π UAC-0063 has been using stolen documents from Kazakhstanβs Ministry of Foreign Affairs to spear-phish targets and deploy HATVIBE malware.
π Read the full details on UAC-0063βs evolving tactics: https://thehackernews.com/2025/01/uac-0063-expands-cyber-attacks-to.html
π Read the full details on UAC-0063βs evolving tactics: https://thehackernews.com/2025/01/uac-0063-expands-cyber-attacks-to.html
π13β‘1
β οΈ A critical flaw (CVE-2025-22604) in Cacti could lead to remote code execution. If exploited, authenticated attackers could steal or manipulate sensitive data.
Patch to version 1.2.29 to fix this flaw and protect your systems.
Learn more: https://thehackernews.com/2025/01/critical-cacti-security-flaw-cve-2025.html
Patch to version 1.2.29 to fix this flaw and protect your systems.
Learn more: https://thehackernews.com/2025/01/critical-cacti-security-flaw-cve-2025.html
π₯9π6β‘1π€1
π¨ Apple Silicon CPUs hit by 2 new vulnerabilities: SLAP & FLOP
These attacks target Load Address and Load Value Predictors in Apple CPUs, risking exposure of your:
β€· Location history
β€· Calendar events
β€· Sensitive data
π Read: https://thehackernews.com/2025/01/new-slap-flop-attacks-expose-apple-m.html
These attacks target Load Address and Load Value Predictors in Apple CPUs, risking exposure of your:
β€· Location history
β€· Calendar events
β€· Sensitive data
π Read: https://thehackernews.com/2025/01/new-slap-flop-attacks-expose-apple-m.html
π16π₯7π±7π4π3π€2β‘1
π₯ AI isnβt just a trend in cybersecurityβitβs already reshaping how teams defend against threats.
But are we fully prepared to tackle its challenges?
In this latest #webinar, youβll discover:
β€· Real insights from 200 cybersecurity professionals using AI today
β€· Whatβs working & whatβs not in the world of AI-driven security
β€· The real hurdlesβdata issues, transparency, and more
π¨βπ» Join Now and discover how to make AI work harder for you: https://thehackernews.com/2025/01/ai-in-cybersecurity-whats-effective-and.html
But are we fully prepared to tackle its challenges?
In this latest #webinar, youβll discover:
β€· Real insights from 200 cybersecurity professionals using AI today
β€· Whatβs working & whatβs not in the world of AI-driven security
β€· The real hurdlesβdata issues, transparency, and more
π¨βπ» Join Now and discover how to make AI work harder for you: https://thehackernews.com/2025/01/ai-in-cybersecurity-whats-effective-and.html
π₯11π9π3β‘1π€―1
π North Korea's Lazarus Group is now using a powerful web-based admin panel to coordinate cyberattacks across the globe.
233 targets, mostly in crypto, with a surge in Indiaβ110 new victims just in January.
Learn more: https://thehackernews.com/2025/01/lazarus-group-uses-react-based-admin.html
233 targets, mostly in crypto, with a surge in Indiaβ110 new victims just in January.
Learn more: https://thehackernews.com/2025/01/lazarus-group-uses-react-based-admin.html
π₯24π14π±7β‘3π3π1
β οΈ New Mirai Botnet Variant Aquabot Targets CVE-2024-41710 in Mitel Phones for DDoS Attacks.
The flaw affects Mitel 6800, 6900, 6900w phones and Mitel 6970 Conference Units. Attackers have been exploiting CVE-2024-41710 since January 2025.
Attackers are using Telegram to sell DDoS servicesβthis threat is already commercialized.
Learn more: https://thehackernews.com/2025/01/new-aquabot-botnet-exploits-cve-2024.html
The flaw affects Mitel 6800, 6900, 6900w phones and Mitel 6970 Conference Units. Attackers have been exploiting CVE-2024-41710 since January 2025.
Attackers are using Telegram to sell DDoS servicesβthis threat is already commercialized.
Learn more: https://thehackernews.com/2025/01/new-aquabot-botnet-exploits-cve-2024.html
π19π4π€3π2
π¨ Security Flaws Discovered in Voyager PHP Package.
