๐จ UPDATE: Outlaw Botnet Returns After 3-Month Silence ๐
Kaspersky confirms: Outlaw, a Perl-based crypto-mining botnet, is backโtargeting Linux systems in Brazil with brute-force SSH attacks.
๐งช New tactics spotted:
Deploys XMRig miner & IRC-based backdoor
Kills rival miners & high-CPU processes
Masquerades as rsync, evades termination
Allows DDoS, remote control, file exfiltration
๐ Victims detected in ๐บ๐ธ๐ง๐ท๐ฉ๐ช๐ฎ๐น๐น๐ญ๐ธ๐ฌ๐น๐ผ๐จ๐ฆ
๐ Full report + latest update (May 1): https://thehackernews.com/2025/04/outlaw-group-uses-ssh-brute-force-to.html
Kaspersky confirms: Outlaw, a Perl-based crypto-mining botnet, is backโtargeting Linux systems in Brazil with brute-force SSH attacks.
๐งช New tactics spotted:
Deploys XMRig miner & IRC-based backdoor
Kills rival miners & high-CPU processes
Masquerades as rsync, evades termination
Allows DDoS, remote control, file exfiltration
๐ Victims detected in ๐บ๐ธ๐ง๐ท๐ฉ๐ช๐ฎ๐น๐น๐ญ๐ธ๐ฌ๐น๐ผ๐จ๐ฆ
๐ Full report + latest update (May 1): https://thehackernews.com/2025/04/outlaw-group-uses-ssh-brute-force-to.html
๐ค10๐4
๐ The tools are evolving. So is the intent.
A stealthy phishing wave is slamming key Russian industries with DarkWatchman malware. It evades detection and vanishes on command.
Meanwhile, a new backdoor called Sheriff breached a major Ukrainian platform to spy on defense targetsโquiet, persistent, and dangerous.
๐ Learn more: https://thehackernews.com/2025/05/darkwatchman-sheriff-malware-hit-russia.html
A stealthy phishing wave is slamming key Russian industries with DarkWatchman malware. It evades detection and vanishes on command.
Meanwhile, a new backdoor called Sheriff breached a major Ukrainian platform to spy on defense targetsโquiet, persistent, and dangerous.
๐ Learn more: https://thehackernews.com/2025/05/darkwatchman-sheriff-malware-hit-russia.html
๐ค11๐8๐ฅ3๐1
๐จ AI meets Influence-as-a-Service with chilling implications.
Anthropic's Claude chatbot was hijacked to run a botnet that:
โข Created 100+ fake personas
โข Engaged thousands of users
โข Spread pro-UAE, anti-EU, and political propaganda in ๐ฎ๐ท, ๐ช๐บ, ๐ฐ๐ช
Worse, it aided criminals in writing malware, scraping security cam passwords, and running job scams.
๐ Read: https://thehackernews.com/2025/05/claude-ai-exploited-to-operate-100-fake.html
Anthropic's Claude chatbot was hijacked to run a botnet that:
โข Created 100+ fake personas
โข Engaged thousands of users
โข Spread pro-UAE, anti-EU, and political propaganda in ๐ฎ๐ท, ๐ช๐บ, ๐ฐ๐ช
Worse, it aided criminals in writing malware, scraping security cam passwords, and running job scams.
๐ Read: https://thehackernews.com/2025/05/claude-ai-exploited-to-operate-100-fake.html
๐12๐2
๐จ 569,000 alerts. Only 202 matter.
OX Securityโs 2025 report reveals: 95โ98% of AppSec alerts are noiseโwasting time, burning budgets, and stalling innovation.
๐ Focus on whatโs realโKEVs, secrets, exploitable flaws.
Learn How: https://thehackernews.com/2025/05/new-research-reveals-95-of-appsec-fixes.html
OX Securityโs 2025 report reveals: 95โ98% of AppSec alerts are noiseโwasting time, burning budgets, and stalling innovation.
๐ Focus on whatโs realโKEVs, secrets, exploitable flaws.
Learn How: https://thehackernews.com/2025/05/new-research-reveals-95-of-appsec-fixes.html
๐10๐ฅ3
๐ Nation-state hackers breached Commvaultโs Azure-hosted environment by exploiting a zero-day in Commvaultโs own web server โ CVE-2025-3928.
