The Hacker News
โœ”
151K subscribers
1.86K photos
10 videos
3 files
7.77K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: [email protected]

๐ŸŒ Website: https://thehackernews.com
Download Telegram
๐Ÿ‘€ Attackers are now using multi-stage payloads that slip past detectionโ€”via simple tricks, not complex code.

One phishing email = 3 malware strains:
โ€ข Agent Tesla
โ€ข Remcos RAT
โ€ข XLoader

๐Ÿ” Plus: a new MysterySnail variant is targeting Mongolia & Russiaโ€”40+ commands, remote access, and evasion built-in.

โžก๏ธ See the full analysis: https://thehackernews.com/2025/04/multi-stage-malware-attack-uses-jse-and.html
๐Ÿ‘17๐Ÿ‘2๐Ÿ”ฅ1
โš ๏ธ Alert: Fake E-ZPass Texts Target Drivers in 8 U.S. States

A widespread smishing scam is tricking drivers into fake toll payments to steal card info.

๐Ÿ”น Linked to China-based Smishing Triad
๐Ÿ”น Phishing kits sold by CS student Wang Duo Yu
๐Ÿ”น Used in 121+ countries

๐Ÿ”— Full story: https://thehackernews.com/2025/04/chinese-smishing-kit-behind-widespread.html

๐Ÿ“ต Avoid clicking toll links in texts.
๐Ÿ‘27๐Ÿคฏ5๐Ÿ˜ฑ3
๐Ÿšจ Critical ASUS Router Flaw Exposed
9.2 CVSS | Remote Hijack Risk

A new bugโ€”CVE-2025-2492โ€”lets attackers remotely execute functions on ASUS routers with AiCloud enabled.

๐Ÿ”— Details: https://thehackernews.com/2025/04/asus-confirms-critical-flaw-in-aicloud.html
๐Ÿ‘20๐Ÿ˜ฑ4๐Ÿ‘3๐Ÿ”ฅ1
๐Ÿšจ Malware Alert for Developers!

3 npm packages are mimicking a popular Telegram bot libraryโ€”but secretly install SSH backdoors & exfiltrate your data.

They replicate the look of node-telegram-bot-api (100K+ weekly users), use starjacking to fake credibility, and target Linux systems. Removal โ‰  protectionโ€”SSH keys stay behind.

Learn more: https://thehackernews.com/2025/04/rogue-npm-packages-mimic-telegram-bot.html
๐Ÿ‘35๐Ÿคฏ7๐Ÿ˜2โšก1
๐Ÿšจ Russiaโ€™s APT29 hits EU diplomats with new malware disguised as wine-tasting invites.

๐Ÿท GRAPELOADER is a stealthy first-stage loader hidden in โ€œwine-zipโ€
๐ŸŽฏ Targets: European Ministries of Foreign Affairs
๐Ÿ”„ Launches WINELOADER for deep system access

๐Ÿ”— Full report: https://thehackernews.com/2025/04/apt29-deploys-grapeloader-malware.html
๐Ÿ‘35๐Ÿ˜25๐Ÿ”ฅ3
๐Ÿšจ Surge in cyberattacks tied to Russian bulletproof host Proton66 since Jan 8, 2025.

New research links it to brute-force, malware, ransomwareโ€”even traffic routed via Kaspersky Labโ€™s network path.

Attackers exploit 2024โ€“25 zero-days, deploy SuperBlack & WeaXor ransomware, and run phishing via hacked WordPress sites.

Learn more: https://thehackernews.com/2025/04/hackers-abuse-russian-bulletproof-host.html
๐Ÿ”ฅ20๐Ÿ‘7
โšก From zero-click iOS exploits to NTLM credential leaks and the 4Chan breach โ€” this weekโ€™s cyber threats hit where trust runs deepest.

THNโ€™s Weekly Recap breaks down the stealth, the strategy, and the systems under fire.

๐Ÿ”— Read: https://thehackernews.com/2025/04/thn-weekly-recap-ios-zero-days-4chan.html
๐Ÿ”ฅ18โšก2
โš ๏ธ Hold your phone near your card... and they drain your bank account.

A new Android malware-as-a-service, SuperCard X, is targeting Italians with NFC relay attacksโ€”letting cybercriminals remotely steal card data and pull off ATM & PoS fraud.

๐Ÿ‘‰ Learn how it works: https://thehackernews.com/2025/04/supercard-x-android-malware-enables.html

Googleโ€™s now working on a new Android update to block risky app installs. But until thenโ€”stay sharp. Think before tapping.
๐Ÿ˜18๐Ÿ”ฅ9๐Ÿ‘5๐Ÿ‘3๐Ÿคฏ3โšก1๐Ÿค”1
๐Ÿšจ Your MDM isnโ€™t enough. Most breaches start with a device you canโ€™t see.

Unmanaged laptops, outdated personal phones, misconfigured toolsโ€”attackers love them.
MDM/EDR miss the mark.

Device Trust closes the gap.

๐Ÿ‘€ See how: https://thehackernews.com/2025/04/5-reasons-device-management-isnt-device.html
๐Ÿ‘12๐Ÿ”ฅ5โšก2๐Ÿ˜2
๐Ÿ•ต๏ธโ€โ™‚๏ธ Kimsuky is backโ€”and digging deep.

A new Larva-24005 campaign is exploiting old RDP bugs (BlueKeep, CVE-2019-0708) to breach systems in South Korea, Japan & beyondโ€”with targets across energy, finance & tech.

