The Hacker News
โœ”
151K subscribers
1.86K photos
10 videos
3 files
7.77K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: [email protected]

๐ŸŒ Website: https://thehackernews.com
Download Telegram
๐Ÿšจ UPDATE: Outlaw Botnet Returns After 3-Month Silence ๐Ÿ‘€

Kaspersky confirms: Outlaw, a Perl-based crypto-mining botnet, is backโ€”targeting Linux systems in Brazil with brute-force SSH attacks.

๐Ÿงช New tactics spotted:
Deploys XMRig miner & IRC-based backdoor
Kills rival miners & high-CPU processes
Masquerades as rsync, evades termination
Allows DDoS, remote control, file exfiltration

๐Ÿ“Š Victims detected in ๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡ง๐Ÿ‡ท๐Ÿ‡ฉ๐Ÿ‡ช๐Ÿ‡ฎ๐Ÿ‡น๐Ÿ‡น๐Ÿ‡ญ๐Ÿ‡ธ๐Ÿ‡ฌ๐Ÿ‡น๐Ÿ‡ผ๐Ÿ‡จ๐Ÿ‡ฆ

๐Ÿ‘‰ Full report + latest update (May 1): https://thehackernews.com/2025/04/outlaw-group-uses-ssh-brute-force-to.html
๐Ÿค”10๐Ÿ‘4
๐Ÿ‘€ The tools are evolving. So is the intent.

A stealthy phishing wave is slamming key Russian industries with DarkWatchman malware. It evades detection and vanishes on command.

Meanwhile, a new backdoor called Sheriff breached a major Ukrainian platform to spy on defense targetsโ€”quiet, persistent, and dangerous.

๐Ÿ”— Learn more: https://thehackernews.com/2025/05/darkwatchman-sheriff-malware-hit-russia.html
๐Ÿค”11๐Ÿ‘8๐Ÿ”ฅ3๐Ÿ‘1
๐Ÿšจ AI meets Influence-as-a-Service with chilling implications.

Anthropic's Claude chatbot was hijacked to run a botnet that:

โ€ข Created 100+ fake personas
โ€ข Engaged thousands of users
โ€ข Spread pro-UAE, anti-EU, and political propaganda in ๐Ÿ‡ฎ๐Ÿ‡ท, ๐Ÿ‡ช๐Ÿ‡บ, ๐Ÿ‡ฐ๐Ÿ‡ช

Worse, it aided criminals in writing malware, scraping security cam passwords, and running job scams.

๐Ÿ”— Read: https://thehackernews.com/2025/05/claude-ai-exploited-to-operate-100-fake.html
๐Ÿ‘12๐Ÿ‘2
๐Ÿšจ 569,000 alerts. Only 202 matter.

OX Securityโ€™s 2025 report reveals: 95โ€“98% of AppSec alerts are noiseโ€”wasting time, burning budgets, and stalling innovation.

๐Ÿ” Focus on whatโ€™s realโ€”KEVs, secrets, exploitable flaws.

Learn How: https://thehackernews.com/2025/05/new-research-reveals-95-of-appsec-fixes.html
๐Ÿ‘10๐Ÿ”ฅ3
๐Ÿ›‘ Nation-state hackers breached Commvaultโ€™s Azure-hosted environment by exploiting a zero-day in Commvaultโ€™s own web server โ€” CVE-2025-3928.

๐Ÿ‘€ Check sign-ins
๐Ÿšซ Block malicious IPs
๐Ÿ“‘ Report activity fast

Read now โ†’ https://thehackernews.com/2025/05/commvault-confirms-hackers-exploited.html
๐Ÿค”9๐Ÿ‘1
๐Ÿšจ Your tools say you're safe. Attackers know you're not.

They slip past EDR, hide in legit traffic, and lurk for weeks.

Thatโ€™s why SOC teams are turning to Network Detection & Response (NDR)โ€”the only way to see what endpoint tools miss.

The network doesnโ€™t lie.

Learn more: https://thehackernews.com/2025/05/why-top-soc-teams-are-shifting-to.html
โšก8๐Ÿ‘6๐Ÿคฏ4๐Ÿ”ฅ2
๐Ÿ›‘ Hackers are disguising malware as security plugins to hijack sites, inject spammy ads, steal credit cards, & even re-install themselves if deleted.

