๐ Microsoft goes passwordless by default for all new accounts.
No more passwords at sign-upโjust passkeys, using biometrics or device PINs. It's phishing-resistant, backed by FIDO standards.
Existing users? You can remove your password now from settings.
Learn more: https://thehackernews.com/2025/05/microsoft-sets-passkeys-default-for-new.html
No more passwords at sign-upโjust passkeys, using biometrics or device PINs. It's phishing-resistant, backed by FIDO standards.
Existing users? You can remove your password now from settings.
Learn more: https://thehackernews.com/2025/05/microsoft-sets-passkeys-default-for-new.html
๐32๐ฑ16๐ฅ8๐ค7โก6
๐ฅ Automate the chaos. Stay ahead of CVEs.
LivePerson slashed vuln ticketing time by 60% using a free Tines workflow that:
โ Auto-pulls CISA alerts
โ Enriches with CrowdStrike
โ Sends Slack buttons
โ Creates ServiceNow tickets
No manual tracking. No delays. Just speed.
๐ See how your team can do it too: https://thehackernews.com/2025/05/how-to-automate-cve-and-vulnerability.html
LivePerson slashed vuln ticketing time by 60% using a free Tines workflow that:
โ Auto-pulls CISA alerts
โ Enriches with CrowdStrike
โ Sends Slack buttons
โ Creates ServiceNow tickets
No manual tracking. No delays. Just speed.
๐ See how your team can do it too: https://thehackernews.com/2025/05/how-to-automate-cve-and-vulnerability.html
๐17๐4๐ค1
๐จ TikTok Fined โฌ530M for secretly storing EU user data in China, violating GDPR rules.
๐ช๐บ Irelandโs DPC says TikTok misled regulators, failed to ensure EU-level privacy, and ignored Chinaโs surveillance risks.
They now have 6 months to stop transfers.
๐ Read more: https://thehackernews.com/2025/05/tiktok-slammed-with-530-million-gdpr.html
๐ Second major GDPR fine after a โฌ345M penalty in 2023.
๐ช๐บ Irelandโs DPC says TikTok misled regulators, failed to ensure EU-level privacy, and ignored Chinaโs surveillance risks.
They now have 6 months to stop transfers.
๐ Read more: https://thehackernews.com/2025/05/tiktok-slammed-with-530-million-gdpr.html
๐ Second major GDPR fine after a โฌ345M penalty in 2023.
๐40๐24๐ฑ11๐คฏ7๐5๐ฅ2
๐จ U.S. charges Yemeni national with deploying Black Kingdom ransomware on 1,500+ systemsโfrom hospitals to schoolsโvia Microsoft ProxyLogon.
๐ฅ Targets paid in Bitcoin.
๐ Read more: https://thehackernews.com/2025/05/us-charges-yemeni-hacker-behind-black.html
๐ฅ Targets paid in Bitcoin.
๐ Read more: https://thehackernews.com/2025/05/us-charges-yemeni-hacker-behind-black.html
๐31๐7๐4๐ค4โก1
๐ฅ Two years inside. Nation-state footprints. Critical infrastructure targeted.
Fortinet links Iranian APT Lemon Sandstorm to a stealthy attack on a Middle East CNI (May '23โFeb '25).
Used VPN exploits, chained proxies, 7 custom backdoors across 4 phases.
Read this story โก๏ธ https://thehackernews.com/2025/05/iranian-hackers-maintain-2-year-access.html
Fortinet links Iranian APT Lemon Sandstorm to a stealthy attack on a Middle East CNI (May '23โFeb '25).
Used VPN exploits, chained proxies, 7 custom backdoors across 4 phases.
Read this story โก๏ธ https://thehackernews.com/2025/05/iranian-hackers-maintain-2-year-access.html
๐12๐10โก5๐ฅ4
๐จ Malicious Go modules are nuking Linux systemsโwiping entire disks beyond recovery using hidden payloads.
๐งจ 3 GitHub-hosted packages posed as dev tools. Once run on Linux, they downloaded a script to overwrite /dev/sdaโkilling the OS.
At the same time, npm & PyPI malware is:
| ๐ช Stealing crypto keys
| ๐ง Using Gmail to exfiltrate data
| ๐ Hiding via WebSockets
๐ Over 75,000+ downloads so far.
Read โ https://thehackernews.com/2025/05/malicious-go-modules-deliver-disk.html
๐งจ 3 GitHub-hosted packages posed as dev tools. Once run on Linux, they downloaded a script to overwrite /dev/sdaโkilling the OS.
