The Hacker News
152K subscribers
1.87K photos
10 videos
3 files
7.79K links
Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

📨 Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
Uber is investigating a new breach of its network after a hacker appears to have compromised an employee's Slack account and accessed other internal systems.

Read: https://thehackernews.com/2022/09/uber-says-its-investigating-potential.html
😱37🔥2117👍10😁9🤔6👏5🤯4
Researchers have uncovered two separate malicious cryptocurrency mining campaigns; one exploiting Oracle WebLogic to control vulnerable servers, while the other targets misconfigured Docker containers.

Read: https://thehackernews.com/2022/09/hackers-targeting-weblogic-servers-and.html
🤯29👍14👏5😁5
North Korean hackers have been found leveraging a "novel spear-phish method" that involves making use of trojanized versions of the PuTTY SSH and Telnet client.

Read: https://thehackernews.com/2022/09/north-korean-hackers-spreading.html
👍32🔥8🤔5👏1
New connections between two widely used pay-per-install (PPI) malware distribution services have been discovered, revealing that PrivateLoader is the proprietary loader for Ruzki's PPI service.

Read: https://thehackernews.com/2022/09/researchers-find-link-bw-privateloader.html
👍38🤔3👏2
A recent breach at password management solution LastPass gave hackers access to the company's systems for a 4-days, but "there is no evidence that customer data or encrypted password vaults were accessed."

Read: https://thehackernews.com/2022/09/hackers-had-access-to-lastpasss.html
😁46😱23🤔21👍209🔥9
Uber claims to have found "no evidence" that users' private data was compromised in the recent breach, but screenshots and information from other sources suggest there may be more to this story.

Read: https://thehackernews.com/2022/09/uber-claims-no-sensitive-data-exposed.html
🔥59😁31🤔26👍217
Microsoft warns of an ongoing large-scale CLICK fraud campaign targeting gamers by secretly installing browser extensions on compromised systems.

Read: https://thehackernews.com/2022/09/microsoft-warns-of-large-scale-click.html
👍46😁11👏4
Bitdefender has released a free decryptor for LockerGoga ransomware in collaboration with Europol and Zurich law enforcement.

Read: https://thehackernews.com/2022/09/europol-and-bitdefender-release-free.html
👏50👍2111🔥4
After Conti group officially withdrew from the threat landscape, ransomware-as-a-service groups such as Quantum and BlackCat have recently been spotted using the Emotet botnet to expand their reach.

Read: https://thehackernews.com/2022/09/emotet-botnet-started-distributing.html
👍368🤔3
American video game publisher Rockstar Games has confirmed that a hacker illegally downloaded early footage of Grand Theft Auto VI.

Read: https://thehackernews.com/2022/09/rockstar-games-confirms-hacker-stole.html
😁75🔥27👍2215🤯14😱11👏3🤔1
Uber says the hacker responsible for the latest security breach is linked to the Lapsus$ extortion group.

Read: https://thehackernews.com/2022/09/uber-blames-lapsus-hacking-group-for.html
🤔42🔥157👍7😁7
Researchers have discovered a threat cluster associated with Sandworm that continues to attack Ukraine with off-the-shelf #malware masquerading as telecommunications providers.

Read: https://thehackernews.com/2022/09/russian-sandworm-hackers-impersonate.html
😁23🤔16👍14🔥5
CISA and Claroty researchers warn of newly identified critical remotely exploitable vulnerabilities in Dataprobe's popular iBoot-PDU power distribution unit product, mostly used in industrial environments and data centers.

Read: https://thehackernews.com/2022/09/critical-remote-hack-flaws-found-in.html
🤯17👍126🤔4
Researchers recorded a massive DDoS attack involving more than 25.3 billion requests from nearly 170,000 IPs that included routers, security cameras and compromised servers in more than 180 countries, including the U.S., Indonesia and Brazil.

https://thehackernews.com/2022/09/record-ddos-attack-with-253-billion.html
🤯6611👍7👏4🔥3
U.S. Federal Communications Commission (FCC) has added two more Chinese telecommunication companies, ComNet & China Unicom, to its list of communications equipment and services deemed a threat to national security.

Read: https://thehackernews.com/2022/09/us-adds-2-more-chinese-telecom-firms-to.html
😁27👍10🤔8👏7🔥65🤯5
Hackers stole $160 million worth of digital assets from crypto trading platform Wintermute.

Read: https://thehackernews.com/2022/09/crypto-trading-firm-wintermute-loses.html
🤯59😁22😱16👍86🔥5👏5🤔3
Researchers found over 39,000 unauthenticated Redis database instances exposed on the Internet, nearly 50% of which showed signs of attempted compromise.

Read: https://thehackernews.com/2022/09/over-39000-unauthenticated-redis.html
👍40🤔8😱6🔥4
Hackers are actively exploiting an unauthenticated RCE vulnerability (CVE-2022-26134) in unpatched Atlassian Confluence servers to deploy cryptocurrency mining malware.

Read: https://thehackernews.com/2022/09/hackers-targeting-unpatched-atlassian.html
👏30🤯12👍10😁8🔥2
A 15-year-old unpatched Python vulnerability potentially affects as many as 350,000 open-source projects, leaving them vulnerable to code execution attacks.

Read: https://thehackernews.com/2022/09/15-year-old-unpatched-python.html
🤯82😱17😁15🤔7👍43👏2
Researchers have uncovered a new vulnerability in Oracle Cloud Infrastructure (OCI) that could be exploited by users to access the virtual disks of other Oracle customers.

Read: https://thehackernews.com/2022/09/researchers-disclose-critical.html
24👍17😱6🤔5👏3
A malicious NPM package masquerading as Material Tailwind has been discovered, indicating that threat actors are attempting to distribute malicious code via open source software repositories.

Read: https://thehackernews.com/2022/09/malicious-npm-package-caught-mimicking.html
😱28👍14🤯6