The Hacker News
βœ”
151K subscribers
1.86K photos
10 videos
3 files
7.78K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
A recently disclosed SSRF vulnerability (CVE-2024-21893) in Ivanti Connect Secure and Policy Secure products is now under mass exploitation.

Learn more: https://thehackernews.com/2024/02/recently-disclosed-ssrf-flaw-in-ivanti.html

Patch now to protect your organization from system takeover.
πŸ‘12😱12⚑9
Job seekers, beware! A new cybercriminal group called ResumeLooters is targeting job search platforms in APAC, stealing millions of resumes and personal data.

Learn more: https://thehackernews.com/2024/02/hackers-exploit-job-boards-in-apac.html
😱20πŸ‘6😁4πŸ€”4
Feeling overwhelmed by your sprawling SaaS stack?

You're not alone. Dramatically improve your SaaS Security posture with 201% ROI. New study reveals how a $10B media company achieved this with an SSPM platform.

Learn more: https://thehackernews.com/2024/02/how-10b-enterprise-customer-drastically.html
πŸ‘12πŸ”₯5
🚨 Beware: Cybercriminals use fake Facebook job ads to spread Ov3r_Stealer, a Windows #malware. It steals sensitive information, risking your personal and financial data.

Read: https://thehackernews.com/2024/02/beware-fake-facebook-job-ads-spreading.html
😁8πŸ‘6πŸ‘2πŸ€”1
πŸ›‘οΈ Researchers uncover details of 3 vulnerabilities in Azure HDInsight's Apache Hadoop, Kafka, and Spark services that could have allowed attackers root access and system disruption.

Learn more: https://thehackernews.com/2024/02/high-severity-flaws-found-in-azure.html
πŸ‘21🀯3πŸ‘2😁1
⚠️ Patch Alert β†’ Critical vulnerability in JetBrains' TeamCity On-Premises (CVE-2024-23917) allows unauthenticated remote attackers to gain administrative control and take over servers.

Learn more: https://thehackernews.com/2024/02/critical-jetbrains-teamcity-on-premises.html
😱11😁7πŸ‘6
πŸ•΅οΈ Chinese state-backed hackers exploited FortiOS SSL-VPN flaws to breach a Dutch military network, deploying a stealthy backdoor called COATHANGER.

Learn more: https://thehackernews.com/2024/02/chinese-hackers-exploited-fortigate.html
πŸ€”13πŸ‘9πŸ‘3🀯3
Governments and tech giants such as France, the U.K., the U.S., Google, Meta, and Microsoft have joined forces to combat the misuse of commercial spyware for human rights violations.

Learn more: https://thehackernews.com/2024/02/global-coalition-and-tech-giants-unite.html
πŸ‘29πŸ€”6
2024 marks the rise of vCISO services, with 45% of MSPs and MSSPs joining the trend. Position yourself as a cybersecurity leader.

Watch the webinar for a 5-phase action plan to vCISO success: https://thehackernews.com/2024/02/new-webinar-5-steps-to-vciso-success.html
πŸ‘15
πŸ”₯ A critical vulnerability has been found in the shim bootloader, leaving millions of Linux systems vulnerable to attack.

Learn more about CVE-2023-40547: https://thehackernews.com/2024/02/critical-bootloader-vulnerability-in.html

Update your device immediately if it uses shim and Secure Boot.
🀯23⚑6πŸ‘5😱5πŸ‘1
🚨 Exciting News from ANYRUN:

Introducing Threat Intelligence Lookup! πŸš€

Unlock contextual data and malware samples related to specific #IOCs, TTPs, and keywords, speeding up your investigations and boosting your cybersecurity defenses.

Try it now! πŸ” https://thehackernews.co/496HXQ1
πŸ‘20😁5πŸ€”4πŸ‘1
πŸ”” URGENT: Cisco, Fortinet, and VMware have (again!) released patches for new critical vulnerabilities in their products.

Patch immediately to prevent device takeover, data theft, and operational disruption.

Learn more: https://thehackernews.com/2024/02/critical-patches-released-for-new-flaws.html
πŸ‘20πŸ€”11πŸ”₯6🀯5
⚠️ North Korean APT Kimsuky caught using new Golang-based info stealer "Troll Stealer" & malware "GoBear," both signed with stolen certificates, targeting sensitive data like SSH keys, browser data & system info.

Learn more β†’ https://thehackernews.com/2024/02/kimsukys-new-golang-stealer-troll-and.html
πŸ‘13πŸ”₯6🀯5😁2
Google starts blocking sideloading of shady Android apps in Singapore. This pilot program targets apps that could potentially abuse permissions to steal one-time passwords and sensitive data.

Learn more: https://thehackernews.com/2024/02/google-starts-blocking-sideloading-of.html
πŸ€”10πŸ‘9⚑1😁1
🚨 Alert: HijackLoader malware evolves with stealthier defense evasion techniques, posing a greater challenge to cybersecurity defenses.

This malware is getting smarter and harder to detect. Click to learn more: https://thehackernews.com/2024/02/hijackloader-evolves-researchers-decode.html
πŸ‘11πŸ”₯7⚑5
Unified identity isn't just a buzzwordβ€”it's a game-changer in cybersecurity. Discover how consolidating identity challenges can bolster your organization's security posture.

Read: https://thehackernews.com/2024/02/unified-identity-look-for-meaning.html
πŸ‘12πŸ€”7πŸ”₯3⚑1
Chinese state-sponsored hacking group, Volt Typhoon, infiltrates U.S. critical infrastructure networks for over five years, posing a significant threat to essential services.

Read: https://thehackernews.com/2024/02/chinese-hackers-operate-undetected-in.html
🀯14πŸ‘11😁8πŸ”₯6πŸ‘4⚑1πŸ€”1
🚨 Deja Vu for Ivanti users!

Another authentication bypass security vulnerability (CVE-2024-22024) has been found in #Ivanti products, affecting Connect Secure, Policy Secure, and ZTA gateways.

Details: https://thehackernews.com/2024/02/warning-new-ivanti-auth-bypass-flaw.html

Don't wait, patch ASAP to secure your devices!
πŸ‘16⚑6
πŸ›‘ Urgent: Patch it now - Hackers are exploiting it!

Fortinet has unveiled a critical security flaw in its SSL VPN, CVE-2024-21762, allowing hackers to execute arbitrary code.

Learn more: https://thehackernews.com/2024/02/fortinet-warns-of-critical-fortios-ssl.html
πŸ‘10πŸ”₯10⚑7😁3
🚨 New backdoor called Zardoor used in cyberattack on Saudi Islamic charity, stealing data for over 2 years. Hackers use everyday tools like WMI to move undetected.

Read our full report: https://thehackernews.com/2024/02/stealthy-zardoor-backdoor-targets-saudi.html
πŸ‘10😁9⚑6
Concerned about the expanded attack surface in the cloud?

Wazuh, an open-source cybersecurity platform, provides real-time threat detection and incident response for your cloud environments.

Check it out: https://thehackernews.com/2024/02/wazuh-in-cloud-era-navigating.html
πŸ‘26⚑4πŸ”₯2πŸ‘1