The Hacker News
โœ”
152K subscribers
1.88K photos
10 videos
3 files
7.79K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: [email protected]

๐ŸŒ Website: https://thehackernews.com
Download Telegram
๐Ÿšจ Ransomware gangs are exploiting unpatched SimpleHelp flaws to hit utility billing customers with double extortion attacks โ€” since Jan 2025.

CISA warns: patch now or risk serious breaches.

Read โ†’ https://thehackernews.com/2025/06/ransomware-gangs-exploit-unpatched.html

Meanwhile, new Fog ransomware uses legit employee monitoring software to stay hidden and persistent for weeks.
๐Ÿ‘14๐Ÿ”ฅ2
Security teams drown in alertsโ€”but real risks slip through unnoticed.

Continuous Threat Exposure Management (CTEM) shifts focus from alerts to actual attack paths, prioritizing prevention over reaction.

Stop chasing every alert. Start managing risk with purpose.

Read more โ†“ https://thehackernews.com/2025/06/ctem-is-new-soc-shifting-from.html
๐Ÿ‘7๐Ÿ‘1
๐Ÿšจ Over 269,000 legit websites hijacked with hidden JavaScript redirecting search engine visitors to malware and scams.

Using a stealthy JSFireTruck obfuscation, attackers fingerprint devices to serve fake CAPTCHAs, tech support scams, and malwareโ€”evading detection at scale.

Learn how this massive campaign works โ†“ https://thehackernews.com/2025/06/over-269000-websites-infected-with.html
๐Ÿคฏ9๐Ÿ‘5
Discord invite links are being hijacked to deliver malware that steals crypto wallets and personal data.

Attackers reuse expired/deleted invites, redirecting to fake servers, tricking users into running malicious PowerShell scripts disguised as verification.

Full details here โ†“ https://thehackernews.com/2025/06/discord-invite-link-hijacking-delivers.html

This Multi-stage attack uses Pastebin & GitHub to evade security tools.
๐Ÿ‘35๐Ÿค”12๐Ÿ‘8๐Ÿ”ฅ3๐Ÿ˜3
โš ๏ธ A fake Python package just stole AWS tokens, Jamf data & CI/CD secrets โ€” from devs at Grab.

The malware posed as a legit helper for ML workflows, hid a multi-stage info-stealer, and targeted macOS too.

Details here โ†’ https://thehackernews.com/2025/06/malicious-pypi-package-masquerades-as.html
๐Ÿ˜ฑ19๐Ÿ”ฅ12๐Ÿ‘10โšก5๐Ÿ‘2๐Ÿ˜2
๐Ÿšจ Most cybersecurity providers are leaving money on the table.

Still selling one-off audits or patch jobs? You're missing the shift.

Strategic services like vCISO programs arenโ€™t just higher valueโ€”theyโ€™re recurring revenue machines.

How to evolve your offering โ†“ https://thehackernews.com/2025/06/playbook-transforming-your.html
๐Ÿ‘7๐Ÿ”ฅ3๐Ÿ‘3
๐Ÿšจ New ransomware โ€œAnubisโ€ can encrypt your filesโ€”and then erase them forever.

Even if you pay, recovery is impossible. Victims span healthcare, hospitality & more.

This rare dual-threat ups the pressure to pay.

Details here โ†’ https://thehackernews.com/2025/06/anubis-ransomware-encrypts-and-wipes.html
๐Ÿคฏ19๐Ÿ”ฅ10๐Ÿ˜ฑ7โšก3๐Ÿ‘2
๐Ÿšจ U.S. seizes $7.7M linked to North Korean IT worker scam targeting crypto firms.

Fake identities, AI tools, and Zoom hacks helped funnel millions to fund Pyongyangโ€™s weapons program.

Hereโ€™s how deep the deception goes โ†“ https://thehackernews.com/2025/06/us-seizes-774m-in-crypto-tied-to-north.html
๐Ÿ˜18๐Ÿค”8๐Ÿคฏ7๐Ÿ‘6โšก5
๐Ÿšจ WhatsApp ads are finally hereโ€”inside your Status updates.

Meta says itโ€™s privacy-friendly, but itโ€™s tapping your location, device data, and even Facebook activity to target you.

Hereโ€™s whatโ€™s changing โ†“ https://thehackernews.com/2025/06/meta-starts-showing-ads-on-whatsapp.html
๐Ÿ˜ฑ25๐Ÿ˜16๐Ÿคฏ14๐Ÿ‘5โšก3๐Ÿค”2๐Ÿ”ฅ1๐Ÿ‘1
๐Ÿšจ VPNs are now a business risk โ€” not just a security hole.

Hackers are using AI to scan for flaws 24/7. One bug in your VPN, and itโ€™s open season.

The fix? Stop trusting the network. Start securing access.

Details here โ†’ https://thehackernews.com/expert-insights/2025/04/its-time-to-rethink-your-security-for.html
๐Ÿ‘18๐Ÿ”ฅ3๐Ÿ‘1๐Ÿคฏ1
๐Ÿšจ CISA just flagged a live exploit in TP-Link routers (CVE-2023-33538, CVSS 8.8) โ€” attackers can run system commands remotely.

