The Hacker News
โœ”
151K subscribers
1.86K photos
10 videos
3 files
7.77K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: [email protected]

๐ŸŒ Website: https://thehackernews.com
Download Telegram
โš ๏ธ Six critical security flaws have been discovered in the Ollama AI framework, enabling potential model poisoning and theft. With a staggering number of unpatched instances, itโ€™s crucial to filter internet-facing endpoints effectively.

Read: https://thehackernews.com/2024/11/critical-flaws-in-ollama-ai-framework.html
๐Ÿ‘8๐Ÿ˜4โšก2
๐Ÿ’ป Don't miss out on our latest #cybersecurity newsletter!

This week, we're diving into the chaos as hackers ramp up attacks, including North Korean ransomware collaboration and evasive password spraying tactics.

https://thehackernews.com/2024/11/thn-recap-top-cybersecurity-threats.html
๐Ÿ”ฅ10๐Ÿ‘8๐Ÿ˜3๐Ÿคฏ3โšก1
Google warns of active exploitation of CVE-2024-43093 in Android.

This #vulnerability allows unauthorized access to critical directories, emphasizing the need for timely updates and patching processes.

https://thehackernews.com/2024/11/google-warns-of-actively-exploited-cve.html
๐Ÿ”ฅ16๐Ÿ‘11๐Ÿ˜4โšก3๐Ÿ˜ฑ2๐Ÿค”1
Canadian authorities have arrested Alexander "Connor" Moucka, a suspect in the Snowflake data breach that impacted around 165 organizations, including major corporations like AT&T and Ticketmaster, some of which were extorted for large sums.

https://thehackernews.com/2024/11/canadian-suspect-arrested-over.html
๐Ÿ‘21๐Ÿคฏ6โšก3๐Ÿ‘3
Synology has released a patch for a critical zero-day vulnerability (CVE-2024-10443) affecting millions of NAS devices, which allows remote code execution without user interaction.

Read: https://thehackernews.com/2024/11/synology-urges-patch-for-critical-zero.html
๐Ÿ‘14โšก3๐Ÿ˜ฑ3
๐Ÿšจ Hundreds of typosquatted versions targeting npm developers are attempting to deliver cross-platform #malware by employing Ethereum smart contracts for command-and-control (C2) communications.

Read: https://thehackernews.com/2024/11/malware-campaign-uses-ethereum-smart.html
โšก5๐Ÿ‘4๐Ÿ‘1
The Android banking malware "ToxicPanda" has infected over 1,500 devices, facilitating fraudulent transactions by bypassing security measures.

It disguises itself as legitimate apps and intercepts OTPs for unauthorized access.

Read: https://thehackernews.com/2024/11/new-android-banking-malware-toxicpanda.html
๐Ÿ”ฅ9๐Ÿ‘7๐Ÿ‘5
Explore how Zero Trust security transforms #cybersecurity by eliminating implicit trust, scrutinizing access requests, and continuously monitoring users to mitigate insider threats and enhance security posture.

Read: https://thehackernews.com/2024/11/leveraging-wazuh-for-zero-trust-security.html
๐Ÿ‘15
The FBI is seeking public assistance to identify those behind cyber intrusions linked to Chinese APT groups that have exploited vulnerabilities in edge devices and networks for cyber espionage against critical infrastructure.

Learn more: https://thehackernews.com/2024/11/fbi-seeks-public-help-to-identify.html
๐Ÿ˜25๐Ÿ‘11โšก2๐Ÿ”ฅ2
Google Cloud will enforce mandatory multi-factor authentication (MFA) for all users by the end of 2025

Learn more: https://thehackernews.com/2024/11/google-cloud-to-enforce-multi-factor.html
๐Ÿ‘26โšก9๐Ÿ˜7๐Ÿค”4๐Ÿคฏ1
South Korea fined Meta $15.67 million for sharing sensitive data from 980,000 users with advertisers without proper consent.

