The Hacker News
βœ”
151K subscribers
1.86K photos
10 videos
3 files
7.77K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
⚠️ Alert: SolarWinds Serv-U vulnerability (CVE-2024-28995) is under active exploitation. Urgent update required to protect sensitive data from unauthorized access.

Learn more: https://thehackernews.com/2024/06/solarwinds-serv-u-vulnerability-under.html
πŸ‘10😁7😱6πŸ‘1
🚨 Searching for Google Chrome or Microsoft Teams? Be cautious!

Cybercriminals are exploiting search engines to redirect users to fake websites & distribute trojanized versions of popular apps to spread the Oyster #malware.

Read: https://thehackernews.com/2024/06/oyster-backdoor-spreading-via.html
😁14πŸ‘11😱7πŸ‘2
πŸ“ Beware of ZIP files!

Discover how a new phishing campaign targets Pakistan using military-themed emails to spread PHANTOM#SPIKE, a custom backdoor granting remote system access.

Learn more: https://thehackernews.com/2024/06/military-themed-emails-used-to-spread.html
πŸ”₯11😱9πŸ‘6πŸ€”3🀯1
🚨 New Threat Alert!

Chinese-speaking SneakyChef hackers are targeting government entities worldwide and AI-focused organizations with sophisticated SugarGh0st and SpiceRAT malware.

Get the latest insights β€” https://thehackernews.com/2024/06/chinese-hackers-deploy-spicerat-and.html
πŸ‘14πŸ”₯5🀯5πŸ€”3
Discover the power of SOC Automation Capability Matrix for cybersecurity incident response and workflow automation. Perfect for enhancing your security operations.

Read: https://thehackernews.com/2024/02/how-to-use-tiness-soc-automation.html
πŸ‘18πŸ€”5😱1
U.S. Treasury sanctions 12 Kaspersky executives following Commerce Department's ban on Kaspersky software in the U.S. The company and CEO remain unaffected.

Learn more: https://thehackernews.com/2024/06/us-treasury-sanctions-12-kaspersky.html
πŸ‘18πŸ€”11🀯6😁4😱4πŸ‘2
🚨 Beware: A new adware, AdsExhaust, is targeting Meta Quest app seekers with malicious downloads, manipulating browsers, and generating unauthorized revenue through sophisticated techniques.

Read: https://thehackernews.com/2024/06/warning-new-adware-campaign-targets.html
πŸ”₯10πŸ‘5😱4
New cybercrime gang ExCobalt targets Russian organizations with sophisticated GoRed backdoor.

Explore their tactics: https://thehackernews.com/2024/06/excobalt-cyber-gang-targets-russian.html
πŸ‘18😁11πŸ€”6πŸ‘5😱4🀯1
Cyber espionage groups are using Rafel RAT, an open-source Android tool, disguised as popular apps like Instagram, WhatsApp, and more. This malware conducts data theft and device manipulation.

Read: https://thehackernews.com/2024/06/iranian-hackers-deploy-rafel-rat-in.html
πŸ‘18😱11🀯6
πŸ›‘ RedJuliett, a suspected China-linked cyber group, target Taiwan and other countries in extensive cyber espionage campaign, exploiting vulnerabilities in internet-facing devices for intelligence gathering.

Read: https://thehackernews.com/2024/06/redjuliett-cyber-espionage-campaign.html
πŸ€”11🀯8πŸ‘3😱2
Join Luke Jennings, VP R&D at Push Security, to explore the impact of the ongoing Snowflake incident and the practical steps that organizations can take to investigate and respond effectively, avoiding some of the common pitfalls relating to how identities are configured in Snowflake

Register for the webinar here: https://go.thn.li/snowflake-webinar-tel
πŸ‘10😱8
🚨 Critical security flaw (CVE-2024-37032) discovered in Ollama, an open-source AI platform, could lead to remote code execution.

Learn more: https://thehackernews.com/2024/06/critical-rce-vulnerability-discovered.html

Over 1,000 exposed instances found. Patch available in v0.1.34.
⚑17πŸ€”6πŸ‘3
Google Project Zero introduces 'Naptime,' an LLM-powered framework for vulnerability research. It boosts LLMs' CyberSecEval 2 performance, using advanced tools to better identify and exploit software flaws.

Read: https://thehackernews.com/2024/06/google-introduces-project-naptime-for.html
😁14πŸ‘11πŸ€”6πŸ”₯2
Overwhelmed by cybersecurity threats?

Cybersixgill’s IQ Report Generator automates CTI reports in minutes, freeing your team for proactive defense measures.

Don’t miss outβ€”see how it works: https://thehackernews.com/2024/06/ease-burden-with-ai-driven-threat.html
πŸ‘16πŸ€”6
🚨 Alert: Popular WordPress plugins backdoored to create rogue admin accounts. Users advised to inspect sites, remove suspicious admins, and update affected plugins.

Learn more: https://thehackernews.com/2024/06/multiple-wordpress-plugins-compromised.html
πŸ”₯13πŸ‘4😁4
πŸ›‘οΈ Four Vietnamese nationals linked to the FIN9 cybercrime group indicted in the U.S., accused of causing over $71 million in losses through computer intrusions.

Learn how they pulled it off and what charges they face: https://thehackernews.com/2024/06/4-fin9-linked-vietnamese-hackers.html
πŸ€”14πŸ‘3πŸ”₯2
WikiLeaks founder Julian Assange freed after 5 years in U.K. prison. His 14-year legal battle ends with a plea deal.

Read details here: https://thehackernews.com/2024/06/wikileaks-julian-assange-released-from.html

Assange has left the U.K. and is en route to Australia.
πŸ‘89πŸ‘15πŸ”₯8⚑3😁1
Researchers uncover a new attack technique called GrimResource, exploited in the wild, which uses specially crafted Microsoft Management Saved Console (MSC) files to achieve full code execution and evade security defenses.

Details: https://thehackernews.com/2024/06/new-attack-technique-exploits-microsoft.html
πŸ”₯11😱6πŸ‘3😁2
New threat actor "Boolka" uses SQL injection to infect websites with BMANAGER trojan, stealing data via malicious scripts.

Learn more about their sophisticated tactics: https://thehackernews.com/2024/06/new-cyberthreat-boolka-deploying.html
😁9πŸ‘6😱5πŸ‘1
πŸ”’ Tight on budget but need to ramp up data security in #Googleworkspace? Don’t miss the exclusive webinar: "Data Loss & Leaks Prevention: Beyond GAM." Peek behind the curtain to see how top IT pros have achieved a stunning 98% increase in compliance and security by maximizing the native capabilities of Googleapps and automating routine Googlework space admin tasks β€” all without breaking the bank.

πŸ’‘ Topics covered will include:

β€’ Automation of External Files Sharing Audits

β€’ Monitoring and Taking Action on Out of Domain Email Forwarding

β€’ Management of 'Zombie Drives' and more

Don’t miss out on this zero-fluff, zero-filler, 100% hands-on live event brought to you by Zenphi! Secure a spot today by registering for free here: https://thn.news/dlp-google-workspace
πŸ‘19πŸ€”5