The Hacker News
βœ”
152K subscribers
1.88K photos
10 videos
3 files
7.79K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
XPOSURE is back! The National Exposure Management Virtual Summit returns for its fourth year, focused on what matters most: reducing cyber exposure and risk.

Join top cybersecurity leaders from Pentera, Forrester, AWS, Armis, Recorded Future, and SecurityScorecard to learn how leading security teams are taking a proactive approach to exposure across the enterprise.

Featuring Jen Easterly, former Director of the Cybersecurity and Infrastructure Security Agency (CISA), as the XPOSURE 2025 keynote.

If you’re building toward a more proactive security model, this is where you need to be.

πŸ“… June 18 | πŸ•š 11 AM ET
πŸŽ“ Up to 3.5 CPE credits
πŸ”— https://thn.news/xposure2025

#XPOSURE2025 #CTEM #CyberSecurityLeadership #EnterpriseSecurity
πŸ‘2
🚨 A 10-year-old flaw (CVE-2025-49113 / CVSS 9.9) in Roundcube Webmail could let hackers take over your system.

Nation-state groups like APT28 have already exploited Roundcube before.

πŸ”— Read: https://thehackernews.com/2025/06/critical-10-year-old-roundcube-webmail.html

πŸ”§ Patch to 1.6.11 or 1.5.10 LTS now.
πŸ“Œ PoC coming soon.
πŸ‘11πŸ”₯5πŸ€”5πŸ‘4
🚨 Watch your clipboard!

A fake DocuSign site tricks users into running malware with a sneaky PowerShell scriptβ€”copied via CAPTCHA.

βœ”οΈ Clipboard poisoning
βœ”οΈ Fake Gitcode & DocuSign sites
βœ”οΈ NetSupport RAT deployed

πŸ‘€ Learn how it works β†’ https://thehackernews.com/2025/06/fake-docusign-gitcode-sites-spread.html
πŸ”₯7πŸ‘6🀯4
🚨 Critical bugs in HPE StoreOnce | 9.8 CVSS flaw allows auth bypass + RCE as root.

πŸ‘€ One bug (CVE-2025-37093) lets attackers skip loginβ€”then chain others for full takeover.

Patch now if you're running pre-4.3.11 versions.

πŸ”— Full details: https://thehackernews.com/2025/06/hpe-issues-security-patch-for-storeonce.html
πŸ‘11πŸ”₯4
🚨 New wave of supply chain attacks hits npm, PyPI & RubyGems.

Hackers are hiding malware in popular open-source packages to:

πŸ”» Steal crypto wallets
πŸ—‘οΈ Delete entire codebases
πŸ•΅οΈ Exfiltrate Telegram bot data

Full story & package list β†’ https://thehackernews.com/2025/06/malicious-pypi-npm-and-ruby-packages.html
🀯11πŸ‘6
🚨 70% of data leaks now happen in-browser.

Legacy DLP tools can’t see what your employees are copy-pasting into AI tools, Slack, or Gmail.

The browser is the new security perimeter.

Read why browser-centric DLP is now a must β†’ https://thehackernews.com/2025/06/your-saas-data-isnt-safe-why.html
πŸ‘14πŸ€”7
🚨 New Chaos RAT variant targets Linux & Windows users

Masquerading as a Linux network tool, the malware spreads via phishing to deploy crypto miners, steal data, and gain full device control.

πŸ”— Full report: https://thehackernews.com/2025/06/chaos-rat-malware-targets-windows-and.html
πŸ‘9πŸ”₯3⚑2πŸ‘1
Do you know how and where AI is running in your org? That customer service agent isn't just an LLMβ€”it's system prompts, tool calls, RAG data, user logs, and MCP servers.

Every untracked component = a breach waiting to happen.

Why AI asset sprawl goes way beyond model discovery β†’ https://thn.news/ai-assets-sprawl
πŸ‘7πŸ‘4
🚨 Google warns: Fake IT calls breaching Salesforce accounts.

Hackers from UNC6040 trick staff into approving a malicious β€œData Loader” app to steal data.

πŸ”— Learn how the scam works: https://thehackernews.com/2025/06/google-exposes-vishing-group-unc6040.html
πŸ‘7πŸ‘5😁3πŸ”₯2
🚨 One PASSWORD to rule them all?

A critical flaw (CVSS 9.9) in Cisco ISE cloud deployments (AWS, Azure, OCI) means static credentials are reused across systemsβ€”allowing unauthenticated attackers to access configs, data, and more.

