The Hacker News
โœ”
151K subscribers
1.86K photos
10 videos
3 files
7.78K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: [email protected]

๐ŸŒ Website: https://thehackernews.com
Download Telegram
๐Ÿ”ฅ Privacy vs AI?

WhatsApp just dropped Private Processingโ€”letting you use AI features like message summaries without Meta (or anyone) seeing your chats.

๐Ÿ›ก๏ธ Encrypted. Auditable. Anonymous.

โ€” Confidential Virtual Machine
โ€” Oblivious HTTP
โ€” Forward Security

๐Ÿ”— Learn how it works: https://thehackernews.com/2025/04/whatsapp-launches-private-processing-to.html
๐Ÿค”23๐Ÿ‘11๐Ÿ˜9โšก1
๐Ÿšจ Proton Mail faces nationwide ban in India ๐Ÿ‡ฎ๐Ÿ‡ณ

Karnataka High Court has ordered the govโ€™t to block the encrypted email provider after a legal complaint tied to AI deepfakes and obscene messages sent via the platform.

๐Ÿ”’ Still accessibleโ€”for now.

Read: https://thehackernews.com/2025/04/indian-court-orders-action-to-block.html
๐Ÿ˜33๐Ÿ˜ฑ19๐Ÿ‘6๐Ÿค”5๐Ÿ‘3๐Ÿคฏ3
๐Ÿ”ฅ Meta just dropped a firewall for AI.

LlamaFirewall is open-sourceโ€”and built to stop jailbreaks, prompt injections, and insecure code in real time.

Itโ€™s modular. Itโ€™s fast. Itโ€™s made for the LLM era.

๐Ÿ›ก๏ธ Also out:
๐Ÿ”น CyberSecEval 4 with AutoPatchBench to test AI-powered vuln fixes
๐Ÿ”น Llama for Defenders to help fight scams, fraud & phishing
๐Ÿ”น Private Processing to run AI features without leaking user data

๐Ÿ”— Full details here: https://thehackernews.com/2025/04/meta-launches-llamafirewall-framework.html
๐Ÿ‘27๐Ÿ”ฅ7๐Ÿ˜5๐Ÿค”4๐Ÿ‘3๐Ÿ˜ฑ1
๐Ÿšจ RansomHub's empire just vanished.

After stealing data from 200+ victims, its dark web site mysteriously went offline on April 1, 2025โ€”triggering panic among affiliates.

Qilin's leaks doubled. DragonForce claims a takeover.

๐Ÿ”— Read More: https://thehackernews.com/2025/04/ransomhub-went-dark-april-1-affiliates.html
๐Ÿ‘11๐Ÿ˜5
๐Ÿšจ China-linked APT โ€œTheWizardsโ€ caught hijacking trusted Chinese apps to deploy malware updates.

Uses IPv6/DNS to turn Sogou Pinyin & Tencent QQ into WizardNet backdoor delivery for users in ๐Ÿ‡จ๐Ÿ‡ณ๐Ÿ‡ญ๐Ÿ‡ฐ๐Ÿ‡ฐ๐Ÿ‡ญ๐Ÿ‡ต๐Ÿ‡ญ๐Ÿ‡ฆ๐Ÿ‡ช.

๐Ÿ‘€ Their tool Spellbinder quietly captures traffic, reroutes updates to attacker servers.

๐Ÿ”— Full story: https://thehackernews.com/2025/04/chinese-hackers-abuse-ipv6-slaac-for.html
๐Ÿ”ฅ8๐Ÿ‘5๐Ÿ˜4
๐Ÿ‘€ โ€œAll my shows were in Spanish. I didnโ€™t change anything.โ€

Thatโ€™s not a glitchโ€”itโ€™s an account takeover.

๐Ÿ”’ 100K+ accounts/mo exposed on major platforms.
๐ŸŽฎ Streaming, gaming, SaaS vulnerable.
๐Ÿง  MFA fails vs. stolen session cookies.

Act now: Monitor infostealers. Reset risk. Rebuild trust.

๐Ÿ”— ReadfFull story + Flareโ€™s ATO report: https://thehackernews.com/2025/04/customer-account-takeovers-multi.html
๐Ÿ‘7๐Ÿคฏ3
๐Ÿšจ New Espionage Alert!

