โ ๏ธ Hackers are abusing AI tool Gamma to craft fake presentations that lead you to spoofed Microsoft SharePoint loginsโand even fake CAPTCHA pages to dodge security scans.
๐Details: https://thehackernews.com/2025/04/ai-powered-gamma-used-to-host-microsoft.html
๐Details: https://thehackernews.com/2025/04/ai-powered-gamma-used-to-host-microsoft.html
๐8๐5๐2๐ฅ1๐ค1
๐จ Supply chain cyberattacks are exploding โ and hitting where it hurts most: healthcare, retail, energy.
๐ฆ One breach = millions exposed.
The risk? Vendors are the backdoor. Hackers are walking right in.
Learn whatโs driving this wave and how to stay ahead: https://thehackernews.com/2025/04/from-third-party-vendors-to-us-tariffs.html
๐ฆ One breach = millions exposed.
The risk? Vendors are the backdoor. Hackers are walking right in.
Learn whatโs driving this wave and how to stay ahead: https://thehackernews.com/2025/04/from-third-party-vendors-to-us-tariffs.html
๐10๐3๐ฅ2๐คฏ1
๐ Google blocked 5.1B bad ads and banned 39.2M advertiser accounts in 2024.
AI flagged scams, deepfakes, and fraud at scaleโ700K accounts suspended for impersonating public figures alone.
๐ 5.1B bad ads blocked
๐ 9.1B restricted
๐ซ 1.3B pages hit
๐ค 5M+ scam accounts suspended
๐ค AI flagged 700K deepfake scams
๐ Full story: https://thehackernews.com/2025/04/google-blocked-51b-harmful-ads-and.html
AI flagged scams, deepfakes, and fraud at scaleโ700K accounts suspended for impersonating public figures alone.
๐ 5.1B bad ads blocked
๐ 9.1B restricted
๐ซ 1.3B pages hit
๐ค 5M+ scam accounts suspended
๐ค AI flagged 700K deepfake scams
๐ Full story: https://thehackernews.com/2025/04/google-blocked-51b-harmful-ads-and.html
๐20๐6๐ฅ5โก1๐ค1
Over 50% of vulnerabilities are exploited within 7 days of discovery.
Learn how to reduce MTTR and secure your apps with insights from ActiveState's 2025 State of Vulnerability Management & Remediation Report.
๐ก๏ธ Stay ahead of threatsโdownload now! https://thn.news/vulnerability-management-2025
#DevSecOps #OpenSource
Learn how to reduce MTTR and secure your apps with insights from ActiveState's 2025 State of Vulnerability Management & Remediation Report.
๐ก๏ธ Stay ahead of threatsโdownload now! https://thn.news/vulnerability-management-2025
#DevSecOps #OpenSource
๐11๐8
๐๐ UPDATE โ CISA extends funding to prevent a shutdown of the CVE Program.
A new CVE Foundation is also launched to ensure global, independent oversightโjust as ENISA rolls out the EU Vulnerability Database.
Read: https://thehackernews.com/2025/04/us-govt-funding-for-mitres-cve-ends.html#update-cisa-extends-cve-program-contract-amid-funding-crisis
A new CVE Foundation is also launched to ensure global, independent oversightโjust as ENISA rolls out the EU Vulnerability Database.
Read: https://thehackernews.com/2025/04/us-govt-funding-for-mitres-cve-ends.html#update-cisa-extends-cve-program-contract-amid-funding-crisis
๐25๐9๐ฅ6๐คฏ3๐1
๐ฅ One task away from total takeover?
4 local privilege escalation flaws found in schtasks.exeโa core part of Windows Task Scheduler.
Attackers can:
โข Bypass UAC
โข Run SYSTEM-level commands
โข Erase security logs
โข Impersonate admins using known passwords.
Fix not yet available.
๐ Full story โ https://thehackernews.com/2025/04/experts-uncover-four-new-privilege.html
4 local privilege escalation flaws found in schtasks.exeโa core part of Windows Task Scheduler.
