The Hacker News
โœ”
152K subscribers
1.87K photos
10 videos
3 files
7.78K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: [email protected]

๐ŸŒ Website: https://thehackernews.com
Download Telegram
๐Ÿ” Microsoft goes passwordless by default for all new accounts.

No more passwords at sign-upโ€”just passkeys, using biometrics or device PINs. It's phishing-resistant, backed by FIDO standards.

Existing users? You can remove your password now from settings.

Learn more: https://thehackernews.com/2025/05/microsoft-sets-passkeys-default-for-new.html
๐Ÿ‘32๐Ÿ˜ฑ16๐Ÿ”ฅ8๐Ÿค”7โšก6
๐Ÿ”ฅ Automate the chaos. Stay ahead of CVEs.

LivePerson slashed vuln ticketing time by 60% using a free Tines workflow that:

โ†’ Auto-pulls CISA alerts
โ†’ Enriches with CrowdStrike
โ†’ Sends Slack buttons
โ†’ Creates ServiceNow tickets

No manual tracking. No delays. Just speed.

๐Ÿ‘€ See how your team can do it too: https://thehackernews.com/2025/05/how-to-automate-cve-and-vulnerability.html
๐Ÿ‘17๐Ÿ‘4๐Ÿค”1
๐Ÿšจ TikTok Fined โ‚ฌ530M for secretly storing EU user data in China, violating GDPR rules.

๐Ÿ‡ช๐Ÿ‡บ Irelandโ€™s DPC says TikTok misled regulators, failed to ensure EU-level privacy, and ignored Chinaโ€™s surveillance risks.

They now have 6 months to stop transfers.

๐Ÿ”— Read more: https://thehackernews.com/2025/05/tiktok-slammed-with-530-million-gdpr.html

๐Ÿ“‰ Second major GDPR fine after a โ‚ฌ345M penalty in 2023.
๐Ÿ‘40๐Ÿ˜24๐Ÿ˜ฑ11๐Ÿคฏ7๐Ÿ‘5๐Ÿ”ฅ2
๐Ÿšจ U.S. charges Yemeni national with deploying Black Kingdom ransomware on 1,500+ systemsโ€”from hospitals to schoolsโ€”via Microsoft ProxyLogon.

๐Ÿ’ฅ Targets paid in Bitcoin.

๐Ÿ”— Read more: https://thehackernews.com/2025/05/us-charges-yemeni-hacker-behind-black.html
๐Ÿ˜31๐Ÿ‘7๐Ÿ‘4๐Ÿค”4โšก1
๐Ÿ”ฅ Two years inside. Nation-state footprints. Critical infrastructure targeted.

Fortinet links Iranian APT Lemon Sandstorm to a stealthy attack on a Middle East CNI (May '23โ€“Feb '25).
Used VPN exploits, chained proxies, 7 custom backdoors across 4 phases.

Read this story โžก๏ธ https://thehackernews.com/2025/05/iranian-hackers-maintain-2-year-access.html
๐Ÿ˜12๐Ÿ‘10โšก5๐Ÿ”ฅ4
๐Ÿšจ Malicious Go modules are nuking Linux systemsโ€”wiping entire disks beyond recovery using hidden payloads.

๐Ÿงจ 3 GitHub-hosted packages posed as dev tools. Once run on Linux, they downloaded a script to overwrite /dev/sdaโ€”killing the OS.

At the same time, npm & PyPI malware is:
| ๐Ÿช™ Stealing crypto keys
| ๐Ÿ“ง Using Gmail to exfiltrate data
| ๐Ÿ” Hiding via WebSockets

๐Ÿ‘€ Over 75,000+ downloads so far.

Read โ†’ https://thehackernews.com/2025/05/malicious-go-modules-deliver-disk.html
๐Ÿ˜ฑ29๐Ÿ‘16๐Ÿค”12๐Ÿคฏ8๐Ÿ˜6โšก3๐Ÿ”ฅ1
๐Ÿšจ New malware drop from Golden Chickens: TerraStealerV2 steals browser logins, crypto wallets, and extensions, while TerraLogger silently records keystrokes.

