The Hacker News
βœ”
151K subscribers
1.84K photos
9 videos
3 files
7.76K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
πŸ’» Hackers linked to Russia have been exploiting a Windows bug for YEARS to deploy GooseEgg malware for escalating attack access.

More insights here... https://thehackernews.com/2024/04/russias-apt28-exploited-windows-print.html
🀯20😁12πŸ‘6
U.S. State Department imposed visa restrictions on 13 individuals linked to selling spyware for surveillance misuse targeting journalists, academics, and human rights defenders.

Read: https://thehackernews.com/2024/04/us-imposes-visa-restrictions-on-13.html
πŸ‘16😁6
The Great Privacy Debate >>

European law enforcement agencies are deeply concerned about the widespread use of end-to-end encryption (E2EE), indicating it could severely hamper efforts to tackle online crimes like child abuse and terrorism.

https://thehackernews.com/2024/04/police-chiefs-call-for-solutions-to.html
πŸ€”20πŸ‘17
Germany issues arrest warrants for 3 citizens accused of spying for China to obtain sensitive tech data that could aid Beijing's military capabilities.

Find details here: https://thehackernews.com/2024/04/german-authorities-issue-arrest.html
πŸ€”14πŸ‘9πŸ”₯8😁5
Lost revenue, angry customers, regulatory fines… cyberattacks have far-reaching consequences.

πŸ‘‰ Projected costs to hit $10.5 trillion by 2025
πŸ‘‰ 88% of breaches due to human error

Get the full story and prepare: https://thehackernews.com/2024/04/unmasking-true-cost-of-cyberattacks.html
πŸ‘22πŸ€”1
🚨 Researchers discovered a "dependency confusion" #vulnerability in an archived Apache project, Cordova App Harness.

Get all the details in our latest post: https://thehackernews.com/2024/04/apache-cordova-app-harness-targeted-in.html
πŸ‘17πŸ€”5
A new malware campaign has been observed distributing three info-stealersβ€”CryptBot, LummaC2, and Rhadamanthysβ€”using CDN cache domains to avoid detection.

Read: https://thehackernews.com/2024/04/coralraider-malware-campaign-exploits.html
πŸ‘7😁6🀯5
⚠️ Malware Alert: A sophisticated campaign called GuptiMiner is exploiting a vulnerability in eScan antivirus to distribute backdoors and crypto miners.

Read on to explore the potential state-sponsored ties: https://thehackernews.com/2024/04/escan-antivirus-update-mechanism.html
πŸ‘9⚑4πŸ‘4
⚑ Major security flaws uncovered in popular Chinese keyboard apps, which could expose users' private keystrokes.

Over 1 billion people using Baidu, Honor, iFlytek, OPPO, Samsung, Tencent, Vivo, and Xiaomi devices may be affected.

Details: https://thehackernews.com/2024/04/major-security-flaws-expose-keystrokes.html
πŸ‘14🀯7😁5πŸ‘1
IT offboarding is my favorite task! Said no one, ever.

Automate 90% of IT manual offboarding tasks with Nudge Security. Discover ALL SaaS identities and automate steps to revoke access, including OAuth grants and non-SSO accounts.

Get started here: https://thn.news/automated-it-offboarding-software
πŸ‘14πŸ”₯8
πŸ•΅οΈβ€β™‚οΈ Heads up! Researchers have uncovered a sneaky attack delivering malware called SSLoad through phishing emails. This cunning malware infiltrates systems, steals sensitive data, and relays it back to the attackers.

Read: https://thehackernews.com/2024/04/researchers-detail-multistage-attack.html
😁7πŸ‘2
U.S. Treasury Department has sanctioned two Iranian firms and four individuals for their involvement in malicious cyber activities targeting U.S. companies and government entities on behalf of the IRGC-CEC.

More details. πŸ‘‡ https://thehackernews.com/2024/04/us-treasury-sanctions-iranian-firms-and.html
😁12πŸ‘5
What to consider when evaluating tools to help activate & keep up with CTEM?🧐

We got your answers right here⬇️

Check out XM Cyber Buyer’s Guide to Meeting & Maintaining CTEM & start building consistent, actionable exposure remediation plans.

Dowload now: https://thn.news/ctem-buyers-guide
πŸ‘10πŸ”₯2
UPDATE β€” Airbus CERT releases Python scripts to scan for the critical CrushFTP flaw (CVE-2024-4040) that allows remote code execution. The zero-day has been exploited in attacks against U.S. entities.

Check: https://thehackernews.com/2024/04/critical-update-crushftp-zero-day-flaw.html

#infosec
πŸ‘20🀯6😁2⚑1
New stealthy malware campaign exploits 2 ZERO-DAY flaws in Cisco devices, enabling covert data collection & reconnaissance by a state-sponsored actor.

Details: https://thehackernews.com/2024/04/state-sponsored-hackers-exploit-two.html

"Line Runner" and "Line Dancer" implants allow config changes and traffic capture.
πŸ‘16πŸ”₯10⚑1
U.S. Department of Justice arrested two founders of cryptocurrency mixer Samourai, seizing the service, for allegedly enabling over $2 billion in illegal transactions and laundering more than $100 million in criminal proceeds.

Learn more: https://thehackernews.com/2024/04/doj-arrests-founders-of-crypto-mixer.html
🀯18πŸ‘12πŸ€”8⚑1😁1
The new #YARA search tool from AnyRun helps you quickly find relevant threats.

πŸ” Scan the service's public malware database using your own YARA rules to identify matching files. Explore the findings further in the sandbox.

Learn more ➑️ https://thehackernews.uk/yara-malware-search
πŸ”₯17πŸ‘10😁4⚑1
North Korean hackers used fake job offers to deliver a new Trojan called Kaolin RAT. It can change file timestamps and load malware - a gateway to the dangerous FudModule rootkit.

Details here: https://thehackernews.com/2024/04/north-koreas-lazarus-group-deploys-new.html
🀯24πŸ‘11πŸ”₯8⚑1😁1
🚨 Attention WordPress users!

A critical SQL injection vulnerability (CVE-2024-27956) in the WP-Automatic plugin is being actively exploited. With a max severity of 9.9/10, this bug enables site takeovers and malicious activities.

Details: https://thehackernews.com/2024/04/hackers-exploiting-wp-automatic-plugin.html
πŸ‘19😁8🀯8πŸ”₯4⚑2
⚠️ Attention Android users!

A new malware called Brokewell is disguising itself as updates for popular apps like Google Chrome and Klarna. Don't fall for these fake updates.

Click to find out more: https://thehackernews.com/2024/04/new-brokewell-android-malware-spread.html
😁12πŸ‘7⚑2πŸ€”2😱1