The Hacker News
βœ”
152K subscribers
1.87K photos
10 videos
3 files
7.79K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
🚨 Warning: A new high-severity Google Chrome flaw is being actively exploited in the wild.

CVE-2025-4664 allows attackers to steal sensitive data like account credentials via crafted HTML + image traps.

It affects Chrome < 136.0.7103.113 β€” and likely other Chromium-based browsers.

πŸ”— Details: https://thehackernews.com/2025/05/new-chrome-vulnerability-enables-cross.html
πŸ‘19😱12πŸ”₯1
🚨 One email. One click. Full inbox compromise.

APT28 is back with Operation RoundPress, exploiting zero-days in MDaemon, Roundcube, Zimbra & Horde to steal emails from govs, defense orgs & academics across Ukraine, Bulgaria, Greece & more.

πŸ”— Read: https://thehackernews.com/2025/05/russia-linked-apt28-exploited-mdaemon.html
😁16πŸ”₯7
🚨 2,000+ devs downloaded this npm package... and it was hiding malware

A seemingly harmless utility used Google Calendar as a stealth command link.

β€”Unicode tricks
β€”Multi-stage payloads
β€”Real downloads
β€”The kicker? It’s still live

Read here: https://thehackernews.com/2025/05/malicious-npm-package-leverages-unicode.html
πŸ‘15πŸ”₯4🀯1
πŸ”₯ Cybercriminals are now using Microsoft’s own Quick Assist tool to deploy ransomware like Black Basta. And with Ransomware-as-a-Service, anyone can launch an attack.

No BCDR? You’re gambling your business.

Learn 5 must-have recovery moves now β†’ https://thehackernews.com/2025/05/top-5-bcdr-capabilities-for-ransomware-defense.html
😁9πŸ‘4πŸ”₯4πŸ€”2
πŸ‘€ Your last pen test passed. So why was there still a breach?

Compliance checks a box. Attackers exploit what happens next. Verizon’s 2025 report shows a 34% spike in exploited vulnerabilities β€” most after audits.

πŸ” It’s time to move beyond point-in-time testing.
Only continuous pen testing + EASM reveals what attackers find first.

πŸ‘‰ See what your strategy might be missing: https://thehackernews.com/2025/05/pen-testing-for-compliance-only-its.html
πŸ‘9😁2
πŸ•·οΈ NEW WEBINAR: Learn about Scattered Spider’s evolving TTPs and how to defend your organization πŸ•·οΈ

Join Push Security to learn about Scattered Spider’s current and future TTPs and how to stop breaches beginning with account takeover.

Register here πŸ‘‰ https://thn.news/scattered-spider-2025
πŸ‘11🀯1
🚨 Coinbase insider breach exposed. Hackers bribed support agents to steal user dataβ€”then tried to extort $20M.

🧠 No crypto lost, but names, emails, and IDs were leaked.
πŸ›‘οΈ Coinbase is reimbursing victims + offering a $20M reward.

πŸ”— Full story β†’ https://thehackernews.com/2025/05/coinbase-agents-bribed-data-of-1-users.html
😱9πŸ‘6😁6πŸ€”2
πŸ‘€ Meta vs. Europeβ€”Round 2

Starting May 27, Meta plans to train its AI using Facebook & Instagram user data across the E.U.β€”without asking for consent.

Privacy watchdog noyb says it’s illegal. A class action may be coming.

Full story: https://thehackernews.com/2025/05/meta-to-train-ai-on-eu-user-data-from.html
😁15πŸ‘9🀯5πŸ€”3
🚫 Your firewall isn't brokenβ€”it's just outdated.

AI-powered attacks are faster than ever. Still exposing your network with public IPs? You're playing defense with a blindfold.

Zscaler's Zero Trust model flips the scriptβ€”no public IPs, no easy targets. It's not magic. It's strategy.

πŸ‘€ The most secure network is the one they can't see.

πŸ”Ž Discover how it works β†’ https://thehackernews.com/expert-insights/2025/05/eliminating-public-ips-case-for-zero.html
πŸ‘13πŸ”₯3πŸ€”3
πŸ’» Spectre Isn’t Dead. It’s Mutating! New CPU flaw hits ALL modern Intel chips.

πŸ›  Researchers at ETH Zurich and VUSec uncovered Spectre-style Intel CPU flaws (CVE-2024-45332, CVE-2024-28956, CVE-2025-24495) that leak memory across users, guests, and hostsβ€”at rates up to 17KB/sec.

