The Hacker News
152K subscribers
1.86K photos
10 videos
3 files
7.78K links
Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

📨 Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
🚨 New OpenSSH vulnerability (CVE-2024-6409) found in RHEL 9's versions 8.7p1 & 8.8p1, allowing RCE via race condition in privsep child process.

Read: https://thehackernews.com/2024/07/new-openssh-vulnerability-discovered.html

⚠️ Active exploits detected! This bug is distinct from CVE-2024-6387 but shares similarities.
😱19🔥9👍6🤯31
Crypto analysts expose HuiOne Guarantee, a key platform for cybercriminals in SE Asia.

Linked to $11B in transactions, HuiOne offers money laundering, tech, & data services, supporting pig butchering scams.

Read: https://thehackernews.com/2024/07/crypto-analysts-expose-huione.html
🔥11👍65😁1
Microsoft's latest Patch Tuesday update addresses 143 security flaws, with 2 already under active exploitation. Critical vulnerabilities include issues in Hyper-V and MSHTML.

Timely updates can prevent significant security incidents. Experts stress the importance of regular updates and vigilance.

Find details here: https://thehackernews.com/2024/07/microsofts-july-update-patches-143.html
🔥176👍3😁3👏1
ITDR is revolutionizing identity protection in the fight against ransomware.

Identity protection lags 20 years behind, but ITDR provides comprehensive coverage and real-time threat mitigation.

Learn more: https://thehackernews.com/2024/07/true-protection-or-false-promise.html

Have you evaluated your ITDR solutions recently? Don't wait until it's too late.
👍103🤔3😁1
New ransomware group EstateRansomware exploits Veeam software vulnerability, uses dormant VPN accounts for initial access, and deploys persistent backdoors in sophisticated attacks.

Learn more: https://thehackernews.com/2024/07/new-ransomware-group-exploiting-veeam.html
🤯7👏4👍32
Over 50% of new flaws exploited in 2023-24 were zero-days. 📉

Explore IoT firmware complexities, state-sponsored threats & the pitfalls of traditional patching.

Discover innovative isolation solutions to secure against rapid exploits: https://thehackernews.com/2024/07/smash-and-grab-extortion.html
😱115👏5👍3😁1
Anyrun's TI Lookup now offers Suricata Search.

🔎 User can find active network threats using details of Suricata detection rules

Rule parameters can be combined with extra indicators like domains and IPs for more specific results

More ⬇️
https://go.thn.li/malware-analysis
🔥12👍62
Who’s using genAI tools in your organization? Find out in minutes with Nudge Security. Start a free trial and discover every SaaS account ever created by anyone in your org, including generative AI tools.

Read: https://thn.news/ai-risks
🤔10👍63🤯2🔥1
⚠️ GitLab has patched a critical vulnerability (CVE-2024-6385) with a CVSS score of 9.6, allowing attackers to run pipeline jobs as any user.

Also, Citrix updates for CVE-2024-6235, & Broadcom addresses flaws in VMware Cloud Director (CVE-2024-22277) & Aria Automation (CVE-2024-22280).

Learn more: https://thehackernews.com/2024/07/gitlab-patches-critical-flaw-allowing.html

Don't wait – secure your development environment now.
👍198
A recently disclosed security flaw in PHP (CVE-2024-4577) is being exploited by multiple threat actors to deploy remote access trojans, cryptocurrency miners, and DDoS botnets.

Learn more https://thehackernews.com/2024/07/php-vulnerability-exploited-to-spread.html
9🤯8👍4🔥4
⚠️ A new phishing campaign is spreading Poco RAT malware among Spanish-speaking sectors, including utilities and manufacturing.

Details here: https://thehackernews.com/2024/07/new-poco-rat-targets-spanish-speaking.html

🔍 Analysts note the malware's unique focus on anti-analysis and C2 activities, making it harder to detect.
🔥9👍8🤔4
APT41 is suspected of using an advanced version of StealthVector, called DodgeBox, to deliver a new backdoor named MoonWalk.

Understanding the advanced evasion techniques used by DodgeBox is essential for maintaining robust cybersecurity.

Read: https://thehackernews.com/2024/07/chinese-apt41-upgrades-malware-arsenal.html
👍8🤔54🔥2
🚨 Developers, be cautious! New wave of malicious packages found in NuGet!

Hackers are using IL Weaving to inject malicious code into legitimate binaries, embedding remote access trojans in popular packages.

Read: https://thehackernews.com/2024/07/60-new-malicious-packages-uncovered-in.html
😱103👍3👏2🤯2
⚠️ Urgent: Palo Alto Networks has rolled out critical security updates to fix five vulnerabilities, including CVE-2024-5910, a severe authentication bypass flaw (CVSS 9.3).

Learn more: https://thehackernews.com/2024/07/palo-alto-networks-patches-critical.html

These updates affect multiple PAN-OS versions and Prisma Access.
🔥8🤯5👍43🤔2
As cybercriminals target smaller firms, affordable Privileged Access Management (PAM) solutions are essential for safeguarding sensitive data.

PAM reduces insider threats and ensures compliance with regulations like GDPR and HIPAA.

Learn more: https://thehackernews.com/2024/07/streamlined-security-solutions-pam-for.html
👍16🤔43🔥2
Alert: U.S. authorities disrupt major Russian influence operation using AI. The campaign targeted multiple countries and exploited social media platform vulnerabilities.

Learn more: https://thehackernews.com/2024/07/us-seizes-domains-used-by-ai-powered.html
🔥18👍8😁8🤯6😱4🤔32
AT&T confirms massive data breach affecting "nearly all" wireless customers. This impacts millions, potentially exposing call records and location data.

Learn more: https://thehackernews.com/2024/07/at-confirms-data-breach-affecting.html

This data could be a goldmine for cybercriminals planning targeted attacks.
👍15🤯13😁12🔥5👏1
🔥 Compromised credentials are now the #1 attack vector in 2024!

Every set of credentials is a potential entry point for attackers. This makes securing them more important than ever.

Learn more in this exclusive Expert-led webinar: https://thehackernews.com/2024/07/ever-wonder-how-hackers-really-steal.html
👍22🤔98😁4
A new version of HardBit ransomware has emerged with advanced obfuscation techniques to evade analysis efforts and unique extortion tactics. Learn about its evolving threat landscape.

Learn more: https://thehackernews.com/2024/07/new-hardbit-ransomware-40-uses.html
👍127👏1🤔1
Singapore banks will soon replace OTPs with digital tokens for online banking authentication to combat phishing attacks, as announced by MAS and ABS.

Learn more: https://thehackernews.com/2024/07/singapore-banks-to-phase-out-otps-for.html

This move significantly reduces the risk of credential theft and account hijacking.
👏21👍86😁5🤔2