The Hacker News
โœ”
151K subscribers
1.86K photos
10 videos
3 files
7.77K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: [email protected]

๐ŸŒ Website: https://thehackernews.com
Download Telegram
LastPassโ€™ parent company GoTo (formerly LogMeIn) has experienced a data breach in which cybercriminals stole customers' encrypted backups and an encryption key used to secure data for some customers.

Read: https://thehackernews.com/2023/01/lastpass-parent-company-goto-suffers.html
๐Ÿคฏ52๐Ÿ”ฅ16๐Ÿ˜13๐Ÿ˜ฑ9๐Ÿ‘7โšก5
North Korean group APT38 is targeting cryptocurrency holders by using credential harvesting as a new weapon in its quest for crypto riches.

Read details: https://thehackernews.com/2023/01/north-korean-hackers-turn-to-credential.html
๐Ÿ‘20๐Ÿคฏ11๐Ÿ”ฅ5๐Ÿ˜5๐Ÿค”4
Warning: A massive malware campaign has infected more than 4,500 WordPress websites and is redirecting their visitors to sketchy ad pages.

Read: https://thehackernews.com/2023/01/over-4500-wordpress-sites-hacked-to.html

Keep your website secure and always be cautious of suspicious links.
๐Ÿ‘38๐Ÿ˜ฑ14๐Ÿ”ฅ9๐Ÿ‘5โšก3๐Ÿ˜1๐Ÿคฏ1
ALERT: Two federal agencies in the U.S. have fallen victim to a widespread malicious campaign using RMM software for phishing scams.

Read details: https://thehackernews.com/2023/01/us-federal-agencies-fall-victim-to.html
๐Ÿคฏ27๐Ÿ‘8๐Ÿ˜ฑ8โšก7๐Ÿ”ฅ7๐Ÿ˜4
New research has uncovered connections between the operations of Moses Staff and Abraham's Ax, two politically motivated hacktivist groups.

Read details: https://thehackernews.com/2023/01/researchers-uncover-connection-bw-moses.html
๐Ÿ‘12โšก3๐Ÿ”ฅ2
Researchers have released proof-of-concept exploit code for a high-severity security vulnerability (CVE-2022-34689) in the Windows CryptoAPI, which was discovered by the NSA and NCSC.

Read details: https://thehackernews.com/2023/01/researchers-release-poc-exploit-for.html
๐Ÿ‘22๐Ÿ˜ฑ10โšก3๐Ÿ”ฅ1
Researchers have identified a new Python-based malware that uses WebSockets for both command and control communication and data exfiltration.

Read details: https://thehackernews.com/2023/01/pyration-new-python-based-rat-utilizes.html
๐Ÿ‘22๐Ÿ”ฅ8โšก5๐Ÿ˜2
Google shuts down pro-Chinese influence operation DRAGONBRIDGE, with over 50,000 instances of activity dismantled in 2022.

Read: https://thehackernews.com/2023/01/google-takes-down-50000-instances-of.html
๐Ÿ‘40๐Ÿ‘9๐Ÿ”ฅ2โšก1๐Ÿคฏ1๐Ÿ˜ฑ1
๐Ÿ”ฅ Victory against cybercrime!

International law enforcement agencies have taken down the infrastructure behind the HIVE ransomware-as-a-service operation in a joint effort across 13 countries.

Details: https://thehackernews.com/2023/01/hive-ransomware-infrastructure-seized.html
๐Ÿ‘73๐Ÿ‘15๐Ÿ”ฅ15๐Ÿ˜ฑ11๐Ÿคฏ1
U.K.'s cybersecurity agency has issued a warning about cyberattacks by Russian & Iranian state-sponsored hacker groups targeting key sectors, including defense, government organizations & even academia, journalists, think tanks and activists.

https://thehackernews.com/2023/01/british-cyber-agency-warns-of-russian.html
๐Ÿ‘16๐Ÿคฏ16โšก5๐Ÿ‘5
PlugX just got sneakier!

Cybersecurity researchers uncover a new variant that infects attached USB media devices to spread the malware to other systems.

