๐ฅ New Cyber Attack Alert!
Senior members of the World Uyghur Congress were targeted by malware hidden in a fake UyghurEdit++ app, Citizen Lab reports (Mar 2025).
โ Custom-made spyware
โ Links to China
โ Started as early as May 2024
Learn more: https://thehackernews.com/2025/04/malware-attack-targets-world-uyghur.html
Senior members of the World Uyghur Congress were targeted by malware hidden in a fake UyghurEdit++ app, Citizen Lab reports (Mar 2025).
โ Custom-made spyware
โ Links to China
โ Started as early as May 2024
Learn more: https://thehackernews.com/2025/04/malware-attack-targets-world-uyghur.html
๐15๐ค9๐3๐คฏ2
๐ Still trusting VPNs to secure remote access?
Recent critical flaws exposed thousands. Every open port and IP address is now a target, not a tool.
Legacy network security can't keep up with AI-driven attacks.
Zero Trust isnโt optional anymore โ itโs survival.
Learn why it matters โ https://thehackernews.com/expert-insights/2025/04/its-time-to-rethink-your-security-for.html
Recent critical flaws exposed thousands. Every open port and IP address is now a target, not a tool.
Legacy network security can't keep up with AI-driven attacks.
Zero Trust isnโt optional anymore โ itโs survival.
Learn why it matters โ https://thehackernews.com/expert-insights/2025/04/its-time-to-rethink-your-security-for.html
๐15๐ค7๐ฑ5
๐ฅ 75 zero-day exploits hit in 2024 | 44% aimed at enterprise tools.
While browser & mobile attacks fell sharply, threat actors shifted focus โ hitting Ivanti, Palo Alto, Cisco & others.
๐ Top targets: Microsoft (26), Google (11), Ivanti (7), Apple (5)
๐ฏ 20 zero-days hit security appliances
๐ต๏ธโโ๏ธ State hackers, spyware firms & cybercrime crews all involved
Read the full story โ https://thehackernews.com/2025/04/google-reports-75-zero-days-exploited.html
While browser & mobile attacks fell sharply, threat actors shifted focus โ hitting Ivanti, Palo Alto, Cisco & others.
๐ Top targets: Microsoft (26), Google (11), Ivanti (7), Apple (5)
๐ฏ 20 zero-days hit security appliances
๐ต๏ธโโ๏ธ State hackers, spyware firms & cybercrime crews all involved
Read the full story โ https://thehackernews.com/2025/04/google-reports-75-zero-days-exploited.html
๐10๐2๐ค1
โก Your AI Copilot could leak your secrets โ without you even knowing.
Microsoft 365 Copilot boosts productivity, but opens the door to massive data risks. Reco spots risky prompts, flags hidden attacks, and locks down your SaaS ecosystem.
Learn how: https://thehackernews.com/2025/04/product-walkthrough-securing-microsoft.html
Microsoft 365 Copilot boosts productivity, but opens the door to massive data risks. Reco spots risky prompts, flags hidden attacks, and locks down your SaaS ecosystem.
Learn how: https://thehackernews.com/2025/04/product-walkthrough-securing-microsoft.html
โก16๐6๐ฑ3
๐จ Cybersecurity firms are under attack!
๐จ๐ณ Chinaโs PurpleHaze hackers targeted SentinelOneโs systems and high-value customers.
๐ญ 360+ fake North Korean IT workers tried to infiltrate the company.
๐ท๐บ Russian ransomware gangs are buying real security products to beat defenses.
Read ๐https://thehackernews.com/2025/04/sentinelone-uncovers-chinese-espionage.html
๐จ๐ณ Chinaโs PurpleHaze hackers targeted SentinelOneโs systems and high-value customers.
๐ญ 360+ fake North Korean IT workers tried to infiltrate the company.
๐ท๐บ Russian ransomware gangs are buying real security products to beat defenses.
Read ๐https://thehackernews.com/2025/04/sentinelone-uncovers-chinese-espionage.html
๐16๐6๐ฅ5๐3
๐จ New jailbreaks ("Inception", "Do-Not-Reply"), memory hacks, tool poisoning, unsafe model upgrades โ CERT, METR, and others warn:
โก ChatGPT, Claude, Copilot, Gemini, Grok, Meta AI can leak code, malware, data.
โก GPT-4.1 is 3X riskier than before.
โก MCP protocols, Chrome extensions now exploited.
The AI arms race is outpacing safety.
Read: https://thehackernews.com/2025/04/new-reports-uncover-jailbreaks-unsafe.html
โก ChatGPT, Claude, Copilot, Gemini, Grok, Meta AI can leak code, malware, data.