Details β†’ https://thehackernews.com/2025/06/critical-cisco-ise-auth-bypass-flaw.html

πŸ” No fixβ€”only factory reset.
πŸ‘11πŸ”₯9😁4⚑1🀯1
🚨 Dark web carding site BidenCash taken down by U.S. DoJ

πŸ”Ή 15M+ stolen credit cards sold
πŸ”Ή $17M in criminal profits
πŸ”Ή 3.3M cards leaked for free to attract buyers
πŸ”Ή 117K+ users served since 2022

Seized in global sting with FBI & Europol.

Read: https://thehackernews.com/2025/06/doj-seizes-145-domains-tied-to.html
😁19πŸ‘9
πŸ”₯ 2025’s biggest cyber threat? The accounts you forgot existed.

Machine IDs now outnumber humans 45:1 β€” and they’re 7.5x more dangerous.

Leaked secrets, orphaned privileges, siloed teams.
Attackers see the full map. Do you?

πŸ‘‰ How to close identity gaps before it’s too late: https://thehackernews.com/expert-insights/2025/06/identity-first-security-multilayered.html
πŸ”₯8
Iran-linked hackers are spying on Kurdish & Iraqi officials using custom malware.

The group BladedFeline breached:
β€’ KRG diplomats
β€’ Iraq gov networks
β€’ Uzbekistan telecom

Backdoors used: Whisper, Spearal, Shahmaran, Slippery Snakelet.

πŸ•΅οΈβ€β™‚οΈ Full story β†’ https://thehackernews.com/2025/06/iran-linked-bladedfeline-hits-iraqi-and.html
⚑7πŸ‘3πŸ”₯3😱3
πŸ”₯ $4.88M average breach cost β€” boards want real ROI, not just patch counts.

Business Value Assessment (BVA) links risk to $$ and shows cost of inaction β€” often $500K+ monthly.

Stop guessing. Measure impact. Turn security into business value.

Try this new ROI Calculator ⬇️ https://thehackernews.com/2025/06/redefining-cyber-value-why-business.html
πŸ”₯7πŸ‘4πŸ€”2
πŸš¨β€œBitter” hacking group targets governments and diplomats worldwide using advanced malware and spear-phishing.

Recent attacks spread from South Asia to Turkey. Active during business hours.

Learn more β†’ https://thehackernews.com/2025/06/bitter-hacker-group-expands-cyber.html
πŸ‘12
⚠️ Ukraine hit by PathWiper malware wiping critical data via hacked admin tools. Linked to Russia-based APT groups.

🚨 Meanwhile, Silent Werewolf launches stealth attacks on Russian & Moldovan sectors using advanced loaders.

Stay informedβ€”learn here: https://thehackernews.com/2025/06/new-pathwiper-data-wiper-malware.html
πŸ”₯23😱5πŸ‘2🀯1
🚨 Enterprise security is under siege!

30% of attacks target web assets, 21% hit APIs & IoT devices.

⚠️ Too many alerts
⚠️ Scattered tests
⚠️ Limited visibility = High risk

πŸ” AI-powered full-path attack simulation + centralized control = real defense.

Learn what it means β†’ https://thehackernews.com/expert-insights/2025/06/solving-enterprise-security-challenge.html
πŸ‘8😁5πŸ”₯2
🚨Alert: Positive Technologies has confirmed the deadly CVE-2025-49113 exploitβ€”authenticated users can run arbitrary commands through PHP object deserialization.

Read: https://thehackernews.com/2025/06/critical-10-year-old-roundcube-webmail.html

Action: Update Roundcube immediately to the latest version.
πŸ‘8πŸ”₯5🀯1
Think like an attacker to defend better.

AEV continuously simulates cyber-attacks to show how hackers exploit your system.

It helps teams prioritize fixesβ€”credentials, misconfigs, etc.β€”beyond patching.

Stay ahead by understanding attackers, not just checking boxes: https://thehackernews.com/2025/06/inside-mind-of-adversary-why-more.html
πŸ‘9πŸ”₯5πŸ‘2
🚨 Tech support scam busted: 4 arrested in India, 2 fake call centers taken down targeting Japanese victims via AI-powered tricks.

66,000+ malicious domains removed since 2024 through global CBI-Microsoft-Japan effort.

Cybercrime is evolvingβ€”global teamwork is the key.

Learn more: https://thehackernews.com/2025/06/microsoft-helps-cbi-dismantle-indian.html
πŸ”₯11🀯7πŸ‘4😁2⚑1