The Hacker News
βœ”
151K subscribers
1.86K photos
10 videos
3 files
7.78K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
Overwhelmed by cybersecurity threats?

Cybersixgill’s IQ Report Generator automates CTI reports in minutes, freeing your team for proactive defense measures.

Don’t miss outβ€”see how it works: https://thehackernews.com/2024/06/ease-burden-with-ai-driven-threat.html
πŸ‘16πŸ€”6
🚨 Alert: Popular WordPress plugins backdoored to create rogue admin accounts. Users advised to inspect sites, remove suspicious admins, and update affected plugins.

Learn more: https://thehackernews.com/2024/06/multiple-wordpress-plugins-compromised.html
πŸ”₯13πŸ‘4😁4
πŸ›‘οΈ Four Vietnamese nationals linked to the FIN9 cybercrime group indicted in the U.S., accused of causing over $71 million in losses through computer intrusions.

Learn how they pulled it off and what charges they face: https://thehackernews.com/2024/06/4-fin9-linked-vietnamese-hackers.html
πŸ€”14πŸ‘3πŸ”₯2
WikiLeaks founder Julian Assange freed after 5 years in U.K. prison. His 14-year legal battle ends with a plea deal.

Read details here: https://thehackernews.com/2024/06/wikileaks-julian-assange-released-from.html

Assange has left the U.K. and is en route to Australia.
πŸ‘89πŸ‘15πŸ”₯8⚑3😁1
Researchers uncover a new attack technique called GrimResource, exploited in the wild, which uses specially crafted Microsoft Management Saved Console (MSC) files to achieve full code execution and evade security defenses.

Details: https://thehackernews.com/2024/06/new-attack-technique-exploits-microsoft.html
πŸ”₯11😱6πŸ‘3😁2
New threat actor "Boolka" uses SQL injection to infect websites with BMANAGER trojan, stealing data via malicious scripts.

Learn more about their sophisticated tactics: https://thehackernews.com/2024/06/new-cyberthreat-boolka-deploying.html
😁9πŸ‘6😱5πŸ‘1
πŸ”’ Tight on budget but need to ramp up data security in #Googleworkspace? Don’t miss the exclusive webinar: "Data Loss & Leaks Prevention: Beyond GAM." Peek behind the curtain to see how top IT pros have achieved a stunning 98% increase in compliance and security by maximizing the native capabilities of Googleapps and automating routine Googlework space admin tasks β€” all without breaking the bank.

πŸ’‘ Topics covered will include:

β€’ Automation of External Files Sharing Audits

β€’ Monitoring and Taking Action on Out of Domain Email Forwarding

β€’ Management of 'Zombie Drives' and more

Don’t miss out on this zero-fluff, zero-filler, 100% hands-on live event brought to you by Zenphi! Secure a spot today by registering for free here: https://thn.news/dlp-google-workspace
πŸ‘19πŸ€”5
πŸ”’ Discover how browser security platforms help CISOs cut costs, boost efficiency, and enhance cybersecurity.

Read real-life success stories: https://thehackernews.com/2024/06/how-to-cut-costs-with-browser-security.html
πŸ€”8πŸ‘7
WARNING: Google blocks ads for websites using polyfill[.]io library due to a supply chain attack where the domain was acquired by a Chinese company and modified to redirect users to malicious sites.

Details: https://thehackernews.com/2024/06/over-110000-websites-affected-by.html
😱18πŸ‘13😁4πŸ‘3
🚨 Alert: Discover how the updated Medusa Android banking trojan targets users in 7 countries, featuring new stealth capabilities and expanded reach.

Read: https://thehackernews.com/2024/06/new-medusa-android-trojan-targets.html
πŸ‘11πŸ”₯6
πŸ•΅οΈβ€β™€οΈ πŸ’³ A new credit card web skimmer called "Caesar Cipher Skimmer" is targeting multiple CMS platforms including WordPress, Magento, and OpenCart to steal financial and payment information.

Details: https://thehackernews.com/2024/06/new-credit-card-skimmer-targets.html
πŸ”₯11πŸ‘9😁1
Apple releases firmware security update for AirPods and Beats devices, addressing a critical Bluetooth vulnerability that could allow unauthorized access and eavesdropping.

Learn more about CVE-2024-27867: https://thehackernews.com/2024/06/apple-patches-airpods-bluetooth.html
πŸ”₯11πŸ€”4🀯4⚑2πŸ‘1
Explore key strategies to secure software supply chains effectively amidst rising cyber threats. Learn about SBOMs, SLSA, and DevSecOps best practices.

Learn more: https://thehackernews.com/2024/06/practical-guidance-for-securing-your.html
πŸ”₯7πŸ€”4πŸ‘2
🌍 State-sponsored cyber groups from China and North Korea have been linked to ransomware attacks on global governments and critical infrastructure.

Learn more about the tactics used ➑️ https://thehackernews.com/2024/06/chinese-and-n-korean-hackers-target.html
😁11πŸ‘6πŸ‘4πŸ€”3🀯1
🚨 Critical security flaw discovered in Progress Software's MOVEit Transfer.

CVE-2024-5806 allows authentication bypass and is already being exploited. Update now to protect your systems.

Read details: https://thehackernews.com/2024/06/new-moveit-transfer-vulnerability-under.html
😁13πŸ‘9🀯1
🚨 Critical security flaw found in Fortra FileCatalyst Workflow. CVE-2024-5276 scores 9.8 on CVSS. Patch now to protect your data from SQL injection attacks.

Details here ➑️ https://thehackernews.com/2024/06/critical-sqli-vulnerability-found-in.html
πŸ‘10
A 22-year-old Russian national has been indicted in the U.S. for cyberattacks against Ukraine and its allies just before Russia's invasion in 2022.

US offers $10M reward. Read more: https://thehackernews.com/2024/06/russian-national-indicted-for-cyber.html
πŸ‘21πŸ”₯8😁8🀯1
⚠️ Attention developers β€” A new high-severity prompt injection flaw (CVE-2024-5565) in Vanna AI library exposes databases to remote code execution.

Find out how this flaw could impact your projects: https://thehackernews.com/2024/06/prompt-injection-flaw-in-vanna-ai.html
πŸ‘14
Discover the power of Python in blockchain development with AlgoKit!

Explore how you can build decentralized applications securely and efficiently.

Learn about setup, benefits, and getting started with dApps: https://thehackernews.com/2024/06/how-to-use-python-to-build-secure.html
πŸ‘17πŸ”₯4
Ensuring data security remains crucial, which is why GigaOm recently released a new DSPM report highlighting industry leaders.

Sentra has emerged as a leader and rapid innovator, receiving high scores for its data mapping, access intelligence, and on-premises capabilities.

View the full report here πŸ‘‡
https://thn.news/data-security-posture
πŸ‘16πŸ”₯6😱1
🚨 Alert: Rust-based worm P2PInfect botnet has evolved to target misconfigured Redis servers with ransomware and cryptocurrency miners, showcasing new financial motivations and advanced evasion techniques.

Learn more: https://thehackernews.com/2024/06/rust-based-p2pinfect-botnet-evolves.html
πŸ‘14πŸ”₯12⚑3😱3