๐Ÿ“ฆ Spread via EXE, MSI, LNK, OCX
๐Ÿ“ค Sends data to Telegram + shady domain

๐Ÿ”— Read this report: https://thehackernews.com/2025/05/golden-chickens-deploy-terrastealerv2.html
๐Ÿ‘25โšก3๐Ÿ‘1๐Ÿคฏ1
๐Ÿšจ Youโ€™re not running a security team. You're the security team.

One inbox. One admin panel. A hundred fire drills. Google Workspace helpsโ€”but attackers slip through the cracks.

๐Ÿ” Identity is the new perimeter.
๐Ÿ” MFA, context-aware access, DLPโ€”start there.
๐Ÿ› ๏ธ Then, monitor, review, remediate.

You donโ€™t need perfection. You need visibility and control.

See how it works โ†’ https://thehackernews.com/2025/05/perfection-is-myth-leverage-isnt-how.html
๐Ÿ‘15๐Ÿ‘5๐Ÿ”ฅ2
๐Ÿšจ Zero-click, max impact โ€” and it's already being exploited.

A critical Commvault bug (CVE-2025-34028, CVSS 10.0) lets hackers upload poisoned ZIPs, leading to full remote code executionโ€”no login needed.

Read: https://thehackernews.com/2025/05/commvault-cve-2025-34028-added-to-cisa.html

Deadline for U.S. agencies: May 23.
โšก13๐Ÿ‘5๐Ÿ˜1
๐Ÿšจ Zero-click. Wormable. Network-spreading.

New flaws in Appleโ€™s AirPlay protocol (๐Ÿ”“ AirBorne) could let hackers hijack your device without a clickโ€”then ride your Wi-Fi into corporate networks.

CVE-2025-24252 + CVE-2025-24132 = silent RCE across Macs, TVs, speakers. Just being on the same Wi-Fi can be enough.

๐Ÿ”— Learn more: https://thehackernews.com/2025/05/wormable-airplay-flaws-enable-zero.html

๐Ÿ“ฒ Update all AirPlay-enabled devices nowโ€”personal & work.
๐Ÿ‘12๐Ÿ”ฅ4
๐Ÿ”ฅ New Edition Just Dropped!

Cybersecurity Weekly Recap | May 5 โ€”โ€” From nation-state hacks to deepfake-ready malware, this weekโ€™s intel is packed:

โ€ข Iranian APT lurked 2 yrs in critical infra
โ€ข Claude chatbot abused for political ops
โ€ข TikTok hit with $601M fine over China data
โ€ข 30+ new CVEs to patch now
โ€ข Magento supply chain backdoor activated after 6 yrs

Read the full recap โ†’ https://thehackernews.com/2025/05/weekly-recap-nation-state-hacks-spyware.html
๐Ÿ‘18โšก2๐Ÿ”ฅ1
๐Ÿ›‘ Critical Langflow Flaw Actively Exploited!

CISA has added CVE-2025-3248 to its Known Exploited Vulnerabilities list.

โ€ข CVSS: 9.8
โ€ข Affects most Langflow versions
โ€ข Allows remote code execution without login
โ€ข PoC exploit published April 9
โ€ข 466 servers exposed worldwide

โžก๏ธ Full story: https://thehackernews.com/2025/05/critical-langflow-flaw-added-to-cisa.html
๐Ÿคฏ5๐Ÿ‘2๐Ÿ˜ฑ1
๐Ÿšจ Exploited in the wild. No user click needed.

Google patches 46 Android flaws, including CVE-2025-27363โ€”a critical System bug tied to the FreeType font engine.

Discovered by Meta in March, it's now confirmed active.

๐Ÿ”— Learn more: https://thehackernews.com/2025/05/google-fixes-actively-exploited-android.html
๐Ÿ˜ฑ10๐Ÿ‘2๐Ÿ”ฅ2
๐Ÿ”ฅ AI agents are the new insider threatโ€”fast, autonomous, and already slipping past security.

Meanwhile, users just want to workโ€”on personal devices, with unsanctioned apps, and now AI tools.

The Access-Trust Gap is realโ€”and growing.

โœ… Itโ€™s time to move from blocking to governing access, for humans and machines.