๐ Check sign-ins
๐ซ Block malicious IPs
๐ Report activity fast
Read now โ https://thehackernews.com/2025/05/commvault-confirms-hackers-exploited.html
๐ Check sign-ins
๐ซ Block malicious IPs
๐ Report activity fast
Read now โ https://thehackernews.com/2025/05/commvault-confirms-hackers-exploited.html
๐ค9๐1
๐จ Your tools say you're safe. Attackers know you're not.
They slip past EDR, hide in legit traffic, and lurk for weeks.
Thatโs why SOC teams are turning to Network Detection & Response (NDR)โthe only way to see what endpoint tools miss.
The network doesnโt lie.
Learn more: https://thehackernews.com/2025/05/why-top-soc-teams-are-shifting-to.html
They slip past EDR, hide in legit traffic, and lurk for weeks.
Thatโs why SOC teams are turning to Network Detection & Response (NDR)โthe only way to see what endpoint tools miss.
The network doesnโt lie.
Learn more: https://thehackernews.com/2025/05/why-top-soc-teams-are-shifting-to.html
โก8๐6๐คฏ4๐ฅ2
๐ Hackers are disguising malware as security plugins to hijack sites, inject spammy ads, steal credit cards, & even re-install themselves if deleted.
Some victims are unknowingly losing their own AdSense earnings.
๐ฃ Features: Remote code execution, reverse proxy skimming, JS-based backdoors.
๐ Read: https://thehackernews.com/2025/05/fake-security-plugin-on-wordpress.html
Some victims are unknowingly losing their own AdSense earnings.
๐ฃ Features: Remote code execution, reverse proxy skimming, JS-based backdoors.
๐ Read: https://thehackernews.com/2025/05/fake-security-plugin-on-wordpress.html
๐20๐6๐ฑ2โก1๐คฏ1
๐จ AI isnโt just writing your code โ itโs leaking your secrets.
New GitGuardian data shows AI-assisted repos leak secrets 40% more often than average.
๐ 1,200+ repos leaked secrets in 2025 alone.
๐ Donโt trust. Verify. Full report: https://thehackernews.com/expert-insights/2025/04/the-new-frontier-of-security-risk-ai.html
New GitGuardian data shows AI-assisted repos leak secrets 40% more often than average.
๐ 1,200+ repos leaked secrets in 2025 alone.
๐ Donโt trust. Verify. Full report: https://thehackernews.com/expert-insights/2025/04/the-new-frontier-of-security-risk-ai.html
๐12โก3๐ฅ2๐1
๐ฅ UPDATE - A public PoC exploit is now available for a serious SonicWall SMA exploit chain.
โก๏ธ CVE-2024-38475: Apache HTTP Server flaw used to bypass auth
โก๏ธ CVE-2023-44221: Post-auth command injection via Diagnostics menu
CISA has added both to the KEV catalog โ federal patch deadline: May 22, 2025.
Exploitation is already active in the wild.
๐ Details + PoC: https://thehackernews.com/2025/05/sonicwall-confirms-active-exploitation.html
โก๏ธ CVE-2024-38475: Apache HTTP Server flaw used to bypass auth
โก๏ธ CVE-2023-44221: Post-auth command injection via Diagnostics menu
CISA has added both to the KEV catalog โ federal patch deadline: May 22, 2025.
Exploitation is already active in the wild.
๐ Details + PoC: https://thehackernews.com/2025/05/sonicwall-confirms-active-exploitation.html
๐16๐ฑ1
๐ Microsoft goes passwordless by default for all new accounts.
No more passwords at sign-upโjust passkeys, using biometrics or device PINs. It's phishing-resistant, backed by FIDO standards.
Existing users? You can remove your password now from settings.
Learn more: https://thehackernews.com/2025/05/microsoft-sets-passkeys-default-for-new.html
No more passwords at sign-upโjust passkeys, using biometrics or device PINs. It's phishing-resistant, backed by FIDO standards.
Existing users? You can remove your password now from settings.
Learn more: https://thehackernews.com/2025/05/microsoft-sets-passkeys-default-for-new.html
๐32๐ฑ16๐ฅ8๐ค7โก6
๐ฅ Automate the chaos. Stay ahead of CVEs.
