The Hacker News
โœ”
151K subscribers
1.86K photos
10 videos
3 files
7.78K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: [email protected]

๐ŸŒ Website: https://thehackernews.com
Download Telegram
โš ๏ธ A high-severity vulnerability in Samsung's Monkey's Audio decoder (CVE-2024-49415) is putting millions of devices at risk.

๐Ÿ”ด No user interaction needed โ€“ attackers can exploit this flaw remotely, allowing them to execute arbitrary code on your phone.

Update your Samsung device immediately to patch this flaw.

Read details here: https://thehackernews.com/2025/01/google-project-zero-researcher-uncovers.html
๐Ÿ”ฅ14๐Ÿ‘6โšก5๐Ÿคฏ3๐Ÿ˜ฑ2
This media is not supported in your browser
VIEW IN TELEGRAM
๐Ÿšจ Shadow AI is hereโ€”and itโ€™s putting your company at risk as employees secretly use AI tools like ChatGPT, transcription apps, and customer support bots.

Identify which apps and AI tools are in use across your organization with Recoโ€™s detection solutionโ€”before they lead to a security incident.

Start securing your apps now: https://thehackernews.com/2025/01/product-review-how-reco-discovers.html
๐Ÿ‘12โšก5
โšก FunkSec, a rising ransomware group, has already hit 85+ victims, demanding ransoms as low as $10,000. Whatโ€™s worse? Theyโ€™re leveraging AI to rapidly evolve their attacks.

With targets like the U.S. and India, FunkSec's motives go beyond moneyโ€”they are blurring the lines between hacktivism and cybercrime.

๐Ÿ‘‰ Learn more: https://thehackernews.com/2025/01/ai-driven-ransomware-funksec-targets-85.html
โšก11๐Ÿ‘8๐Ÿ”ฅ5
Kick off 2025 with a game plan to grow your MSPโ€™s revenue and deliver outstanding value to your clients.

Join us on January 15 to "10x Your MSP Profits in 2025 with Automated Network Pentesting" and discover how vPenTest can help you set the tone for a successful year.

Save your spot: https://thn.news/webinar-automated-pentesting-2025
๐Ÿ‘6๐Ÿ”ฅ5โšก3๐Ÿ‘2๐Ÿ˜1
๐Ÿ“Š Reporting is broken! Is YOUR cybersecurity reporting still a โ€œcheck the boxโ€ task?

Clients donโ€™t want to hear about firewall logsโ€”they want to understand how YOU are safeguarding their business.

Find out how to improve it here: https://thehackernews.com/2025/01/taking-pain-out-of-cybersecurity.html
โšก7๐Ÿ”ฅ4๐Ÿ˜ฑ3๐Ÿ˜2๐Ÿ‘1
๐Ÿ’ฐ How One U.S. Health System Cut Security Costs by 76% ...

๐Ÿ‘‰ The system deployed Elisity with just 2 staff members per site, compared to 14 for traditional segmentation.

โšก Elisity is a seamless, lightweight solution that integrates with existing switches and works with Cisco, Juniper, and Arista devices, taking less than 30 minutes to deploy without any network downtime.

Get the full details here: https://thehackernews.com/2025/01/hands-on-walkthrough-microsegmentation.html
โšก11๐Ÿ‘7๐Ÿ”ฅ5๐Ÿ˜5๐Ÿค”5
๐Ÿ›‘ U.S. Justice Department indicts 3 Russian nationals involved in laundering millions through cryptocurrency mixers Blender`io and Sinbad`io.

Full details inside: https://thehackernews.com/2025/01/doj-indicts-three-russians-for.html
โšก19๐Ÿ‘10๐Ÿ˜ฑ6๐Ÿ”ฅ3
๐Ÿ”ฅ Microsoft has taken legal action against hackers using stolen Azure credentials to exploit AI services like OpenAI and DALL-E for malicious purposes.

Read the full story: https://thehackernews.com/2025/01/microsoft-sues-hacking-group-exploiting.html
๐Ÿ˜44๐Ÿ‘25๐Ÿ”ฅ13๐Ÿค”7โšก1๐Ÿคฏ1
๐Ÿ‘€ Over 4,000 web backdoors hijackedโ€”by registering abandoned domains for as little as $20.

๐Ÿ”‘ Researchers gained control of backdoors targeting government & academic networks in Bangladesh, China, Nigeria, South Korea, and more!

Read now: https://thehackernews.com/2025/01/expired-domains-allowed-control-over.html
๐Ÿ˜24๐Ÿ‘12โšก8๐Ÿ”ฅ8
๐Ÿšจ New Vulnerability Alert!

CISA has added another critical BeyondTrust flaw to its "Known Exploited Vulnerabilities" catalogโ€”this time, impacting Privileged Remote Access (PRA) and Remote Support (RS).

Attackers are actively exploiting it โ€” CVE-2024-12686.

Read more: https://thehackernews.com/2025/01/cisa-adds-new-beyondtrust-flaw-to-kev.html
๐Ÿ‘15๐Ÿ‘4
โš ๏ธ VMware vCenter = Goldmine for Attackers.

Attackers are exploiting root-level access with the โ€œvpxuserโ€ account to control ESXi infrastructure. If itโ€™s breached, everything is at risk.

