The Hacker News
βœ”
151K subscribers
1.86K photos
10 videos
3 files
7.78K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
A high-severity vulnerability (CVE-2024-6242) has been found in Rockwell Automation ControlLogix 1756 devices.

Exploiting this vulnerability could lead to unauthorized CIP commands, affecting device configurations and user projects.

Read: https://thehackernews.com/2024/08/critical-flaw-in-rockwell-automation.html
πŸ‘13πŸ”₯5⚑1
Cybersecurity incident response faces major challenges: timely detection, data collection, and coordination.

Quick, effective responses minimize damage. Tools like Wazuh boost readiness through automation and third-party integration.

Learn more: https://thehackernews.com/2024/08/enhancing-incident-response-readiness.html
πŸ‘9🀯5⚑1πŸ”₯1πŸ€”1
Organizations in Kazakhstan are targeted by a new threat cluster, Bloody Wolf, distributing STRRAT malware.

This #malware allows attackers to hijack corporate computers and steal restricted data for as little as $80.

Phishing emails impersonating government agencies trick victims into installing malicious Java files.

Read: https://thehackernews.com/2024/08/kazakh-organizations-targeted-by-bloody.html

Ensure your team is aware of these tactics and bolster email security measures.
πŸ‘15⚑3πŸ”₯1🀯1
Researchers uncover design flaws in Windows Smart App Control and SmartScreen, allowing hackers to bypass security measures and gain system access undetected.

Learn more: https://thehackernews.com/2024/08/researchers-uncover-flaws-in-windows.html
πŸ”₯13😁7πŸ‘6⚑4
A zero-day vulnerability in Apache OFBiz ERP system has been disclosed, allowing remote code execution.

This vulnerability, CVE-2024-38856, has a critical CVSS score of 9.8, making it extremely dangerous for businesses using this software.

Read: https://thehackernews.com/2024/08/new-zero-day-flaw-in-apache-ofbiz-erp.html

Share this to raise awareness!
πŸ‘13🀯10πŸ”₯4😱4😁2
Google has patched a new Android kernel vulnerability, CVE-2024-36971, that allows RCE.

It has been actively exploited by commercial spyware vendors in targeted attacks, posing a severe risk to Android users.

Read: https://thehackernews.com/2024/08/google-patches-new-android-kernel.html
πŸ€”13😁7πŸ‘6πŸ”₯4😱3
Kaspersky has identified a new Android spyware, LianSpy, targeting users in Russia since 2021.

This malware captures screencasts, exfiltrates user files, and harvests call logs and app lists.

Find details here: https://thehackernews.com/2024/08/new-android-spyware-lianspy-evades.html
πŸ”₯15πŸ‘11πŸ€”7😱4😁3
North Korea's Moonstone Sleet is pushing malicious npm packages to infect Windows systems.

Despite low downloads, the packages aimed to mimic popular libraries and potentially cause significant harm.

Read: https://thehackernews.com/2024/08/north-korean-hackers-moonstone-sleet.html
πŸ‘16😱3πŸ”₯2
Innovate with AI Pioneers Gather and connect with developers across the community at Intel Innovation, September 24-25. Witness the breakthroughs propelling AI into the future and be a part of the revolution.

Don’t miss out – register now: https://thn.news/innovation-2024
πŸ”₯10πŸ‘6⚑3😱3πŸ€”1
Insider threats account for 26% of SaaS security incidents.

These threats are challenging to detect because insiders often have valid credentials and access.

ITDR platforms can help by monitoring behavioral clues and flagging anomalies.

Learn how: https://thehackernews.com/2024/08/suspicious-minds-insider-threats-in.html
πŸ‘10πŸ€”4πŸ”₯1πŸ‘1
NTERPOL recovers $39 million in largest BEC scam bust. Global stop-payment mechanism halts massive business email fraud. Seven arrested in Singapore.

Learn more: https://thehackernews.com/2024/08/interpol-recovers-41-million-in-largest.html
πŸ”₯17πŸ‘7πŸ€”5😱1
Apple tightens Gatekeeper protections in macOS Sequoia.

This enhances security against malware by making it harder for users to bypass critical security checks.

Now, users must navigate to System Settings > Privacy & Security to authorize apps, preventing easy overrides.

Read: https://thehackernews.com/2024/08/apples-new-macos-sequoia-tightens.html

How do you feel about this update? Share your thoughts!
πŸ‘17🀯8πŸ”₯3πŸ€”3😁1
A new Android banking trojan, Chameleon, is targeting Canadian users by posing as a CRM app.

Chameleon can bypass Android restrictions, making it a significant threat.

Learn more: https://thehackernews.com/2024/08/chameleon-android-banking-trojan.html
πŸ‘17πŸ”₯5
CrowdStrike reveals root cause of global Windows device crash, implements new safety measures, and faces potential lawsuit from Delta Air Lines.

Read details here: https://thehackernews.com/2024/08/crowdstrike-reveals-root-cause-of.html
⚑15πŸ”₯12😁8πŸ€”3πŸ‘1
A South Asian media organization was targeted with a new Go-based backdoor, GoGra.

GoGra utilizes Microsoft Graph API for command-and-control, mimicking techniques used by other advanced threats.

Read: https://thehackernews.com/2024/08/new-go-based-backdoor-gogra-targets.html
πŸ‘11πŸ”₯6πŸ€”3
New vulnerabilities in Roundcube webmail could allow attackers to steal emails & passwords via malicious JavaScript.

Three CVEs have been addressed in the latest Roundcube updates. Make sure you're using versions 1.6.8 or 1.5.8 to stay protected.

Read: https://thehackernews.com/2024/08/roundcube-webmail-flaws-allow-hackers.html
πŸ‘13⚑7πŸ”₯2
New #Linux Kernel Exploitation Technique Unveiled: SLUBStick

This technique could elevate limited heap vulnerabilities to arbitrary memory read-and-write capabilities, threatening system security.

Researchers have shown SLUBStick can successfully bypass defenses like KASLR with a 99% success rate.

Read: https://thehackernews.com/2024/08/new-linux-kernel-exploit-technique.html
🀯27πŸ‘8πŸ”₯7😱1
A critical security flaw in Progress Software's WhatsUp Gold is under active exploitation.

This vulnerability allows unauthenticated remote code execution, posing a severe threat to network security.

The flaw (CVE-2024-4885) affects versions released before 2023.1.3. A PoC exploit is already in circulation.

Read: https://thehackernews.com/2024/08/critical-security-flaw-in-whatsup-gold.html

Update to the latest version immediately to protect your systems!
πŸ”₯13πŸ‘6😁4
FBI and CISA warn of BlackSuit ransomware, with demands soaring to $500M and individual ransoms hitting $60M. These actors use sophisticated methods like phishing, RDP exploits, and legitimate RMM tools to infiltrate and persist in networks.

https://thehackernews.com/2024/08/fbi-and-cisa-warn-of-blacksuit.html
πŸ”₯16πŸ‘7😱3🀯2
Researchers have uncovered a sophisticated phishing campaign leveraging Google Drawings and WhatsApp links.

This attack cleverly uses trusted platforms to bypass security measures, making it more challenging to detect.

Read: https://thehackernews.com/2024/08/new-phishing-scam-uses-google-drawings.html
πŸ”₯12😁5πŸ‘3😱3🀯2
Microsoft is addressing two critical vulnerabilities in the Windows Update system.

These flaws could allow attackers to stage downgrade attacks, replacing current Windows files with older, vulnerable versions.

Read: https://thehackernews.com/2024/08/windows-downgrade-attack-risks-exposing.html
😁15🀯10πŸ”₯8πŸ‘6