The Hacker News
βœ”
151K subscribers
1.86K photos
10 videos
3 files
7.78K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
A new #vulnerability in Styra's Open Policy Agent (CVE-2024-8260) could expose NTLM credentials to attackers.

Attackers can exploit it to relay authentication, reinforcing the need for stringent input validation across all applications.

Read: https://thehackernews.com/2024/10/security-flaw-in-styras-opa-exposes.html
🀯11πŸ‘4😁3
North Korea's Lazarus Group exploits a zero-day #vulnerability (CVE-2024-4947) in Google Chrome to target the #cryptocurrency sector.

Exploitation strategy involved social media manipulation and fake game promotions.

Learn more: https://thehackernews.com/2024/10/lazarus-group-exploits-google-chrome.html
πŸ”₯15πŸ‘10🀯4
Cisco has patched CVE-2024-20481, a #vulnerability affecting its ASA and Firepower devices that could lead to a denial-of-service (DoS) for Remote Access VPNs.

Learn more: https://thehackernews.com/2024/10/cisco-issues-urgent-fix-for-asa-and-ftd.html
πŸ‘7πŸ”₯7πŸ‘3😁1
Researchers identified a #vulnerability in AWS CDK that may lead to account takeover, with over 1% of users at risk from predictable S3 bucket names.

The solution: update your CDK version and customize bucket names.

Read: https://thehackernews.com/2024/10/aws-cloud-development-kit-vulnerability.html
πŸ‘10πŸ€”5πŸ”₯4😁3
Attention: CVE-2024-41992 #vulnerability in Wi-Fi Test Suite could give attackers full control over Arcadyan routers. The flaw allows for command injection, enabling full administrative access.

Find details here β†’ https://thehackernews.com/2024/10/researchers-discover-command-injection.html
🀯12😁10⚑3πŸ‘2
High-severity CVE-2024-50550 #vulnerability in LiteSpeed Cache plugin allows unauthorized access, highlighting critical security implications for WordPress users.

Read: https://thehackernews.com/2024/10/litespeed-cache-plugin-vulnerability.html
⚑7πŸ‘5πŸ”₯4😱4
Google warns of active exploitation of CVE-2024-43093 in Android.

This #vulnerability allows unauthorized access to critical directories, emphasizing the need for timely updates and patching processes.

https://thehackernews.com/2024/11/google-warns-of-actively-exploited-cve.html
πŸ”₯16πŸ‘11😁4⚑3😱2πŸ€”1
🚨 CISA has added a critical #vulnerability (CVE-2024-5910) in Palo Alto Networks Expedition to its Known Exploited Vulnerabilities catalog.

This flaw allows attackers to take over admin accounts, risking sensitive data.

πŸ‘‰ Read details: https://thehackernews.com/2024/11/cisa-alerts-to-active-exploitation-of.html
⚑10🀯7
Researchers have identified a #vulnerability in Citrix Virtual Apps that allows unauthenticated RCE through improper deserialization.

Read more: https://thehackernews.com/2024/11/new-flaws-in-citrix-virtual-apps-enable.html

Patches are available, but many organizations may still be exposed if not updated.
πŸ”₯14πŸ‘1
Exploit alert: Russia-linked threat actors have actively exploited the CVE-2024-43451 #vulnerability to deploy Spark RAT, with the potential for significant damage through credential theft.

Read: https://thehackernews.com/2024/11/russian-hackers-exploit-new-ntlm-flaw.html
πŸ‘12πŸ”₯6πŸ‘3⚑2
⚠️ Researchers have identified a high-severity #vulnerability (CVE-2024-10979) in PostgreSQL, allowing unprivileged users to alter environment variables, leading to potential code execution or information leaks.

Read: https://thehackernews.com/2024/11/high-severity-flaw-in-postgresql-allows.html
⚑13πŸ”₯8πŸ‘5🀯4
πŸ”΄ New Threat Alert: BrazenBamboo, a well-resourced group, is exploiting an UNPATCHED zero-day #vulnerability in Fortinet's FortiClient for Windows to extract VPN credentials.

Learn more: https://thehackernews.com/2024/11/warning-deepdata-malware-exploiting.html
😁9πŸ€”5⚑2
Google's AI-driven tool OSS-Fuzz uncovered 26 flaws across various open-source repositories, including a serious flaw (CVE-2024-9143) in OpenSSL, marking a milestone in automated #vulnerability detection.

Read the full article here β€” https://thehackernews.com/2024/11/googles-ai-powered-oss-fuzz-tool-finds.html
πŸ‘15πŸ”₯15😁5πŸ‘3
False positives are a headache, but a false negative? That’s where the real danger lies.

Imagine thinking you've fixed a #vulnerability, only for attackers to sneak in undetected. Aesop’s Boy Who Cried Wolf is still relevant today.

A false negative could cost your company everythingβ€”from compromised credentials to ransomware. Are your defenses really working?

Find out why ASV tools are the cybersecurity game-changer you need. Read the full story here: https://thehackernews.com/2024/11/cyber-story-time-boy-who-cried-secure.html
πŸ‘5πŸ”₯3🀯3πŸ‘2⚑1
A critical #vulnerability (CVE-2024-11680) in the ProjectSend file-sharing app is being actively exploited.

It allows attackers to execute malicious code on vulnerable servers.

Don’t wait for an attackβ€”patch now: https://thehackernews.com/2024/11/critical-flaw-in-projectsend-under.html
πŸ‘26😱9⚑4πŸ‘2😁2
U.S. has unsealed charges against a Chinese hacker for exploiting a zero-day #vulnerability in 81,000 Sophos firewalls, enabling the infiltration of critical systems, the theft of sensitive data, and targeting U.S. infrastructure.

Learn more: https://thehackernews.com/2024/12/us-charges-chinese-hacker-for.html
😁43πŸ‘26🀯3
🚨 Apple's TCC framework #vulnerability exposed!

A now-patched flaw (CVE-2024-44131) allowed unauthorized apps to access sensitive data like Health info, microphone, and #iCloud backupsβ€”without users knowing.

Learn more: https://thehackernews.com/2024/12/researchers-uncover-symlink-exploit.html
😁14😱10πŸ‘4⚑2πŸ”₯2πŸ€”1
πŸ›‘οΈ Critical OpenWrt #vulnerability (CVE-2024-54143) discovered β€” With just a 12-character hash collision, attackers can replace legitimate firmware with a malicious alternative, all without authentication.

Discover the technical details: https://thehackernews.com/2024/12/critical-openwrt-vulnerability-exposes.html
🀯15πŸ‘12πŸ”₯7😱6😁2⚑1