The Hacker News
โœ”
152K subscribers
1.87K photos
10 videos
3 files
7.79K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: [email protected]

๐ŸŒ Website: https://thehackernews.com
Download Telegram
๐Ÿšจ New wave of supply chain attacks hits npm, PyPI & RubyGems.

Hackers are hiding malware in popular open-source packages to:

๐Ÿ”ป Steal crypto wallets
๐Ÿ—‘๏ธ Delete entire codebases
๐Ÿ•ต๏ธ Exfiltrate Telegram bot data

Full story & package list โ†’ https://thehackernews.com/2025/06/malicious-pypi-npm-and-ruby-packages.html
๐Ÿคฏ11๐Ÿ‘6
๐Ÿšจ 70% of data leaks now happen in-browser.

Legacy DLP tools canโ€™t see what your employees are copy-pasting into AI tools, Slack, or Gmail.

The browser is the new security perimeter.

Read why browser-centric DLP is now a must โ†’ https://thehackernews.com/2025/06/your-saas-data-isnt-safe-why.html
๐Ÿ‘14๐Ÿค”7
๐Ÿšจ New Chaos RAT variant targets Linux & Windows users

Masquerading as a Linux network tool, the malware spreads via phishing to deploy crypto miners, steal data, and gain full device control.

๐Ÿ”— Full report: https://thehackernews.com/2025/06/chaos-rat-malware-targets-windows-and.html
๐Ÿ‘9๐Ÿ”ฅ3โšก2๐Ÿ‘1
Do you know how and where AI is running in your org? That customer service agent isn't just an LLMโ€”it's system prompts, tool calls, RAG data, user logs, and MCP servers.

Every untracked component = a breach waiting to happen.

Why AI asset sprawl goes way beyond model discovery โ†’ https://thn.news/ai-assets-sprawl
๐Ÿ‘7๐Ÿ‘4
๐Ÿšจ Google warns: Fake IT calls breaching Salesforce accounts.

Hackers from UNC6040 trick staff into approving a malicious โ€œData Loaderโ€ app to steal data.

๐Ÿ”— Learn how the scam works: https://thehackernews.com/2025/06/google-exposes-vishing-group-unc6040.html
๐Ÿ‘7๐Ÿ‘5๐Ÿ˜3๐Ÿ”ฅ2
๐Ÿšจ One PASSWORD to rule them all?

A critical flaw (CVSS 9.9) in Cisco ISE cloud deployments (AWS, Azure, OCI) means static credentials are reused across systemsโ€”allowing unauthenticated attackers to access configs, data, and more.

Details โ†’ https://thehackernews.com/2025/06/critical-cisco-ise-auth-bypass-flaw.html

๐Ÿ” No fixโ€”only factory reset.
๐Ÿ‘11๐Ÿ”ฅ9๐Ÿ˜4โšก1๐Ÿคฏ1
๐Ÿšจ Dark web carding site BidenCash taken down by U.S. DoJ

๐Ÿ”น 15M+ stolen credit cards sold
๐Ÿ”น $17M in criminal profits
๐Ÿ”น 3.3M cards leaked for free to attract buyers
๐Ÿ”น 117K+ users served since 2022

Seized in global sting with FBI & Europol.

Read: https://thehackernews.com/2025/06/doj-seizes-145-domains-tied-to.html
๐Ÿ˜19๐Ÿ‘9
๐Ÿ”ฅ 2025โ€™s biggest cyber threat? The accounts you forgot existed.

Machine IDs now outnumber humans 45:1 โ€” and theyโ€™re 7.5x more dangerous.

Leaked secrets, orphaned privileges, siloed teams.
Attackers see the full map. Do you?

๐Ÿ‘‰ How to close identity gaps before itโ€™s too late: https://thehackernews.com/expert-insights/2025/06/identity-first-security-multilayered.html
๐Ÿ”ฅ8
Iran-linked hackers are spying on Kurdish & Iraqi officials using custom malware.

The group BladedFeline breached:
โ€ข KRG diplomats
โ€ข Iraq gov networks
โ€ข Uzbekistan telecom

Backdoors used: Whisper, Spearal, Shahmaran, Slippery Snakelet.

๐Ÿ•ต๏ธโ€โ™‚๏ธ Full story โ†’ https://thehackernews.com/2025/06/iran-linked-bladedfeline-hits-iraqi-and.html
โšก7๐Ÿ‘3๐Ÿ”ฅ3๐Ÿ˜ฑ3
๐Ÿ”ฅ $4.88M average breach cost โ€” boards want real ROI, not just patch counts.

Business Value Assessment (BVA) links risk to $$ and shows cost of inaction โ€” often $500K+ monthly.

Stop guessing. Measure impact. Turn security into business value.