โก GPT-4.1 is 3X riskier than before.
โก MCP protocols, Chrome extensions now exploited.
The AI arms race is outpacing safety.
Read: https://thehackernews.com/2025/04/new-reports-uncover-jailbreaks-unsafe.html
๐16โก2
๐ฅ Privacy vs AI?
WhatsApp just dropped Private Processingโletting you use AI features like message summaries without Meta (or anyone) seeing your chats.
๐ก๏ธ Encrypted. Auditable. Anonymous.
โ Confidential Virtual Machine
โ Oblivious HTTP
โ Forward Security
๐ Learn how it works: https://thehackernews.com/2025/04/whatsapp-launches-private-processing-to.html
WhatsApp just dropped Private Processingโletting you use AI features like message summaries without Meta (or anyone) seeing your chats.
๐ก๏ธ Encrypted. Auditable. Anonymous.
โ Confidential Virtual Machine
โ Oblivious HTTP
โ Forward Security
๐ Learn how it works: https://thehackernews.com/2025/04/whatsapp-launches-private-processing-to.html
๐ค23๐11๐9โก1
๐จ Proton Mail faces nationwide ban in India ๐ฎ๐ณ
Karnataka High Court has ordered the govโt to block the encrypted email provider after a legal complaint tied to AI deepfakes and obscene messages sent via the platform.
๐ Still accessibleโfor now.
Read: https://thehackernews.com/2025/04/indian-court-orders-action-to-block.html
Karnataka High Court has ordered the govโt to block the encrypted email provider after a legal complaint tied to AI deepfakes and obscene messages sent via the platform.
๐ Still accessibleโfor now.
Read: https://thehackernews.com/2025/04/indian-court-orders-action-to-block.html
๐33๐ฑ19๐6๐ค5๐3๐คฏ3
๐ฅ Meta just dropped a firewall for AI.
LlamaFirewall is open-sourceโand built to stop jailbreaks, prompt injections, and insecure code in real time.
Itโs modular. Itโs fast. Itโs made for the LLM era.
๐ก๏ธ Also out:
๐น CyberSecEval 4 with AutoPatchBench to test AI-powered vuln fixes
๐น Llama for Defenders to help fight scams, fraud & phishing
๐น Private Processing to run AI features without leaking user data
๐ Full details here: https://thehackernews.com/2025/04/meta-launches-llamafirewall-framework.html
LlamaFirewall is open-sourceโand built to stop jailbreaks, prompt injections, and insecure code in real time.
Itโs modular. Itโs fast. Itโs made for the LLM era.
๐ก๏ธ Also out:
๐น CyberSecEval 4 with AutoPatchBench to test AI-powered vuln fixes
๐น Llama for Defenders to help fight scams, fraud & phishing
๐น Private Processing to run AI features without leaking user data
๐ Full details here: https://thehackernews.com/2025/04/meta-launches-llamafirewall-framework.html
๐27๐ฅ7๐5๐ค4๐3๐ฑ1
๐จ RansomHub's empire just vanished.
After stealing data from 200+ victims, its dark web site mysteriously went offline on April 1, 2025โtriggering panic among affiliates.
Qilin's leaks doubled. DragonForce claims a takeover.
๐ Read More: https://thehackernews.com/2025/04/ransomhub-went-dark-april-1-affiliates.html
After stealing data from 200+ victims, its dark web site mysteriously went offline on April 1, 2025โtriggering panic among affiliates.
Qilin's leaks doubled. DragonForce claims a takeover.
๐ Read More: https://thehackernews.com/2025/04/ransomhub-went-dark-april-1-affiliates.html
๐11๐5
๐จ China-linked APT โTheWizardsโ caught hijacking trusted Chinese apps to deploy malware updates.
Uses IPv6/DNS to turn Sogou Pinyin & Tencent QQ into WizardNet backdoor delivery for users in ๐จ๐ณ๐ญ๐ฐ๐ฐ๐ญ๐ต๐ญ๐ฆ๐ช.
๐ Their tool Spellbinder quietly captures traffic, reroutes updates to attacker servers.
๐ Full story: https://thehackernews.com/2025/04/chinese-hackers-abuse-ipv6-slaac-for.html
Uses IPv6/DNS to turn Sogou Pinyin & Tencent QQ into WizardNet backdoor delivery for users in ๐จ๐ณ๐ญ๐ฐ๐ฐ๐ญ๐ต๐ญ๐ฆ๐ช.
