The Hacker News
151K subscribers
1.86K photos
10 videos
3 files
7.77K links
Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

📨 Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
🤖 Nim-Based #malware on the rise.

Attackers are increasingly using Nim language for threats like NimzaLoader and Dark Power ransomware.

Learn more: https://thehackernews.com/2023/12/decoy-microsoft-word-documents-used-to.html
🔥12👍51😁1
🕵️‍♂️🔒 Indian government and defense entities under attack! A phishing campaign dubbed "Operation RusticWeb" deploys Rust-based malware for intel gathering.

Learn more: https://thehackernews.com/2023/12/operation-rusticweb-rust-based-malware.html
🔥14👍6😱21
🚨 Rogue WordPress Plugin Alert!

A malicious plugin capable of stealing credit card info has been discovered. It pretends to be "WordPress Cache Addons" and is part of a Magecart campaign targeting e-commerce websites.

Learn more: https://thehackernews.com/2023/12/rogue-wordpress-plugin-exposes-e.html
👍18🔥8😱6🤔52👏2
Two British teens, part of the LAPSUS$ cybercrime gang, sentenced for orchestrating high-profile attacks against companies.

Read: https://thehackernews.com/2023/12/british-lapsus-teen-members-sentenced.html

One receives an indefinite hospital order due to intent to return to cybercrime.
👍41😱8🔥5🤯42👏2
🚨Cloud Atlas, a mysterious cyber espionage group, has launched spear-phishing attacks on Russian enterprises, targeting critical sectors.

Learn how these attacks unfold in this report: https://thehackernews.com/2023/12/cloud-atlas-spear-phishing-attacks.html
👍24🔥14👏6😁3🤯31
Carbanak malware is back, and it's using new tactics in ransomware attacks. Learn how it's impersonating business software to infiltrate systems.

Learn more: https://thehackernews.com/2023/12/carbanak-banking-malware-resurfaces.html
😱26🔥8👍62
🚨 Poorly secured Linux SSH servers are under attack!

Threat actors are installing tools to guess credentials, co-opt other servers, and launch cryptocurrency mining and DDoS attacks.

Read: https://thehackernews.com/2023/12/warning-poorly-secured-linux-ssh.html
🔥17👍65
📱 Beware of Xamalicious! It masquerades as legitimate apps on Android devices but secretly carries out fraudulent actions like clicking on ads.

Over 327,000 installs!

Learn more: https://thehackernews.com/2023/12/new-sneaky-xamalicious-android-malware.html
🔥11👍76
⚠️ALERT: Chinese threat actors exploited a new zero-day vulnerability (CVE-2023-7102) in Barracuda's Email Security Gateway (ESG) appliances.

Learn how they deployed a backdoor on select devices.

Read details: https://thehackernews.com/2023/12/chinese-hackers-exploited-new-zero-day.html
👍11🔥5👏2🤯2😱2😁1
🚨 A new zero-day security flaw discovered in Apache OfBiz ERP system could allow unauthorized access.

CVE-2023-51467 exposes incomplete patch for CVE-2023-49070 with a high CVSS score of 9.8.

Details: https://thehackernews.com/2023/12/critical-zero-day-in-apache-ofbiz-erp.html

Update now to protect your system!
🤯21👍11👏2😁2
🚨 New Malware Alert - Threat actors are using the Rugmi loader to deliver information stealers like Lumma Stealer and Vidar.

Learn more: https://thehackernews.com/2023/12/new-rugmi-malware-loader-surges-with.html
🔥12👍6🤯4😁3😱3
"Most Sophisticated" SPYWARE attack campaign called 'Operation Triangulation' targeted Apple iOS devices with never-before-seen exploits, including exploiting an unknown hardware feature.

Learn more: https://thehackernews.com/2023/12/most-sophisticated-iphone-hack-ever.html
🔥24🤯14👍12
🚨 Alert - Google Cloud addresses a medium-severity security flaw that could allow attackers to escalate privileges in Kubernetes clusters.

Learn more about this issue: https://thehackernews.com/2023/12/google-cloud-resolves-privilege.html
👍23🤔4🤯4👏3😁3
🔒 Microsoft is disabling the ms-appinstaller protocol handler by default due to its abuse by multiple threat actors for distributing malware.

Read details: https://thehackernews.com/2023/12/microsoft-disables-msix-app-installer.html
👏21👍12🔥6
💻 North Korean hackers are using spear-phishing attacks to compromise machines and deploy malware like AppleSeed and Meterpreter.

Read more about the cyber threat: https://thehackernews.com/2023/12/kimsuky-hackers-deploying-appleseed.html
🔥8👍65🤯1
🚨 ALERT: Ukraine's CERT warns of a new phishing campaign by Russia-linked APT28.

They're deploying stealthy malware like MASEPIE and STEELHOOK to target government entities.

Read details: https://thehackernews.com/2023/12/cert-ua-uncovers-new-malware-wave.html
👍26🔥5👏3😁3🤔1
Iranian hacker group Homeland Justice claims responsibility for the cyber attacks that targeted the Assembly of the Republic and the telecom company One Albania.

Read details: https://thehackernews.com/2023/12/albanian-parliament-and-one-albania.html
👍30👏12😁9🔥7🤔52
🚨 Warning: Phishing attacks, especially Angel Drainer, offered as a "scam-as-a-service," are targeting 💰 cryptocurrency wallets, draining them of digital assets.

Find details here: https://thehackernews.com/2023/12/beware-scam-as-service-aiding.html
🤯24🔥12👍11😁3👏21
Beware: JinxLoader, a new Go-based malware loader, is proliferating via phishing attacks, providing access to Formbook and XLoader.

Find details here: https://thehackernews.com/2024/01/new-jinxloader-targeting-users-with.html
🔥16😱6👍3🤯21🤔1
🔒 Alert: Researchers have discovered a new SSH protocol vulnerability, "Terrapin" (CVE-2023-48795), enabling attackers to downgrade SSH connection security.

Learn more: https://thehackernews.com/2024/01/new-terrapin-flaw-could-let-attackers.html

Update and patch your SSH servers ASAP.
🤯21🔥105👍5🤔3