The Hacker News
βœ”
151K subscribers
1.86K photos
10 videos
3 files
7.77K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
North Korean hackers are using fake video conferencing apps, like FreeConference, in job interview scams to deliver malware capable of remote control, browser data theft, and cryptocurrency wallet hacking.

Read: https://thehackernews.com/2024/09/north-korean-hackers-targets-job.html
🀯16πŸ”₯5😁3πŸ‘2
New supply chain attack, Revival Hijack, could target 22,000+ PyPI packages, risking thousands of malicious downloads. Removed packages are being re-registered, exposing developers to supply chain risks. Check your DevOps pipelines!
https://thehackernews.com/2024/09/hackers-hijack-22000-removed-pypi.html
πŸ”₯9🀯2πŸ‘1πŸ€”1
Cisco has issued urgent updates for two critical flaws (CVSS 9.8) in its Smart Licensing Utility. These flaws (CVE-2024-20439 & CVE-2024-20440) let unauthenticated attackers elevate privileges or access sensitive data via crafted HTTP requests.

Read: https://thehackernews.com/2024/09/cisco-fixes-two-critical-flaws-in-smart.html
πŸ‘6πŸ”₯5😱5
Earth Lusca's KTLVdoor malware targets Windows & #Linux, enabling file manipulation and remote scanning via 50+ command-and-control servers, likely shared with other threat actors.

Learn more: https://thehackernews.com/2024/09/new-cross-platform-malware-ktlvdoor.html
πŸ€”8😱6πŸ‘4🀯2😁1
Researchers found hackers using MacroPack, a red teaming tool, to deploy advanced #malware like Havoc and PhantomCore. This global threat shows how attackers use legitimate software to bypass detection.

Read: https://thehackernews.com/2024/09/malware-attackers-using-macropack-to.html
😁9πŸ”₯6πŸ‘5πŸ‘4🀯1
🚨 Mindblowing numbers alert! 🚨 According to recent research, 45% of employees still have access to their ex-employer’s data, and over 25% of companies have had their reputations damaged due to ex-employees misusing data after leaving the company 🀑

Want to make sure your organization doesn’t fall into this risky 1/3? Learn how to safeguard your data and create a bulletproof offboarding protocol in just 20 minutes! πŸ’Ό

Join ex-Google expert Ben King and the Zenphi team in a free webinar on β€˜Offboarding in Google Workspace’. Get hands-on tips for:

β€” Automating access revokes
β€” Securing accounts post-departure
β€” Preventing unauthorized access

πŸ“‹ Bonus: Register for free and receive an Employees offboarding checklist!

πŸ’‘This webinar will set you apart as a cybersecurity pro β€” don’t miss it : https://thn.news/offboarding-best-practices
😁16πŸ‘5πŸ€”3πŸ”₯1
DOJ seized 32 pro-Russian propaganda domains that mimicked news outlets to spread disinformation. The goal: reduce global support for Ukraine and influence elections in the U.S. and abroad.

Learn more: https://thehackernews.com/2024/09/us-seizes-32-pro-russian-propaganda.html
πŸ”₯19😁9πŸ€”6πŸ‘4😱1
πŸ” NIST released CSF 2.0!

It’s all about continuous improvement with proactive, ongoing cybersecurity. New guidance on emerging threats + a β€œGovern” function to integrate cybersecurity into enterprise risk.

Is your org ready? Learn more: https://thehackernews.com/2024/09/nist-cybersecurity-framework-csf-and.html
πŸ‘12😁6πŸ”₯4
⚠️ Veeam has patched 18 security flaws, including 5 critical ones allowing remote code execution (e.g., CVE-2024-40711 with a 9.8 CVSS score). Update now to protect your data.

Learn more: https://thehackernews.com/2024/09/veeam-releases-security-updates-to-fix.html
πŸ‘11😁2πŸ”₯1
Tropic Trooper is back, targeting government entities in the Middle East and Malaysia with new cyber tactics! Detected in June 2024, this group has shifted focus to human rights studiesβ€”escalating the risk.

Find details here: https://thehackernews.com/2024/09/chinese-speaking-hacker-group-targets.html
πŸ‘8πŸ‘2πŸ”₯2😱2⚑1
Telegram’s CEO, Pavel Durov, speaks out after his arrest in France, calling the charges misguided.

Read: https://thehackernews.com/2024/09/paul-durov-criticizes-outdated-laws.html
πŸ‘39πŸ”₯11πŸ‘10⚑5
Apache OFBiz just patched a high-severity #vulnerability (CVE-2024-45195) that allowed unauthenticated remote code execution.

Read: https://thehackernews.com/2024/09/apache-ofbiz-update-fixes-high-severity.html
πŸ‘11πŸ‘3
New LiteSpeed Cache flaw (CVE-2024-44000) risks unauthorized access to WordPress sites via exposed debug logs.

Read: https://thehackernews.com/2024/09/critical-security-flaw-found-in.html

Even old logs can be exploited. Update and purge now!
πŸ‘14πŸ€”6😁2πŸ”₯1
GitHub Actions users are vulnerable to typosquatting, where simple misspellings (e.g. "actons/checkout") can run malicious code, compromising software supply chains.

Read: https://thehackernews.com/2024/09/github-actions-vulnerable-to.html

Protect your codeβ€”double-check your CI/CD pipelines!
πŸ‘10😁5πŸ”₯4πŸ€”3⚑1
🚨 Alert: OSGeo GeoServer GeoTools (CVE-2024-36401) with a CVSS score of 9.8 is being exploited to deploy crypto miners, botnets, and the SideWalk backdoor. CISA has listed it as a KEV affecting IT and government sectors.

Read: https://thehackernews.com/2024/09/geoserver-vulnerability-targeted-by.html

Patch your systems NOW!
πŸ‘7😁7😱5πŸ‘2πŸ€”2⚑1
vCISO services are essential: 98% of MSPs/MSSPs will offer them as SMBs seek affordable, top-tier security to protect assets & ensure compliance. It's a revenue booster & positions providers as trusted leaders.

Read: https://thehackernews.com/2024/09/the-state-of-virtual-ciso-report.html
πŸ‘8😁3😱2⚑1πŸ‘1πŸ€”1
πŸ”₯ A SonicWall #vulnerability (CVE-2024-40766) is under active exploitation.

This critical flaw allows attackers to bypass access controls and potentially crash firewalls, compromising business operations. Don't wait.

https://thehackernews.com/2024/09/sonicwall-urges-users-to-patch-critical.html

Patch now or risk falling victim.
πŸ‘19πŸ‘7⚑2πŸ”₯2😱1
Two men were indicted for running WWH Club, a dark web marketplace with 350,000+ users selling stolen personal data and hacking services. Despite law enforcement, WWH Club remains active, underscoring the resilience of cybercrime.

Read: https://thehackernews.com/2024/09/fbi-cracks-down-on-dark-web-marketplace.html
πŸ‘12πŸ”₯7πŸ€”5😱4⚑2πŸ‘2
North Korean hackers are targeting developers on #LinkedIn with fake job offers, using coding tests to infect macOS. Once inside, they steal credentials, access code, and drain crypto funds. Social engineering remains a serious cyber threat

Read: https://thehackernews.com/2024/09/north-korean-threat-actors-deploy.html
🀯35πŸ”₯16😁14πŸ‘12πŸ‘7😱5πŸ€”3⚑2