/new-case-study-global-retailer.html
😁6πŸ‘3
🚨 Think SMS phishing is old news? Think again.

A new PhaaS platform called Lucid is hijacking iMessage & Android RCS to dodge filters and hit 169 targets in 88 countries.

πŸ’³ Goal? Steal credit cards + PII, at scale.

πŸ”— Learn more: https://thehackernews.com/2025/04/lucid-phaas-hits-169-targets-in-88.html
😁13πŸ”₯6πŸ€”2πŸ‘1
This media is not supported in your browser
VIEW IN TELEGRAM
πŸ”₯ On its 21st birthday, Google rolls out built-in end-to-end encryption for enterprise Gmail usersβ€”no extensions, no certificate swaps.

πŸ”’ Just click, send, secure. Powered by client-side encryption.

πŸ› οΈ Admins hold the keys | Google can’t see a thing.

πŸ‘‰ See how it works: https://thehackernews.com/2025/04/enterprise-gmail-users-can-now-send-end.html
😁24πŸ‘5πŸ€”4πŸ‘2😱2
πŸ”₯ 1,500+ PostgreSQL servers hacked for crypto mining.

A threat group tracked as JINX-0126 is exploiting publicly exposed PostgreSQL instances with weak passwords.

What’s happening:
β€’ Malware: PG_MEM (fileless, evasive)
β€’ Goal: Deploy XMRig miner
β€’ Victims: Over 1,500 servers, 3 wallets, ~550 miners each

πŸ”— Full story: https://thehackernews.com/2025/04/over-1500-postgresql-servers.html
πŸ”₯26πŸ‘7πŸ€”5
πŸ‘€ AI is attacking AI β€” and it just got real.

A new worm, Morris II, is targeting AI apps + email assistants.

But here’s the key: AI can defend us too.
πŸ›‘οΈ Zero Trust stops spread
πŸ” Smart vuln management cuts real risk
⚑ AI vs AI is the new norm

Don’t wait. AI attacks move fast.

Fight AI with AI β€” or fall behind πŸ‘‰ https://thehackernews.com/expert-insights/2025/03/what-it-means-to-fight-ai-with-ai-using.html
😁17⚑5πŸ‘4🀯4πŸ€”3
🚨 A new wave of stealth malware loaders is hereβ€”modular, evasive, and cloud-integrated.

🧬 Hijack Loader: API spoofing, anti-VM, Avast evasion
πŸ’» SHELBY: GitHub as C2β€”payloads & commands via commits
πŸ§ͺ SmokeLoader: .NET Reactor obfuscation + 7-Zip phishing

πŸ”— Read the full report: https://thehackernews.com/2025/04/new-malware-loaders-use-call-stack.html
😱8πŸ‘4⚑2πŸ‘2
🚨 They’re back. Russian threat group FIN7 is using Anubisβ€”a lightweight Python backdoor that grants full remote access to Windows machines without leaving detectable files.

It runs entirely in memory, evades most defenses, and can steal passwords, take screenshots, and exfiltrate dataβ€”all masked with Base64 and hosted on compromised SharePoint sites.

πŸ”— Full analysis: https://thehackernews.com/2025/04/fin7-deploys-anubis-backdoor-to-hijack.html
🀯14πŸ”₯10πŸ‘8⚑5😁4
πŸ”₯ New Linux botnet ALERT!

Outlawβ€”a Romanian-linked groupβ€”is actively hijacking SSH servers to mine crypto via auto-spreading malware.

– Targets servers with weak SSH creds
– Uses BLITZ to self-propagate
– Installs SHELLBOT for remote control, DDoS, and data theft
– Exploits old bugs like Dirty COW (CVE-2016-5195)

πŸ”— Full report: https://thehackernews.com/2025/04/outlaw-group-uses-ssh-brute-force-to.html
πŸ”₯12πŸ‘4πŸ€”3
53.5% of websites have weak SSL.

Not firewalls. Not zero-days. Just bad encryption setups.