At the same time, npm & PyPI malware is:
| ๐ช Stealing crypto keys
| ๐ง Using Gmail to exfiltrate data
| ๐ Hiding via WebSockets
๐ Over 75,000+ downloads so far.
Read โ https://thehackernews.com/2025/05/malicious-go-modules-deliver-disk.html
๐ฑ29๐16๐ค12๐คฏ8๐6โก3๐ฅ1
๐จ New malware drop from Golden Chickens: TerraStealerV2 steals browser logins, crypto wallets, and extensions, while TerraLogger silently records keystrokes.
๐ฆ Spread via EXE, MSI, LNK, OCX
๐ค Sends data to Telegram + shady domain
๐ Read this report: https://thehackernews.com/2025/05/golden-chickens-deploy-terrastealerv2.html
๐ฆ Spread via EXE, MSI, LNK, OCX
๐ค Sends data to Telegram + shady domain
๐ Read this report: https://thehackernews.com/2025/05/golden-chickens-deploy-terrastealerv2.html
๐25โก3๐1๐คฏ1
๐จ Youโre not running a security team. You're the security team.
One inbox. One admin panel. A hundred fire drills. Google Workspace helpsโbut attackers slip through the cracks.
๐ Identity is the new perimeter.
๐ MFA, context-aware access, DLPโstart there.
๐ ๏ธ Then, monitor, review, remediate.
You donโt need perfection. You need visibility and control.
See how it works โ https://thehackernews.com/2025/05/perfection-is-myth-leverage-isnt-how.html
One inbox. One admin panel. A hundred fire drills. Google Workspace helpsโbut attackers slip through the cracks.
๐ Identity is the new perimeter.
๐ MFA, context-aware access, DLPโstart there.
๐ ๏ธ Then, monitor, review, remediate.
You donโt need perfection. You need visibility and control.
See how it works โ https://thehackernews.com/2025/05/perfection-is-myth-leverage-isnt-how.html
๐15๐5๐ฅ2
๐จ Zero-click, max impact โ and it's already being exploited.
A critical Commvault bug (CVE-2025-34028, CVSS 10.0) lets hackers upload poisoned ZIPs, leading to full remote code executionโno login needed.
Read: https://thehackernews.com/2025/05/commvault-cve-2025-34028-added-to-cisa.html
Deadline for U.S. agencies: May 23.
A critical Commvault bug (CVE-2025-34028, CVSS 10.0) lets hackers upload poisoned ZIPs, leading to full remote code executionโno login needed.
Read: https://thehackernews.com/2025/05/commvault-cve-2025-34028-added-to-cisa.html
Deadline for U.S. agencies: May 23.
โก13๐5๐1
๐จ Zero-click. Wormable. Network-spreading.
New flaws in Appleโs AirPlay protocol (๐ AirBorne) could let hackers hijack your device without a clickโthen ride your Wi-Fi into corporate networks.
CVE-2025-24252 + CVE-2025-24132 = silent RCE across Macs, TVs, speakers. Just being on the same Wi-Fi can be enough.
๐ Learn more: https://thehackernews.com/2025/05/wormable-airplay-flaws-enable-zero.html
๐ฒ Update all AirPlay-enabled devices nowโpersonal & work.
New flaws in Appleโs AirPlay protocol (๐ AirBorne) could let hackers hijack your device without a clickโthen ride your Wi-Fi into corporate networks.
CVE-2025-24252 + CVE-2025-24132 = silent RCE across Macs, TVs, speakers. Just being on the same Wi-Fi can be enough.
๐ Learn more: https://thehackernews.com/2025/05/wormable-airplay-flaws-enable-zero.html
๐ฒ Update all AirPlay-enabled devices nowโpersonal & work.
๐12๐ฅ4
๐ฅ New Edition Just Dropped!