๐ Their tool Spellbinder quietly captures traffic, reroutes updates to attacker servers.
๐ Full story: https://thehackernews.com/2025/04/chinese-hackers-abuse-ipv6-slaac-for.html
๐ฅ8๐5๐4
๐ โAll my shows were in Spanish. I didnโt change anything.โ
Thatโs not a glitchโitโs an account takeover.
๐ 100K+ accounts/mo exposed on major platforms.
๐ฎ Streaming, gaming, SaaS vulnerable.
๐ง MFA fails vs. stolen session cookies.
Act now: Monitor infostealers. Reset risk. Rebuild trust.
๐ ReadfFull story + Flareโs ATO report: https://thehackernews.com/2025/04/customer-account-takeovers-multi.html
Thatโs not a glitchโitโs an account takeover.
๐ 100K+ accounts/mo exposed on major platforms.
๐ฎ Streaming, gaming, SaaS vulnerable.
๐ง MFA fails vs. stolen session cookies.
Act now: Monitor infostealers. Reset risk. Rebuild trust.
๐ ReadfFull story + Flareโs ATO report: https://thehackernews.com/2025/04/customer-account-takeovers-multi.html
๐7๐คฏ3
๐จ New Espionage Alert!
A Russian-speaking APT group, Nebulous Mantis, is deploying the stealthy RomCom RAT to target NATO-linked entities, gov agencies, and critical infra โ using bulletproof hosting, IPFS, and over 40 remote commands.
๐ See how it works, whoโs behind it, and why it matters now: https://thehackernews.com/2025/04/nebulous-mantis-targets-nato-linked.html
A Russian-speaking APT group, Nebulous Mantis, is deploying the stealthy RomCom RAT to target NATO-linked entities, gov agencies, and critical infra โ using bulletproof hosting, IPFS, and over 40 remote commands.
๐ See how it works, whoโs behind it, and why it matters now: https://thehackernews.com/2025/04/nebulous-mantis-targets-nato-linked.html
๐14๐6
Itโs back! XPOSURE 2025 returns for its fourth year, focused on what matters most: reducing cyber risk exposure.
Join Pentera and top cybersecurity leaders at the National Exposure Management vSummit to discover how leading security teams are taking a proactive approach to managing enterprise-wide exposure.
๐ Bonus: The first 150 registrants will receive an Uber Eats voucher upon registration!
๐ June 18 | 11 AM ET | Virtual
๐ Register now: https://thn.news/xposure2025-pentera
#XPOSURE2025 #ExposureManagement #CyberSecurityLeadership #EnterpriseSecurity
Join Pentera and top cybersecurity leaders at the National Exposure Management vSummit to discover how leading security teams are taking a proactive approach to managing enterprise-wide exposure.
๐ Bonus: The first 150 registrants will receive an Uber Eats voucher upon registration!
๐ June 18 | 11 AM ET | Virtual
๐ Register now: https://thn.news/xposure2025-pentera
#XPOSURE2025 #ExposureManagement #CyberSecurityLeadership #EnterpriseSecurity
๐10๐4๐ฅ1
This media is not supported in your browser
VIEW IN TELEGRAM
๐จ AI tools are learning too fastโand so are attackers.
New report reveals how MCP & A2A protocols can be hijacked to leak emails, spoof agents, and silently override tool logic.
๐ Tool poisoning
๐ง Prompt injection
๐ต๏ธ Agent impersonation
Even benign tools can flip maliciousโno warning, no second prompt.
๐ Learn about this new AI attack surface โ https://thehackernews.com/2025/04/experts-uncover-critical-mcp-and-a2a.html
New report reveals how MCP & A2A protocols can be hijacked to leak emails, spoof agents, and silently override tool logic.
๐ Tool poisoning
๐ง Prompt injection
๐ต๏ธ Agent impersonation
Even benign tools can flip maliciousโno warning, no second prompt.
๐ Learn about this new AI attack surface โ https://thehackernews.com/2025/04/experts-uncover-critical-mcp-and-a2a.html
๐15
๐ค Hackers arenโt cracking passwords anymoreโtheyโre impersonating you.
From AI deepfakes to social engineering, attackers now exploit weak links before and after loginโlike during account recovery or onboarding.
๐ Orgs secure login, but not full identity lifecycle. Join free webinar to learn:
โ Enforce phishing-resistant MFA
โ Secure device trust
โ Protect identity from onboarding to recovery
๐ Register now โ https://thehackernews.com/2025/04/free-webinar-guide-to-securing-your.html
From AI deepfakes to social engineering, attackers now exploit weak links before and after loginโlike during account recovery or onboarding.