Worse? Many affected models may be end-of-life, with no fix coming.

Hereโ€™s what you need to know โ†“ https://thehackernews.com/2025/06/tp-link-router-flaw-cve-2023-33538.html
๐Ÿ˜ฑ17๐Ÿ‘5๐Ÿ”ฅ1
๐Ÿšจ Langflow flaw (CVSS 9.8) now exploited in the wild โ€” installs new Flodrix botnet

No login needed. One HTTP request = full remote control.

Targets AI servers for encrypted DDoS via TOR.

Details here โ†’ https://thehackernews.com/2025/06/new-flodrix-botnet-variant-exploits.html
๐Ÿ‘11๐Ÿ”ฅ4๐Ÿ‘1
๐Ÿšจ Sitecore flaw gives hackers full access โ€” with a single-character password.

A default login of โ€œbโ€ can be chained to remote code execution. It works pre-auth.

Used by banks, airlines, global firms. The blast radius is huge.

Hereโ€™s what you need to know โ†“ https://thehackernews.com/2025/06/hard-coded-b-password-in-sitecore-xp.html
๐Ÿ˜11๐Ÿ”ฅ4๐Ÿ‘2๐Ÿ˜ฑ1
๐Ÿšจ Ransomware is now destroying your backups first.

Hackers are targeting snapshots, wiping cloud copies, and deleting recovery paths โ€” before locking your systems.

The worst part? Many orgs donโ€™t realize it until itโ€™s too late.

Hereโ€™s how to bulletproof your backups โ†“ https://thehackernews.com/2025/06/how-to-protect-your-backups-from-ransomware-attacks.html
๐Ÿคฏ13๐Ÿ˜7๐Ÿ‘4๐Ÿ”ฅ3๐Ÿ‘2๐Ÿ˜ฑ1
๐Ÿšจ 24 million secrets exposed on GitHubโ€”and AI is making it worse.

Repos using Copilot are 40% more likely to leak credentials.

Think API keys, SSH tokensโ€ฆ the stuff attackers love.
The worst part? Most devs donโ€™t even know theyโ€™re leaking them.

Hereโ€™s how to fix it โ†“ https://thehackernews.com/expert-insights/2025/06/exposed-developer-secrets-are-big.html
๐Ÿ˜15๐Ÿ˜ฑ4๐Ÿ‘3๐Ÿ”ฅ2
๐Ÿ•ท๏ธ Scattered Spider is now hitting U.S. insurance giants โ€” not just retailers.

โš ๏ธ Theyโ€™re bypassing MFA, tricking help desks, and breaching entire IT ecosystems.

Hereโ€™s how they do it โ€” and how to stop them โ†“ https://thehackernews.com/2025/06/google-warns-of-scattered-spider.html
๐Ÿคฏ7๐Ÿ‘5๐Ÿ”ฅ1๐Ÿ‘1
๐Ÿšจ New phishing campaign hits Taiwan, delivering stealthy malware like Gh0stCringe and HoldingHands RAT.

Hackers use fake tax emails, sneaky PDFs, and ZIP traps to hijack systems and spy on users.

Itโ€™s all linked to China-backed Silver Fox APT.

Hereโ€™s whatโ€™s happening โ†’ https://thehackernews.com/2025/06/silver-fox-apt-targets-taiwan-with.html
๐Ÿ˜ฑ8๐Ÿ‘7๐Ÿ˜4๐Ÿค”1
๐Ÿšจ 130,000 devices. One forgotten service account.

A 2024 botnet attack used stale Microsoft 365 accounts with weak passwordsโ€”bypassing MFA silently via legacy auth.

If you're not auditing AD service accounts, you're already exposed.

Hereโ€™s how to fix it โ†“ https://thehackernews.com/2025/06/are-forgotten-ad-service-accounts.html
๐Ÿ˜21๐Ÿ‘1
๐Ÿšจ A LangChain vulnerability let attackers steal OpenAI API keys, prompts & filesโ€”just by clicking โ€œTry It.โ€

All data silently routed through a malicious proxy.

Details โ†’ https://thehackernews.com/2025/06/langchain-langsmith-bug-let-hackers.html

Patched nowโ€”but the risk was real.
๐Ÿคฏ7๐Ÿค”5๐Ÿ‘2๐Ÿ˜2
๐Ÿšจ A Chrome zero-day (CVE-2025-2783) was used in a live attack to drop a stealthy backdoor.

The hacker group TaxOff tricked targets with fake forum invitesโ€”one click, full compromise.

Hereโ€™s how the Trinper malware quietly hijacked systems โ†“ https://thehackernews.com/2025/06/google-chrome-zero-day-cve-2025-2783.html
๐Ÿ”ฅ21๐Ÿค”9โšก4๐Ÿ‘3๐Ÿ˜1๐Ÿคฏ1