The Hacker News
152K subscribers
1.88K photos
10 videos
3 files
7.79K links
Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

📨 Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
Critical flaw affecting ME RTU remote terminal units!

CISA has issued an advisory about the security vulnerability tracked as CVE-2023-2131, which has received the highest severity rating of 10.0 on the CVSS scoring system.

Details: https://thehackernews.com/2023/05/cisa-issues-advisory-on-critical-rce.html
👍13😁7🔥2
🚨 Cybersecurity alert! Over 50,000 attempts to exploit a 5-year-old unpatched flaw in TBK digital video recording devices were observed in April.

Learn more about the critical vulnerability and its impact on camera video feeds: https://thehackernews.com/2023/05/hackers-exploiting-5-year-old-unpatched.html
🔥13👍10😁62🤯2
Apple and Google are joining forces to tackle unauthorized tracking on Bluetooth location-tracking devices like AirTags.

https://thehackernews.com/2023/05/apple-and-google-join-forces-to-stop.html

They are working on a draft industry-wide specification that will detect and alert users of any unauthorized tracking.
👍50👏8🔥63🤔3
Operation SpecTor has resulted in the arrest of 288 dark web vendors involved in drug trafficking. This coordinated effort also seized $53.4 million, 850 kg of drugs, and 117 firearms.

Read details: https://thehackernews.com/2023/05/operation-spector-534-million-seized.html
😱24👍12👏9🤔76🔥3
Chinese state-sponsored hacking outfit Earth Longzhi, a subgroup within APT41, has launched a new hacking campaign targeting government, healthcare, tech & manufacturing entities in Taiwan, Thailand, the Philippines, and Fiji.

Details: https://thehackernews.com/2023/05/chinese-hacker-group-earth-longzhi.html
👍16😁4🔥2👏2🤯2😱1
Google is rolling out Passkeys across all platforms, making it a passwordless solution for Google Accounts.

Learn how it works: https://thehackernews.com/2023/05/google-introduces-passwordless-secure.html

Passkeys, backed by the FIDO Alliance, are more secure than passwords and resistant to online attacks such as phishing.
👍55🤔9🤯65🔥3👏3😁1
🤖 Facebook has taken action against malicious campaigns leveraging popular topics like ChatGPT, Google BERT, and TikTok marketing tools as a lure to trick users into downloading malware.

Details: https://thehackernews.com/2023/05/meta-takes-down-malware-campaign-that.html

Stay cautious and avoid clicking on suspicious links!
👍18🤔13🔥7😁6😱6
Meta, the parent company of Facebook and Instagram, has taken down several cyber espionage campaigns that targeted South Asia through coordinated inauthentic behavior on social media platforms.

Read more to learn about it: https://thehackernews.com/2023/05/meta-uncovers-massive-social-media.html
👍28😁7🤔4🔥2
🔥 Researchers have developed a new PoC exploit for a critical PaperCut server vulnerability that can bypass all current detections, allowing attackers to execute arbitrary code with SYSTEM privileges.

Learn details here: https://thehackernews.com/2023/05/researchers-uncover-new-exploit-for.html
12🤯8👏3👍2🔥2😱2😁1🤔1
🚨 Three new security flaws discovered in Microsoft Azure API Management service that could expose sensitive information and compromise backend services.

Learn more about these vulnerabilities: https://thehackernews.com/2023/05/researchers-discover-3-vulnerabilities.html
😁17🤔8😱85👍5🔥3🤯1
Beware Android users! A new subscription #malware named Fleckpe has been discovered on Google Play Store. The #malware was disguised as photo editing apps, camera, and wallpaper packs, amassing over 620,000 downloads since 2022.

https://thehackernews.com/2023/05/fleckpe-android-malware-sneaks-onto.html
😱24😁10👍6🤯6
Cisco has warned of a critical vulnerability (CVE-2023-20126) in SPA112 2-Port Phone Adapters that could allow remote attackers to execute arbitrary code.

Learn more: https://thehackernews.com/2023/05/cisco-warns-of-vulnerability-in-popular.html

Upgrade now to protect your devices!
👍20😁5👏4
🚨 Packagist, the PHP package repository, suffered a security incident where an attacker gained access to four inactive accounts and hijacked over a dozen packages with 500 million installs.

Read details: https://thehackernews.com/2023/05/packagist-repository-hacked-over-dozen.html
👏13👍12🔥5😁4😱1
⚠️ North Korean hackers Kimsuky using new ReconShark reconnaissance tool to target individuals via spear-phishing emails, OneDrive links & malicious macros.

Read more about "ReconShark" tool here: https://thehackernews.com/2023/05/n-korean-kimsuky-hackers-using-new.html
13👍12😱6😁1🤔1
Italian corporate banking clients are under attack by a sophisticated financial fraud campaign that uses a new web-inject toolkit called drIBAN.

Learn how it works: https://thehackernews.com/2023/05/hackers-targeting-italian-corporate.html
👍19😁9🤯4👏3
🚨 Alert: East Asian markets hit by a new Android malware named FluHorse. It abuses the Flutter software development framework to mimic legitimate apps and steal credentials.

Learn more about it here: https://thehackernews.com/2023/05/new-android-malware-fluhorse-targeting.html
🤯24👍94🤔4😱4😁3
If you're using the Advanced Custom Fields plugin for WordPress, make sure to update to version 6.1.6 as soon as possible!

A security flaw (CVE-2023-30777) has been discovered that could allow for reflected cross-site scripting attacks.

https://thehackernews.com/2023/05/new-vulnerability-in-popular-wordpress.html
👍54😁11🤔6🔥43
Dragon Breath APT group has added another layer of complexity to its attacks.

Learn how they use the double-clean-app technique to sideload malicious DLLs and target the online gaming and gambling industries: https://thehackernews.com/2023/05/dragon-breath-apt-group-using-double.html
👍42😁102
Ukraine's CERT-UA warns of RoarBAT wiper malware causing destructive attacks on state organizations, and invoice-themed phishing campaigns spreading SmokeLoader malware.

Learn more: https://thehackernews.com/2023/05/cert-ua-warns-of-smokeloader-and.html
👍25😁6🤔4🔥1
Action RAT and AllaKore RAT are the latest strains of malware deployed by SideCopy to carry out spear-phishing email attacks using #Indian government and defense-related social engineering lures.

Read latest report: https://thehackernews.com/2023/05/sidecopy-using-action-rat-and-allakore.html
11🤔5👍4😁4🔥2