The Hacker News
βœ”
151K subscribers
1.85K photos
10 videos
3 files
7.77K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
🚨 New cyber threat alert!

Pakistan-linked hackers are ramping up attacks on India's oil, railways, and external affairs sectors using Xeno RAT, Spark RAT, and new malware CurlBack RAT.

They're now using MSI packagesβ€”ditching old methodsβ€”to steal browser data, files, and credentials across Windows & Linux.

Find details here: https://thehackernews.com/2025/04/pakistan-linked-hackers-expand-targets.html
😁19πŸ”₯10πŸ‘7πŸ€”4πŸ‘1
AI is already rewriting cybersecurityβ€”and most defenders are unprepared.

Hackers are using AI to automate attacks in minutes, while security teams still react manually.

The new arms race isn’t humans vs. humans.

It’s AI vs. AI.

Learn more β†’ https://thehackernews.com/2025/04/cybersecurity-in-ai-era-evolve-faster.html
πŸ‘25🀯10😁8πŸ”₯7
πŸ”₯ Defenses can fail. Trusted tools can turn.

This week's newsletter covers how breaches happen before you even know they're possible.

⚑ Read and prepare β†’ https://thehackernews.com/2025/04/weekly-recap-windows-0-day-vpn-exploits.html
πŸ”₯14πŸ‘7
🚨 Precision-targeted attacks are validating emails in real-time before stealing credentials.

πŸ” Only verified, high-value accounts see fake login screens. No email? You’re redirected to Wikipedia to dodge detection.

Learn more: https://thehackernews.com/2025/04/phishing-campaigns-use-real-time-checks.html
πŸ‘23😁6😱1
🚨 Threat ALERT: ResolverRAT is hitting healthcare and pharma sectors hard β€” phishing, fear-bait, stealth attacks.

πŸ›‘οΈ Sophisticated multi-stage RAT
🌐 Localized lures: Hindi, Italian, Turkish + more
πŸ•΅οΈβ€β™‚οΈ Advanced evasion: encryption, IP rotation, memory-only payload

πŸ”— Read: https://thehackernews.com/2025/04/resolverrat-campaign-targets-healthcare.html
πŸ‘28πŸ”₯4πŸ‘1
πŸ”₯ Meta’s AI is coming for your public posts β€” but you can still opt out.

Starting this week, Meta is using public EU content from Facebook, Instagram & more (comments, posts, AI chats β€” not DMs).

Regulators approved it after a 1-year pause. Opt-out links are rolling out. Check your app or email.

πŸ‘‰ Act now β†’ https://thehackernews.com/2025/04/meta-resumes-eu-ai-training-using.html
πŸ€”13πŸ‘7😱2🀯1
🚨 Alert β€” A 9.0 CVSS flaw in Gladinet’s CentreStack also affects Triofoxβ€”both used for remote access.

Attackers exploited it as a zero-day in March, hitting 7 orgs by April 11.

πŸ”‘ Root cause: Hardcoded crypto keys β†’ enabled RCE via PowerShell + DLL sideloading

πŸ”— Read: https://thehackernews.com/2025/04/gladinets-triofox-and-centrestack-under.html
πŸ‘16
🚨 Hired by Hackers?

Devs on LinkedIn targeted in stealth malware attacks disguised as job offers.

Slow Pisces, linked to North Korea’s Bybit hack (Feb 2025), is now luring coders with fake challenges to drop RN Stealerβ€”a macOS info-stealer pulling iCloud, SSH, and cloud config files.

➑️ Learn how it works: https://thehackernews.com/2025/04/crypto-developers-targeted-by-python.html
πŸ‘13
🚨 Apache Roller Hit by 10.0 CVSS Flaw!

Old sessions stay active even after a password change (CVE-2025-24859). Hackers can keep access silently.

All versions ≀6.1.4 affected.

πŸ‘‰ Full details: https://thehackernews.com/2025/04/critical-apache-roller-vulnerability.html

πŸ”’ Fixed in v6.1.5. Patch now.
😁14πŸ‘5
🚨 Your biggest enterprise risk might be hiding in plain sight β€” THE BROWSER EXTENSIONS.

πŸ‘€ 99% of employees use them
πŸ‘€ 53% access sensitive data
πŸ‘€ 54% have unknown publishers

πŸ”₯ Your entire org could be one extension away from compromise.

πŸ”— Act now β†’ Audit, assess, and lock down. Learn how: https://thehackernews.com/2025/04/majority-of-browser-extensions-can.html
πŸ”₯13😁10πŸ‘6
Sophisticated phishing attacks are now routinely bypassing MFA, SSO, and multiple security layers across email, network, and endpoints.

Join the latest webinar from Push Security to learn why phishing attacks are more attractive than ever for attackers in 2025 β€” and what you can do to stop it.

