The Hacker News
βœ”
151K subscribers
1.85K photos
10 videos
3 files
7.77K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: [email protected]

🌐 Website: https://thehackernews.com
Download Telegram
Manufacturing & healthcare sectors are being targeted by SmokeLoader #malwareβ€”modular, evasive, and deadly.

With plugins that steal data, mine crypto, and launch DDoS, no system is safe.

Full story here: https://thehackernews.com/2024/12/smokeloader-malware-resurfaces.html
πŸ‘13😁5⚑3πŸ€”1
🚨 Over 1,000 victims targeted by the new Horns&Hooves malware campaign.

Using fake emails disguised as customer requests, attackers deploy NetSupport RAT & BurnsRAT, leading to data theft & ransomware risks.

πŸ”— Read more: https://thehackernews.com/2024/12/horns-campaign-delivers-rats-via-fake.html
πŸ‘16⚑4😁3πŸ”₯2🀯2
πŸ“§ Kimsuky, a North Korea-aligned #hacking group, now uses Russian email services like Mail[.]ru to disguise phishing attacks aimed at stealing credentials.

Discover how these campaigns operate: https://thehackernews.com/2024/12/north-korean-kimsuky-hackers-use.html
πŸ‘13😁3πŸ”₯2
Researchers have uncovered critical vulnerabilities in Palo Alto Networks and SonicWall VPN clients, which could allow attackers to achieve remote code execution on Windows and macOS systems, install malicious root certificates, and execute privileged commands.

A proof-of-concept tool, NachoVPN, has been released.

πŸ”— Read more: https://thehackernews.com/2024/12/nachovpn-tool-exploits-flaws-in-popular.html
πŸ‘17πŸ‘5⚑4😁1
Cybersecurity is moving beyond 'castle & moat' defenses. Modern threats target critical systemsβ€”lights, water, citiesβ€”raising stakes to safety & national security.

Legacy OT systems need modern solutions like PAM & Zero Trust to stay secure.

Learn more: https://thehackernews.com/expert-insights/2024/11/beyond-castle-walls-operational.html
πŸ‘14πŸ”₯3⚑1😁1
A 10-year-old flaw in Cisco ASA (CVE-2014-2120) is being actively exploited. This vulnerability allows attackers to execute XSS attacks remotely.

If your Cisco ASA isn't updated, you could be the next target.

Learn more: https://thehackernews.com/2024/12/cisco-warns-of-exploitation-of-decade.html
😁14πŸ‘8😱4⚑3πŸ”₯2
🌊 Attacks using stolen credentials are surging, fueled by the rise in infostealers and the criminal marketplaces dealing in them.



TI feeds can alert you to stolen credentials when they appear for sale, but TI providers have no way to check if the credentials are actually valid or not.



Using Push Security, you can now eliminate the noise and get alerts only when verified credentials belonging to your employees appear on criminal marketplaces.



Push’s browser extension compares stolen credentials from widely-used TI feeds directly against the credentials your employees are actually using βœ…



Find out more here πŸ‘‰ https://thn.news/push-credential-detection
πŸ‘17😁6⚑4πŸ”₯4
🚨 A new phishing campaign is slipping past email defenses! Corrupted ZIP files and Office documents bypass antivirus and spam filters, landing directly in your inbox.

🚩 Why care? These cleverly crafted files could lead you straight to fake login pages or malware-laden sites. One wrong click could cost your dataβ€”or worse.

Read the full breakdown: https://thehackernews.com/2024/12/hackers-use-corrupted-zips-and-office.html
πŸ‘17⚑5πŸ”₯2😁1
🚨 Alert: A critical vulnerability (CVE-2024-10905) in SailPoint's IdentityIQ software exposes sensitive content.

CVSS score? A whopping 10.0β€”maximum severity.

Affected versions span from 8.2 to 8.4 and earlier, putting countless systems at risk. Static files that should be locked down are now vulnerable to unauthorized access.

Learn more: https://thehackernews.com/2024/12/critical-sailpoint-identityiq.html
πŸ€”9πŸ”₯5πŸ‘3⚑1
πŸ›‘οΈ Veeam users, take note! A critical flaw in the Service Provider Console (CVE-2024-42448) could allow remote code execution (RCE).

