The Hacker News
151K subscribers
1.84K photos
10 videos
3 files
7.76K links
Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

📨 Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
Microsoft and Okta confirm the breach after LAPSUS$ hackers posted stolen source code and screenshots online showing access to the company's internal systems.

Read details: https://thehackernews.com/2022/03/microsoft-and-okta-confirm-breach-by.html
👍1
More than 200,000 MicroTik routers worldwide are controlled by botnet malware, described by cybersecurity researchers as one of the largest botnet-as-a-service cybercrime operations in recent years.

Details: https://thehackernews.com/2022/03/over-200000-microtik-routers-worldwide.html
👍2
A new variant of Gimmick malware has been spotted that's designed to target Apple macOS systems.

Read details: https://thehackernews.com/2022/03/new-variant-of-chinese-gimmick-malware.html
Hackers from the Chinese cyberespionage group "Mustang Panda" deploying a new variant of the Korplug malware, dubbed Hodur.

Read details: https://thehackernews.com/2022/03/chinese-mustang-panda-hackers-spotted.html
👍1
VMware releases patches for critical vulnerabilities in Carbon Black App Control, including a command injection (CVE-2022-22951) and a file upload vulnerability (CVE-2022-22952).

Read details: https://thehackernews.com/2022/03/vmware-issues-patches-for-critical.html
Researchers identified over 200 malicious NPM packages distributed via official repositories that targeted Microsoft Azure developers.

Read: https://thehackernews.com/2022/03/over-200-malicious-npm-packages-caught.html
Researchers have traced the LAPSUS$ cyberattacks to a 16-year-old hacker in England.

Read details: https://thehackernews.com/2022/03/researchers-trace-lapsus-cyber-attacks.html
A 23-year-old Russian national has been indicted in the U.S. and added to the FBI's Cyber Most Wanted list for allegedly administering a cybercrime forum that sold stolen login credentials, personal and credit card data.

Read: https://thehackernews.com/2022/03/23-year-old-russian-hacker-wanted-by.html
At least 2 distinct groups of North Korean state- sponsored hackers exploited a ZERO-DAY (CVE-2022-0609) vulnerability in Google Chrome to launch cyberattacks on the fintech, IT, and media industries.

Read details: https://thehackernews.com/2022/03/north-korean-hackers-exploited-chrome.html
British police have arrested seven suspected members, aged 16 to 21, of the cyber extortion and hacking gang LAPSUS$, which attacked Okta, Microsoft, and Nvidia.

Read details: https://thehackernews.com/2022/03/7-suspected-members-of-lapsus-hacker.html
🔥1
Google has rolled out an urgent out-of-band update for the Chrome browser for millions of Windows, macOS, and Linux users to patch a new actively exploited zero-day vulnerability.

Read details: https://thehackernews.com/2022/03/google-issues-urgent-chrome-update-to.html
Another Chinese hacker group has entered the fray of the Ukraine conflict and is attacking victims with the HeaderTip backdoor.

Read details: https://thehackernews.com/2022/03/another-chinese-hacking-group-spotted.html
U.S. Federal Communications Commission (FCC) has added Russian cybersecurity firm Kaspersky Lab and two Chinese telecom firms on its list of national security threats, saying they pose an "unacceptable risk" to the country's national security.

https://thehackernews.com/2022/03/fcc-adds-kaspersky-and-chinese-telecom.html
Muhstik botnet is targeting Redis servers using a recently disclosed highly critical vulnerability (CVE-2022-0543 / CVSS 10.0) in the database system.

Read details: https://thehackernews.com/2022/03/muhstik-botnet-targeting-redis-servers.html
"Purple Fox" hackers have been using a new FatalRAT variant in their recent malware distribution campaigns and have also improved evasion mechanisms to bypass security software.

Read details: https://thehackernews.com/2022/03/purple-fox-hackers-spotted-using-new.html
Cybercriminals are exploiting unpatched Microsoft Exchange servers to hijack email reply chains, tricking victims into installing IceID info-stealing malware.

Read details: https://thehackernews.com/2022/03/hackers-hijack-email-reply-chains-on.html
This Mandiant incident report for Okta's Lapsus$ breach details the entire timeline of events.

Read details: https://thehackernews.com/2022/03/new-report-on-okta-hack-reveals-entire.html
Researchers have uncovered a large-scale supply chain attack which exploited dependency confusion attacks on NPM repository by uploading more than 800 malicious packages.

Read details: https://thehackernews.com/2022/03/a-threat-actor-dubbed-red-lili-has-been.html
Hackers using a "complex and powerful" malware loader with the goal of installing cryptocurrency miners on compromised systems and potentially enabling the theft of #Discord tokens.

Details: https://thehackernews.com/2022/03/new-malware-loader-verblecon-infects.html
👍1
A group of academics has designed a new system called "Privid" that provides privacy-preserving surveillance video analytics to combat concerns about invasive tracking.

Read details: https://thehackernews.com/2022/03/privid-privacy-preserving-surveillance.html
👍1