LivePerson slashed vuln ticketing time by 60% using a free Tines workflow that:
โ Auto-pulls CISA alerts
โ Enriches with CrowdStrike
โ Sends Slack buttons
โ Creates ServiceNow tickets
No manual tracking. No delays. Just speed.
๐ See how your team can do it too: https://thehackernews.com/2025/05/how-to-automate-cve-and-vulnerability.html
LivePerson slashed vuln ticketing time by 60% using a free Tines workflow that:
โ Auto-pulls CISA alerts
โ Enriches with CrowdStrike
โ Sends Slack buttons
โ Creates ServiceNow tickets
No manual tracking. No delays. Just speed.
๐ See how your team can do it too: https://thehackernews.com/2025/05/how-to-automate-cve-and-vulnerability.html
๐17๐4๐ค1
๐จ TikTok Fined โฌ530M for secretly storing EU user data in China, violating GDPR rules.
๐ช๐บ Irelandโs DPC says TikTok misled regulators, failed to ensure EU-level privacy, and ignored Chinaโs surveillance risks.
They now have 6 months to stop transfers.
๐ Read more: https://thehackernews.com/2025/05/tiktok-slammed-with-530-million-gdpr.html
๐ Second major GDPR fine after a โฌ345M penalty in 2023.
๐ช๐บ Irelandโs DPC says TikTok misled regulators, failed to ensure EU-level privacy, and ignored Chinaโs surveillance risks.
They now have 6 months to stop transfers.
๐ Read more: https://thehackernews.com/2025/05/tiktok-slammed-with-530-million-gdpr.html
๐ Second major GDPR fine after a โฌ345M penalty in 2023.
๐40๐24๐ฑ11๐คฏ7๐5๐ฅ2
๐จ U.S. charges Yemeni national with deploying Black Kingdom ransomware on 1,500+ systemsโfrom hospitals to schoolsโvia Microsoft ProxyLogon.
๐ฅ Targets paid in Bitcoin.
๐ Read more: https://thehackernews.com/2025/05/us-charges-yemeni-hacker-behind-black.html
๐ฅ Targets paid in Bitcoin.
๐ Read more: https://thehackernews.com/2025/05/us-charges-yemeni-hacker-behind-black.html
๐31๐7๐4๐ค4โก1
๐ฅ Two years inside. Nation-state footprints. Critical infrastructure targeted.
Fortinet links Iranian APT Lemon Sandstorm to a stealthy attack on a Middle East CNI (May '23โFeb '25).
Used VPN exploits, chained proxies, 7 custom backdoors across 4 phases.
Read this story โก๏ธ https://thehackernews.com/2025/05/iranian-hackers-maintain-2-year-access.html
Fortinet links Iranian APT Lemon Sandstorm to a stealthy attack on a Middle East CNI (May '23โFeb '25).
Used VPN exploits, chained proxies, 7 custom backdoors across 4 phases.
Read this story โก๏ธ https://thehackernews.com/2025/05/iranian-hackers-maintain-2-year-access.html
๐12๐10โก5๐ฅ4
๐จ Malicious Go modules are nuking Linux systemsโwiping entire disks beyond recovery using hidden payloads.
๐งจ 3 GitHub-hosted packages posed as dev tools. Once run on Linux, they downloaded a script to overwrite /dev/sdaโkilling the OS.
At the same time, npm & PyPI malware is:
| ๐ช Stealing crypto keys
| ๐ง Using Gmail to exfiltrate data
| ๐ Hiding via WebSockets
๐ Over 75,000+ downloads so far.
Read โ https://thehackernews.com/2025/05/malicious-go-modules-deliver-disk.html
๐งจ 3 GitHub-hosted packages posed as dev tools. Once run on Linux, they downloaded a script to overwrite /dev/sdaโkilling the OS.
At the same time, npm & PyPI malware is:
| ๐ช Stealing crypto keys
| ๐ง Using Gmail to exfiltrate data
| ๐ Hiding via WebSockets
๐ Over 75,000+ downloads so far.
Read โ https://thehackernews.com/2025/05/malicious-go-modules-deliver-disk.html
๐ฑ29๐16๐ค12๐คฏ8๐6โก3๐ฅ1
๐จ New malware drop from Golden Chickens: TerraStealerV2 steals browser logins, crypto wallets, and extensions, while TerraLogger silently records keystrokes.