πŸ‘€ That’s how attackers walk in the front door.
SSL misconfigs = MITM attacks, eavesdropping & breaches.

πŸ”₯ Your attack surface is growing. Fix it before it spreads.

πŸ”— Learn more: https://thehackernews.com/2025/04/how-ssl-misconfigurations-impact-your.html
😁8πŸ‘5⚑4😱4
πŸ”₯ 93% of service providers struggle with cybersecurity compliance.

Only 2% feel confident. That’s a problemβ€”and an opportunity.

This guide breaks down NIST compliance into clear, doable steps for MSPs & MSSPs.

βœ… Find gaps
βœ… Automate tasks
βœ… Build client trust
βœ… Cut manual work by 70%

Start here β†’ https://thehackernews.com/2025/04/helping-your-clients-achieve-nist.html
πŸ‘7πŸ‘2
This media is not supported in your browser
VIEW IN TELEGRAM
πŸ‘€ New Google Cloud vulnerability exposed private containersβ€”now patched.

A flaw in Google Cloud Run (ImageRunner) let attackers with limited access pull private images and inject malicious code.

Attackers could exploit this to steal secrets or run malicious containers.

πŸ”— Learn more: https://thehackernews.com/2025/04/google-fixed-cloud-run-vulnerability.html
πŸ‘9πŸ‘6😁2
🚨 Kidflix Taken Down!

The largest CSAM platformβ€”1.8M users, 91K videosβ€”has been dismantled in a global sting across 38 countries.

⚑ Operation Stream seized 72,000 files on March 11. Crypto. Tokens. Gamified abuse.
Real kids. Real crimes.

πŸ”— Read: https://thehackernews.com/2025/04/europol-dismantles-kidflix-with-72000.html
πŸ‘32πŸ”₯13πŸ‘12😁1
🚨 New web skimming campaign abuses old Stripe API to steal real credit cards

πŸ’³ 49+ sites hit. Real Stripe screen, fake iframe. Cloned buttons.

Targets: WooCommerce, WordPress, PrestaShop.

πŸ”Ž Details β†’ https://thehackernews.com/2025/04/legacy-stripe-api-exploited-to-validate.html
😁16πŸ‘8
πŸ›‘ Think that cheap Android phone is a bargain? It might come loaded with Triadaβ€”a powerful malware pre-installed on counterfeit devices.

πŸ‘€ 2,600+ victims hit in just two weeks; and hackers stole πŸ’° $270K+ in crypto.

πŸ”— Learn more: https://thehackernews.com/2025/04/triada-malware-preloaded-on-counterfeit.html
πŸ‘9😁5πŸ€”5πŸ”₯4πŸ‘1
🚨 New Google Quick Share flaw exposed.
πŸ“Œ CVE-2024-10668

Attackers could crash your PC or send files to it without approval via Quick Share for Windows.

πŸ”— Learn more: https://thehackernews.com/2025/04/google-patches-quick-share.html
😁16πŸ‘4πŸ”₯3πŸ‘1🀯1
🚨 AI isn’t waiting for your compliance checklist.

CISOs want faster, smarter SOCsβ€”but GRC teams hit pause. Result? Missed threats. Wasted time. Rising risk.

βœ… The fix: Practical AI governance.

πŸ‘‰ Break the deadlock now. Read the guide: https://thehackernews.com/2025/04/ai-adoption-in-enterprise-breaking.html
😱5πŸ‘4
πŸ”₯ North Korea’s Lazarus Group is backβ€”with a new twist on fake job scams.

They’re using ClickFix tricks to infect crypto job seekers with GolangGhost, a stealthy Go-based backdoor hitting Windows & macOS.

Now expanding fast in Europeβ€”with IT workers faking identities to infiltrate companies in πŸ‡©πŸ‡ͺGermany, πŸ‡΅πŸ‡ΉPortugal & πŸ‡¬πŸ‡§UK.

πŸ”— Full story: https://thehackernews.com/2025/04/lazarus-group-targets-job-seekers-with.html
πŸ‘16πŸ”₯6😁6πŸ€”2