The Hacker News
βœ”
151K subscribers
1.84K photos
10 videos
3 files
7.76K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
Play ransomware has turned into Ransomware-as-a-Service (RaaS), allowing other cybercriminals to use it.

Operators offering a complete packageβ€”documentation, forums, technical support, and even help with negotiating ransoms.

Read: https://thehackernews.com/2023/11/play-ransomware-goes-commercial-now.html
😁16😱12πŸ‘9πŸ€”4πŸ‘3
πŸ”’ Critical Security Alert: Threat actors, including LockBit ransomware affiliates, exploit the Citrix NetScaler flaw ("Citrix Bleed") to hijack user sessions and gain unauthorized access.

Learn more in this article: https://thehackernews.com/2023/11/lockbit-ransomware-exploiting-critical.html
πŸ”₯13πŸ‘7
🚨 macOS users beware! Atomic Stealer, a $1,000/month malware, is now spreading through deceptive web browser updates via ClearFake.

Find out how it infiltrates your device through compromised websites: https://thehackernews.com/2023/11/clearfake-campaign-expands-to-deliver.html
πŸ‘14πŸ”₯6πŸ‘4
⚠️ North Korean hackers posing as recruiters infect software developers with cross-platform malware named "BeaverTail" and "InvisibleFerret," targeting Windows, Linux, and macOS systems during fake interviews.

Learn more: https://thehackernews.com/2023/11/north-korean-hackers-pose-as-job.html
πŸ”₯20πŸ‘6🀯5😱1
πŸ‘©β€πŸ’Ό Employees are embracing AI tools, and the pressure on CISOs is rising. The rapid adoption of AI, like ChatGPT, is reshaping cybersecurity.

Are we prepared for the risks?

Discover the risks and how to mitigate them: https://thehackernews.com/2023/11/ai-solutions-are-new-shadow-it.html
πŸ”₯16πŸ‘6πŸ€”5😁1
πŸ”’ Multiple vulnerabilities have been discovered in laptop fingerprint sensors, potentially allowing attackers to bypass Windows Hello authentication on Dell, Lenovo, and Microsoft laptops.

Find out more:https://thehackernews.com/2023/11/new-flaws-in-fingerprint-sensors-let.html
πŸ”₯31πŸ‘8😁7😱5πŸ‘2πŸ€”2
North Korean hackers, aka Diamond Sleet, spread a trojanized version of CyberLink's legit app.

Beware - They're using supply chain tricks to smuggle in malicious code.

Learn more about this attack: https://thehackernews.com/2023/11/north-korean-hackers-distribute.html
πŸ‘11πŸ”₯8🀯3πŸ€”2
Protect your organization from cyber threats with a Master's in Cybersecurity Risk Management from Georgetown University.

Attend a Sample Class β€” Security Architecture Design β€” on November 30 : https://thn.news/PqRskMsW
πŸ‘18πŸ”₯6😁4πŸ€”3
🚨 Alert: Active malware campaign exploits zero-day vulnerabilities to create a Mirai-based DDoS botnet targeting routers and NVR devices.

Learn more: https://thehackernews.com/2023/11/mirai-based-botnet-exploiting-zero-day.html
πŸ”₯9πŸ‘6⚑2πŸ€”2🀯2
Effective Incident Response is more than just tools. It's a process.

Explore the 6-step framework for successful IR: Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned.

Readn here: https://thehackernews.com/2023/11/6-steps-to-accelerate-cybersecurity.html
πŸ‘10πŸ”₯5🀯3⚑2πŸ‘2
⚠️ Beware: WailingCrab malware is spreading.

This sneaky loader spreads through shipping-themed emails. Once in your system, it establishes persistence and communicates via MQTT protocol.

Learn more: https://thehackernews.com/2023/11/alert-new-wailingcrab-malware-loader.html
πŸ”₯9πŸ‘7
🚨 Threat actor Konni, potentially tied to North Korea, deploys RAT in cyber espionage using Russian Word doc, exploiting WinRAR flaw, obfuscated VB scripts, UAC bypass payload, and using encrypted C2 communication.

Learn more: https://thehackernews.com/2023/11/konni-group-using-russian-language.html
πŸ”₯12πŸ‘5😁2🀯2
🚨 Alert: Researchers have discovered publicly exposed Kubernetes configuration secrets, posing a risk of supply chain attacks to blockchain and Fortune-500 companies.

Details: https://thehackernews.com/2023/11/kubernetes-secrets-of-fortune-500.html

46% of records may have valid container image registry credentials.
πŸ”₯18πŸ‘9🀯4
Researchers found a Rust version of SysJoker, a cross-platform backdoor used by Hamas-affiliated threat actor targeting Israel during ongoing conflict.

Read details here: https://thehackernews.com/2023/11/hamas-linked-cyberattacks-using-rust.html
πŸ”₯14😁10πŸ‘8🀯2πŸ‘1
⚑️ Has Your Secret Leaked? Here's the easiest way to find out.

GitGuardian launches the "HasMySecretLeaked" service to help developers check if their sensitive information has been exposed on GitHub, such as passwords, API keys, cryptographic certificates.

Read: https://thehackernews.com/2023/11/tell-me-your-secrets-without-telling-me.html
πŸ‘21πŸ‘9⚑6😁5πŸ€”4
🚨 Watch Out! Cybercriminals are using a malicious Telegram bot called "Telekopye" for large-scale phishing scams, creating fake websites, emails, and more.

Learn more: https://thehackernews.com/2023/11/cybercriminals-using-telekopye-telegram.html
πŸ‘23πŸ”₯9😁6🀯6
🚨 Critical Security Alert β€” ownCloud, an open-source file-sharing software, has disclosed 3 critical vulnerabilities. These can lead to sensitive information disclosure and unauthorized file modification.

Learn more: https://thehackernews.com/2023/11/warning-3-critical-vulnerabilities.html
πŸ”₯19πŸ‘7😁4😱4⚑2
πŸ•΅οΈβ€β™‚οΈ New Threat Alert: A new web shell called HrServ is part of a suspected APT attack in Afghanistan. HrServ can erase tracks and execute code in memory, increasing the threat's complexity.

Learn more: https://thehackernews.com/2023/11/new-hrservdll-web-shell-detected-in-apt.html
πŸ”₯19πŸ‘13😁7
U.K., U.S., and 16 other international partners have released new GUIDELINES for the development of secure Artificial Intelligence (AI) systems.

Read details here: https://thehackernews.com/2023/11/us-uk-and-global-partners-release.html
πŸ‘32πŸ€”17🀯10πŸ”₯6⚑4😁4😱2πŸ‘1
Did you know retailers face a vast cyber attack surface on #CyberMonday?

Today's retail isn't just about sales; it's about securing the SaaS apps that power those sales.

Learn how to fortify your SaaS apps against cyber threats: https://thehackernews.com/2023/11/how-to-handle-retail-saas-security-on.html
πŸ”₯11πŸ‘6