The Hacker News
151K subscribers
1.85K photos
10 videos
3 files
7.76K links
Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

📨 Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
Popular online services like Grammarly, Vidio, and Bukalapak faced critical security vulnerabilities in their OAuth implementation that could have allowed hackers to hijack user accounts.

Find details here: https://thehackernews.com/2023/10/critical-oauth-flaws-uncovered-in.html
😱17👍10😁9
⚠️ WARNING — Winter Vivern, a notorious nation-state hacker group with links to Belarus and Russia, exploiting a zero-day flaw in Roundcube webmail software to steal email messages.

Learn more: https://thehackernews.com/2023/10/nation-state-hackers-exploiting-zero.html
👍17🤯11👏3😁2🔥1
🚨 Meet YoroTrooper: A mysterious threat actor with ties to Kazakhstan. Learn how they're using custom tools and stealthy tactics to infiltrate state-owned entities across CIS countries.

Read: https://thehackernews.com/2023/10/yorotrooper-researchers-warn-of.html
🤯9👍5👏4
🚑 Healthcare IT professionals, take note.

A critical RCE vulnerability (CVE-2023-43208) has been uncovered in Mirth Connect, a healthcare data integration platform.

Read: https://thehackernews.com/2023/10/critical-flaw-in-nextgens-mirth-connect.html

Update to version 4.4.1 immediately to prevent unauthorized access.
👍17🔥3😱3
🚨 ALERT: Iranian threat actor, Tortoiseshell, strikes again with new malware, IMAPLoader.

This .NET malware uses email as a command-and-control channel and targets maritime and logistics sectors.

Learn more: https://thehackernews.com/2023/10/iranian-group-tortoiseshell-launches.html
🔥19👍11🤯11😁4🤔21
🚨Cloudflare thwarts massive DDoS attacks exceeding 100M requests/second.

Find out how HTTP/2 Rapid Reset flaw triggered a 65% increase in Q3 attacks.

Read more: https://thehackernews.com/2023/10/record-breaking-100-million-rps-ddos.html
🤯25👍15🤔6🔥2
🔒 Web security matters more than ever. Don't miss this eye-opening case study by Reflectiz, revealing the hidden risks of rogue pixels on websites.

Privacy violations can happen even without hacking.

Learn more: https://thehackernews.com/2023/10/the-danger-of-forgotten-pixels-on.html
👍21🔥2😁21
Microsoft warns of Scattered Spider, a financially motivated hacking crew that infiltrates firms worldwide using SMS phishing, SIM swapping, and by posing as new employees, leading to data breaches and takeovers.

Find out more: https://thehackernews.com/2023/10/microsoft-warns-as-scattered-spider.html
😱15👍11🔥7
⚠️ Alert — Researchers expose new "iLeakage" side-channel attack targeting iOS, iPadOS, and macOS devices running on Apple's A and M-series CPUs.

Discover how sensitive data can be extracted using this new Safari exploit.

Read: https://thehackernews.com/2023/10/ileakage-new-safari-exploit-impacts.html
🤯30😁10👍9🔥2
Urgent — F5 warns of a critical vulnerability (CVE-2023-46747) in BIG-IP, allowing unauthenticated remote code execution.

Learn more: https://thehackernews.com/2023/10/f5-issues-warning-big-ip-vulnerability.html
🔥24👍15🤯9🤔1
🤖 Google expands Vulnerability Rewards Program to address vulnerabilities and attack scenarios tailored to generative artificial intelligence (AI) systems, while also strengthening the supply chain.

Learn more: https://thehackernews.com/2023/10/google-expands-its-bug-bounty-program.html
👍26🔥7👏7
Continuous monitoring is key. Discover how Fidelis Security's Network Detection and Response (NDR) solutions offer real-time threat detection to help you stay ahead of cyber threats.

Read: https://thehackernews.com/2023/10/how-to-keep-your-business-running-in.html
🔥12👍11👏8🤔5😱3
🚨 North Korea's Lazarus Group strikes again. Discover how they hacked a software vendor using known security flaws.

Read more: https://thehackernews.com/2023/10/n-korean-lazarus-group-targets-software.html
😁29👍18👏9
Wiretapping attempt discovered on XMPP-based messaging service involving Hetzner and Linode hosting providers in Germany. Evidence points to a lawful foreign police request.

Learn more: https://thehackernews.com/2023/10/researchers-uncover-wiretapping-of-xmpp.html
👍26🤯14😱97😁6🔥1
🔒 Beware! A new cyber threat is using bogus MSIX Windows app packages for popular software like Google Chrome, Microsoft Edge, Brave, Grammarly, and Cisco Webex to spread a dangerous malware called GHOSTPULSE.

Learn more ➜ https://thehackernews.com/2023/10/hackers-using-msix-app-packages-to.html
👍26😱5👏3🤯3🔥2
🚨 Three new high-severity security flaws discovered in NGINX Ingress controller for Kubernetes. Hackers can steal secret credentials.

Learn more: https://thehackernews.com/2023/10/urgent-new-security-flaws-discovered-in.html
🔥28😱7👍6😁2
⚠️ Alert: EleKtra-Leak cryptojacking campaign is exploiting exposed AWS IAM credentials on public GitHub repositories.

Find details here: https://thehackernews.com/2023/10/elektra-leak-cryptojacking-attacks.html
👍22😱7🔥3
ServiceNow exposes sensitive data due to misconfigurations. Learn how this could've jeopardized your business and the steps to ensure your data is secure.

Read more: https://thehackernews.com/2023/10/servicenow-data-exposure-wake-up-call.html
👍17🔥7😁6
Join our expert panel of security veterans Emo Gokay, Multi-Cloud Security Engineer at EY Technologies and George Prichici, VP of products at OPSWAT, as they share insights and strategies gathered from the frontlines of securing critical infrastructure from advanced and persistent malware.

Join: https://thehackernews.com/2023/10/new-webinar-5-must-know-trends.html
👍26👏42
⚡️ Pro-Hamas hacktivist group using a new Linux-based malware, BiBi-Linux Wiper, to target Israeli entities amid ongoing conflict.

Read: https://thehackernews.com/2023/10/pro-hamas-hacktivists-targeting-israeli.html
👏88🤔21🔥19😁18🤯14👍107