The Hacker News
โœ”
151K subscribers
1.86K photos
10 videos
3 files
7.78K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: [email protected]

๐ŸŒ Website: https://thehackernews.com
Download Telegram
๐Ÿšจ RansomHub's empire just vanished.

After stealing data from 200+ victims, its dark web site mysteriously went offline on April 1, 2025โ€”triggering panic among affiliates.

Qilin's leaks doubled. DragonForce claims a takeover.

๐Ÿ”— Read More: https://thehackernews.com/2025/04/ransomhub-went-dark-april-1-affiliates.html
๐Ÿ‘11๐Ÿ˜5
๐Ÿšจ China-linked APT โ€œTheWizardsโ€ caught hijacking trusted Chinese apps to deploy malware updates.

Uses IPv6/DNS to turn Sogou Pinyin & Tencent QQ into WizardNet backdoor delivery for users in ๐Ÿ‡จ๐Ÿ‡ณ๐Ÿ‡ญ๐Ÿ‡ฐ๐Ÿ‡ฐ๐Ÿ‡ญ๐Ÿ‡ต๐Ÿ‡ญ๐Ÿ‡ฆ๐Ÿ‡ช.

๐Ÿ‘€ Their tool Spellbinder quietly captures traffic, reroutes updates to attacker servers.

๐Ÿ”— Full story: https://thehackernews.com/2025/04/chinese-hackers-abuse-ipv6-slaac-for.html
๐Ÿ”ฅ8๐Ÿ‘5๐Ÿ˜4
๐Ÿ‘€ โ€œAll my shows were in Spanish. I didnโ€™t change anything.โ€

Thatโ€™s not a glitchโ€”itโ€™s an account takeover.

๐Ÿ”’ 100K+ accounts/mo exposed on major platforms.
๐ŸŽฎ Streaming, gaming, SaaS vulnerable.
๐Ÿง  MFA fails vs. stolen session cookies.

Act now: Monitor infostealers. Reset risk. Rebuild trust.

๐Ÿ”— ReadfFull story + Flareโ€™s ATO report: https://thehackernews.com/2025/04/customer-account-takeovers-multi.html
๐Ÿ‘7๐Ÿคฏ3
๐Ÿšจ New Espionage Alert!

A Russian-speaking APT group, Nebulous Mantis, is deploying the stealthy RomCom RAT to target NATO-linked entities, gov agencies, and critical infra โ€” using bulletproof hosting, IPFS, and over 40 remote commands.

๐Ÿ”— See how it works, whoโ€™s behind it, and why it matters now: https://thehackernews.com/2025/04/nebulous-mantis-targets-nato-linked.html
๐Ÿ‘14๐Ÿ˜6
Itโ€™s back! XPOSURE 2025 returns for its fourth year, focused on what matters most: reducing cyber risk exposure.

Join Pentera and top cybersecurity leaders at the National Exposure Management vSummit to discover how leading security teams are taking a proactive approach to managing enterprise-wide exposure.

๐ŸŽ Bonus: The first 150 registrants will receive an Uber Eats voucher upon registration!

๐Ÿ“… June 18 | 11 AM ET | Virtual

๐Ÿ”— Register now: https://thn.news/xposure2025-pentera

#XPOSURE2025 #ExposureManagement #CyberSecurityLeadership #EnterpriseSecurity
๐Ÿ‘10๐Ÿ˜4๐Ÿ”ฅ1
This media is not supported in your browser
VIEW IN TELEGRAM
๐Ÿšจ AI tools are learning too fastโ€”and so are attackers.

New report reveals how MCP & A2A protocols can be hijacked to leak emails, spoof agents, and silently override tool logic.

๐Ÿ” Tool poisoning
๐Ÿง  Prompt injection
๐Ÿ•ต๏ธ Agent impersonation

Even benign tools can flip maliciousโ€”no warning, no second prompt.

๐Ÿ‘‰ Learn about this new AI attack surface โ†’ https://thehackernews.com/2025/04/experts-uncover-critical-mcp-and-a2a.html
๐Ÿ‘15
๐Ÿ‘ค Hackers arenโ€™t cracking passwords anymoreโ€”theyโ€™re impersonating you.

From AI deepfakes to social engineering, attackers now exploit weak links before and after loginโ€”like during account recovery or onboarding.

