The Hacker News
βœ”
152K subscribers
1.92K photos
10 videos
3 files
7.84K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
Researchers have identified a #vulnerability in Citrix Virtual Apps that allows unauthenticated RCE through improper deserialization.

Read more: https://thehackernews.com/2024/11/new-flaws-in-citrix-virtual-apps-enable.html

Patches are available, but many organizations may still be exposed if not updated.
πŸ”₯14πŸ‘1
Exploit alert: Russia-linked threat actors have actively exploited the CVE-2024-43451 #vulnerability to deploy Spark RAT, with the potential for significant damage through credential theft.

Read: https://thehackernews.com/2024/11/russian-hackers-exploit-new-ntlm-flaw.html
πŸ‘12πŸ”₯6πŸ‘3⚑2
⚠️ Researchers have identified a high-severity #vulnerability (CVE-2024-10979) in PostgreSQL, allowing unprivileged users to alter environment variables, leading to potential code execution or information leaks.

Read: https://thehackernews.com/2024/11/high-severity-flaw-in-postgresql-allows.html
⚑13πŸ”₯8πŸ‘5🀯4
πŸ”΄ New Threat Alert: BrazenBamboo, a well-resourced group, is exploiting an UNPATCHED zero-day #vulnerability in Fortinet's FortiClient for Windows to extract VPN credentials.

Learn more: https://thehackernews.com/2024/11/warning-deepdata-malware-exploiting.html
😁9πŸ€”5⚑2
Google's AI-driven tool OSS-Fuzz uncovered 26 flaws across various open-source repositories, including a serious flaw (CVE-2024-9143) in OpenSSL, marking a milestone in automated #vulnerability detection.

Read the full article here β€” https://thehackernews.com/2024/11/googles-ai-powered-oss-fuzz-tool-finds.html
πŸ‘15πŸ”₯15😁5πŸ‘3
False positives are a headache, but a false negative? That’s where the real danger lies.

Imagine thinking you've fixed a #vulnerability, only for attackers to sneak in undetected. Aesop’s Boy Who Cried Wolf is still relevant today.

A false negative could cost your company everythingβ€”from compromised credentials to ransomware. Are your defenses really working?

Find out why ASV tools are the cybersecurity game-changer you need. Read the full story here: https://thehackernews.com/2024/11/cyber-story-time-boy-who-cried-secure.html
πŸ‘5πŸ”₯3🀯3πŸ‘2⚑1
A critical #vulnerability (CVE-2024-11680) in the ProjectSend file-sharing app is being actively exploited.

It allows attackers to execute malicious code on vulnerable servers.

Don’t wait for an attackβ€”patch now: https://thehackernews.com/2024/11/critical-flaw-in-projectsend-under.html
πŸ‘26😱9⚑4πŸ‘2😁2
U.S. has unsealed charges against a Chinese hacker for exploiting a zero-day #vulnerability in 81,000 Sophos firewalls, enabling the infiltration of critical systems, the theft of sensitive data, and targeting U.S. infrastructure.

Learn more: https://thehackernews.com/2024/12/us-charges-chinese-hacker-for.html
😁43πŸ‘26🀯3
🚨 Apple's TCC framework #vulnerability exposed!

A now-patched flaw (CVE-2024-44131) allowed unauthorized apps to access sensitive data like Health info, microphone, and #iCloud backupsβ€”without users knowing.

Learn more: https://thehackernews.com/2024/12/researchers-uncover-symlink-exploit.html
😁14😱10πŸ‘4⚑2πŸ”₯2πŸ€”1
πŸ›‘οΈ Critical OpenWrt #vulnerability (CVE-2024-54143) discovered β€” With just a 12-character hash collision, attackers can replace legitimate firmware with a malicious alternative, all without authentication.

Discover the technical details: https://thehackernews.com/2024/12/critical-openwrt-vulnerability-exposes.html
🀯15πŸ‘12πŸ”₯7😱6😁2⚑1