Learn more: https://thehackernews.com/2024/11/south-korea-fines-meta-1567m-for.html
๐Ÿ‘28๐Ÿ‘7๐Ÿ”ฅ5โšก4๐Ÿ˜ฑ3๐Ÿ˜2
INTERPOL has taken down over 22,000 malicious servers in its Operation Synergia II, targeting phishing, ransomware, and malware.

Learn more: https://thehackernews.com/2024/11/interpols-operation-synergia-ii.html
๐Ÿ‘22โšก6๐Ÿ‘4๐Ÿค”3๐Ÿคฏ2๐Ÿ˜ฑ1
Continuous Threat Exposure Management (CTEM) is no longer optionalโ€”it's essential!

As threats evolve, CTEM empowers organizations to proactively identify and mitigate vulnerabilities before they lead to costly breaches. ๐Ÿ”—

Read the full article to discover how to keep CTEM on your 2025 budget radar: https://thehackernews.com/2024/11/9-steps-to-get-ctem-on-your-2025.html
๐Ÿ‘9โšก6๐Ÿ‘6
๐Ÿšจ Warning: New Winos 4.0 malware is targeting users through ๐ŸŽฎ gaming applications. This advanced framework can take control of compromised systems and harvest sensitive data, targeting educational organizations and cryptocurrency wallets.

Read: https://thehackernews.com/2024/11/new-winos-40-malware-infects-gamers.html
๐Ÿ‘7๐Ÿ”ฅ4๐Ÿ‘2๐Ÿคฏ2
๐Ÿ”ฅ Did you know? Advanced threat actors can breach identity systems in days.

Learn about SaaS and cloud vulnerabilities. Join our LIVE WEBINAR to learn crucial strategies for securing your identity infrastructure.

๐Ÿ‘‰ Join now: https://thehacker.news/identity-based-attacks
๐Ÿ‘17๐Ÿ‘7
๐Ÿ”’ Canada orders TikTok to shut down operations over national security concerns.

Read more here: https://thehackernews.com/2024/11/canada-orders-tiktok-to-shut-down.html
๐Ÿ‘26๐Ÿ˜14โšก8๐Ÿ‘5๐Ÿค”5๐Ÿ”ฅ1
๐ŸŒฉ๏ธ Cyber Alert: VEILDrive Attack!

A new attack exploits Microsoft SaaS tools like Teams and OneDrive, enabling malware distribution through trusted channels.

Read the article: https://thehackernews.com/2024/11/veildrive-attack-exploits-microsoft.html
๐Ÿ‘14โšก10๐Ÿ˜6
๐Ÿšจ Cisco has issued updates for CVE-2024-20418, a critical vulnerability in Ultra-Reliable Wireless Backhaul Access Points (CVSS: 10.0) that allows unauthorized root command execution.

Read: https://thehackernews.com/2024/11/cisco-releases-patch-for-critical-urwb.html

Update to version 17.15.1 ASAP to protect your network!
๐Ÿ˜13โšก6๐Ÿ‘3๐Ÿ”ฅ3๐Ÿ˜ฑ1
๐Ÿ’ป๐Ÿ”‘ Developers, beware!

A malicious package named "fabrice" has been discovered on PyPI, stealthily stealing AWS credentials for over three years.

With more than 37,100 downloads, this typosquatting threat poses serious risks.

Read: https://thehackernews.com/2024/11/malicious-pypi-package-fabrice-found.html
๐Ÿ˜ฑ13๐Ÿ‘8โšก3๐Ÿคฏ2
๐Ÿšจ Cyber alert: The CopyRh(ight)adamantys phishing campaign is leveraging copyright themes to spread the Rhadamanthys stealer, while Kaspersky reveals SteelFox #malware, exploiting vulnerable drivers for data theft.

Learn more: https://thehackernews.com/2024/11/steelfox-and-rhadamanthys-malware-use.html
โšก6๐Ÿ”ฅ5๐Ÿ‘2