Read details: https://thehackernews.com/2023/01/researchers-discover-new-plugx-malware.html
๐Ÿ‘19๐Ÿ”ฅ12โšก6๐Ÿ˜3๐Ÿ‘1
Cybersecurity researchers have uncovered the true identity of the threat actor behind the Golden Chickens malware-as-a-service.

Read details: https://thehackernews.com/2023/01/experts-uncover-identity-of-mastermind.html
๐Ÿ‘27๐Ÿ‘12โšก6๐Ÿ˜ฑ5๐Ÿ˜2๐Ÿคฏ2
Ukraine is under attack from a new Golang-based data wiper malware called "SwiftSlicer." The attackers have been identified as Sandworm, a known nation-state group with ties to the Russian military.

Read: https://thehackernews.com/2023/01/ukraine-hit-with-new-golang-based.html
๐Ÿ˜ฑ32๐Ÿ‘23๐Ÿ‘12๐Ÿ”ฅ9โšก6๐Ÿค”3๐Ÿคฏ3๐Ÿ˜2
The Internet Systems Consortium (ISC) has released security patches for multiple new vulnerabilities in the BIND DNS software suite that could lead to a DoS condition and system failures.

Read: https://thehackernews.com/2023/01/isc-releases-security-patches-for-new.html
๐Ÿคฏ25๐Ÿ‘13โšก7๐Ÿ‘4๐Ÿ˜ฑ3๐Ÿค”1
Microsoft urges customers to keep their servers up to date and implement additional security measures, such as enabling Windows Extended Protection & configuring certificate-based signing of #PowerShell serialization payloads.

Read: https://thehackernews.com/2023/01/microsoft-urges-customers-to-secure-on.html
โšก34๐Ÿ‘28๐Ÿ˜ฑ7๐Ÿ‘6๐Ÿ˜2
Gootkit malware continues to evolve and become more sophisticated, with notable changes to the toolkit, adding new components and obfuscations to their infection chains.

Read: https://thehackernews.com/2023/01/gootkit-malware-continues-to-evolve.html
๐Ÿ”ฅ25๐Ÿ‘21๐Ÿ˜ฑ5๐Ÿ˜4โšก3๐Ÿ‘3
Urgent Alert โ€” A critical RCE vulnerability in the Realtek Jungle SDK is being weaponized by attackers to hack IoT devices, with 134 MILLION exploitation attempts recorded in the past 2 months alone.

Read: https://thehackernews.com/2023/01/realtek-vulnerability-under-attack-134.html
๐Ÿคฏ16๐Ÿ‘8๐Ÿ˜ฑ7โšก5๐Ÿ”ฅ5๐Ÿ˜4
Beware of the latest cyber threat๐Ÿšจ

Hackers are distributing a new Golang-based info stealer malware, known as Titan Stealer, through Telegram channels to other cybercriminals โ€” that can steal browser credentials, crypto wallets, and more.

Read: https://thehackernews.com/2023/01/titan-stealer-new-golang-based.html
๐Ÿคฏ41๐Ÿ‘25๐Ÿ”ฅ7โšก5๐Ÿ˜5๐Ÿ˜ฑ5๐Ÿ‘3
GitHub reports unauthorized access ๐Ÿ’ป๐Ÿ‘ฎโ€โ™‚๏ธ to Desktop & Atom apps repositories, leading to exposure of encrypted ๐Ÿ”’ code-signing certificates.

Read details: https://thehackernews.com/2023/01/github-breach-hackers-stole-code.html
๐Ÿคฏ21๐Ÿ‘11๐Ÿ˜ฑ8
Don't risk losing your data!

QNAP has released security updates to address a critical vulnerability (CVE-2022-27596 / CVSS 9.8) in the NAS devices QTS 5.0.1 & QuTS hero h5.0.1 that can be used to inject arbitrary code.

Read: https://thehackernews.com/2023/01/qnap-fixes-critical-vulnerability-in.html
๐Ÿ‘29๐Ÿ”ฅ8๐Ÿคฏ7๐Ÿ‘4๐Ÿ˜2