The Hacker News
βœ”
151K subscribers
1.85K photos
10 videos
3 files
7.77K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
🚨 Cisco issued an alert about a new zero-day vulnerability in IOS XE (CVE-2023-20273). Attackers are actively exploiting it to install a malicious Lua-based implant on vulnerable devices.

Learn more: https://thehackernews.com/2023/10/cisco-zero-day-exploited-to-implant.html
πŸ”₯20πŸ‘10πŸ€”5🀯3
🚨 Alert: Identity services provider Okta discloses breach, impacting customers including BeyondTrust and Cloudflare. Unidentified threat actors accessed the support system.

Learn more: https://thehackernews.com/2023/10/oktas-support-system-breach-exposes.html
πŸ‘27😁13😱11πŸ”₯7🀯3
Big Wins Against Cybercrime!

β€” Europol takes down Ragnar Locker ransomware's infrastructure, arrests key suspect in France.

β€” Trigona leak site infiltrated and shut down.

β€” India's CBI conducts nationwide raids on cyber-enabled financial crime infrastructure.

Read: https://thehackernews.com/2023/10/europol-dismantles-ragnar-locker.html
πŸ”₯63πŸ‘32πŸ‘11😱10😁6πŸ€”4⚑2🀯2
πŸ•΅οΈβ€β™‚οΈ Beware of Quasar RAT: A sneaky malware exploiting DLL side-loading to hide its tracks on compromised Windows systems.

Learn more: https://thehackernews.com/2023/10/quasar-rat-leverages-dll-side-loading.html
πŸ‘22😁5🀯4
DoNot Team Strikes Again. Learn about the new .NET-based backdoor, Firebird, targeting victims in Pakistan and Afghanistan.

Learn more: https://thehackernews.com/2023/10/donot-teams-new-firebird-backdoor-hits.html
πŸ‘29😁7
Worried about AI tool proliferation in your organization? Get immediate visibility with Nudge Security.

Discover what AI tools your employees are using from Day 1. Stay in control of AI's impact on your business.

Read: https://thehackernews.com/2023/10/whos-experimenting-with-ai-tools-in.html
πŸ‘30πŸ”₯9😱3
πŸ“£ Heads up! Popular password management solution "1Password" detected suspicious activity related to a recent "Okta" support system breach.

Fortunately, user data was unaffected, but here's what you need to know: https://thehackernews.com/2023/10/1password-detects-suspicious-activity.html
πŸ‘17🀯15😁6
🚨 Discover how threat actors modified the backdoor implanted on compromised Cisco devices by exploiting zero-day flaws in IOS XE software, evading detection with new techniques.

Learn about the implant's updated behavior: https://thehackernews.com/2023/10/backdoor-implant-on-hacked-cisco.html
πŸ”₯22πŸ‘11
πŸ“’ Attention iOS users:

Experts have unearthed crucial insights about the TriangleDB implant, which targets Apple iOS devices. It can record audio, pilfer #iCloud Keychain data, and more.

Learn more: https://thehackernews.com/2023/10/operation-triangulation-experts-uncover.html
πŸ”₯15πŸ‘12🀯8😁5πŸ‘4⚑1
Spanish authorities bust cybercriminal group behind €3 million online scam. Weapons, cash, and more seized.

Full story: https://thehackernews.com/2023/10/34-cybercriminals-arrested-in-spain-for.html
πŸ”₯17πŸ‘7πŸ‘5πŸ€”5
Strong security is no longer a luxuryβ€”it's a necessity.

Find out how to secure your APIs with modern authentication and encryption methods in our latest article: https://thehackernews.com/2023/10/make-api-management-less-scary-for-your.html
πŸ‘19πŸ‘13
⚑️ Ex-NSA employeeβ€”working as an Information Systems Security Designerβ€”has pleaded guilty to attempting to transmit classified defense information to Russia, seeking $85,000 in exchange.

Read details here: https://thehackernews.com/2023/10/ex-nsa-employee-pleads-guilty-to.html
🀯39πŸ‘20😁11πŸ‘9πŸ”₯7⚑5😱5
🚨 Urgent: Proof-of-concept (PoC) exploits have been publicly released for the recently discovered vulnerabilities in VMware Aria Operations, Citrix NetScaler ADC, and NetScaler Gateway.

Read: https://thehackernews.com/2023/10/alert-poc-exploits-released-for-citrix.html

Don't waitβ€”apply fixes now and safeguard your systems.
πŸ”₯18πŸ‘8⚑4πŸ€”4🀯4😱2
Cybercriminals are targeting Brazil's popular PIX payment system using a new malware called GoPIX, delivered to users via malvertising campaigns when they search for "WhatsApp web."

Learn more πŸ‘‰ https://thehackernews.com/2023/10/malvertising-campaign-targets-brazils.html
πŸ”₯16⚑4πŸ‘4🀯3
🚨 VMware releases crucial security updates to fix a new critical vulnerability (CVE-2023-34048) in vCenter Server.

Details in the article: https://thehackernews.com/2023/10/act-now-vmware-releases-patch-for.html

Protect your systems from remote code execution.
πŸ‘17πŸ‘16πŸ”₯1
CloudTrail and Server Access Logs provide critical insights into Amazon S3 security. Find out how to use them effectively to prevent ransomware attacks.

Read: https://thehackernews.com/2023/10/the-rise-of-s3-ransomware-how-to.html
πŸ‘21🀯1
Popular online services like Grammarly, Vidio, and Bukalapak faced critical security vulnerabilities in their OAuth implementation that could have allowed hackers to hijack user accounts.

Find details here: https://thehackernews.com/2023/10/critical-oauth-flaws-uncovered-in.html
😱17πŸ‘10😁9
⚠️ WARNING β€” Winter Vivern, a notorious nation-state hacker group with links to Belarus and Russia, exploiting a zero-day flaw in Roundcube webmail software to steal email messages.

Learn more: https://thehackernews.com/2023/10/nation-state-hackers-exploiting-zero.html
πŸ‘17🀯11πŸ‘3😁2πŸ”₯1
🚨 Meet YoroTrooper: A mysterious threat actor with ties to Kazakhstan. Learn how they're using custom tools and stealthy tactics to infiltrate state-owned entities across CIS countries.

Read: https://thehackernews.com/2023/10/yorotrooper-researchers-warn-of.html
🀯9πŸ‘5πŸ‘4
πŸš‘ Healthcare IT professionals, take note.

A critical RCE vulnerability (CVE-2023-43208) has been uncovered in Mirth Connect, a healthcare data integration platform.

Read: https://thehackernews.com/2023/10/critical-flaw-in-nextgens-mirth-connect.html

Update to version 4.4.1 immediately to prevent unauthorized access.
πŸ‘17πŸ”₯3😱3
🚨 ALERT: Iranian threat actor, Tortoiseshell, strikes again with new malware, IMAPLoader.

This .NET malware uses email as a command-and-control channel and targets maritime and logistics sectors.

Learn more: https://thehackernews.com/2023/10/iranian-group-tortoiseshell-launches.html
πŸ”₯19πŸ‘11🀯11😁4πŸ€”2⚑1