Register here πŸ‘‰ https://thn.news/phishing-webinar-it
πŸ‘10😁2
⚠️ UNC5174 (aka Uteus), tied to China, is quietly breaching Linux & macOS systems using SNOWLIGHT malware + a fake Cloudflare app (VShell).

πŸ” Targets: 20+ nations | Sectors: Gov, finance, defense
πŸ›  Tactics: Open-source tools, fileless payloads, fake authenticator apps
πŸ‘€ Risk: Remote control, in-memory attacks, hard-to-trace

πŸ”— Full details: https://thehackernews.com/2025/04/chinese-hackers-target-linux-systems.html
πŸ‘21😁1
"Your firewall won’t save you."

Hackers are using ChatGPT to craft phishing lures & scan attack surfaces.

Meanwhile, most orgs still cling to VPNs & 30-year-old security models.

πŸ”₯ Zero Trust + AI isn’t hype β€” it’s survival.

Don’t fall behind: https://thehackernews.com/expert-insights/2025/04/rethinking-cyber-defense-with-zero.html
πŸ‘13😁7🀯3
πŸ›‘ CRITICAL ALERT β†’ U.S. funding for MITRE’s CVE vulnerability database program ends Wednesday.

MITRE warns: no funding = no new CVEs, degraded threat advisories, and slower incident response.

πŸ› οΈ CVEs power security tools, alerts, and patching across critical infrastructure.

πŸ” Without it, defenders lose a key part of their playbook.

πŸ”— Full story β†’ https://thehackernews.com/2025/04/us-govt-funding-for-mitres-cve-ends.html
🀯38πŸ€”7πŸ‘6πŸ‘4πŸ”₯3😱3⚑2😁1
🚨 New Android Phones, Pre-Loaded with Malware?!

Since June 2024, cheap Androids from Chinese brands like SHOWJI come with trojanized WhatsApp/Telegram apps out of the box.

πŸ“± Fake models: β€œS24 Ultra”, β€œNote 13 Pro”, etc.
πŸ’Έ Malware replaces your crypto wallet address in chats
🧠 Scans your images for mnemonic phrases
πŸ’° Hackers netted $1.6M+ via 40+ infected apps & 60+ C2 servers

πŸ”— Check the list & protect your crypto β†’ https://thehackernews.com/2025/04/chinese-android-phones-shipped-with.html
πŸ‘12😁6πŸ”₯3
🚨 BPFDoor is backβ€”with a stealthy new controller in play.

A fresh wave of BPFDoor attacks has hit telecom, finance & retail sectors in πŸ‡°πŸ‡·πŸ‡²πŸ‡ΎπŸ‡­πŸ‡°πŸ‡²πŸ‡²πŸ‡ͺπŸ‡¬ β€” using a stealth controller that opens reverse shells & moves laterally inside Linux networks.

πŸ”— Read β†’ https://thehackernews.com/2025/04/new-bpfdoor-controller-enables-stealthy.html
πŸ‘11πŸ”₯3
⚠️ Why hack in… when you can just log in?

80% of breaches stem from SaaS identity misconfigurations.

One compromised account can trigger a chain: Entra ID takeover β†’ GitHub exfiltration β†’ Slack leaks

Wing Security gives full SaaS visibilityβ€”no agents, no blind spots.

βœ… Identity & app mapping
βœ… Real-time threat detection
βœ… Full attack timeline

πŸ” See how it works: https://thehackernews.com/2025/04/product-walkthrough-look-inside-wing.html
πŸ‘9😁5
⚠️ Hackers are abusing AI tool Gamma to craft fake presentations that lead you to spoofed Microsoft SharePoint loginsβ€”and even fake CAPTCHA pages to dodge security scans.

πŸ”—Details: https://thehackernews.com/2025/04/ai-powered-gamma-used-to-host-microsoft.html
πŸ‘8😁5πŸ‘2πŸ”₯1πŸ€”1
🚨 Supply chain cyberattacks are exploding β€” and hitting where it hurts most: healthcare, retail, energy.

🦠 One breach = millions exposed.

The risk? Vendors are the backdoor. Hackers are walking right in.

Learn what’s driving this wave and how to stay ahead: https://thehackernews.com/2025/04/from-third-party-vendors-to-us-tariffs.html
πŸ‘10😁3πŸ”₯2🀯1
πŸ‘‡ Google blocked 5.1B bad ads and banned 39.2M advertiser accounts in 2024.

AI flagged scams, deepfakes, and fraud at scaleβ€”700K accounts suspended for impersonating public figures alone.

πŸ”’ 5.1B bad ads blocked
πŸ” 9.1B restricted
🚫 1.3B pages hit
πŸ‘€ 5M+ scam accounts suspended
πŸ€– AI flagged 700K deepfake scams

πŸ”— Full story: https://thehackernews.com/2025/04/google-blocked-51b-harmful-ads-and.html
πŸ‘20πŸ‘6πŸ”₯5⚑1πŸ€”1