Cybersecurity Weekly Recap | May 5 โโ From nation-state hacks to deepfake-ready malware, this weekโs intel is packed:
โข Iranian APT lurked 2 yrs in critical infra
โข Claude chatbot abused for political ops
โข TikTok hit with $601M fine over China data
โข 30+ new CVEs to patch now
โข Magento supply chain backdoor activated after 6 yrs
Read the full recap โ https://thehackernews.com/2025/05/weekly-recap-nation-state-hacks-spyware.html
Cybersecurity Weekly Recap | May 5 โโ From nation-state hacks to deepfake-ready malware, this weekโs intel is packed:
โข Iranian APT lurked 2 yrs in critical infra
โข Claude chatbot abused for political ops
โข TikTok hit with $601M fine over China data
โข 30+ new CVEs to patch now
โข Magento supply chain backdoor activated after 6 yrs
Read the full recap โ https://thehackernews.com/2025/05/weekly-recap-nation-state-hacks-spyware.html
๐18โก2๐ฅ1
๐ Critical Langflow Flaw Actively Exploited!
CISA has added CVE-2025-3248 to its Known Exploited Vulnerabilities list.
โข CVSS: 9.8
โข Affects most Langflow versions
โข Allows remote code execution without login
โข PoC exploit published April 9
โข 466 servers exposed worldwide
โก๏ธ Full story: https://thehackernews.com/2025/05/critical-langflow-flaw-added-to-cisa.html
CISA has added CVE-2025-3248 to its Known Exploited Vulnerabilities list.
โข CVSS: 9.8
โข Affects most Langflow versions
โข Allows remote code execution without login
โข PoC exploit published April 9
โข 466 servers exposed worldwide
โก๏ธ Full story: https://thehackernews.com/2025/05/critical-langflow-flaw-added-to-cisa.html
๐คฏ5๐2๐ฑ1
๐จ Exploited in the wild. No user click needed.
Google patches 46 Android flaws, including CVE-2025-27363โa critical System bug tied to the FreeType font engine.
Discovered by Meta in March, it's now confirmed active.
๐ Learn more: https://thehackernews.com/2025/05/google-fixes-actively-exploited-android.html
Google patches 46 Android flaws, including CVE-2025-27363โa critical System bug tied to the FreeType font engine.
Discovered by Meta in March, it's now confirmed active.
๐ Learn more: https://thehackernews.com/2025/05/google-fixes-actively-exploited-android.html
๐ฑ10๐2๐ฅ2
๐ฅ AI agents are the new insider threatโfast, autonomous, and already slipping past security.
Meanwhile, users just want to workโon personal devices, with unsanctioned apps, and now AI tools.
The Access-Trust Gap is realโand growing.
โ Itโs time to move from blocking to governing access, for humans and machines.
๐ Read more from Dave Lewis, Global Advisory CISO at 1Password: https://thehackernews.com/expert-insights/2025/05/ai-access-trust-gap-droids-were-looking.html
Meanwhile, users just want to workโon personal devices, with unsanctioned apps, and now AI tools.
The Access-Trust Gap is realโand growing.
โ Itโs time to move from blocking to governing access, for humans and machines.
๐ Read more from Dave Lewis, Global Advisory CISO at 1Password: https://thehackernews.com/expert-insights/2025/05/ai-access-trust-gap-droids-were-looking.html
๐ฅ8๐5
This media is not supported in your browser
VIEW IN TELEGRAM
๐จ UPDATE - Darculaโs secret weapon exposed!
NRK & Mnemonic uncover Magic Cat โ a phishing toolkit behind 884K+ stolen cards in 7 months.
๐น 13M+ clicked links
๐น 600+ scammers
๐น Real-time data & PIN capture
๐น 19K+ victims in Norway alone
Dev behind it? A 24-year-old from China.
The company? Claims itโs just โa website builder.โ
๐ Full story: https://thehackernews.com/2025/04/darcula-adds-genai-to-phishing-toolkit.html
NRK & Mnemonic uncover Magic Cat โ a phishing toolkit behind 884K+ stolen cards in 7 months.
๐น 13M+ clicked links
๐น 600+ scammers
๐น Real-time data & PIN capture
๐น 19K+ victims in Norway alone
Dev behind it? A 24-year-old from China.
The company? Claims itโs just โa website builder.โ
๐ Full story: https://thehackernews.com/2025/04/darcula-adds-genai-to-phishing-toolkit.html
๐ฑ15๐6๐ฅ4โก1๐คฏ1
๐จ Plug-and-play โ safe.
Default Helm charts are silently exposing your Kubernetes clusters to attackers.
Microsoft warns: popular open-source tools like Apache Pinot, Meshery & Selenium Grid ship with no auth, open ports, and public IPs by default.
