The Hacker News
βœ”
151K subscribers
1.85K photos
10 videos
3 files
7.76K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
⚑️ Ex-NSA employeeβ€”working as an Information Systems Security Designerβ€”has pleaded guilty to attempting to transmit classified defense information to Russia, seeking $85,000 in exchange.

Read details here: https://thehackernews.com/2023/10/ex-nsa-employee-pleads-guilty-to.html
🀯39πŸ‘20😁11πŸ‘9πŸ”₯7⚑5😱5
🚨 Urgent: Proof-of-concept (PoC) exploits have been publicly released for the recently discovered vulnerabilities in VMware Aria Operations, Citrix NetScaler ADC, and NetScaler Gateway.

Read: https://thehackernews.com/2023/10/alert-poc-exploits-released-for-citrix.html

Don't waitβ€”apply fixes now and safeguard your systems.
πŸ”₯18πŸ‘8⚑4πŸ€”4🀯4😱2
Cybercriminals are targeting Brazil's popular PIX payment system using a new malware called GoPIX, delivered to users via malvertising campaigns when they search for "WhatsApp web."

Learn more πŸ‘‰ https://thehackernews.com/2023/10/malvertising-campaign-targets-brazils.html
πŸ”₯16⚑4πŸ‘4🀯3
🚨 VMware releases crucial security updates to fix a new critical vulnerability (CVE-2023-34048) in vCenter Server.

Details in the article: https://thehackernews.com/2023/10/act-now-vmware-releases-patch-for.html

Protect your systems from remote code execution.
πŸ‘17πŸ‘16πŸ”₯1
CloudTrail and Server Access Logs provide critical insights into Amazon S3 security. Find out how to use them effectively to prevent ransomware attacks.

Read: https://thehackernews.com/2023/10/the-rise-of-s3-ransomware-how-to.html
πŸ‘21🀯1
Popular online services like Grammarly, Vidio, and Bukalapak faced critical security vulnerabilities in their OAuth implementation that could have allowed hackers to hijack user accounts.

Find details here: https://thehackernews.com/2023/10/critical-oauth-flaws-uncovered-in.html
😱17πŸ‘10😁9
⚠️ WARNING β€” Winter Vivern, a notorious nation-state hacker group with links to Belarus and Russia, exploiting a zero-day flaw in Roundcube webmail software to steal email messages.

Learn more: https://thehackernews.com/2023/10/nation-state-hackers-exploiting-zero.html
πŸ‘17🀯11πŸ‘3😁2πŸ”₯1
🚨 Meet YoroTrooper: A mysterious threat actor with ties to Kazakhstan. Learn how they're using custom tools and stealthy tactics to infiltrate state-owned entities across CIS countries.

Read: https://thehackernews.com/2023/10/yorotrooper-researchers-warn-of.html
🀯9πŸ‘5πŸ‘4
πŸš‘ Healthcare IT professionals, take note.

A critical RCE vulnerability (CVE-2023-43208) has been uncovered in Mirth Connect, a healthcare data integration platform.

Read: https://thehackernews.com/2023/10/critical-flaw-in-nextgens-mirth-connect.html

Update to version 4.4.1 immediately to prevent unauthorized access.
πŸ‘17πŸ”₯3😱3
🚨 ALERT: Iranian threat actor, Tortoiseshell, strikes again with new malware, IMAPLoader.

This .NET malware uses email as a command-and-control channel and targets maritime and logistics sectors.

Learn more: https://thehackernews.com/2023/10/iranian-group-tortoiseshell-launches.html
πŸ”₯19πŸ‘11🀯11😁4πŸ€”2⚑1
πŸ“’ Upcoming Webinars Alert:

1️⃣ Kickstart your SaaS Security Strategies
2️⃣ Dive into the State of Web App Security
3️⃣ Lock down your Financial Data

Reserve your seat now: https://www.linkedin.com/pulse/expert-led-cybersecurity-webinars-saas-web-apps-financial-gfrif/
⚑16πŸ‘16🀯6😱4
🚨Cloudflare thwarts massive DDoS attacks exceeding 100M requests/second.

Find out how HTTP/2 Rapid Reset flaw triggered a 65% increase in Q3 attacks.

Read more: https://thehackernews.com/2023/10/record-breaking-100-million-rps-ddos.html
🀯25πŸ‘15πŸ€”6πŸ”₯2
πŸ”’ Web security matters more than ever. Don't miss this eye-opening case study by Reflectiz, revealing the hidden risks of rogue pixels on websites.

Privacy violations can happen even without hacking.

Learn more: https://thehackernews.com/2023/10/the-danger-of-forgotten-pixels-on.html
πŸ‘21πŸ”₯2😁2⚑1
Microsoft warns of Scattered Spider, a financially motivated hacking crew that infiltrates firms worldwide using SMS phishing, SIM swapping, and by posing as new employees, leading to data breaches and takeovers.

Find out more: https://thehackernews.com/2023/10/microsoft-warns-as-scattered-spider.html
😱15πŸ‘11πŸ”₯7
⚠️ Alert β€” Researchers expose new "iLeakage" side-channel attack targeting iOS, iPadOS, and macOS devices running on Apple's A and M-series CPUs.

Discover how sensitive data can be extracted using this new Safari exploit.

Read: https://thehackernews.com/2023/10/ileakage-new-safari-exploit-impacts.html
🀯30😁10πŸ‘9πŸ”₯2
⚑ Urgent β€” F5 warns of a critical vulnerability (CVE-2023-46747) in BIG-IP, allowing unauthenticated remote code execution.

Learn more: https://thehackernews.com/2023/10/f5-issues-warning-big-ip-vulnerability.html
πŸ”₯24πŸ‘15🀯9πŸ€”1
πŸ€– Google expands Vulnerability Rewards Program to address vulnerabilities and attack scenarios tailored to generative artificial intelligence (AI) systems, while also strengthening the supply chain.

Learn more: https://thehackernews.com/2023/10/google-expands-its-bug-bounty-program.html
πŸ‘26πŸ”₯7πŸ‘7
Continuous monitoring is key. Discover how Fidelis Security's Network Detection and Response (NDR) solutions offer real-time threat detection to help you stay ahead of cyber threats.

Read: https://thehackernews.com/2023/10/how-to-keep-your-business-running-in.html
πŸ”₯12πŸ‘11πŸ‘8πŸ€”5😱3
🚨 North Korea's Lazarus Group strikes again. Discover how they hacked a software vendor using known security flaws.

Read more: https://thehackernews.com/2023/10/n-korean-lazarus-group-targets-software.html
😁29πŸ‘18πŸ‘9
Wiretapping attempt discovered on XMPP-based messaging service involving Hetzner and Linode hosting providers in Germany. Evidence points to a lawful foreign police request.

Learn more: https://thehackernews.com/2023/10/researchers-uncover-wiretapping-of-xmpp.html
πŸ‘26🀯14😱9⚑7😁6πŸ”₯1
πŸ”’ Beware! A new cyber threat is using bogus MSIX Windows app packages for popular software like Google Chrome, Microsoft Edge, Brave, Grammarly, and Cisco Webex to spread a dangerous malware called GHOSTPULSE.

Learn more ➜ https://thehackernews.com/2023/10/hackers-using-msix-app-packages-to.html
πŸ‘26😱5πŸ‘3🀯3πŸ”₯2