The Hacker News
152K subscribers
1.88K photos
10 videos
3 files
7.79K links
Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

📨 Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
🚨 New ransomware “Anubis” can encrypt your files—and then erase them forever.

Even if you pay, recovery is impossible. Victims span healthcare, hospitality & more.

This rare dual-threat ups the pressure to pay.

Details here → https://thehackernews.com/2025/06/anubis-ransomware-encrypts-and-wipes.html
🤯19🔥10😱73👍2
🚨 U.S. seizes $7.7M linked to North Korean IT worker scam targeting crypto firms.

Fake identities, AI tools, and Zoom hacks helped funnel millions to fund Pyongyang’s weapons program.

Here’s how deep the deception goes ↓ https://thehackernews.com/2025/06/us-seizes-774m-in-crypto-tied-to-north.html
😁18🤔8🤯7👍65
🚨 WhatsApp ads are finally here—inside your Status updates.

Meta says it’s privacy-friendly, but it’s tapping your location, device data, and even Facebook activity to target you.

Here’s what’s changing ↓ https://thehackernews.com/2025/06/meta-starts-showing-ads-on-whatsapp.html
😱25😁16🤯14👍53🤔2🔥1👏1
🚨 VPNs are now a business risk — not just a security hole.

Hackers are using AI to scan for flaws 24/7. One bug in your VPN, and it’s open season.

The fix? Stop trusting the network. Start securing access.

Details here → https://thehackernews.com/expert-insights/2025/04/its-time-to-rethink-your-security-for.html
👍18🔥3👏1🤯1
🚨 CISA just flagged a live exploit in TP-Link routers (CVE-2023-33538, CVSS 8.8) — attackers can run system commands remotely.

Worse? Many affected models may be end-of-life, with no fix coming.

Here’s what you need to know ↓ https://thehackernews.com/2025/06/tp-link-router-flaw-cve-2023-33538.html
😱17👍5🔥1
🚨 Langflow flaw (CVSS 9.8) now exploited in the wild — installs new Flodrix botnet

No login needed. One HTTP request = full remote control.

Targets AI servers for encrypted DDoS via TOR.

Details here → https://thehackernews.com/2025/06/new-flodrix-botnet-variant-exploits.html
👍11🔥4👏1
🚨 Sitecore flaw gives hackers full access — with a single-character password.

A default login of “b” can be chained to remote code execution. It works pre-auth.

Used by banks, airlines, global firms. The blast radius is huge.

Here’s what you need to know ↓ https://thehackernews.com/2025/06/hard-coded-b-password-in-sitecore-xp.html
😁11🔥4👍2😱1
🚨 Ransomware is now destroying your backups first.

Hackers are targeting snapshots, wiping cloud copies, and deleting recovery paths — before locking your systems.

The worst part? Many orgs don’t realize it until it’s too late.

Here’s how to bulletproof your backups ↓ https://thehackernews.com/2025/06/how-to-protect-your-backups-from-ransomware-attacks.html
🤯13😁7👍4🔥3👏2😱1
🚨 24 million secrets exposed on GitHub—and AI is making it worse.

Repos using Copilot are 40% more likely to leak credentials.

Think API keys, SSH tokens… the stuff attackers love.
The worst part? Most devs don’t even know they’re leaking them.

Here’s how to fix it ↓ https://thehackernews.com/expert-insights/2025/06/exposed-developer-secrets-are-big.html
😁15😱4👍3🔥2
🕷️ Scattered Spider is now hitting U.S. insurance giants — not just retailers.

⚠️ They’re bypassing MFA, tricking help desks, and breaching entire IT ecosystems.

Here’s how they do it — and how to stop them ↓ https://thehackernews.com/2025/06/google-warns-of-scattered-spider.html
🤯7👍5🔥1👏1
🚨 New phishing campaign hits Taiwan, delivering stealthy malware like Gh0stCringe and HoldingHands RAT.

Hackers use fake tax emails, sneaky PDFs, and ZIP traps to hijack systems and spy on users.

It’s all linked to China-backed Silver Fox APT.

Here’s what’s happening → https://thehackernews.com/2025/06/silver-fox-apt-targets-taiwan-with.html
😱8👍7😁4🤔1
🚨 130,000 devices. One forgotten service account.

A 2024 botnet attack used stale Microsoft 365 accounts with weak passwords—bypassing MFA silently via legacy auth.

If you're not auditing AD service accounts, you're already exposed.

Here’s how to fix it ↓ https://thehackernews.com/2025/06/are-forgotten-ad-service-accounts.html
😁21👍1
🚨 A LangChain vulnerability let attackers steal OpenAI API keys, prompts & files—just by clicking “Try It.”

All data silently routed through a malicious proxy.

Details → https://thehackernews.com/2025/06/langchain-langsmith-bug-let-hackers.html

Patched now—but the risk was real.
🤯7🤔5👍2😁2
🚨 A Chrome zero-day (CVE-2025-2783) was used in a live attack to drop a stealthy backdoor.

The hacker group TaxOff tricked targets with fake forum invites—one click, full compromise.

Here’s how the Trinper malware quietly hijacked systems ↓ https://thehackernews.com/2025/06/google-chrome-zero-day-cve-2025-2783.html
🔥21🤔94👍3😁1🤯1
🚨 Iran slows internet access following Israeli missile strikes and cyber attacks on Bank Sepah.

Both sides ramp up digital warfare as state hackers and hacktivist groups escalate regional cyber conflict.

Here’s what’s unfolding ↓ https://thehackernews.com/2025/06/iran-restricts-internet-access-to.html
😁19😱14👍4🔥1
⚠️ Critical flaw in Veeam Backup (CVSS 9.9) lets attackers execute code remotely—even after a prior patch.

Researchers warn: the old fix could be bypassed. New version out now.

Don’t wait. Update now → https://thehackernews.com/2025/06/veeam-patches-cve-2025-23121-critical.html
👍16😱1
🛠️🔓 A critical Linux kernel flaw (CVE-2023-0386) is now confirmed actively exploited—granting root access via a simple trick.

CISA just added it to the KEV list. Agencies have until July 8 to fix it.

Details here → https://thehackernews.com/2025/06/cisa-warns-of-active-exploitation-of.html
🔥20😱2👍1
A CIA analyst stole Top Secret docs—including Israel's plans to strike Iran—and leaked them online.

He tried to cover his tracks with image edits and file wipes.

Now? Just 37 months in prison.

Here’s what happened ↓ https://thehackernews.com/2025/06/ex-cia-analyst-sentenced-to-37-months.html
👍23👏8😁6🤯4🤔2
Tacking on compliance late? You risk more than fines—think failed audits, stalled deals, and fragile systems.

Build it in from day one.

Here's why ↓ https://thehackernews.com/expert-insights/2025/06/the-hidden-cost-of-treating-compliance.html
🤯5👏3👍2
🧪⚠️ Water Curse hijacked 76 GitHub repos to spread stealthy, multi-stage malware.

Posing as dev tools, it steals credentials, hijacks sessions, and persists undetected—active since March 2023.

Details → https://thehackernews.com/2025/06/water-curse-hijacks-76-github-accounts.html
🤯13😱5