Attackers can exploit these UNPATCHED flaws with just one clickβallowing them to execute arbitrary code remotely.
Click here to learn more: https://thehackernews.com/2025/01/unpatched-php-voyager-flaws-leave.html
Attackers can exploit these UNPATCHED flaws with just one clickβallowing them to execute arbitrary code remotely.
Click here to learn more: https://thehackernews.com/2025/01/unpatched-php-voyager-flaws-leave.html
π₯11π6π1π€―1
π¨ AI Startup #DeepSeek Exposes Sensitive Data!
A ClickHouse database was exposed on the internet, allowing anyone to access internal secrets, chat logs, API secrets, and moreβall unprotected.
Read more: https://thehackernews.com/2025/01/deepseek-ai-database-exposed-over-1.html
A ClickHouse database was exposed on the internet, allowing anyone to access internal secrets, chat logs, API secrets, and moreβall unprotected.
Read more: https://thehackernews.com/2025/01/deepseek-ai-database-exposed-over-1.html
π39π±20π₯9π5π5
β‘ SOC Analysts Are Burning Out!
Manual tasks, false positives, and tool overloadβAI is the solution SOC teams need NOW.
AI enables faster research, quicker analysis, and smarter responses to emerging threats.
Learn more: https://thehackernews.com/2025/01/soc-analysts-reimagining-their-role.html
Manual tasks, false positives, and tool overloadβAI is the solution SOC teams need NOW.
AI enables faster research, quicker analysis, and smarter responses to emerging threats.
Learn more: https://thehackernews.com/2025/01/soc-analysts-reimagining-their-role.html
π13π7π€6β‘4π€―4π±3
β οΈ Warning: Critical Flaw Discovered in Lightning AI Studio!
The vulnerability allowed attackers to run commands with root privileges, potentially compromising entire AI projects.
Get the full analysis: https://thehackernews.com/2025/01/lightning-ai-studio-vulnerability.html
The vulnerability allowed attackers to run commands with root privileges, potentially compromising entire AI projects.
Get the full analysis: https://thehackernews.com/2025/01/lightning-ai-studio-vulnerability.html
π₯13π7π2π2β‘1
π International law enforcement has dismantled infamous cybercrime hubs linked to platforms like Cracked, Nulled, StarkRDP and Sellix.
These platforms sold malware, hack tools, and personal data.
π Read more about the "Operation Talent" β https://thehackernews.com/2025/01/authorities-seize-domains-of-popular.html
These platforms sold malware, hack tools, and personal data.
π Read more about the "Operation Talent" β https://thehackernews.com/2025/01/authorities-seize-domains-of-popular.html
π14π9π€―6β‘4π±1
π¨ ALERT: Over 57 threat actors from China, Iran, North Korea, and Russia are now using Google's Gemini AI to power their malicious cyber operations.
From researching vulnerabilities to crafting phishing campaigns, theyβre leveraging GenAI for faster, more efficient cybercrime.
Learn more: https://thehackernews.com/2025/01/google-over-57-nation-state-threat.html
From researching vulnerabilities to crafting phishing campaigns, theyβre leveraging GenAI for faster, more efficient cybercrime.
Learn more: https://thehackernews.com/2025/01/google-over-57-nation-state-threat.html
π30π16π±14π€―7β‘3π€3π₯2
π¨ High-Risk VMware Vulnerabilities Discovered β Update ASAP!
5 major flaws have been found in VMware Aria Operations & Aria Operations for Logs, with CVSS scores ranging from 4.3 to 8.5. Attackers could escalate privileges, steal credentials, or inject malicious scripts.
π Read more: https://thehackernews.com/2025/01/broadcom-patches-vmware-aria-flaws.html
5 major flaws have been found in VMware Aria Operations & Aria Operations for Logs, with CVSS scores ranging from 4.3 to 8.5. Attackers could escalate privileges, steal credentials, or inject malicious scripts.
π Read more: https://thehackernews.com/2025/01/broadcom-patches-vmware-aria-flaws.html
π₯15π±7π6π3π2π€―2β‘1
π¨ Google Blocks 2.36 Million Harmful Android Apps in 2024. Over 158,000 bad developer accounts banned.