Attackers can:
โข Bypass UAC
โข Run SYSTEM-level commands
โข Erase security logs
โข Impersonate admins using known passwords.
Fix not yet available.
๐ Full story โ https://thehackernews.com/2025/04/experts-uncover-four-new-privilege.html
๐ฅ18๐12
๐จ Targeted iPhone attacks in the wild.
Apple just patched 2 new zero-daysโbringing 2025โs total to 5 actively exploited flaws.
โ One lets hackers run code via malicious audio files
โ Another bypasses Pointer Authentication using memory tricks
๐ Details here: https://thehackernews.com/2025/04/apple-patches-two-actively-exploited.html
Update now: iOS 18.4.1, macOS Sequoia 15.4.1, tvOS, visionOS
Apple just patched 2 new zero-daysโbringing 2025โs total to 5 actively exploited flaws.
โ One lets hackers run code via malicious audio files
โ Another bypasses Pointer Authentication using memory tricks
๐ Details here: https://thehackernews.com/2025/04/apple-patches-two-actively-exploited.html
Update now: iOS 18.4.1, macOS Sequoia 15.4.1, tvOS, visionOS
๐20๐4๐ฅ2๐ค1
๐จ Actively Exploited SonicWall Flaw Hits CISAโs KEV List.
Remote attackers can execute code via SMA 100 Series bug (CVE-2021-20035, CVSS 7.2).
โก๏ธ Injects OS commands as โnobodyโ user
โก๏ธ Impacts SMA 200โ500v on outdated firmware
โก๏ธ FCEB agencies must patch by May 7, 2025
Your VPN gateway could be the backdoor. Patch it
Learn more: https://thehackernews.com/2025/04/cisa-flags-actively-exploited.html
Remote attackers can execute code via SMA 100 Series bug (CVE-2021-20035, CVSS 7.2).
โก๏ธ Injects OS commands as โnobodyโ user
โก๏ธ Impacts SMA 200โ500v on outdated firmware
โก๏ธ FCEB agencies must patch by May 7, 2025
Your VPN gateway could be the backdoor. Patch it
Learn more: https://thehackernews.com/2025/04/cisa-flags-actively-exploited.html
๐20๐ฅ2
๐จ Microsoft Alert: Node.js-Powered Malware Campaign Ongoing...
Since Oct 2024, fake Binance & TradingView installers have been used to deploy malware via Node.js and PowerShell.
Linked threats include ClickFix tricks, SectopRAT malware, fake PDF tools, and HR-themed phishing kits.
Learn more: https://thehackernews.com/2025/04/nodejs-malware-campaign-targets-crypto.html
Since Oct 2024, fake Binance & TradingView installers have been used to deploy malware via Node.js and PowerShell.
Linked threats include ClickFix tricks, SectopRAT malware, fake PDF tools, and HR-themed phishing kits.
Learn more: https://thehackernews.com/2025/04/nodejs-malware-campaign-targets-crypto.html
๐คฏ16๐11
๐จ CVSS 10.0 ALERT: Remote Code Execution in Erlang/OTP SSH (CVE-2025-32433)
No auth. Full control. Widespread impact.
Used in Cisco, Ericsson, OT/IoT, and edge systems, this bug lets attackers run code without logging in.
If SSH runs as root? Game over. ๐
๐ Full details โ https://thehackernews.com/2025/04/critical-erlangotp-ssh-vulnerability.html
๐ฅ Fix now โ OTP-27.3.3 / 26.2.5.11 / 25.3.2.20 Block SSH ports as temp fix.
No auth. Full control. Widespread impact.
Used in Cisco, Ericsson, OT/IoT, and edge systems, this bug lets attackers run code without logging in.
If SSH runs as root? Game over. ๐
๐ Full details โ https://thehackernews.com/2025/04/critical-erlangotp-ssh-vulnerability.html
๐ฅ Fix now โ OTP-27.3.3 / 26.2.5.11 / 25.3.2.20 Block SSH ports as temp fix.
