The Hacker News
151K subscribers
1.85K photos
10 videos
3 files
7.77K links
Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

📨 Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
Big 4 mobile carriers in the U.S. — Verizon, AT&T, Sprint and T-Mobile — join forces to replace ancient SMS service with RCS-based enhanced messaging protocol in 2020.

Read ➤ https://thehackernews.com/2019/10/rcs-messaging-sms.html
Here We ADOBE Again!

An Unsecured Adobe’s 'Prototype' Server Exposes Data for 7.5 Million Creative Cloud Users

Read details ➤ https://thehackernews.com/2019/10/adobe-database-leaked.html
CVE-2019-11043 🔥

A new RCE flaw in PHP 7+ could allow attackers to hack sites running on Nginx with php-fpm enabled on certain configurations—which is reportedly not uncommon.

Read Details ➤ https://t.co/coTu2lh1bK

➡️ PHP released patches
➡️ Researcher released PoC exploit
Russian Hackers Spotted Targeting Anti-Doping Agencies Worldwide Ahead of Tokyo 2020 Olympics

https://thehackernews.com/2019/10/cyber-attack-tokyo-olympics.html

Cyber attacks began apparently after the World Anti-Doping Agency warned Russian athletes could face a ban from competing at the Olympics over finding irregularities in a database from Russia's national anti-doping laboratory.
The Pirate Bay torrent search website was recently down for over a week due to a DDoS attack, reportedly launched by sending specially crafted search queries to the buggy open-source text search software used by the website.





https://thehackernews.com/2019/10/the-pirate-bay-down.html
Facebook Sues Infamous Israeli Spyware Firm NSO Group For Hacking WhatsApp Users

https://thehackernews.com/2019/10/whatsapp-nso-group-malware.html

According to a lawsuit filed today, Facebook accused the surveillance firm of its involvement in exploiting a WhatsApp 0-day flaw (in May 2019) to install Pegasus spyware on nearly 1400 targeted Android and iOS devices.

Finally, for the very first time, encrypted messaging service provider is taking legal action against a private entity that has carried out malicious attacks against its users.
North Korean Hackers Target India's Kudankulam Nuclear Power Plant – Here's Everything We Know So Far

Details ➤ https://thehackernews.com/2019/10/nuclear-power-plant-cyberattack.html
Two hackers — who extorted money from Uber (~ $100,000) and LinkedIn in exchange for promises to delete data of millions of customers they had stolen — have pleaded guilty of the offences charged.

Read ➤ https://thehackernews.com/2019/10/hackers-extorted-money.html
5 Places Where Hackers Are Stealthily Stealing Your Data In 2019

https://thehackernews.com/2019/10/hacking-data-breach-protection.html
Leading Web Domain Name Registrars Disclose Data Breach Incidents Affecting Millions of their Customers.

1️⃣ Web[.]com
2️⃣ Network Solutions
3️⃣ Register[.]com

Details ➤ https://thehackernews.com/2019/10/domain-name-registrars-hacked.html
🔥💬👆

Chinese hackers compromise Telecom servers with a new “MessageTap” malware that spies on SMS messages sent/received by high-ranking individuals with specific phone numbers, IMSI or messages containing certain keywords.

Read details ➤ https://thehackernews.com/2019/10/sms-spying-malware.html
👍1
🔥 Watch out! It’s finally happening. Cybersecurity researchers have spotted first cyberattack that’s 'mass-exploiting' BlueKeep RDP flaw in the wild. However, fortunately, this attack isn’t wormable and typically an immature attempt, but still exploits vulnerable systems connected to the Internet to install cryptocurrency malware.

Find more details on THN ➤ https://thehackernews.com/2019/11/bluekeep-rdp-vulnerability.html
Watch Out IT Admins!

PoC exploits for two new "unpatched RCE flaws" in rConfig network configuration management tool have been disclosed publicly, allowing unauthenticated remote hackers to compromise targeted servers and subsequent network devices.

https://thehackernews.com/2019/11/rConfig-network-vulnerability.html
In case you missed them, 🙂 here are some interesting cybersecurity stories from last week.

https://www.linkedin.com/pulse/newsletter-last-weeks-top-cyber-security-stories-mohit-kumar
This is interesting...

Hackers can covertly inject inaudible commands into voice controlled devices—Google Home, Alexa, Apple Siri—by shining a laser at them from several meters away.

Read ➤ https://thehackernews.com/2019/11/hacking-voice-assistant-laser.html

OK Google, open the garage door
Hey Siri, unlock my car
👍1
Two former Twitter employees have been caught helping Saudi Arabia spy on dissidents and critics by selling out their personal information.

Read more: https://thehackernews.com/2019/11/twitter-spying-saudi-arabia.html
Tech giants announce support for "Delegated Credentials for TLS," a new protocol designed for security that offers websites a reliable way to deploy TLS certificates with a validity of a short period, i.e., up to 7 days.

In this article we have covered:

Over of the current TLS infrastructure
Why we need Delegated Credentials for TLS?
What is Delegated Credentials for TLS?
How does it boost TLS protocol security?

Read more: https://thehackernews.com/2019/11/delegated-credentials-for-tls.html
Facebook’s Latest Privacy Mishap:

Social media company today revealed that a bug in its system unknowingly allowed 100 app developers to ‘improperly access’ data on members in certain Facebook groups.

Read more: https://thehackernews.com/2019/11/facebook-groups-data-leak.html
A security vulnerability in Amazon's Smart Ring Video Doorbell 🔔 Pro devices could have let remote attackers steal your Wi-Fi password.

Learn how ➤ https://thehackernews.com/2019/11/ring-doorbell-wifi-password.html