Try this new ROI Calculator โฌ‡๏ธ https://thehackernews.com/2025/06/redefining-cyber-value-why-business.html
๐Ÿ”ฅ7๐Ÿ‘4๐Ÿค”2
๐Ÿšจโ€œBitterโ€ hacking group targets governments and diplomats worldwide using advanced malware and spear-phishing.

Recent attacks spread from South Asia to Turkey. Active during business hours.

Learn more โ†’ https://thehackernews.com/2025/06/bitter-hacker-group-expands-cyber.html
๐Ÿ‘12
โš ๏ธ Ukraine hit by PathWiper malware wiping critical data via hacked admin tools. Linked to Russia-based APT groups.

๐Ÿšจ Meanwhile, Silent Werewolf launches stealth attacks on Russian & Moldovan sectors using advanced loaders.

Stay informedโ€”learn here: https://thehackernews.com/2025/06/new-pathwiper-data-wiper-malware.html
๐Ÿ”ฅ23๐Ÿ˜ฑ5๐Ÿ‘2๐Ÿคฏ1
๐Ÿšจ Enterprise security is under siege!

30% of attacks target web assets, 21% hit APIs & IoT devices.

โš ๏ธ Too many alerts
โš ๏ธ Scattered tests
โš ๏ธ Limited visibility = High risk

๐Ÿ” AI-powered full-path attack simulation + centralized control = real defense.

Learn what it means โ†’ https://thehackernews.com/expert-insights/2025/06/solving-enterprise-security-challenge.html
๐Ÿ‘8๐Ÿ˜5๐Ÿ”ฅ2
๐ŸšจAlert: Positive Technologies has confirmed the deadly CVE-2025-49113 exploitโ€”authenticated users can run arbitrary commands through PHP object deserialization.

Read: https://thehackernews.com/2025/06/critical-10-year-old-roundcube-webmail.html

Action: Update Roundcube immediately to the latest version.
๐Ÿ‘8๐Ÿ”ฅ5๐Ÿคฏ1
Think like an attacker to defend better.

AEV continuously simulates cyber-attacks to show how hackers exploit your system.

It helps teams prioritize fixesโ€”credentials, misconfigs, etc.โ€”beyond patching.

Stay ahead by understanding attackers, not just checking boxes: https://thehackernews.com/2025/06/inside-mind-of-adversary-why-more.html
๐Ÿ‘9๐Ÿ”ฅ5๐Ÿ‘2
๐Ÿšจ Tech support scam busted: 4 arrested in India, 2 fake call centers taken down targeting Japanese victims via AI-powered tricks.

66,000+ malicious domains removed since 2024 through global CBI-Microsoft-Japan effort.

Cybercrime is evolvingโ€”global teamwork is the key.

Learn more: https://thehackernews.com/2025/06/microsoft-helps-cbi-dismantle-indian.html
๐Ÿ”ฅ11๐Ÿคฏ7๐Ÿ‘4๐Ÿ˜2โšก1
โš ๏ธ macOS Alert โ€” Fake Spectrum CAPTCHA is a trap!

Russian hackers use clipboard hacks + terminal scripts to steal passwords & install Atomic Stealer.

Victims unknowingly run commands โ€” handing over control.

This sneaky ClickFix tactic preys on your โ€œsecurity checkโ€ fatigue.

Read: https://thehackernews.com/2025/06/new-atomic-macos-stealer-campaign.html
๐Ÿ”ฅ13๐Ÿ˜6๐Ÿคฏ3๐Ÿ‘2โšก1
โš ๏ธ Generative AI is leaking your sensitive dataโ€”4 million+ blocked attempts just in Zscalerโ€™s cloud alone.

Blocking AI apps wonโ€™t stop employees; it just pushes data risks into the shadows.

The real fix? Visibility, context-aware policies, and secure AI alternatives that keep productivity high and data safe.

Hereโ€™s what smart AI security looks like โ†“

Details here โ†’ https://thehackernews.com/2025/06/empower-users-and-protect-against-genai.html
๐Ÿ‘16๐Ÿค”7๐Ÿ‘3
๐Ÿšจ Over 700 downloads of multiple malicious Chrome extensions are stealing banking data from Brazilians and 70+ companies.

Phishing emails disguised as invoices install spyware targeting Banco do Brasil.

Details here โ†“ https://thehackernews.com/2025/06/malicious-browser-extensions-infect-722.html
๐Ÿ‘13๐Ÿ˜ฑ5โšก4๐Ÿ”ฅ1
๐Ÿšจ Supply chain attacks hit npm & PyPI: malware in 1M+ downloads steals data, runs commands, and wipes files.

A PyPI package steals Instagram creds, spreading them to botnets.

Check your dependencies NOW.

Full details โ†“ https://thehackernews.com/2025/06/new-supply-chain-malware-operation-hits.html
๐Ÿ‘10๐Ÿ”ฅ4๐Ÿ˜2๐Ÿ‘1๐Ÿคฏ1