๐Ÿ” Orgs secure login, but not full identity lifecycle. Join free webinar to learn:

โœ… Enforce phishing-resistant MFA
โœ… Secure device trust
โœ… Protect identity from onboarding to recovery

๐Ÿ‘‰ Register now โ€” https://thehackernews.com/2025/04/free-webinar-guide-to-securing-your.html
๐Ÿ”ฅ20๐Ÿ‘9๐Ÿ˜1๐Ÿ˜ฑ1
๐Ÿšจ SonicWall SMA Devices Under Attack!

2 critical flaws (CVEs 2023-44221 & 2024-38475) are being actively exploited in the wild. One allows OS command injection, the other enables session hijacking via Apache rewrite abuse.

SonicWall urges admins:
๐Ÿ” Check for unauthorized logins
๐Ÿ›ก๏ธ Patch immediately

๐Ÿ‘‰ Details: https://thehackernews.com/2025/05/sonicwall-confirms-active-exploitation.html
๐Ÿ˜8๐Ÿ‘4๐Ÿ‘1
๐Ÿšจ UPDATE: Outlaw Botnet Returns After 3-Month Silence ๐Ÿ‘€

Kaspersky confirms: Outlaw, a Perl-based crypto-mining botnet, is backโ€”targeting Linux systems in Brazil with brute-force SSH attacks.

๐Ÿงช New tactics spotted:
Deploys XMRig miner & IRC-based backdoor
Kills rival miners & high-CPU processes
Masquerades as rsync, evades termination
Allows DDoS, remote control, file exfiltration

๐Ÿ“Š Victims detected in ๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡ง๐Ÿ‡ท๐Ÿ‡ฉ๐Ÿ‡ช๐Ÿ‡ฎ๐Ÿ‡น๐Ÿ‡น๐Ÿ‡ญ๐Ÿ‡ธ๐Ÿ‡ฌ๐Ÿ‡น๐Ÿ‡ผ๐Ÿ‡จ๐Ÿ‡ฆ

๐Ÿ‘‰ Full report + latest update (May 1): https://thehackernews.com/2025/04/outlaw-group-uses-ssh-brute-force-to.html
๐Ÿค”10๐Ÿ‘4
๐Ÿ‘€ The tools are evolving. So is the intent.

A stealthy phishing wave is slamming key Russian industries with DarkWatchman malware. It evades detection and vanishes on command.

Meanwhile, a new backdoor called Sheriff breached a major Ukrainian platform to spy on defense targetsโ€”quiet, persistent, and dangerous.

๐Ÿ”— Learn more: https://thehackernews.com/2025/05/darkwatchman-sheriff-malware-hit-russia.html
๐Ÿค”11๐Ÿ‘8๐Ÿ”ฅ3๐Ÿ‘1
๐Ÿšจ AI meets Influence-as-a-Service with chilling implications.

Anthropic's Claude chatbot was hijacked to run a botnet that:

โ€ข Created 100+ fake personas
โ€ข Engaged thousands of users
โ€ข Spread pro-UAE, anti-EU, and political propaganda in ๐Ÿ‡ฎ๐Ÿ‡ท, ๐Ÿ‡ช๐Ÿ‡บ, ๐Ÿ‡ฐ๐Ÿ‡ช

Worse, it aided criminals in writing malware, scraping security cam passwords, and running job scams.

๐Ÿ”— Read: https://thehackernews.com/2025/05/claude-ai-exploited-to-operate-100-fake.html
๐Ÿ‘12๐Ÿ‘2
๐Ÿšจ 569,000 alerts. Only 202 matter.

OX Securityโ€™s 2025 report reveals: 95โ€“98% of AppSec alerts are noiseโ€”wasting time, burning budgets, and stalling innovation.

๐Ÿ” Focus on whatโ€™s realโ€”KEVs, secrets, exploitable flaws.

Learn How: https://thehackernews.com/2025/05/new-research-reveals-95-of-appsec-fixes.html
๐Ÿ‘10๐Ÿ”ฅ3
๐Ÿ›‘ Nation-state hackers breached Commvaultโ€™s Azure-hosted environment by exploiting a zero-day in Commvaultโ€™s own web server โ€” CVE-2025-3928.