๐Ÿ‘‡ Discover expert tips on strengthening your defenses and preventing catastrophic breaches: https://thehackernews.com/2025/01/ransomware-on-esxi-mechanization-of.html
๐Ÿ‘17๐Ÿ‘3๐Ÿคฏ1
A new credit card skimmer targeting WordPress e-commerce sites has been discovered.

โคท Malicious JavaScript code is injected into WordPress databases.
โคท It activates ONLY on checkout pages to steal sensitive payment info.
โคท This stealthy malware evades traditional detection tools, making it a serious threat.

This attack is incredibly difficult to spot, putting your customers' data and your reputation at risk.

๐Ÿ”— Read more: https://thehackernews.com/2025/01/wordpress-skimmers-evade-detection-by.html
๐Ÿ”ฅ20๐Ÿ‘11๐Ÿคฏ8
โš ๏ธ WARNING: Zero-Day Exploit Likely Behind Fortinet Attack.

Attackers created super admin accounts, hijacked SSL VPNs, and moved laterally through networks to extract credentials.

Learn more in the full article: https://thehackernews.com/2025/01/zero-day-vulnerability-suspected-in.html
๐Ÿคฏ23๐Ÿ‘8๐Ÿ”ฅ8๐Ÿค”3
HuiOne Guarantee, an illicit Telegram-based marketplace, has surpassed Hydra with $24B in crypto inflows.

โคท $150K funneled from North Koreaโ€™s Lazarus hacking group ๐Ÿ’ป
โคท Facilitating romance scams, human trafficking, and money laundering
โคท Monthly inflows up 51% since July 2024 ๐Ÿ“ˆ

Learn more: https://thehackernews.com/2025/01/illicit-huione-telegram-market.html
๐Ÿ˜16๐Ÿ‘7๐Ÿค”4๐Ÿ‘1
๐Ÿšจ Russian cyber attackers are actively targeting Kazakhstanโ€™s Ministry of Foreign Affairsโ€”this isn't just a cyber attack; itโ€™s an espionage campaign to steal sensitive political and economic data.

The attackers use infected Microsoft Office docs to bypass security and deploy powerful malware like HATVIBEโ€”designed to remain undetected.

Learn more: https://thehackernews.com/2025/01/russian-linked-hackers-target.html
๐Ÿ‘22๐Ÿ”ฅ7๐Ÿ˜ฑ7๐Ÿค”5๐Ÿ˜3๐Ÿคฏ1
๐Ÿšจ 4 Reasons Your SaaS Attack Surface Can No Longer be Ignored in 2025!

๐Ÿš€ 200 new SaaS accounts/month for 100 employeesโ€”each a potential breach point.
๐ŸŽฏ 50% of breaches target SaaS apps.
๐Ÿค– Unmanaged GenAI tools pose huge security risks.
โš–๏ธ Weak SaaS security = GDPR/CCPA violations.
Securing your SaaS is no longer optional!

๐Ÿ‘‰ Learn how to protect your SaaS environment now: https://thehackernews.com/2025/01/4-reasons-your-saas-attack-surface-can.html
๐Ÿ‘8๐Ÿ‘2โšก1
๐Ÿ“ฃ Tomorrow! Join a live webinar on AI security. Explore how agentic systems are reshaping traditional DevSecOps practices and discover top AI security use cases in todayโ€™s enterprises.

Join James Berthoty, Ron Bitton, and Dor Sarig for an in-depth discussion on agentic-related risks and a 2025 forecast. Donโ€™t miss out!

๐Ÿ“… Wednesday, January 15th, 11:30am ET
๐Ÿ‘‰ Register here: https://thn.news/ai-security-navigating
๐Ÿ‘14๐Ÿค”4๐Ÿ‘1
Googleโ€™s OAuth login exposes a critical vulnerability, allowing attackers to access old employee accounts simply by purchasing a defunct domain from a failed startup.

Learn how this vulnerability could affect your organization: https://thehackernews.com/2025/01/google-oauth-vulnerability-exposes.html
๐Ÿ˜16๐Ÿ˜ฑ9๐Ÿ‘5๐Ÿคฏ5๐Ÿ‘2
๐Ÿ”“ New macOS flaw (CVE-2024-44243) discovered!

Attackers could have bypassed crucial protections to install persistent malware and rootkits, potentially letting them take full control of your system.

Explore the details: https://thehackernews.com/2025/01/microsoft-uncovers-macos-vulnerability.html
๐Ÿ”ฅ13๐Ÿ‘6๐Ÿ˜ฑ6๐Ÿ‘1
๐Ÿšจ UPDATE: Fortinet Confirms Critical Zero-Day ๐Ÿšจ

CVE-2024-55591 in FortiOS & FortiProxy (CVSS 9.6) allows attackers to gain super-admin access & hijack firewalls.

Affected versions: FortiOS 7.0.0-7.0.16 & FortiProxy 7.0.0-7.2.12.

Upgrade now to 7.0.17+ or 7.0.20+ to mitigate risk.

https://thehackernews.com/2025/01/zero-day-vulnerability-suspected-in.html
๐Ÿ”ฅ29๐Ÿ‘17โšก6๐Ÿ˜2