Some victims are unknowingly losing their own AdSense earnings.

๐Ÿ’ฃ Features: Remote code execution, reverse proxy skimming, JS-based backdoors.

๐Ÿ”— Read: https://thehackernews.com/2025/05/fake-security-plugin-on-wordpress.html
๐Ÿ‘20๐Ÿ‘6๐Ÿ˜ฑ2โšก1๐Ÿคฏ1
๐Ÿšจ AI isnโ€™t just writing your code โ€” itโ€™s leaking your secrets.

New GitGuardian data shows AI-assisted repos leak secrets 40% more often than average.

๐Ÿ“Š 1,200+ repos leaked secrets in 2025 alone.

๐Ÿ‘‰ Donโ€™t trust. Verify. Full report: https://thehackernews.com/expert-insights/2025/04/the-new-frontier-of-security-risk-ai.html
๐Ÿ˜12โšก3๐Ÿ”ฅ2๐Ÿ‘1
๐Ÿ”ฅ UPDATE - A public PoC exploit is now available for a serious SonicWall SMA exploit chain.

โžก๏ธ CVE-2024-38475: Apache HTTP Server flaw used to bypass auth
โžก๏ธ CVE-2023-44221: Post-auth command injection via Diagnostics menu

CISA has added both to the KEV catalog โ€” federal patch deadline: May 22, 2025.
Exploitation is already active in the wild.

๐Ÿ“Ž Details + PoC: https://thehackernews.com/2025/05/sonicwall-confirms-active-exploitation.html
๐Ÿ‘16๐Ÿ˜ฑ1
๐Ÿ” Microsoft goes passwordless by default for all new accounts.

No more passwords at sign-upโ€”just passkeys, using biometrics or device PINs. It's phishing-resistant, backed by FIDO standards.

Existing users? You can remove your password now from settings.

Learn more: https://thehackernews.com/2025/05/microsoft-sets-passkeys-default-for-new.html
๐Ÿ‘32๐Ÿ˜ฑ16๐Ÿ”ฅ8๐Ÿค”7โšก6
๐Ÿ”ฅ Automate the chaos. Stay ahead of CVEs.

LivePerson slashed vuln ticketing time by 60% using a free Tines workflow that:

โ†’ Auto-pulls CISA alerts
โ†’ Enriches with CrowdStrike
โ†’ Sends Slack buttons
โ†’ Creates ServiceNow tickets

No manual tracking. No delays. Just speed.

๐Ÿ‘€ See how your team can do it too: https://thehackernews.com/2025/05/how-to-automate-cve-and-vulnerability.html
๐Ÿ‘17๐Ÿ‘4๐Ÿค”1
๐Ÿšจ TikTok Fined โ‚ฌ530M for secretly storing EU user data in China, violating GDPR rules.

๐Ÿ‡ช๐Ÿ‡บ Irelandโ€™s DPC says TikTok misled regulators, failed to ensure EU-level privacy, and ignored Chinaโ€™s surveillance risks.

They now have 6 months to stop transfers.

๐Ÿ”— Read more: https://thehackernews.com/2025/05/tiktok-slammed-with-530-million-gdpr.html

๐Ÿ“‰ Second major GDPR fine after a โ‚ฌ345M penalty in 2023.
๐Ÿ‘40๐Ÿ˜24๐Ÿ˜ฑ11๐Ÿคฏ7๐Ÿ‘5๐Ÿ”ฅ2
๐Ÿšจ U.S. charges Yemeni national with deploying Black Kingdom ransomware on 1,500+ systemsโ€”from hospitals to schoolsโ€”via Microsoft ProxyLogon.

๐Ÿ’ฅ Targets paid in Bitcoin.

๐Ÿ”— Read more: https://thehackernews.com/2025/05/us-charges-yemeni-hacker-behind-black.html
๐Ÿ˜31๐Ÿ‘7๐Ÿ‘4๐Ÿค”4โšก1
๐Ÿ”ฅ Two years inside. Nation-state footprints. Critical infrastructure targeted.

