The Hacker News Most trusted, widely-read independent cybersecurity news source for everyone; supported by hackers and IT professionals — Send TIPs to [email protected]
- 200+ Trojanized GitHub Repositories Found in Campaign Targeting Gamers and Developersby [email protected] (The Hacker News) on 20 June 2025 at 7:41 am
Cybersecurity researchers have uncovered a new campaign in which the threat actors have published more than 67 GitHub repositories that claim to offer Python-based hacking tools, but deliver trojanized payloads instead. The activity, codenamed Banana Squad by ReversingLabs, is assessed to be a continuation of a rogue Python campaign that was identified in 2023 as targeting the Python Package
- New Android Malware Surge Hits Devices via Overlays, Virtualization Fraud and NFC Theftby [email protected] (The Hacker News) on 19 June 2025 at 5:23 pm
Cybersecurity researchers have exposed the inner workings of an Android malware called AntiDot that has compromised over 3,775 devices as part of 273 unique campaigns. "Operated by the financially motivated threat actor LARVA-398, AntiDot is actively sold as a Malware-as-a-Service (MaaS) on underground forums and has been linked to a wide range of mobile campaigns," PRODAFT said in a report
- BlueNoroff Deepfake Zoom Scam Hits Crypto Employee with macOS Backdoor Malwareby [email protected] (The Hacker News) on 19 June 2025 at 11:38 am
The North Korea-aligned threat actor known as BlueNoroff has been observed targeting an employee in the Web3 sector with deceptive Zoom calls featuring deepfaked company executives to trick them into installing malware on their Apple macOS devices. Huntress, which revealed details of the cyber intrusion, said the attack targeted an unnamed cryptocurrency foundation employee, who received a
- Secure Vibe Coding: The Complete New Guideby [email protected] (The Hacker News) on 19 June 2025 at 11:25 am
DALL-E for coders? That’s the promise behind vibe coding, a term describing the use of natural language to create software. While this ushers in a new era of AI-generated code, it introduces "silent killer" vulnerabilities: exploitable flaws that evade traditional security tools despite perfect test performance. A detailed analysis of secure vibe coding practices is available here. TL;DR: Secure
- Uncover LOTS Attacks Hiding in Trusted Tools — Learn How in This Free Expert Sessionby [email protected] (The Hacker News) on 19 June 2025 at 10:00 am
Most cyberattacks today don’t start with loud alarms or broken firewalls. They start quietly—inside tools and websites your business already trusts. It’s called “Living Off Trusted Sites” (LOTS)—and it’s the new favorite strategy of modern attackers. Instead of breaking in, they blend in. Hackers are using well-known platforms like Google, Microsoft, Dropbox, and Slack as launchpads. They hide