๐Ÿ‘€ Check sign-ins
๐Ÿšซ Block malicious IPs
๐Ÿ“‘ Report activity fast

Read now โ†’ https://thehackernews.com/2025/05/commvault-confirms-hackers-exploited.html
๐Ÿค”9๐Ÿ‘1
๐Ÿšจ Your tools say you're safe. Attackers know you're not.

They slip past EDR, hide in legit traffic, and lurk for weeks.

Thatโ€™s why SOC teams are turning to Network Detection & Response (NDR)โ€”the only way to see what endpoint tools miss.

The network doesnโ€™t lie.

Learn more: https://thehackernews.com/2025/05/why-top-soc-teams-are-shifting-to.html
โšก8๐Ÿ‘6๐Ÿคฏ4๐Ÿ”ฅ2
๐Ÿ›‘ Hackers are disguising malware as security plugins to hijack sites, inject spammy ads, steal credit cards, & even re-install themselves if deleted.

Some victims are unknowingly losing their own AdSense earnings.

๐Ÿ’ฃ Features: Remote code execution, reverse proxy skimming, JS-based backdoors.

๐Ÿ”— Read: https://thehackernews.com/2025/05/fake-security-plugin-on-wordpress.html
๐Ÿ‘20๐Ÿ‘6๐Ÿ˜ฑ2โšก1๐Ÿคฏ1
๐Ÿšจ AI isnโ€™t just writing your code โ€” itโ€™s leaking your secrets.

New GitGuardian data shows AI-assisted repos leak secrets 40% more often than average.

๐Ÿ“Š 1,200+ repos leaked secrets in 2025 alone.

๐Ÿ‘‰ Donโ€™t trust. Verify. Full report: https://thehackernews.com/expert-insights/2025/04/the-new-frontier-of-security-risk-ai.html
๐Ÿ˜12โšก3๐Ÿ”ฅ2๐Ÿ‘1
๐Ÿ”ฅ UPDATE - A public PoC exploit is now available for a serious SonicWall SMA exploit chain.

โžก๏ธ CVE-2024-38475: Apache HTTP Server flaw used to bypass auth
โžก๏ธ CVE-2023-44221: Post-auth command injection via Diagnostics menu

CISA has added both to the KEV catalog โ€” federal patch deadline: May 22, 2025.
Exploitation is already active in the wild.

๐Ÿ“Ž Details + PoC: https://thehackernews.com/2025/05/sonicwall-confirms-active-exploitation.html
๐Ÿ‘16๐Ÿ˜ฑ1
๐Ÿ” Microsoft goes passwordless by default for all new accounts.

No more passwords at sign-upโ€”just passkeys, using biometrics or device PINs. It's phishing-resistant, backed by FIDO standards.

Existing users? You can remove your password now from settings.

Learn more: https://thehackernews.com/2025/05/microsoft-sets-passkeys-default-for-new.html
๐Ÿ‘32๐Ÿ˜ฑ16๐Ÿ”ฅ8๐Ÿค”7โšก6
๐Ÿ”ฅ Automate the chaos. Stay ahead of CVEs.

LivePerson slashed vuln ticketing time by 60% using a free Tines workflow that:

โ†’ Auto-pulls CISA alerts
โ†’ Enriches with CrowdStrike
โ†’ Sends Slack buttons
โ†’ Creates ServiceNow tickets

No manual tracking. No delays. Just speed.

๐Ÿ‘€ See how your team can do it too: https://thehackernews.com/2025/05/how-to-automate-cve-and-vulnerability.html
๐Ÿ‘17๐Ÿ‘4๐Ÿค”1
๐Ÿšจ TikTok Fined โ‚ฌ530M for secretly storing EU user data in China, violating GDPR rules.

๐Ÿ‡ช๐Ÿ‡บ Irelandโ€™s DPC says TikTok misled regulators, failed to ensure EU-level privacy, and ignored Chinaโ€™s surveillance risks.

They now have 6 months to stop transfers.

๐Ÿ”— Read more: https://thehackernews.com/2025/05/tiktok-slammed-with-530-million-gdpr.html

๐Ÿ“‰ Second major GDPR fine after a โ‚ฌ345M penalty in 2023.
๐Ÿ‘40๐Ÿ˜24๐Ÿ˜ฑ11๐Ÿคฏ7๐Ÿ‘5๐Ÿ”ฅ2