A Russian-speaking APT group, Nebulous Mantis, is deploying the stealthy RomCom RAT to target NATO-linked entities, gov agencies, and critical infra โ€” using bulletproof hosting, IPFS, and over 40 remote commands.

๐Ÿ”— See how it works, whoโ€™s behind it, and why it matters now: https://thehackernews.com/2025/04/nebulous-mantis-targets-nato-linked.html
๐Ÿ‘14๐Ÿ˜6
Itโ€™s back! XPOSURE 2025 returns for its fourth year, focused on what matters most: reducing cyber risk exposure.

Join Pentera and top cybersecurity leaders at the National Exposure Management vSummit to discover how leading security teams are taking a proactive approach to managing enterprise-wide exposure.

๐ŸŽ Bonus: The first 150 registrants will receive an Uber Eats voucher upon registration!

๐Ÿ“… June 18 | 11 AM ET | Virtual

๐Ÿ”— Register now: https://thn.news/xposure2025-pentera

#XPOSURE2025 #ExposureManagement #CyberSecurityLeadership #EnterpriseSecurity
๐Ÿ‘10๐Ÿ˜4๐Ÿ”ฅ1
This media is not supported in your browser
VIEW IN TELEGRAM
๐Ÿšจ AI tools are learning too fastโ€”and so are attackers.

New report reveals how MCP & A2A protocols can be hijacked to leak emails, spoof agents, and silently override tool logic.

๐Ÿ” Tool poisoning
๐Ÿง  Prompt injection
๐Ÿ•ต๏ธ Agent impersonation

Even benign tools can flip maliciousโ€”no warning, no second prompt.

๐Ÿ‘‰ Learn about this new AI attack surface โ†’ https://thehackernews.com/2025/04/experts-uncover-critical-mcp-and-a2a.html
๐Ÿ‘15
๐Ÿ‘ค Hackers arenโ€™t cracking passwords anymoreโ€”theyโ€™re impersonating you.

From AI deepfakes to social engineering, attackers now exploit weak links before and after loginโ€”like during account recovery or onboarding.

๐Ÿ” Orgs secure login, but not full identity lifecycle. Join free webinar to learn:

โœ… Enforce phishing-resistant MFA
โœ… Secure device trust
โœ… Protect identity from onboarding to recovery

๐Ÿ‘‰ Register now โ€” https://thehackernews.com/2025/04/free-webinar-guide-to-securing-your.html
๐Ÿ”ฅ20๐Ÿ‘9๐Ÿ˜1๐Ÿ˜ฑ1
๐Ÿšจ SonicWall SMA Devices Under Attack!

2 critical flaws (CVEs 2023-44221 & 2024-38475) are being actively exploited in the wild. One allows OS command injection, the other enables session hijacking via Apache rewrite abuse.

SonicWall urges admins:
๐Ÿ” Check for unauthorized logins
๐Ÿ›ก๏ธ Patch immediately

๐Ÿ‘‰ Details: https://thehackernews.com/2025/05/sonicwall-confirms-active-exploitation.html
๐Ÿ˜8๐Ÿ‘4๐Ÿ‘1
๐Ÿšจ UPDATE: Outlaw Botnet Returns After 3-Month Silence ๐Ÿ‘€

Kaspersky confirms: Outlaw, a Perl-based crypto-mining botnet, is backโ€”targeting Linux systems in Brazil with brute-force SSH attacks.

๐Ÿงช New tactics spotted:
Deploys XMRig miner & IRC-based backdoor
Kills rival miners & high-CPU processes
Masquerades as rsync, evades termination
Allows DDoS, remote control, file exfiltration

๐Ÿ“Š Victims detected in ๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡ง๐Ÿ‡ท๐Ÿ‡ฉ๐Ÿ‡ช๐Ÿ‡ฎ๐Ÿ‡น๐Ÿ‡น๐Ÿ‡ญ๐Ÿ‡ธ๐Ÿ‡ฌ๐Ÿ‡น๐Ÿ‡ผ๐Ÿ‡จ๐Ÿ‡ฆ

๐Ÿ‘‰ Full report + latest update (May 1): https://thehackernews.com/2025/04/outlaw-group-uses-ssh-brute-force-to.html
๐Ÿค”10๐Ÿ‘4
๐Ÿ‘€ The tools are evolving. So is the intent.

A stealthy phishing wave is slamming key Russian industries with DarkWatchman malware. It evades detection and vanishes on command.

