The Hacker News Most trusted, widely-read independent cybersecurity news source for everyone; supported by hackers and IT professionals — Send TIPs to [email protected]
- WooCommerce Users Targeted by Fake Patch Phishing Campaign Deploying Site Backdoorsby [email protected] (The Hacker News) on 28 April 2025 at 8:06 am
Cybersecurity researchers are warning about a large-scale phishing campaign targeting WooCommerce users with a fake security alert urging them to download a "critical patch" but deploy a backdoor instead. WordPress security company Patchstack described the activity as sophisticated and a variant of another campaign observed in December 2023 that employed a fake CVE ploy to breach sites running
- Hackers Exploit Critical Craft CMS Flaws; Hundreds of Servers Likely Compromisedby [email protected] (The Hacker News) on 28 April 2025 at 7:13 am
Threat actors have been observed exploiting two newly disclosed critical security flaws in Craft CMS in zero-day attacks to breach servers and gain unauthorized access. The attacks, first observed by Orange Cyberdefense SensePost on February 14, 2025, involve chaining the below vulnerabilities - CVE-2024-58136 (CVSS score: 9.0) - An improper protection of alternate path flaw in the Yii PHP
- Storm-1977 Hits Education Clouds with AzureChecker, Deploys 200+ Crypto Mining Containersby [email protected] (The Hacker News) on 27 April 2025 at 5:02 am
Microsoft has revealed that a threat actor it tracks as Storm-1977 has conducted password spraying attacks against cloud tenants in the education sector over the past year. "The attack involves the use of AzureChecker.exe, a Command Line Interface (CLI) tool that is being used by a wide range of threat actors," the Microsoft Threat Intelligence team said in an analysis. The tech giant noted that
- ToyMaker Uses LAGTOY to Sell Access to CACTUS Ransomware Gangs for Double Extortionby [email protected] (The Hacker News) on 26 April 2025 at 10:38 am
Cybersecurity researchers have detailed the activities of an initial access broker (IAB) dubbed ToyMaker that has been observed handing over access to double extortion ransomware gangs like CACTUS. The IAB has been assessed with medium confidence to be a financially motivated threat actor, scanning for vulnerable systems and deploying a custom malware called LAGTOY (aka HOLERUN). "LAGTOY can be
- North Korean Hackers Spread Malware via Fake Crypto Firms and Job Interview Luresby [email protected] (The Hacker News) on 25 April 2025 at 2:05 pm
North Korea-linked threat actors behind the Contagious Interview have set up front companies as a way to distribute malware during the fake hiring process. "In this new campaign, the threat actor group is using three front companies in the cryptocurrency consulting industry—BlockNovas LLC (blocknovas[.] com), Angeloper Agency (angeloper[.]com), and SoftGlide LLC (softglide[.]co)—to spread