๐ฆ Spread via EXE, MSI, LNK, OCX
๐ค Sends data to Telegram + shady domain
๐ Read this report: https://thehackernews.com/2025/05/golden-chickens-deploy-terrastealerv2.html
๐ฆ Spread via EXE, MSI, LNK, OCX
๐ค Sends data to Telegram + shady domain
๐ Read this report: https://thehackernews.com/2025/05/golden-chickens-deploy-terrastealerv2.html
๐25โก3๐1๐คฏ1
๐จ Youโre not running a security team. You're the security team.
One inbox. One admin panel. A hundred fire drills. Google Workspace helpsโbut attackers slip through the cracks.
๐ Identity is the new perimeter.
๐ MFA, context-aware access, DLPโstart there.
๐ ๏ธ Then, monitor, review, remediate.
You donโt need perfection. You need visibility and control.
See how it works โ https://thehackernews.com/2025/05/perfection-is-myth-leverage-isnt-how.html
One inbox. One admin panel. A hundred fire drills. Google Workspace helpsโbut attackers slip through the cracks.
๐ Identity is the new perimeter.
๐ MFA, context-aware access, DLPโstart there.
๐ ๏ธ Then, monitor, review, remediate.
You donโt need perfection. You need visibility and control.
See how it works โ https://thehackernews.com/2025/05/perfection-is-myth-leverage-isnt-how.html
๐15๐5๐ฅ2
๐จ Zero-click, max impact โ and it's already being exploited.
A critical Commvault bug (CVE-2025-34028, CVSS 10.0) lets hackers upload poisoned ZIPs, leading to full remote code executionโno login needed.
Read: https://thehackernews.com/2025/05/commvault-cve-2025-34028-added-to-cisa.html
Deadline for U.S. agencies: May 23.
A critical Commvault bug (CVE-2025-34028, CVSS 10.0) lets hackers upload poisoned ZIPs, leading to full remote code executionโno login needed.
Read: https://thehackernews.com/2025/05/commvault-cve-2025-34028-added-to-cisa.html
Deadline for U.S. agencies: May 23.
โก13๐5๐1
๐จ Zero-click. Wormable. Network-spreading.
New flaws in Appleโs AirPlay protocol (๐ AirBorne) could let hackers hijack your device without a clickโthen ride your Wi-Fi into corporate networks.
CVE-2025-24252 + CVE-2025-24132 = silent RCE across Macs, TVs, speakers. Just being on the same Wi-Fi can be enough.
๐ Learn more: https://thehackernews.com/2025/05/wormable-airplay-flaws-enable-zero.html
๐ฒ Update all AirPlay-enabled devices nowโpersonal & work.
New flaws in Appleโs AirPlay protocol (๐ AirBorne) could let hackers hijack your device without a clickโthen ride your Wi-Fi into corporate networks.
CVE-2025-24252 + CVE-2025-24132 = silent RCE across Macs, TVs, speakers. Just being on the same Wi-Fi can be enough.
๐ Learn more: https://thehackernews.com/2025/05/wormable-airplay-flaws-enable-zero.html
๐ฒ Update all AirPlay-enabled devices nowโpersonal & work.
๐12๐ฅ4
๐ฅ New Edition Just Dropped!
Cybersecurity Weekly Recap | May 5 โโ From nation-state hacks to deepfake-ready malware, this weekโs intel is packed:
โข Iranian APT lurked 2 yrs in critical infra
โข Claude chatbot abused for political ops
โข TikTok hit with $601M fine over China data
โข 30+ new CVEs to patch now
โข Magento supply chain backdoor activated after 6 yrs
Read the full recap โ https://thehackernews.com/2025/05/weekly-recap-nation-state-hacks-spyware.html
Cybersecurity Weekly Recap | May 5 โโ From nation-state hacks to deepfake-ready malware, this weekโs intel is packed:
โข Iranian APT lurked 2 yrs in critical infra
โข Claude chatbot abused for political ops
โข TikTok hit with $601M fine over China data
โข 30+ new CVEs to patch now
โข Magento supply chain backdoor activated after 6 yrs
Read the full recap โ https://thehackernews.com/2025/05/weekly-recap-nation-state-hacks-spyware.html
๐18โก2๐ฅ1