๐คฏ15๐9๐ฅ4
๐ฅ Blockchain wonโt kill passwords yetโbut it may change how we authenticate.
Decentralized IDs + cryptographic keys = fewer breaches, no central targets.
Used in finance (KYC) & healthcare (patient data), itโs realโand growing.
But until blockchain scales, passwords stay. Just make them strong.
โก๏ธ Learn more: https://thehackernews.com/2025/04/blockchain-offers-security-benefits-but.html
Decentralized IDs + cryptographic keys = fewer breaches, no central targets.
Used in finance (KYC) & healthcare (patient data), itโs realโand growing.
But until blockchain scales, passwords stay. Just make them strong.
โก๏ธ Learn more: https://thehackernews.com/2025/04/blockchain-offers-security-benefits-but.html
๐17๐ค3
๐จ Copy. Paste. Get hacked.
North Korea, Iran & Russia are now pushing ClickFixโa sneaky trick that fools users into running malware on their own devices.
Learn more โ https://thehackernews.com/2025/04/state-sponsored-hackers-weaponize.html
North Korea, Iran & Russia are now pushing ClickFixโa sneaky trick that fools users into running malware on their own devices.
Learn more โ https://thehackernews.com/2025/04/state-sponsored-hackers-weaponize.html
๐27๐6๐ฅ3โก2
๐จ AI isnโt just coding fasterโitโs rewriting the rulebook.
LLMs have entered the threat landscape. From spear-phishing and voice fraud to malware with OCR, attackers are now using AI to scale, blend, and evolve.
Defenders use AI tooโbut GenAI interfaces expose a new attack surface.
๐ Full deep dive in Security Navigator 2025: https://thehackernews.com/2025/04/artificial-intelligence-whats-all-fuss.html
LLMs have entered the threat landscape. From spear-phishing and voice fraud to malware with OCR, attackers are now using AI to scale, blend, and evolve.
Defenders use AI tooโbut GenAI interfaces expose a new attack surface.
๐ Full deep dive in Security Navigator 2025: https://thehackernews.com/2025/04/artificial-intelligence-whats-all-fuss.html
๐ค15๐6๐3
๐จ China-backed hackers are deploying TONESHELL v3, StarProxy, and stealth tools like SplatCloak to breach Myanmar targetsโdodging EDR, logging keystrokes, and hopping across networks with FakeTLS tricks.
โข 3 TONESHELL variants
โข 2 new keyloggers (PAKLOG, CorKLOG)
โข StarProxy โ a lateral movement proxy over FakeTLS
โข SplatCloak โ a Windows kernel-level EDR evasion driver
Details here ๐ https://thehackernews.com/2025/04/mustang-panda-targets-myanmar-with.html
โข 3 TONESHELL variants
โข 2 new keyloggers (PAKLOG, CorKLOG)
โข StarProxy โ a lateral movement proxy over FakeTLS
โข SplatCloak โ a Windows kernel-level EDR evasion driver
Details here ๐ https://thehackernews.com/2025/04/mustang-panda-targets-myanmar-with.html
๐ฅ17๐9๐5โก1
๐จ New NTLM flaw (CVE-2025-24054) is being actively exploited to steal Windows credentialsโjust by downloading a file. No clicks, no execution needed.
This "low-interaction" bug leaks NTLMv2 hashes via SMBโperfect for pass-the-hash attacks.
๐ Details here: https://thehackernews.com/2025/04/cve-2025-24054-under-active.html
This "low-interaction" bug leaks NTLMv2 hashes via SMBโperfect for pass-the-hash attacks.
๐ Details here: https://thehackernews.com/2025/04/cve-2025-24054-under-active.html
๐22๐คฏ16
๐จ New XorDDoS Variant Targets U.S. Servers!
