The Hacker News
βœ”
151K subscribers
1.85K photos
10 videos
3 files
7.77K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
🚨 Hackers could take control of your LG Smart TV – Multiple security vulnerabilities have been uncovered in LG webOS, allowing unauthorized access.

Get the details and check if you need the update πŸ‘‡
https://thehackernews.com/2024/04/researchers-discover-lg-smart-tv.html
πŸ€”10😁6🀯4πŸ‘2😱1
Did you know that 80% of app security issues stem from outdated dependencies?

Join Justin Clareburt, Product Owner at Mend Renovate, for a live session on April 17th. Discover how automated dependency updates can keep your apps modern, secure, and bug-free.

Register now: https://thn.news/updating-dependencies-webinar
πŸ‘17
⚠️ Researchers uncover Starry Addax, a sophisticated threat actor targeting human rights activists in Morocco & the Western Sahara region with fake #Android apps & Windows login pages.

Learn more: https://thehackernews.com/2024/04/hackers-targeting-human-rights.html
πŸ‘17πŸ‘4
πŸ•΅οΈβ€β™‚οΈ RUBYCARP, a sophisticated hacker group suspected to be from Romania and active for over a decade, has been discovered operating a long-standing botnet for cryptocurrency mining, DDoS, and phishing attacks.

Details: https://thehackernews.com/2024/04/10-year-old-rubycarp-romanian-hacker.html
🀯13πŸ‘8πŸ”₯6πŸ‘2
⚠️ Attention Developers: A severe vulnerability (CVE-2024-24576) in the Rust standard library could lead to command injection attacks on Windows systems.

https://thehackernews.com/2024/04/critical-batbadbut-rust-vulnerability.html

CVSS score of 10.0. Patch any apps using vulnerable Rust versions ASAP!
😁21πŸ‘17πŸ”₯11πŸ€”1
πŸ”₯ Urgent Patch Alert!

Microsoft releases a massive patch for April 2024, fixing a record 149 flaws. Two vulnerabilities are ALREADY under attack.

https://thehackernews.com/2024/04/microsoft-fixes-149-flaws-in-huge-april.html

Update your systems NOW.
πŸ‘25😁10⚑6πŸ‘6πŸ€”1
Researchers found the "first native Spectre v2 exploit" targeting Linux kernel on Intel systems, bypassing existing memory leak protections and privilege escalation defenses.

Read details here: https://thehackernews.com/2024/04/researchers-uncover-first-native.html
πŸ‘11🀯9πŸ‘8πŸ”₯4
Misconfigured systems? Forgotten accounts? These are like secret tunnels for hackers into your systems.

Want to find these hidden security weaknesses? Join our FREE webinar: "Top 4 Identity Security Threat Exposures: Are You Vulnerable?"

Save your spot: https://thehackernews.com/2024/04/webinar-learn-how-to-stop-hackers-from.html
πŸ‘14πŸ”₯7⚑3πŸ‘2🀯1
⚠️ BEWARE: Hackers are exploiting GitHub's search featureβ€”using popular names and boosting rankings with fake starsβ€”to lure developers into downloading #malware-infected repositories.

https://thehackernews.com/2024/04/beware-githubs-fake-popularity-scam.html
πŸ‘18🀯9πŸ”₯6😁4😱2
⚠️ Researchers uncover a fresh wave of the Raspberry Robin campaign spreading malware through malicious Windows Script Files (WSFs) since March 2024.

Read more about this evolving threat: https://thehackernews.com/2024/04/raspberry-robin-returns-new-malware.html
πŸ‘15😱5πŸ‘3😁3πŸ”₯1
Active Android spyware campaign 'eXotic Visit' targeting users in India and Pakistan.

Fake messaging apps like "ChitChat" and "Alpha Chat" actually contain the trojan.

https://thehackernews.com/2024/04/exotic-visit-spyware-campaign-targets.html

Bad news: Some of these apps were on Google Play.
πŸ€”13πŸ‘9😁7πŸ‘6πŸ”₯3
🚨 Urgent security warning - If you use FortiClientLinux, update immediately. Critical vulnerability could let attackers run code on your system.

Patch now, get the details here: https://thehackernews.com/2024/04/fortinet-has-released-patches-to.html
πŸ‘14😁11⚑2😱1
πŸ›‘οΈ Apple's updated Spyware Alert System now warns individual users of potential targeting by mercenary spyware attacks.

Details here πŸ‘‰ https://thehackernews.com/2024/04/apple-expands-spyware-alert-system-to.html
πŸ‘11⚑10πŸ”₯8πŸ‘3😁2
🚨 TA547 hacker group adopts new tactics, possibly harnessing the power of generative AI, to deploy the Rhadamanthys info stealer in attacks on German organizations.

Find details here: https://thehackernews.com/2024/04/ta547-phishing-attack-hits-german-firms.html
πŸ‘19😁3😱2
The question you need to ask: Are you affected by the XZ Util Backdoor?

Prevent future risks and make sure you have a defense-in-depth strategy using Wiz CDR and runtime sensor.

See Wiz in Action: https://thn.news/wiz-cloud-security
πŸ‘19🀯4πŸ”₯2
😱 Yikes! Did you know that over 11,000 secrets (passwords, API keys...) were leaked on the Python repository PyPI, and over 12.8 million on GitHub in 2023?

GitGuardian's findings are alarming - read the details: https://thehackernews.com/2024/04/gitguardian-report-pypi-secrets.html
😁16πŸ‘10🀯9πŸ”₯5😱4⚑1
🚨 Urgent - CISA issues emergency directive urging federal agencies to analyze compromised emails and ramp up cybersecurity measures following the recent compromise of Microsoft's systems by a Russian nation-state group.

Details > https://thehackernews.com/2024/04/us-federal-agencies-ordered-to-hunt-for.html
😱12πŸ‘10😁6πŸ”₯4⚑3
🚨 E-commerce website owners and admins – BEWARE!

Reseachers uncover a credit card skimmer hidden within a bogus Meta Pixel tracker script.

Check your website's security now: https://thehackernews.com/2024/04/sneaky-credit-card-skimmer-disguised-as.html
πŸ‘16😁6πŸ€”3πŸ”₯1πŸ‘1🀯1
πŸ›‘ URGENT - Critical zero-day security vulnerability (CVE-2024-3400) discovered in Palo Alto Networks firewalls.

Hackers are already exploiting it in the wild, enabling them "to execute arbitrary code with root privileges."

DetailsπŸ‘‡ https://thehackernews.com/2024/04/zero-day-alert-critical-palo-alto.html
πŸ”₯17πŸ‘13😁8🀯3πŸ‘2
MuddyWater's new C2 infrastructure, DarkBeatC2, has been spotted in the wild, targeting Israeli institutions with a fresh attack campaign.

Read: https://thehackernews.com/2024/04/iranian-muddywater-hackers-adopt-new-c2.html
πŸ”₯17πŸ‘13
Software systems have a hidden world of 'non-human' identities... think of them like API keys on steroids.

Learn how to protect your systems from attacks targeting these identities: https://thehackernews.com/2024/04/code-keepers-mastering-non-human.html
πŸ”₯12πŸ€”8πŸ‘7πŸ‘1