๐ Orgs secure login, but not full identity lifecycle. Join free webinar to learn:
โ Enforce phishing-resistant MFA
โ Secure device trust
โ Protect identity from onboarding to recovery
๐ Register now โ https://thehackernews.com/2025/04/free-webinar-guide-to-securing-your.html
๐ฅ20๐9๐1๐ฑ1
๐จ SonicWall SMA Devices Under Attack!
2 critical flaws (CVEs 2023-44221 & 2024-38475) are being actively exploited in the wild. One allows OS command injection, the other enables session hijacking via Apache rewrite abuse.
SonicWall urges admins:
๐ Check for unauthorized logins
๐ก๏ธ Patch immediately
๐ Details: https://thehackernews.com/2025/05/sonicwall-confirms-active-exploitation.html
2 critical flaws (CVEs 2023-44221 & 2024-38475) are being actively exploited in the wild. One allows OS command injection, the other enables session hijacking via Apache rewrite abuse.
SonicWall urges admins:
๐ Check for unauthorized logins
๐ก๏ธ Patch immediately
๐ Details: https://thehackernews.com/2025/05/sonicwall-confirms-active-exploitation.html
๐8๐4๐1
๐จ UPDATE: Outlaw Botnet Returns After 3-Month Silence ๐
Kaspersky confirms: Outlaw, a Perl-based crypto-mining botnet, is backโtargeting Linux systems in Brazil with brute-force SSH attacks.
๐งช New tactics spotted:
Deploys XMRig miner & IRC-based backdoor
Kills rival miners & high-CPU processes
Masquerades as rsync, evades termination
Allows DDoS, remote control, file exfiltration
๐ Victims detected in ๐บ๐ธ๐ง๐ท๐ฉ๐ช๐ฎ๐น๐น๐ญ๐ธ๐ฌ๐น๐ผ๐จ๐ฆ
๐ Full report + latest update (May 1): https://thehackernews.com/2025/04/outlaw-group-uses-ssh-brute-force-to.html
Kaspersky confirms: Outlaw, a Perl-based crypto-mining botnet, is backโtargeting Linux systems in Brazil with brute-force SSH attacks.
๐งช New tactics spotted:
Deploys XMRig miner & IRC-based backdoor
Kills rival miners & high-CPU processes
Masquerades as rsync, evades termination
Allows DDoS, remote control, file exfiltration
๐ Victims detected in ๐บ๐ธ๐ง๐ท๐ฉ๐ช๐ฎ๐น๐น๐ญ๐ธ๐ฌ๐น๐ผ๐จ๐ฆ
๐ Full report + latest update (May 1): https://thehackernews.com/2025/04/outlaw-group-uses-ssh-brute-force-to.html
๐ค10๐4
๐ The tools are evolving. So is the intent.
A stealthy phishing wave is slamming key Russian industries with DarkWatchman malware. It evades detection and vanishes on command.
Meanwhile, a new backdoor called Sheriff breached a major Ukrainian platform to spy on defense targetsโquiet, persistent, and dangerous.
๐ Learn more: https://thehackernews.com/2025/05/darkwatchman-sheriff-malware-hit-russia.html
A stealthy phishing wave is slamming key Russian industries with DarkWatchman malware. It evades detection and vanishes on command.
Meanwhile, a new backdoor called Sheriff breached a major Ukrainian platform to spy on defense targetsโquiet, persistent, and dangerous.
๐ Learn more: https://thehackernews.com/2025/05/darkwatchman-sheriff-malware-hit-russia.html
๐ค11๐8๐ฅ3๐1
๐จ AI meets Influence-as-a-Service with chilling implications.
Anthropic's Claude chatbot was hijacked to run a botnet that:
โข Created 100+ fake personas
โข Engaged thousands of users
โข Spread pro-UAE, anti-EU, and political propaganda in ๐ฎ๐ท, ๐ช๐บ, ๐ฐ๐ช
Worse, it aided criminals in writing malware, scraping security cam passwords, and running job scams.
๐ Read: https://thehackernews.com/2025/05/claude-ai-exploited-to-operate-100-fake.html
Anthropic's Claude chatbot was hijacked to run a botnet that:
โข Created 100+ fake personas
โข Engaged thousands of users
โข Spread pro-UAE, anti-EU, and political propaganda in ๐ฎ๐ท, ๐ช๐บ, ๐ฐ๐ช
Worse, it aided criminals in writing malware, scraping security cam passwords, and running job scams.
๐ Read: https://thehackernews.com/2025/05/claude-ai-exploited-to-operate-100-fake.html
๐12๐2