Read details β†’ https://thehackernews.com/2025/05/researchers-expose-new-intel-cpu-flaws.html

Patches are out. But is this just another Band-Aid?
⚑15πŸ‘7πŸ”₯3πŸ‘3
🚨 A new Windows-based botnetβ€”HTTPBotβ€”is quietly choking login and payment systems across China’s gaming and tech sectors.

πŸ”₯ Over 200 targeted attacks since April 2025
🧠 Mimics real users with Chrome, cookies & HTTP/2

Learn more about this: https://thehackernews.com/2025/05/new-httpbot-botnet-launches-200.html
πŸ€”11😁5🀯4πŸ‘3πŸ‘2
πŸ”’ What if your most sensitive data is already exposedβ€”and no one knows yet?

AI-powered DLP, zero trust, browser isolation, and cloud posture control are reshaping data defense.

Learn 10 must-do strategies now β†’ https://thehackernews.com/2025/05/top-10-best-practices-for-effective.html
πŸ‘28🀯5😁2😱1
πŸ›‘ 2 critical Firefox zero-days β€” CVE-2025-4918 & CVE-2025-4919 β€” proven exploitable.

Attackers can read/write sensitive data or trigger remote code execution.

Affects all versions before: β€’ Firefox 138.0.4 β€’ ESR 128.10.1 / 115.23.1
πŸ”— Patch now. Full story: https://thehackernews.com/2025/05/firefox-patches-2-zero-days-exploited.html
😁30πŸ‘15🀯9😱2πŸ€”1
β€œWe never drop tools on machines.”

84% of major cyberattacks now use built-in system tools like PowerShell & netsh.exe β€” not malware.

πŸ‘€ Bitdefender analyzed 700,000 incidents: attackers are hiding in plain sight using legit admin utilities.

Living Off the Land isn’t just stealthβ€”it’s standard.

β†’ See how PHASR flips the script: smart blocking, zero disruption.

πŸ”— Read: https://thehackernews.com/expert-insights/2025/05/living-off-land-what-we-learned-from.html
πŸ‘23😱2
⚑ Weekly Recap: Zero-days are just the tip. This week’s threat activity points to a deeper shift in how attackers operate.

Read now, recalibrate faster β†’ https://thehackernews.com/2025/05/weekly-recap-zero-day-exploits-insider.html
😁6πŸ‘4
🚨 New favorite toy of ransomware gangs? A stealthy malware called Skitnetβ€”now seen in live attacks.

First sold on dark forums in 2024, it's now powering phishing campaigns from groups like Black Basta in 2025.

β†’ Reverse shell via DNS
β†’ Evades AV using GetProcAddress
β†’ Deploys legit tools like AnyDesk
β†’ Modular, stealthy, persistent

Learn how it works: https://thehackernews.com/2025/05/ransomware-gangs-use-skitnet-malware.html
πŸ€”15πŸ‘7⚑1πŸ”₯1
πŸ”₯ CTEM is the new must-have for cybersecurity leaders.

Forget yearly audits. This is about always-on risk testing β€” and it’s working.

CTEM uses attack simulations, real-time testing & exposure tracking to stay ahead.

Why are top CISOs making the switch?

πŸ‘‰ Learn how it works: https://thehackernews.com/2025/05/why-ctem-is-winning-bet-for-cisos-in.html
😁6πŸ‘3
πŸ›‘ WARNING: Popular VMware tool RVTools was hacked to spread Bumblebee malware via its official site.

The site is now offline β€” but ⚠️ do not download from unofficial sources either.

Meanwhile, Procolored printer software was found carrying a Delphi backdoor and a $974K crypto clipper named SnipVex, which infects .exe files to hijack Bitcoin transactions.

πŸ”Ž Full details here: https://thehackernews.com/2025/05/rvtools-official-site-hacked-to-deliver.html
⚑16πŸ‘14🀯7πŸ€”5😁1
πŸ‘€ Devs, you're being hunted.

3 Python packages quietly turned stolen emails into verified TikTok & Instagram targets. Another posed as a dev toolβ€”actually a stealth backdoor.

πŸ”— Full story β†’ https://thehackernews.com/2025/05/malicious-pypi-packages-exploit.html
🀯16πŸ‘9πŸ”₯7😁3😱1
🚨 RedisRaider is hereβ€”and it's hunting Linux servers.

A new cryptojacking campaign is weaponizing Redis config commands to silently hijack Linux systems and mine Monero.

πŸ”— Learn more: https://thehackernews.com/2025/05/go-based-malware-deploys-xmrig-miner-on.html
πŸ‘7πŸ”₯7🀯4πŸ‘1