The Hacker News
151K subscribers
1.85K photos
10 videos
3 files
7.77K links
Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

📨 Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
🚨Cloud Atlas, a mysterious cyber espionage group, has launched spear-phishing attacks on Russian enterprises, targeting critical sectors.

Learn how these attacks unfold in this report: https://thehackernews.com/2023/12/cloud-atlas-spear-phishing-attacks.html
👍24🔥14👏6😁3🤯31
Carbanak malware is back, and it's using new tactics in ransomware attacks. Learn how it's impersonating business software to infiltrate systems.

Learn more: https://thehackernews.com/2023/12/carbanak-banking-malware-resurfaces.html
😱26🔥8👍62
🚨 Poorly secured Linux SSH servers are under attack!

Threat actors are installing tools to guess credentials, co-opt other servers, and launch cryptocurrency mining and DDoS attacks.

Read: https://thehackernews.com/2023/12/warning-poorly-secured-linux-ssh.html
🔥17👍65
📱 Beware of Xamalicious! It masquerades as legitimate apps on Android devices but secretly carries out fraudulent actions like clicking on ads.

Over 327,000 installs!

Learn more: https://thehackernews.com/2023/12/new-sneaky-xamalicious-android-malware.html
🔥11👍76
⚠️ALERT: Chinese threat actors exploited a new zero-day vulnerability (CVE-2023-7102) in Barracuda's Email Security Gateway (ESG) appliances.

Learn how they deployed a backdoor on select devices.

Read details: https://thehackernews.com/2023/12/chinese-hackers-exploited-new-zero-day.html
👍11🔥5👏2🤯2😱2😁1
🚨 A new zero-day security flaw discovered in Apache OfBiz ERP system could allow unauthorized access.

CVE-2023-51467 exposes incomplete patch for CVE-2023-49070 with a high CVSS score of 9.8.

Details: https://thehackernews.com/2023/12/critical-zero-day-in-apache-ofbiz-erp.html

Update now to protect your system!
🤯21👍11👏2😁2
🚨 New Malware Alert - Threat actors are using the Rugmi loader to deliver information stealers like Lumma Stealer and Vidar.

Learn more: https://thehackernews.com/2023/12/new-rugmi-malware-loader-surges-with.html
🔥12👍6🤯4😁3😱3
"Most Sophisticated" SPYWARE attack campaign called 'Operation Triangulation' targeted Apple iOS devices with never-before-seen exploits, including exploiting an unknown hardware feature.

Learn more: https://thehackernews.com/2023/12/most-sophisticated-iphone-hack-ever.html
🔥24🤯14👍12
🚨 Alert - Google Cloud addresses a medium-severity security flaw that could allow attackers to escalate privileges in Kubernetes clusters.

Learn more about this issue: https://thehackernews.com/2023/12/google-cloud-resolves-privilege.html
👍23🤔4🤯4👏3😁3
🔒 Microsoft is disabling the ms-appinstaller protocol handler by default due to its abuse by multiple threat actors for distributing malware.

Read details: https://thehackernews.com/2023/12/microsoft-disables-msix-app-installer.html
👏21👍12🔥6
💻 North Korean hackers are using spear-phishing attacks to compromise machines and deploy malware like AppleSeed and Meterpreter.

Read more about the cyber threat: https://thehackernews.com/2023/12/kimsuky-hackers-deploying-appleseed.html
🔥8👍65🤯1
🚨 ALERT: Ukraine's CERT warns of a new phishing campaign by Russia-linked APT28.

They're deploying stealthy malware like MASEPIE and STEELHOOK to target government entities.

Read details: https://thehackernews.com/2023/12/cert-ua-uncovers-new-malware-wave.html
👍26🔥5👏3😁3🤔1
Iranian hacker group Homeland Justice claims responsibility for the cyber attacks that targeted the Assembly of the Republic and the telecom company One Albania.

Read details: https://thehackernews.com/2023/12/albanian-parliament-and-one-albania.html
👍30👏12😁9🔥7🤔52
🚨 Warning: Phishing attacks, especially Angel Drainer, offered as a "scam-as-a-service," are targeting 💰 cryptocurrency wallets, draining them of digital assets.

Find details here: https://thehackernews.com/2023/12/beware-scam-as-service-aiding.html
🤯24🔥12👍11😁3👏21
Beware: JinxLoader, a new Go-based malware loader, is proliferating via phishing attacks, providing access to Formbook and XLoader.

Find details here: https://thehackernews.com/2024/01/new-jinxloader-targeting-users-with.html
🔥16😱6👍3🤯21🤔1
🔒 Alert: Researchers have discovered a new SSH protocol vulnerability, "Terrapin" (CVE-2023-48795), enabling attackers to downgrade SSH connection security.

Learn more: https://thehackernews.com/2024/01/new-terrapin-flaw-could-let-attackers.html

Update and patch your SSH servers ASAP.
🤯21🔥105👍5🤔3
🚨Researchers uncover a novel DLL search order hijacking technique that threatens Windows 10 and 11 systems. Attackers exploit trusted folders to execute malicious code without elevated privileges.

Learn more: https://thehackernews.com/2024/01/new-variant-of-dll-search-order.html
🔥19🤯7🤔6👍5
Google settles a $5 billion class-action lawsuit over tracking in 'incognito mode.' Users believed their online activity was private on web browsers, but the settlement reveals hidden data collection.

Learn more: https://thehackernews.com/2024/01/google-settles-5-billion-privacy.html
😁57😱22👍15🔥11🤔94🤯4👏3
The browser is the heart of the modern enterprise, but it's also a prime target for cyberattacks.

Learn how to protect your workspace and choose the right solution for your organization's needs.

Read: https://thehackernews.com/2024/01/the-definitive-enterprise-browser.html
👍25🔥8👏6😁4🤔3😱1
XCast, a VoIP provider, faces a $10 million penalty for facilitating illegal robocalls and deceptive telemarketing campaigns since 2018.

Read: https://thehackernews.com/2024/01/doj-slams-xcast-with-10-million-fine.html
🔥18👍16👏5🤯4
⚠️ A new exploitation technique called '📩 SMTP Smuggling' could let attackers send malicious emails with fake sender addresses while bypassing security measures.

Read more 👉 https://thehackernews.com/2024/01/smtp-smuggling-new-threat-enables.html
🔥23👍13😱12🤔4