The Hacker News
151K subscribers
1.84K photos
10 videos
3 files
7.76K links
Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

📨 Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
Ugh, not again! Multiple malware campaigns discovered targeting Python and JavaScript developers via the official PyPI and npm repositories.

Read: https://thehackernews.com/2022/12/malware-strains-targeting-python-and.html
🤯29👍128👏4🤔2
Cybersecurity researchers have unveiled the inner workings of a devastating new ransomware known as Azov, designed to corrupt data and inflict "impeccable damage" on compromised systems.

Read: https://thehackernews.com/2022/12/cybersecurity-experts-uncover-inner.html
18👍9🔥3😱3👏2
This severe vulnerability affecting the Amazon ECR Public Gallery may have opened the repositories to potential "deep #software supply chain" attacks.

Read: https://thehackernews.com/2022/12/serious-attacks-could-have-been-staged.html
🤯19👍10🔥41
Google launches open source availability of OSV-Scanner, a scanner that aims to offer easy access to vulnerability information about various projects.

Read: https://thehackernews.com/2022/12/google-launches-largest-distributed.html
🤔20👏12🔥9👍52
Zero-day vulnerability alert!

Apple has released security updates to patch a new "actively exploited" 0-day code execution vulnerability.

Make sure to update your iOS, iPadOS, macOS, tvOS, and Safari to keep your devices secure.

https://thehackernews.com/2022/12/new-actively-exploited-zero-day.html
🔥26👍16😁64😱4
Warning: Hackers are exploiting a new critical zero-day RCE vulnerability (CVE-2022-27518) in Citrix ADC & Gateway to gain control of affected systems.

https://thehackernews.com/2022/12/hackers-actively-exploiting-citrix-adc.html

It is important that users apply latest security patches immediately to protect against this threat.
👍20😱112
Stay protected against new vulnerabilities and zero-day attacks by ensuring your devices are up to date with the latest December 2022 Patch Tuesday security updates from Microsoft, Adobe, Apple, Cisco and other major vendors.

https://thehackernews.com/2022/12/december-2022-patch-tuesday-get-latest.html
🔥23👍14👏53
Researchers reveal attackers use legitimate Microsoft-signed drivers in ransomware and malware campaigns against various companies

Read: https://thehackernews.com/2022/12/ransomware-attackers-use-microsoft.html
16🤯11👍10🔥4
New Go-Based "GoTrim" Botnet Threatens WordPress Sites: Protect Your Admin Account Now!

Details: https://thehackernews.com/2022/12/new-gotrim-botnet-attempting-to-break.html
👍23😱129😁7
FBI has charged 6 individuals and seized 48 domains linked to DDoS-for-hire service platforms.

Read: https://thehackernews.com/2022/12/fbi-charges-6-seizes-48-domains-linked.html
👏23👍8😁6🔥42
Have you heard about how attackers can use SVG files to secretly sneak QBot malware onto Windows systems?

Read this report for more details: https://thehackernews.com/2022/12/hacking-using-svg-files-to-smuggle-qbot.html
🤯32👍96🔥3😁1
Open source repositories under attack: hackers flood NuGet, NPM, and PyPi with over 144,000 malicious packages

Details: https://thehackernews.com/2022/12/hackers-bombard-open-source.html
😱36👍14🤯109🔥7👏4🤔2
MoneyMonger!

Be on alert for a new Android malware campaign using money-lending apps to blackmail victims with stolen personal information.

Read: https://thehackernews.com/2022/12/android-malware-campaign-leverages.html
😱19👍1413🤯7🔥2
Windows users, beware!

Microsoft has reclassified SPNEGO Extended Negotiation Security vulnerability as CRITICAL because it can be exploited to perform RCE attacks via Windows app protocols that use authentication, such as HTTP, SMB, and RDP.

https://thehackernews.com/2022/12/microsoft-reclassifies-spnego-extended.html
🤯41👍18😁98🤔7🔥5
GitHub is making its secret scanning service available for free to all public repositories and also plans to require 2-factor authentication for "distinct groups of users."

Read: https://thehackernews.com/2022/12/github-announces-free-secret-scanning.html
👍23👏12😁1
U.S. cybersecurity agency CISA has added two critical vulnerabilities in Veeam Backup & Replication software to its list of known exploited vulnerabilities, as they are actively being exploited in attacks.

Details: https://thehackernews.com/2022/12/cisa-alert-veeam-backup-and-replication.html
👍21😁2🔥1
NIST has formally retired the widely used 27-year-old SHA-1 cryptographic algorithm, bringing cryptographic security into the modern age.

Read: https://thehackernews.com/2022/12/goodbye-sha-1-nist-retires-27-year-old.html
👍48
Microsoft has identified a cross-platform botnet malware that is targeting private Minecraft servers with DDoS attacks.

Details: https://thehackernews.com/2022/12/minecraft-servers-under-attack.html
👍29😱3🤔1🤯1
Chinese MirrorFace APT hacker group has been blamed for a malicious campaign aimed at Japanese political entities.

Read: https://thehackernews.com/2022/12/researchers-uncover-mirrorface-cyber.html
👍18😱7👏2🔥1
A former Twitter employee has been sentenced to three and a half years in prison for spying on data about certain individuals and passing it on to the Saudi government.

Read: https://thehackernews.com/2022/12/ex-twitter-employee-gets-35-years-jail.html
👍37🤯21😁15👏10🔥94
Researchers have uncovered a new cyberattack campaign targeting Ukrainian government entities via trojanized Windows 10 operating system installers to perform post-exploitation activities.

Read: https://thehackernews.com/2022/12/trojanized-windows-10-installer-used-in.html
👍34🔥13🤯11🤔3😱3