Details โ https://thehackernews.com/2025/05/microsoft-warns-default-helm-charts-for.html
Act now:
โ๏ธ Audit Helm charts & YAMLs
โ๏ธ Lock down network exposure
โ๏ธ Monitor container behavior
Default Helm charts are silently exposing your Kubernetes clusters to attackers.
Microsoft warns: popular open-source tools like Apache Pinot, Meshery & Selenium Grid ship with no auth, open ports, and public IPs by default.
Details โ https://thehackernews.com/2025/05/microsoft-warns-default-helm-charts-for.html
Act now:
โ๏ธ Audit Helm charts & YAMLs
โ๏ธ Lock down network exposure
โ๏ธ Monitor container behavior
๐13๐ฑ3
๐จ 600 million attacks hit Microsoft Entra IDโevery single day.
Itโs the heart of your access and identity. If it goes down, everything stops:
โ No logins
โ No compliance
โ No recovery
Built-in tools wonโt save you.
You need full backup and fast recovery. Because when identity breaks, so does your business.
Learn more: https://thehackernews.com/2025/05/entra-id-data-protectionessential-or.html
Itโs the heart of your access and identity. If it goes down, everything stops:
โ No logins
โ No compliance
โ No recovery
Built-in tools wonโt save you.
You need full backup and fast recovery. Because when identity breaks, so does your business.
Learn more: https://thehackernews.com/2025/05/entra-id-data-protectionessential-or.html
๐16๐7๐2
๐ฅ Not your typical breachโฆ
Verizonโs 2025 DBIR shows:
โก๏ธ Third-party breaches doubled (15% โ 30%)
โก๏ธ Attackers now target machine accounts more than ever
๐ Identity sprawl = rising risk.
Human or machine โ if itโs not governed, itโs vulnerable.
๐ Learn why unified identity security is no longer optional โ https://thehackernews.com/2025/05/third-parties-and-machine-credentials.html
Verizonโs 2025 DBIR shows:
โก๏ธ Third-party breaches doubled (15% โ 30%)
โก๏ธ Attackers now target machine accounts more than ever
๐ Identity sprawl = rising risk.
Human or machine โ if itโs not governed, itโs vulnerable.
๐ Learn why unified identity security is no longer optional โ https://thehackernews.com/2025/05/third-parties-and-machine-credentials.html
๐10
๐จ Cybercrime meets Hollywood glitz โ and it's all fake.
Two threat groups, Reckless Rabbit & Ruthless Rabbit, are scamming thousands using AI deepfakes, celebrity endorsements, and fake investment sites via Facebook ads.
Victims? Lured in, validated, then drained.
Meanwhile, Facebook ad slots are being flooded with โmystery boxโ clearance scams for $2 Apple products โ but the only surprise is recurring charges and stolen data.
Read. Verify. Warn others. | Full story โ https://thehackernews.com/2025/05/new-investment-scams-use-facebook-ads.html
Two threat groups, Reckless Rabbit & Ruthless Rabbit, are scamming thousands using AI deepfakes, celebrity endorsements, and fake investment sites via Facebook ads.
Victims? Lured in, validated, then drained.
Meanwhile, Facebook ad slots are being flooded with โmystery boxโ clearance scams for $2 Apple products โ but the only surprise is recurring charges and stolen data.
Read. Verify. Warn others. | Full story โ https://thehackernews.com/2025/05/new-investment-scams-use-facebook-ads.html
๐12๐ฅ3
๐ฅ Old IoT devices are now botnet soldiers.
Hackers are hijacking end-of-life GeoVision gear & Samsung MagicINFO servers to spread Mirai malware, launching DDoS attacks via unpatched flaws (CVSS 9.8, 8.8).
Exploits live. PoC dropped. Attacks rising.
If youโre running outdated firmwareโyouโre already a target.
Read this report: https://thehackernews.com/2025/05/hackers-exploit-samsung-magicinfo.html
Hackers are hijacking end-of-life GeoVision gear & Samsung MagicINFO servers to spread Mirai malware, launching DDoS attacks via unpatched flaws (CVSS 9.8, 8.8).
Exploits live. PoC dropped. Attacks rising.
If youโre running outdated firmwareโyouโre already a target.
Read this report: https://thehackernews.com/2025/05/hackers-exploit-samsung-magicinfo.html
๐ค17๐11๐5๐ฅ3