Meanwhile, a new backdoor called Sheriff breached a major Ukrainian platform to spy on defense targetsโ€”quiet, persistent, and dangerous.

๐Ÿ”— Learn more: https://thehackernews.com/2025/05/darkwatchman-sheriff-malware-hit-russia.html
๐Ÿค”11๐Ÿ‘8๐Ÿ”ฅ3๐Ÿ‘1
๐Ÿšจ AI meets Influence-as-a-Service with chilling implications.

Anthropic's Claude chatbot was hijacked to run a botnet that:

โ€ข Created 100+ fake personas
โ€ข Engaged thousands of users
โ€ข Spread pro-UAE, anti-EU, and political propaganda in ๐Ÿ‡ฎ๐Ÿ‡ท, ๐Ÿ‡ช๐Ÿ‡บ, ๐Ÿ‡ฐ๐Ÿ‡ช

Worse, it aided criminals in writing malware, scraping security cam passwords, and running job scams.

๐Ÿ”— Read: https://thehackernews.com/2025/05/claude-ai-exploited-to-operate-100-fake.html
๐Ÿ‘12๐Ÿ‘2
๐Ÿšจ 569,000 alerts. Only 202 matter.

OX Securityโ€™s 2025 report reveals: 95โ€“98% of AppSec alerts are noiseโ€”wasting time, burning budgets, and stalling innovation.

๐Ÿ” Focus on whatโ€™s realโ€”KEVs, secrets, exploitable flaws.

Learn How: https://thehackernews.com/2025/05/new-research-reveals-95-of-appsec-fixes.html
๐Ÿ‘10๐Ÿ”ฅ3
๐Ÿ›‘ Nation-state hackers breached Commvaultโ€™s Azure-hosted environment by exploiting a zero-day in Commvaultโ€™s own web server โ€” CVE-2025-3928.

๐Ÿ‘€ Check sign-ins
๐Ÿšซ Block malicious IPs
๐Ÿ“‘ Report activity fast

Read now โ†’ https://thehackernews.com/2025/05/commvault-confirms-hackers-exploited.html
๐Ÿค”9๐Ÿ‘1
๐Ÿšจ Your tools say you're safe. Attackers know you're not.

They slip past EDR, hide in legit traffic, and lurk for weeks.

Thatโ€™s why SOC teams are turning to Network Detection & Response (NDR)โ€”the only way to see what endpoint tools miss.

The network doesnโ€™t lie.

Learn more: https://thehackernews.com/2025/05/why-top-soc-teams-are-shifting-to.html
โšก8๐Ÿ‘6๐Ÿคฏ4๐Ÿ”ฅ2
๐Ÿ›‘ Hackers are disguising malware as security plugins to hijack sites, inject spammy ads, steal credit cards, & even re-install themselves if deleted.

Some victims are unknowingly losing their own AdSense earnings.

๐Ÿ’ฃ Features: Remote code execution, reverse proxy skimming, JS-based backdoors.

๐Ÿ”— Read: https://thehackernews.com/2025/05/fake-security-plugin-on-wordpress.html
๐Ÿ‘20๐Ÿ‘6๐Ÿ˜ฑ2โšก1๐Ÿคฏ1
๐Ÿšจ AI isnโ€™t just writing your code โ€” itโ€™s leaking your secrets.

New GitGuardian data shows AI-assisted repos leak secrets 40% more often than average.

๐Ÿ“Š 1,200+ repos leaked secrets in 2025 alone.

๐Ÿ‘‰ Donโ€™t trust. Verify. Full report: https://thehackernews.com/expert-insights/2025/04/the-new-frontier-of-security-risk-ai.html
๐Ÿ˜12โšก3๐Ÿ”ฅ2๐Ÿ‘1
๐Ÿ”ฅ UPDATE - A public PoC exploit is now available for a serious SonicWall SMA exploit chain.

โžก๏ธ CVE-2024-38475: Apache HTTP Server flaw used to bypass auth
โžก๏ธ CVE-2023-44221: Post-auth command injection via Diagnostics menu

CISA has added both to the KEV catalog โ€” federal patch deadline: May 22, 2025.
Exploitation is already active in the wild.

๐Ÿ“Ž Details + PoC: https://thehackernews.com/2025/05/sonicwall-confirms-active-exploitation.html
๐Ÿ‘16๐Ÿ˜ฑ1