Even apps outside the official store are being scrutinizedβyour deviceβs defense is constantly evolving.
π Learn more: https://thehackernews.com/2025/01/google-bans-158000-malicious-android.html
Even apps outside the official store are being scrutinizedβyour deviceβs defense is constantly evolving.
π Learn more: https://thehackernews.com/2025/01/google-bans-158000-malicious-android.html
π21π10π₯4
β οΈ Italy Bans DeepSeek AI Service Over Questionable Data Practices and Privacy Concerns!
Meanwhile, malicious hackers are exploiting DeepSeek's AI models to generate dangerous content.
π Read the full story: https://thehackernews.com/2025/01/italy-bans-chinese-deepseek-ai-over.html
Meanwhile, malicious hackers are exploiting DeepSeek's AI models to generate dangerous content.
π Read the full story: https://thehackernews.com/2025/01/italy-bans-chinese-deepseek-ai-over.html
π48π21π€―11β‘7π€6π±5π₯3π3
π¨ AI is changing the game of social engineeringβforever.
Hackers now manipulate trust & emotions to launch attacks at scale. AI lets hackers replicate voices, faces, and even your colleagues.
π Read the full story: https://thehackernews.com/2025/01/top-5-ai-powered-social-engineering.html
Hackers now manipulate trust & emotions to launch attacks at scale. AI lets hackers replicate voices, faces, and even your colleagues.
π Read the full story: https://thehackernews.com/2025/01/top-5-ai-powered-social-engineering.html
π₯19π8π2π1π€1π€―1
π CISA and FDA have just issued urgent warnings about critical flaws in Contec CMS8000 and Epsimed MN-120 patient monitors.
Hackers could exploit these flaws to gain remote access to devices, overwrite files & even steal sensitive patient data.
Read: https://thehackernews.com/2025/01/cisa-and-fda-warn-of-critical-backdoor.html
Hackers could exploit these flaws to gain remote access to devices, overwrite files & even steal sensitive patient data.
Read: https://thehackernews.com/2025/01/cisa-and-fda-warn-of-critical-backdoor.html
π22π€―12π₯7π±1
π¨ Attack Alert: Cybercriminals are using bogus Google ads to direct Microsoft advertisers to phishing pages designed to capture login details and 2FA codes.
Over 630 phishing pages detected, with domains mostly hosted in Brazil.
Read the full report: https://thehackernews.com/2025/02/malvertising-scam-uses-fake-google-ads.html
Over 630 phishing pages detected, with domains mostly hosted in Brazil.
Read the full report: https://thehackernews.com/2025/02/malvertising-scam-uses-fake-google-ads.html
π±21π₯9π4π3β‘1
π¨ WARNING: WhatsApp uncovers major spyware campaign targeting journalists!
β€ 90+ victims were attacked by Israeli firm Paragon Solutions.
β€ Zero-click spyware deployed via a PDF fileβno action from the user needed
π Full story: https://thehackernews.com/2025/02/meta-confirms-zero-click-whatsapp.html
β€ 90+ victims were attacked by Israeli firm Paragon Solutions.
β€ Zero-click spyware deployed via a PDF fileβno action from the user needed
π Full story: https://thehackernews.com/2025/02/meta-confirms-zero-click-whatsapp.html
π₯15π€―12π6π4π±3β‘2
π BeyondTrustβs breach compromised 17 Remote Support SaaS customers, caused by a compromised API key.
Attackers exploited a zero-day vulnerability in a third-party app to reset application passwords.
Federal agencies, including the U.S. Treasury, were affected by this breach.
Read the full report: https://thehackernews.com/2025/02/beyondtrust-zero-day-breach-exposes-17.html
Attackers exploited a zero-day vulnerability in a third-party app to reset application passwords.
Federal agencies, including the U.S. Treasury, were affected by this breach.
Read the full report: https://thehackernews.com/2025/02/beyondtrust-zero-day-breach-exposes-17.html
β‘13π₯9π4π3