Learn more: https://thehackernews.com/2025/04/kimsuky-exploits-bluekeep-rdp.html
๐Ÿ”ฅ17๐Ÿ‘9
๐Ÿ’ฃ Lotus Panda, a China-linked APT, breached key sectors across Southeast Asiaโ€”govt, telecom, air trafficโ€”from Aug 2024 to Feb 2025.

New tools. Stolen Chrome data. Hijacked legit software.

Read full report ๐Ÿ‘‰ https://thehackernews.com/2025/04/lotus-panda-hacks-se-asian-governments.html
๐Ÿค”13๐Ÿ‘2๐Ÿคฏ2๐Ÿ˜ฑ1
โš ๏ธ AI is Supercharging DDoS Attacks.

Hackers now use AI to launch smarter, harder-to-stop DDoS attacks. Most defenses fail because theyโ€™re poorly set up โ€” not because theyโ€™re weak.

๐Ÿ”— Free DDoS Threat Check โ†’ https://thehackernews.com/expert-insights/2025/04/how-ai-and-iot-are-supercharging-ddos.html
๐Ÿ”ฅ13๐Ÿ‘4
๐Ÿ”ฅ Microsoft boosts security after major China-backed breach.

โ€”MSA sign-ins moved to Azure confidential VMs

โ€”92% of staff now use phishing-resistant MFA

โ€”81% of code branches protected with proof-of-presence

โ€”New Quick Machine Recovery auto-fixes Windows boot failures

See details: https://thehackernews.com/2025/04/microsoft-secures-msa-signing-with.html
๐Ÿ˜20๐Ÿ‘8๐Ÿ‘1
๐Ÿšจ Signed by Google. Hosted by Google. Hijacked by Hackers.

๐Ÿ‘€ Hackers sent real emails from [email protected] โ€” fully verified, signed, no warnings. Victims handed over passwords, believing it was legit.

โœ”๏ธ Real Google email
โœ”๏ธ Fake login on Google Sites
โœ”๏ธ Passed DKIM, SPF, DMARC

๐Ÿ”— Full story: https://thehackernews.com/2025/04/phishers-exploit-google-sites-and-dkim.html
๐Ÿ˜ฑ52๐Ÿ‘14๐Ÿ”ฅ11๐Ÿ˜10โšก3๐Ÿ‘2๐Ÿคฏ2
Each user is unique. Their security should be too.

Join Bitdefender on April 23 for the LIVE launch of GravityZone PHASR โ€” a breakthrough in reducing employee attack surfaces by up to 95%.

๐Ÿ”’ Adaptive, user-focused protection
๐ŸŽฅ Live demo + expert insights

๐Ÿ“… Secure your spot here: https://thn.news/gravityzone-bitdefender-x
๐Ÿ‘10๐Ÿ‘6๐Ÿค”2๐Ÿ”ฅ1
This media is not supported in your browser
VIEW IN TELEGRAM
๐Ÿ›‘ Privilege Escalation in Google Cloud!

A serious bug in Cloud Composer (GCP) let attackers with edit access take control of key services like Cloud Storage and Artifact Registry by uploading malicious code.

๐Ÿ”— Read this story here: https://thehackernews.com/2025/04/gcp-cloud-composer-bug-let-attackers.html
๐Ÿ‘12๐Ÿ”ฅ5๐Ÿค”3๐Ÿ‘2
๐Ÿ‘€ Browsers are the new battleground. 70% of modern malware starts here, yet most organizations overlook it.

AI tools, phishing, shadow IT, and risky extensions hide in plain sight.

Legacy security is inadequate. Monitor where work happensโ€”the browser.

๐Ÿ‘‰ Explore new risks. Read: https://thehackernews.com/2025/04/5-major-concerns-with-employees-using.html
๐Ÿ‘11๐Ÿ‘5๐Ÿ”ฅ3
๐Ÿ›‘ New Malware Targets Docker โ€” but itโ€™s not about crypto mining anymore.

Hackers are hijacking Docker to run fake nodes on a Web3 network called Teneo. Instead of mining, they farm TENEO tokens by sending fake heartbeat signals.

๐Ÿ”น 325+ downloads from Docker Hub

Read more โž https://thehackernews.com/2025/04/docker-malware-exploits-teneo-web3-node.html
๐Ÿ‘25๐Ÿ”ฅ3๐Ÿ‘3
๐Ÿ”ฅ Google pulls the plug on third-party cookie prompts in Chrome.

No more new pop-ups โ€” just Incognito upgrades & IP protection by Q3 2025.

While Firefox & Safari banned 3rd-party cookies in 2020, Google stallsโ€”caught between privacy & profit.

Read โ€” https://thehackernews.com/2025/04/google-drops-cookie-prompt-in-chrome.html
๐Ÿ‘23๐Ÿ˜14๐Ÿ‘1
๐Ÿšจ Crypto Devs, Watch Out!

Ripple's xrpl.js library was backdoored to steal private keys! Over 2.9M downloads, 135K devs at risk.

๐Ÿ—“๏ธ Malicious versions: 4.2.1โ€“4.2.4, 2.14.2
๐Ÿ›ก๏ธ Safe versions: 4.2.5, 2.14.3
๐Ÿ‘ค Hacker hijacked a Ripple dev's npm account on April 21, 2025.

๐Ÿ”— Learn more: https://thehackernews.com/2025/04/ripples-xrpljs-npm-package-backdoored.html
๐Ÿ‘16๐Ÿคฏ5โšก1