The Hacker News
152K subscribers
1.87K photos
10 videos
3 files
7.78K links
Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

📨 Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
Popular PAX PoS systems used in countless stores worldwide are vulnerable to crippling attacks.

Hackers could hijack transactions, steal data, and wreak havoc.

Are you patched? Read the full story: https://thehackernews.com/2024/01/pax-pos-terminal-flaw-could-allow.html
🤯8👍4🔥4
99.7% of orgs use AI-powered SaaS. Your favorite productivity apps might be quietly learning from your data & code.

Wing Security's free discovery tool exposes the hidden AI in your SaaS & lets you take back control.

Learn more: https://thehackernews.com/2024/01/combating-ip-leaks-into-ai-applications.html
👍14🤯8👏3😁3🤔3
🔒 Multiple vulnerabilities, called "PixieFail," found in UEFI firmware used by major manufacturers like AMI and Intel. Attackers can exploit these vulnerabilities to gain control, steal data, or cause damage.

Details ➡️ https://thehackernews.com/2024/01/pixiefail-uefi-flaws-expose-millions-of.html
🤯12👍8👏8
Remember those annoying texts you keep approving? They might be hacker traps!

Learn about MFA spamming and expert tips ➡️ https://thehackernews.com/2024/01/mfa-spamming-and-fatigue-when-security.html
🔥11👍6🤯5🤔4
⚠️ Developers, beware! Hackers can poison AI models and software. Vulnerabilities found in TensorFlow CI/CD pipeline allow #malware upload and token theft.

Learn about the AI/ML threat: https://thehackernews.com/2024/01/tensorflow-cicd-flaw-exposed-supply.html
👏15😱7👍5😁5
Russian Spy Group Now Deploying Custom "SPICA" Backdoor!

TAG exposes COLDRIVER's evolution from phishing to malware attacks targeting Ukraine, NATO, and beyond.

Learn their sneaky tactics: https://thehackernews.com/2024/01/russian-coldriver-hackers-expand-beyond.html
👏11👍6😱4
A new attack targets Docker servers and uses a combo of cryptocurrency mining and website traffic generation for profit. It could leave a backdoor for attackers to exploit later.

Patch your systems and monitor for suspicious activity: https://thehackernews.com/2024/01/new-docker-malware-steals-cpu-for.html
🤯16👍9🔥9
🆘 Patch your Ivanti ASAP! CISA urges action, especially for government agencies.

A critical flaw (CVE-2023-35082) in Ivanti EPMM is being exploited in the wild, giving attackers access to your data.

Don't wait, read more: https://thehackernews.com/2024/01/us-cybersecurity-agency-warns-of.html
👍14👏7
Ransomware, hardware failure, human error - the data loss threats in Exchange Servers are real.

Protect your Exchange Server from financial ruin & reputational nightmares with these 5 backup methods & proactive measures: https://thehackernews.com/2024/01/preventing-data-loss-backup-and.html
👍12🔥7
RAT Alert! Malicious "oscompatible" package on npm deployed a sophisticated trojan on Windows machines. It steals data, hides your screen, and even disables shutdowns

Read details here: https://thehackernews.com/2024/01/npm-trojan-bypasses-uac-installs.html
👍20🤯8🤔3
Thinking of downloading a pirated copy of that software?

⚠️ Think again. A new backdoor malware has been discovered in pirated macOS apps, granting hackers full control of users' devices.

Learn more: https://thehackernews.com/2024/01/experts-warn-of-macos-backdoor-hidden.html
😁35🤔95😱5👍4
🛡️ TA866 is back with thousands of invoice-themed, booby-trapped emails targeting users with WasabiSeed and Screenshotter malware to spy on your screen and steal valuable data.

Learn more: https://thehackernews.com/2024/01/invoice-phishing-alert-ta866-deploys.html
👍16😁4
🔐 Microsoft discloses Russian APT infiltrated its systems through a test account, stealing emails and attachments of senior executives and others in cybersecurity and legal departments.

Find details here ➡️ https://thehackernews.com/2024/01/microsofts-top-execs-emails-breached-in.html
😁23🔥11😱9👍8👏4
🚨CISA issues emergency directive against two major zero-day actively exploited flaws in Ivanti products.

Learn more: https://thehackernews.com/2024/01/cisa-issues-emergency-directive-to.html

Patch your Ivanti Connect Secure and Policy Secure ASAP.
👍22🤯4
Age ain't nothin' but a number... for vulnerabilities, that is. 35% of serious flaws linger for months! Time to prioritize patching.

Learn how in "Security Navigator 24" - https://thehackernews.com/2024/01/52-of-serious-vulnerabilities-we-find.html
👍19
Alert! New Java malware "NS-STEALER" uses bots to steal your logins and wallet data from popular browsers and exfiltrates secrets via Discord.

Learn more: https://thehackernews.com/2024/01/ns-stealer-uses-discord-bots-to.html
👍17
FTC bans another data broker, InMarket, for selling our movements without consent. Protect yourself: learn how they track you & what you can do

Read: https://thehackernews.com/2024/01/ftc-bans-inmarket-for-selling-precise.html
👍7
Hackers Feast on Unpatched ActiveMQ! CVE-2023-46604, a critical remote code execution flaw, is back in the spotlight.

Learn more: https://thehackernews.com/2024/01/apache-activemq-flaw-exploited-in-new.html

Update your Apache ASAP or risk ransomware, rootkits, and botnets.
👍9😁6
Java & Android libraries vulnerable to new supply chain attack — MavenGate!

Hackers can hijack popular abandoned libraries & inject malware into your apps.

Click to read more: https://thehackernews.com/2024/01/hackers-hijack-popular-java-and-android.html
😱19🤯7👍4
North Korea's ScarCruft targeting media & experts.

A new attack campaign using fake threat reports & infected ZIPs aimed at gathering intel on defense strategies.

Find details here: https://thehackernews.com/2024/01/north-korean-hackers-weaponize-fake.html
👍9🤔5😱5👏2