The Hacker News
βœ”
151K subscribers
1.86K photos
10 videos
3 files
7.77K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
Don't miss out on the upcoming webinar from Push Security demoing infostealers, showing how to steal cookies and hijack sessions for MFA-protected services like M365 and downstream SaaS apps.

Pick a time and register here: https://thn.news/infostealers-webinar-other
πŸ€”8πŸ”₯6πŸ‘3
Account takeover attacks are increasing in SaaS environments, with browsers being the key battleground. A new report highlights how browser security can prevent phishing, malicious extensions, and credential theft.

Learn more now: https://thehackernews.com/2024/09/the-new-effective-way-to-prevent.html
⚑10πŸ‘2πŸ”₯1
North Korean hackers are using fake video conferencing apps, like FreeConference, in job interview scams to deliver malware capable of remote control, browser data theft, and cryptocurrency wallet hacking.

Read: https://thehackernews.com/2024/09/north-korean-hackers-targets-job.html
🀯16πŸ”₯5😁3πŸ‘2
New supply chain attack, Revival Hijack, could target 22,000+ PyPI packages, risking thousands of malicious downloads. Removed packages are being re-registered, exposing developers to supply chain risks. Check your DevOps pipelines!
https://thehackernews.com/2024/09/hackers-hijack-22000-removed-pypi.html
πŸ”₯9🀯2πŸ‘1πŸ€”1
Cisco has issued urgent updates for two critical flaws (CVSS 9.8) in its Smart Licensing Utility. These flaws (CVE-2024-20439 & CVE-2024-20440) let unauthenticated attackers elevate privileges or access sensitive data via crafted HTTP requests.

Read: https://thehackernews.com/2024/09/cisco-fixes-two-critical-flaws-in-smart.html
πŸ‘6πŸ”₯5😱5
Earth Lusca's KTLVdoor malware targets Windows & #Linux, enabling file manipulation and remote scanning via 50+ command-and-control servers, likely shared with other threat actors.

Learn more: https://thehackernews.com/2024/09/new-cross-platform-malware-ktlvdoor.html
πŸ€”8😱6πŸ‘4🀯2😁1
Researchers found hackers using MacroPack, a red teaming tool, to deploy advanced #malware like Havoc and PhantomCore. This global threat shows how attackers use legitimate software to bypass detection.

Read: https://thehackernews.com/2024/09/malware-attackers-using-macropack-to.html
😁9πŸ”₯6πŸ‘5πŸ‘4🀯1
🚨 Mindblowing numbers alert! 🚨 According to recent research, 45% of employees still have access to their ex-employer’s data, and over 25% of companies have had their reputations damaged due to ex-employees misusing data after leaving the company 🀑

Want to make sure your organization doesn’t fall into this risky 1/3? Learn how to safeguard your data and create a bulletproof offboarding protocol in just 20 minutes! πŸ’Ό

Join ex-Google expert Ben King and the Zenphi team in a free webinar on β€˜Offboarding in Google Workspace’. Get hands-on tips for:

β€” Automating access revokes
β€” Securing accounts post-departure
β€” Preventing unauthorized access

πŸ“‹ Bonus: Register for free and receive an Employees offboarding checklist!

πŸ’‘This webinar will set you apart as a cybersecurity pro β€” don’t miss it : https://thn.news/offboarding-best-practices
😁16πŸ‘5πŸ€”3πŸ”₯1
DOJ seized 32 pro-Russian propaganda domains that mimicked news outlets to spread disinformation. The goal: reduce global support for Ukraine and influence elections in the U.S. and abroad.

Learn more: https://thehackernews.com/2024/09/us-seizes-32-pro-russian-propaganda.html
πŸ”₯19😁9πŸ€”6πŸ‘4😱1
πŸ” NIST released CSF 2.0!

It’s all about continuous improvement with proactive, ongoing cybersecurity. New guidance on emerging threats + a β€œGovern” function to integrate cybersecurity into enterprise risk.

Is your org ready? Learn more: https://thehackernews.com/2024/09/nist-cybersecurity-framework-csf-and.html
πŸ‘12😁6πŸ”₯4
⚠️ Veeam has patched 18 security flaws, including 5 critical ones allowing remote code execution (e.g., CVE-2024-40711 with a 9.8 CVSS score). Update now to protect your data.

Learn more: https://thehackernews.com/2024/09/veeam-releases-security-updates-to-fix.html
πŸ‘11😁2πŸ”₯1
Tropic Trooper is back, targeting government entities in the Middle East and Malaysia with new cyber tactics! Detected in June 2024, this group has shifted focus to human rights studiesβ€”escalating the risk.

Find details here: https://thehackernews.com/2024/09/chinese-speaking-hacker-group-targets.html
πŸ‘8πŸ‘2πŸ”₯2😱2⚑1
Telegram’s CEO, Pavel Durov, speaks out after his arrest in France, calling the charges misguided.

Read: https://thehackernews.com/2024/09/paul-durov-criticizes-outdated-laws.html
πŸ‘39πŸ”₯11πŸ‘10⚑5
Apache OFBiz just patched a high-severity #vulnerability (CVE-2024-45195) that allowed unauthenticated remote code execution.

Read: https://thehackernews.com/2024/09/apache-ofbiz-update-fixes-high-severity.html
πŸ‘11πŸ‘3
New LiteSpeed Cache flaw (CVE-2024-44000) risks unauthorized access to WordPress sites via exposed debug logs.

Read: https://thehackernews.com/2024/09/critical-security-flaw-found-in.html

Even old logs can be exploited. Update and purge now!
πŸ‘14πŸ€”6😁2πŸ”₯1
GitHub Actions users are vulnerable to typosquatting, where simple misspellings (e.g. "actons/checkout") can run malicious code, compromising software supply chains.

Read: https://thehackernews.com/2024/09/github-actions-vulnerable-to.html

Protect your codeβ€”double-check your CI/CD pipelines!
πŸ‘10😁5πŸ”₯4πŸ€”3⚑1
🚨 Alert: OSGeo GeoServer GeoTools (CVE-2024-36401) with a CVSS score of 9.8 is being exploited to deploy crypto miners, botnets, and the SideWalk backdoor. CISA has listed it as a KEV affecting IT and government sectors.

Read: https://thehackernews.com/2024/09/geoserver-vulnerability-targeted-by.html

Patch your systems NOW!
πŸ‘7😁7😱5πŸ‘2πŸ€”2⚑1
vCISO services are essential: 98% of MSPs/MSSPs will offer them as SMBs seek affordable, top-tier security to protect assets & ensure compliance. It's a revenue booster & positions providers as trusted leaders.

Read: https://thehackernews.com/2024/09/the-state-of-virtual-ciso-report.html
πŸ‘8😁3😱2⚑1πŸ‘1πŸ€”1
πŸ”₯ A SonicWall #vulnerability (CVE-2024-40766) is under active exploitation.

This critical flaw allows attackers to bypass access controls and potentially crash firewalls, compromising business operations. Don't wait.

https://thehackernews.com/2024/09/sonicwall-urges-users-to-patch-critical.html

Patch now or risk falling victim.
πŸ‘19πŸ‘7⚑2πŸ”₯2😱1