The Hacker News
βœ”
151K subscribers
1.86K photos
10 videos
3 files
7.77K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
Another day, another vulnerability!

Researchers have uncovered a new vulnerability affecting multiple services related to Microsoft Azure, which could result in RCE attacks, data theft, and lateral movement within Azure services.

https://thehackernews.com/2023/01/new-microsoft-azure-vulnerability.html
πŸ”₯46πŸ‘15😱10🀯7⚑5πŸ‘5😁5πŸ€”4
Researchers are warning of a new Chinese #malware called "BOLDMOVE" that exploited a recently discovered vulnerability in Fortinet FortiOS SSL-VPN (CVE-2022-42475) as a zero-day to attack government entities & managed service providers.

https://thehackernews.com/2023/01/new-chinese-malware-spotted-exploiting.html
πŸ‘34πŸ€”14πŸ”₯9🀯5⚑2
Big fines for WhatsApp!

Irish Data Protection Commission imposed a €5.5 million penalty for violating data protection laws when processing users' personal information.

Details: https://thehackernews.com/2023/01/whatsapp-hit-with-55-million-fine-for.html
πŸ‘43πŸ‘22😁11πŸ”₯10
Russian state-sponsored cyber espionage group Gamaredon is back and targeting Ukraine's military and law enforcement entities through Telegram.

Read: https://thehackernews.com/2023/01/gamaredon-group-launches-cyberattacks.html
πŸ”₯41πŸ‘19πŸ€”11⚑8🀯6πŸ‘4😱4😁1
Beware of 'Roaming Mantis' cybercriminals spreading an updated version of its mobile malware, called "Wroba", β€” it now hijacks DNS settings of connected Wi-Fi routers for malicious attacks.

Read details: https://thehackernews.com/2023/01/roaming-mantis-spreading-mobile-malware.html
πŸ‘47🀯18πŸ‘9😱8⚑6πŸ€”3
Researchers have successfully shut down a large-scale AD fraud scheme known as VASTFLUX, which targeted a total of 11 million devices and involved over 1,700 spoofed apps.

Details: https://thehackernews.com/2023/01/massive-ad-fraud-scheme-targeted-over.html
πŸ‘23πŸ‘17πŸ”₯9⚑6😱6
New findings indicate that the Sliver C2 framework is gaining popularity among threat actors as a versatile alternative to traditional C2 tools such as Cobalt Strike and Metasploit.

Read details: https://thehackernews.com/2023/01/threat-actors-turn-to-sliver-as-open.html
πŸ‘30⚑8
Researchers report two vulnerabilities in Samsung's Galaxy Store app that could be exploited to secretly install malicious apps or redirect users to fake landing pages on the Internet.

Read details: https://thehackernews.com/2023/01/samsung-galaxy-store-app-found.html
🀯38πŸ‘17😱9😁8πŸ€”3πŸ‘1
Over the next few months, millions of people around the world will have access to end-to-end encrypted chats on Facebook Messenger, as well as access to new additional features.

Read details: https://thehackernews.com/2023/01/facebook-introduces-new-features-for.html
πŸ‘42😁15πŸ€”5πŸ‘3
Apple has released updates for a security vulnerability in Webkit that affects older iPhone & iPad devices.

Read: https://thehackernews.com/2023/01/apple-issues-updates-for-older-devices.html

This vulnerability is currently being exploited, so it is important to update your device immediately.
πŸ‘40😁7😱5πŸ‘4πŸ”₯3
Cybercriminals are always evolving their tactics, and the Emotet operation is no exception.

Emotet malware now using new tactics to fly under the radar and act as a conduit for other dangerous malware like Bumblebee and IcedID.

Read: https://thehackernews.com/2023/01/emotet-malware-makes-comeback-with-new.html
πŸ”₯23πŸ‘9πŸ‘3⚑2🀯1😱1
FBI has confirmed that the North Korean state-sponsored hacking group known as Lazarus Group and APT38 are responsible for the theft of $100 million in cryptocurrency assets from Harmony Horizon Bridge.

Details: https://thehackernews.com/2023/01/fbi-says-north-korean-hackers-behind.html
πŸ‘35😱26πŸ”₯11πŸ€”7⚑5😁5
Chinese-speaking actor behind DragonSpark attacks targeting organizations in East Asia using Golang malware and unusual techniques to evade detection.

Read details: https://thehackernews.com/2023/01/chinese-hackers-utilize-golang-malware.html
πŸ‘33⚑11πŸ‘3😁2πŸ€”2🀯2
VMware releases patch for 4 vulnerabilities in vRealize Log Insight, including 2 critical flaws (CVE-2022-31706 and CVE-2022-31704) that could lead to remote code execution attacks.

Read details: https://thehackernews.com/2023/01/vmware-releases-patches-for-critical.html
πŸ‘30πŸ‘2
LastPass’ parent company GoTo (formerly LogMeIn) has experienced a data breach in which cybercriminals stole customers' encrypted backups and an encryption key used to secure data for some customers.

Read: https://thehackernews.com/2023/01/lastpass-parent-company-goto-suffers.html
🀯52πŸ”₯16😁13😱9πŸ‘7⚑5
North Korean group APT38 is targeting cryptocurrency holders by using credential harvesting as a new weapon in its quest for crypto riches.

Read details: https://thehackernews.com/2023/01/north-korean-hackers-turn-to-credential.html
πŸ‘20🀯11πŸ”₯5😁5πŸ€”4
Warning: A massive malware campaign has infected more than 4,500 WordPress websites and is redirecting their visitors to sketchy ad pages.

Read: https://thehackernews.com/2023/01/over-4500-wordpress-sites-hacked-to.html

Keep your website secure and always be cautious of suspicious links.
πŸ‘38😱14πŸ”₯9πŸ‘5⚑3😁1🀯1
ALERT: Two federal agencies in the U.S. have fallen victim to a widespread malicious campaign using RMM software for phishing scams.

Read details: https://thehackernews.com/2023/01/us-federal-agencies-fall-victim-to.html
🀯27πŸ‘8😱8⚑7πŸ”₯7😁4
New research has uncovered connections between the operations of Moses Staff and Abraham's Ax, two politically motivated hacktivist groups.

Read details: https://thehackernews.com/2023/01/researchers-uncover-connection-bw-moses.html
πŸ‘12⚑3πŸ”₯2
Researchers have released proof-of-concept exploit code for a high-severity security vulnerability (CVE-2022-34689) in the Windows CryptoAPI, which was discovered by the NSA and NCSC.

Read details: https://thehackernews.com/2023/01/researchers-release-poc-exploit-for.html
πŸ‘22😱10⚑3πŸ”₯1
Researchers have identified a new Python-based malware that uses WebSockets for both command and control communication and data exfiltration.

Read details: https://thehackernews.com/2023/01/pyration-new-python-based-rat-utilizes.html
πŸ‘22πŸ”₯8⚑5😁2