๐Ÿ‘‰ Read more from Dave Lewis, Global Advisory CISO at 1Password: https://thehackernews.com/expert-insights/2025/05/ai-access-trust-gap-droids-were-looking.html
๐Ÿ”ฅ8๐Ÿ‘5
This media is not supported in your browser
VIEW IN TELEGRAM
๐Ÿšจ UPDATE - Darculaโ€™s secret weapon exposed!

NRK & Mnemonic uncover Magic Cat โ€” a phishing toolkit behind 884K+ stolen cards in 7 months.

๐Ÿ”น 13M+ clicked links
๐Ÿ”น 600+ scammers
๐Ÿ”น Real-time data & PIN capture
๐Ÿ”น 19K+ victims in Norway alone

Dev behind it? A 24-year-old from China.
The company? Claims itโ€™s just โ€œa website builder.โ€

๐Ÿ”— Full story: https://thehackernews.com/2025/04/darcula-adds-genai-to-phishing-toolkit.html
๐Ÿ˜ฑ15๐Ÿ‘6๐Ÿ”ฅ4โšก1๐Ÿคฏ1
๐Ÿšจ Plug-and-play โ‰  safe.

Default Helm charts are silently exposing your Kubernetes clusters to attackers.

Microsoft warns: popular open-source tools like Apache Pinot, Meshery & Selenium Grid ship with no auth, open ports, and public IPs by default.

Details โ†’ https://thehackernews.com/2025/05/microsoft-warns-default-helm-charts-for.html

Act now:
โœ”๏ธ Audit Helm charts & YAMLs
โœ”๏ธ Lock down network exposure
โœ”๏ธ Monitor container behavior
๐Ÿ‘13๐Ÿ˜ฑ3
๐Ÿšจ 600 million attacks hit Microsoft Entra IDโ€”every single day.

Itโ€™s the heart of your access and identity. If it goes down, everything stops:

โŒ No logins
โŒ No compliance
โŒ No recovery

Built-in tools wonโ€™t save you.

You need full backup and fast recovery. Because when identity breaks, so does your business.

Learn more: https://thehackernews.com/2025/05/entra-id-data-protectionessential-or.html
๐Ÿ‘16๐Ÿ˜7๐Ÿ‘2
๐Ÿ”ฅ Not your typical breachโ€ฆ

Verizonโ€™s 2025 DBIR shows:
โžก๏ธ Third-party breaches doubled (15% โ†’ 30%)
โžก๏ธ Attackers now target machine accounts more than ever

๐Ÿ‘€ Identity sprawl = rising risk.

Human or machine โ€” if itโ€™s not governed, itโ€™s vulnerable.

๐Ÿ”— Learn why unified identity security is no longer optional โ†’ https://thehackernews.com/2025/05/third-parties-and-machine-credentials.html
๐Ÿ‘10
๐Ÿšจ Cybercrime meets Hollywood glitz โ€” and it's all fake.

Two threat groups, Reckless Rabbit & Ruthless Rabbit, are scamming thousands using AI deepfakes, celebrity endorsements, and fake investment sites via Facebook ads.

Victims? Lured in, validated, then drained.

Meanwhile, Facebook ad slots are being flooded with โ€œmystery boxโ€ clearance scams for $2 Apple products โ€” but the only surprise is recurring charges and stolen data.

Read. Verify. Warn others. | Full story โž https://thehackernews.com/2025/05/new-investment-scams-use-facebook-ads.html
๐Ÿ‘12๐Ÿ”ฅ3
๐Ÿ”ฅ Old IoT devices are now botnet soldiers.

Hackers are hijacking end-of-life GeoVision gear & Samsung MagicINFO servers to spread Mirai malware, launching DDoS attacks via unpatched flaws (CVSS 9.8, 8.8).

Exploits live. PoC dropped. Attacks rising.

If youโ€™re running outdated firmwareโ€”youโ€™re already a target.

Read this report: https://thehackernews.com/2025/05/hackers-exploit-samsung-magicinfo.html
๐Ÿค”17๐Ÿ‘11๐Ÿ˜5๐Ÿ”ฅ3