CVSS score: 9.9/10β€”this is as serious as it gets.

πŸ”— Don't wait, secure your systems today β€” https://thehackernews.com/2024/12/veeam-issues-patch-for-critical-rce.html
πŸ‘14🀯5⚑1
Cybersecurity agencies have issued a coordinated advisory along with an urgent checklist to combat the Salt Typhoon threatβ€”a nation-state group linked to China that has been infiltrating U.S. telecom networks to steal sensitive data.

Dive into the full story: https://thehackernews.com/2024/12/joint-advisory-warns-of-prc-backed.html
🀯14⚑5😁3
A software supply chain attack targeted Solana's popular Solana's web3.js npm library (400,000+ weekly downloads). Malicious versions (1.95.6 and 1.95.7) were designed to steal users' private keys and drain cryptocurrency wallets.

The backdoor was cleverly hidden in the β€œaddToQueue” function, seamlessly blending into legitimate code.

Learn more here πŸ‘‰ https://thehackernews.com/2024/12/researchers-uncover-backdoor-in-solanas.html
😱18πŸ€”10😁6⚑3πŸ‘2πŸ”₯2πŸ‘2🀯2
Check out @anyrun_app's Black Friday specials πŸš€

🎁 Get up to 3 sandbox licenses for your team as a gift
πŸ”Ž Double your search limit in TI Lookup β€” #ANYRUN's threat intelligence database β€” for FREE

Secure your deal before Dec 8 πŸ‘‰ https://thn.news/anyrun-black-friday-tg
πŸ‘9πŸ‘5
Europol has dismantled MATRIX, an invite-only encrypted messaging service used by criminals, intercepting 2.3 million messages tied to drug trafficking, arms deals, and money laundering.

Read the full story: https://thehackernews.com/2024/12/europol-dismantles-criminal-messaging.html
⚑19🀯13πŸ‘7πŸ‘6😁4πŸ€”3πŸ”₯2😱2
Russia-linked APT group Turla has been hijacking the infrastructure of a Pakistani hacking group to spy on Afghan and Indian government targets by deploying custom #malware, TwoDash and Statuezy.

Learn more: https://thehackernews.com/2024/12/russia-linked-turla-exploits-pakistani.html
πŸ‘24πŸ”₯8🀯6😁5⚑2πŸ‘1
🚨 CISA flags ProjectSend, Zyxel and CyberPanel flaws as actively exploited.

One of these enables attackers to bypass authentication and execute arbitrary commands β€” ransomware campaigns like PSAUX & Helldown are already exploiting it.

Read: https://thehackernews.com/2024/12/cisa-warns-of-active-exploitation-of.html
πŸ”₯16😁3πŸ‘2
U.K. National Crime Agency has disrupted Russian money laundering networks, leading to 84 arrests and the seizure of Β£20 million in cash and #cryptocurrency.

These networks weren’t just about moneyβ€”they funded Russian espionage and connected to cybercriminal gangs across the globe.

πŸ”— Read more: https://thehackernews.com/2024/12/nca-busts-russian-crypto-networks.html
😁18πŸ‘10⚑4
MirrorFace, a China-linked group, is deploying the dormant ANEL backdoorβ€”unused since 2018β€”in a new spear-phishing campaign targeting Japan.

Explore how these tactics are bypassing security measures: https://thehackernews.com/2024/12/anel-and-noopdoor-backdoors-weaponized.html
😁28πŸ‘5πŸ‘1
🚨 Chinese hackers launched a stealthy four-month-long cyberattack targeting a major U.S. organization, harvesting emails and stealing sensitive data.

The attackers exploited Exchange Servers and used advanced tools like FileZilla and PowerShell.

Read the full story πŸ‘‰ https://thehackernews.com/2024/12/researchers-uncover-4-month-cyberattack.html
πŸ‘24πŸ€”8πŸ‘5😁5⚑2🀯1
🚨 Earth Minotaur is using an advanced toolkit, MOONSHINE, to deploy the DarkNimbus backdoor across Android and Windows devices, targeting vulnerable communities like Tibetans and Uyghurs.

Find details here β€”https://thehackernews.com/2024/12/hackers-target-uyghurs-and-tibetans.html
πŸ‘19πŸ‘3πŸ€”2