The malware is now hijacking Docker and Linux systems via SSH brute-force attacks.
A new โVIPโ controller spotted in 2024 suggests itโs being sold as a service, expanding botnet operations.
Full story โ https://thehackernews.com/2025/04/experts-uncover-new-xorddos-controller.html
The malware is now hijacking Docker and Linux systems via SSH brute-force attacks.
A new โVIPโ controller spotted in 2024 suggests itโs being sold as a service, expanding botnet operations.
Full story โ https://thehackernews.com/2025/04/experts-uncover-new-xorddos-controller.html
๐14๐11๐ค2
AI is already in your SaaS. The real question: Do you know whereโor how risky it is?
Employees are using ChatGPT, bots, and AI tools without security oversight. Shadow AI is realโand your old playbook wonโt catch it.
๐ฅ WEBINAR โ Join AI security expert and learn:
๐ Real breach cases
โ๏ธ Detection strategies that actually work
๐จ What to do before your next silent breach
Join the webinar โ https://thehackernews.com/2025/04/webinar-ai-is-already-inside-your-saas.html
Employees are using ChatGPT, bots, and AI tools without security oversight. Shadow AI is realโand your old playbook wonโt catch it.
๐ฅ WEBINAR โ Join AI security expert and learn:
๐ Real breach cases
โ๏ธ Detection strategies that actually work
๐จ What to do before your next silent breach
Join the webinar โ https://thehackernews.com/2025/04/webinar-ai-is-already-inside-your-saas.html
๐คฏ9๐ฅ5๐4
๐ Attackers are now using multi-stage payloads that slip past detectionโvia simple tricks, not complex code.
One phishing email = 3 malware strains:
โข Agent Tesla
โข Remcos RAT
โข XLoader
๐ Plus: a new MysterySnail variant is targeting Mongolia & Russiaโ40+ commands, remote access, and evasion built-in.
โก๏ธ See the full analysis: https://thehackernews.com/2025/04/multi-stage-malware-attack-uses-jse-and.html
One phishing email = 3 malware strains:
โข Agent Tesla
โข Remcos RAT
โข XLoader
๐ Plus: a new MysterySnail variant is targeting Mongolia & Russiaโ40+ commands, remote access, and evasion built-in.
โก๏ธ See the full analysis: https://thehackernews.com/2025/04/multi-stage-malware-attack-uses-jse-and.html
๐17๐2๐ฅ1
โ ๏ธ Alert: Fake E-ZPass Texts Target Drivers in 8 U.S. States
A widespread smishing scam is tricking drivers into fake toll payments to steal card info.
๐น Linked to China-based Smishing Triad
๐น Phishing kits sold by CS student Wang Duo Yu
๐น Used in 121+ countries
๐ Full story: https://thehackernews.com/2025/04/chinese-smishing-kit-behind-widespread.html
๐ต Avoid clicking toll links in texts.
A widespread smishing scam is tricking drivers into fake toll payments to steal card info.
๐น Linked to China-based Smishing Triad
๐น Phishing kits sold by CS student Wang Duo Yu
๐น Used in 121+ countries
๐ Full story: https://thehackernews.com/2025/04/chinese-smishing-kit-behind-widespread.html
๐ต Avoid clicking toll links in texts.
๐27๐คฏ5๐ฑ3
๐จ Critical ASUS Router Flaw Exposed
9.2 CVSS | Remote Hijack Risk
A new bugโCVE-2025-2492โlets attackers remotely execute functions on ASUS routers with AiCloud enabled.
๐ Details: https://thehackernews.com/2025/04/asus-confirms-critical-flaw-in-aicloud.html
9.2 CVSS | Remote Hijack Risk
A new bugโCVE-2025-2492โlets attackers remotely execute functions on ASUS routers with AiCloud enabled.
๐ Details: https://thehackernews.com/2025/04/asus-confirms-critical-flaw-in-aicloud.html
๐20๐ฑ4๐3๐ฅ1