Fortinet links Iranian APT Lemon Sandstorm to a stealthy attack on a Middle East CNI (May '23โ€“Feb '25).
Used VPN exploits, chained proxies, 7 custom backdoors across 4 phases.

Read this story โžก๏ธ https://thehackernews.com/2025/05/iranian-hackers-maintain-2-year-access.html
๐Ÿ˜12๐Ÿ‘10โšก5๐Ÿ”ฅ4
๐Ÿšจ Malicious Go modules are nuking Linux systemsโ€”wiping entire disks beyond recovery using hidden payloads.

๐Ÿงจ 3 GitHub-hosted packages posed as dev tools. Once run on Linux, they downloaded a script to overwrite /dev/sdaโ€”killing the OS.

At the same time, npm & PyPI malware is:
| ๐Ÿช™ Stealing crypto keys
| ๐Ÿ“ง Using Gmail to exfiltrate data
| ๐Ÿ” Hiding via WebSockets

๐Ÿ‘€ Over 75,000+ downloads so far.

Read โ†’ https://thehackernews.com/2025/05/malicious-go-modules-deliver-disk.html
๐Ÿ˜ฑ29๐Ÿ‘16๐Ÿค”12๐Ÿคฏ8๐Ÿ˜6โšก3๐Ÿ”ฅ1
๐Ÿšจ New malware drop from Golden Chickens: TerraStealerV2 steals browser logins, crypto wallets, and extensions, while TerraLogger silently records keystrokes.

๐Ÿ“ฆ Spread via EXE, MSI, LNK, OCX
๐Ÿ“ค Sends data to Telegram + shady domain

๐Ÿ”— Read this report: https://thehackernews.com/2025/05/golden-chickens-deploy-terrastealerv2.html
๐Ÿ‘25โšก3๐Ÿ‘1๐Ÿคฏ1
๐Ÿšจ Youโ€™re not running a security team. You're the security team.

One inbox. One admin panel. A hundred fire drills. Google Workspace helpsโ€”but attackers slip through the cracks.

๐Ÿ” Identity is the new perimeter.
๐Ÿ” MFA, context-aware access, DLPโ€”start there.
๐Ÿ› ๏ธ Then, monitor, review, remediate.

You donโ€™t need perfection. You need visibility and control.

See how it works โ†’ https://thehackernews.com/2025/05/perfection-is-myth-leverage-isnt-how.html
๐Ÿ‘15๐Ÿ‘5๐Ÿ”ฅ2
๐Ÿšจ Zero-click, max impact โ€” and it's already being exploited.

A critical Commvault bug (CVE-2025-34028, CVSS 10.0) lets hackers upload poisoned ZIPs, leading to full remote code executionโ€”no login needed.

Read: https://thehackernews.com/2025/05/commvault-cve-2025-34028-added-to-cisa.html

Deadline for U.S. agencies: May 23.
โšก13๐Ÿ‘5๐Ÿ˜1
๐Ÿšจ Zero-click. Wormable. Network-spreading.

New flaws in Appleโ€™s AirPlay protocol (๐Ÿ”“ AirBorne) could let hackers hijack your device without a clickโ€”then ride your Wi-Fi into corporate networks.

CVE-2025-24252 + CVE-2025-24132 = silent RCE across Macs, TVs, speakers. Just being on the same Wi-Fi can be enough.

๐Ÿ”— Learn more: https://thehackernews.com/2025/05/wormable-airplay-flaws-enable-zero.html

๐Ÿ“ฒ Update all AirPlay-enabled devices nowโ€”personal & work.
๐Ÿ‘12๐Ÿ”ฅ4
๐Ÿ”ฅ New Edition Just Dropped!

Cybersecurity Weekly Recap | May 5 โ€”โ€” From nation-state hacks to deepfake-ready malware, this weekโ€™s intel is packed:

โ€ข Iranian APT lurked 2 yrs in critical infra
โ€ข Claude chatbot abused for political ops
โ€ข TikTok hit with $601M fine over China data
โ€ข 30+ new CVEs to patch now
โ€ข Magento supply chain backdoor activated after 6 yrs

Read the full recap โ†’ https://thehackernews.com/2025/05/weekly-recap-nation-state-hacks-spyware.html
๐Ÿ‘18โšก2๐Ÿ”ฅ1