The Hacker News
βœ”
151K subscribers
1.84K photos
9 videos
3 files
7.75K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
⚑️ SonicWall and Fortinet both address critical vulnerabilities in their network security software. Update SonicWall's GMS and Analytics, and Fortinet's FortiOS and FortiProxy immediately to protect against unauthorized access.

Read: https://thehackernews.com/2023/07/new-vulnerabilities-disclosed-in.html
πŸ”₯19πŸ‘9🀯3πŸ€”2
A sophisticated China-based hacking campaign has targeted U.S. government agencies and organizations, compromising email accounts via Microsoft Outlook Web Access in Exchange Online (OWA) & Outlook.

Read: https://thehackernews.com/2023/07/us-government-agencies-emails.html
πŸ‘22πŸ‘6😁4😱1
U.S. CISA warns of critical vulnerabilities in Rockwell Automation ControlLogix ENIP modules, allowing remote code execution and DoS attacks.

Read details: https://thehackernews.com/2023/07/rockwell-automation-controllogix-bugs.html
πŸ‘10😁10
Watch out, researchers! A recently discovered proof-of-concept (PoC) exploit on GitHub for CVE-2023-35829 turns out to be a malicious downloader. It silently executes a bash script disguised as a kernel-level process.

Read more: https://thehackernews.com/2023/07/blog-post.html
🀯29πŸ‘11😁11😱5πŸ€”4
🚨 A highly aggressive cloud campaign by the TeamTNT group called Silentbob has infected 196 hosts! They're targeting Docker, Kubernetes, Redis, Postgres, and more. The focus appears to be testing the botnet rather than cryptomining.

Read: https://thehackernews.com/2023/07/teamtnts-silentbob-botnet-infecting-196.html
😱14πŸ”₯6πŸ‘4
A new report reveals a series of cyberattacks targeting government entities, military organizations, & civilian users in #Ukraine & Poland. The attacks aim to steal sensitive data and gain remote access to infected systems.

Learn more: https://thehackernews.com/2023/07/picassoloader-malware-used-in-ongoing.html
πŸ‘17πŸ‘7😁6πŸ€”5😱5🀯2
Zimbra users, be cautious! Email collaboration software company has warned of an actively exploited zero-day vulnerability in its software.

Read details here: https://thehackernews.com/2023/07/zimbra-warns-of-critical-zero-day-flaw.html

Apply the patch ASAP to eliminate the attack vector.
πŸ‘20πŸ€”4🀯3😁2
🚨 Alert! A new malware strain called AVrecon has quietly targeted over 70,000 small office/home office (SOHO) routers worldwide, forming a massive botnet of 40,000 nodes across 20 countries.

Read: http://thehackernews.com/2023/07/new-soho-router-botnet-avrecon-spreads.html
πŸ‘19🀯10πŸ”₯4😱4
TeamTNT has expanded its cloud credential stealing campaign beyond AWS, now also targeting Azure and Google Cloud Platform.

Learn more about it: https://thehackernews.com/2023/07/teamtnts-cloud-credential-stealing.html
πŸ€”10πŸ‘9😱8😁4
⚠️ Heads up: Over a million WordPress sites are affected by a critical bug in the All-In-One Security (AIOS) plugin.

It stored user passwords in plaintext, posing a risk if admins reused them on other services.

Read: https://thehackernews.com/2023/07/aios-wordpress-plugin-faces-backlash.html
😁32🀯22πŸ‘17πŸ”₯10πŸ€”9
🚨 πŸ” Microsoft admits a validation issue in its code that enabled China-based hackers to forge authentication tokens, granting unauthorized access to Azure AD and Outlook[.]com accounts of over two dozen organizations.

Read: https://thehackernews.com/2023/07/microsoft-bug-allowed-hackers-to-breach.html
😁31🀯23πŸ‘12πŸ”₯5⚑3
A new generative AI cybercrime tool called WormGPT is gaining popularity in underground forums. It enables cybercriminals to automate advanced phishing and BEC attacks, using personalized fake emails to increase success rates.

Read: https://thehackernews.com/2023/07/wormgpt-new-ai-tool-allows.html
🀯48πŸ‘32😁21πŸ”₯11πŸ€”5⚑4😱1
⚠️ New report reveals the alarming activities of Gamaredon, a notorious Russian hacking crew. They exploit email and messaging platforms to compromise systems, exfiltrating files in a matter of minutes.

Read: https://thehackernews.com/2023/07/cert-ua-uncovers-gamaredons-rapid-data.html
πŸ‘23🀯14πŸ‘2
Cybercriminals are leveraging exploits for CVE-2021-40444 and CVE-2022-30190 to execute code through malicious Word files. Once opened, LokiBot malware is downloaded, logging keystrokes, capturing screenshots, and stealing data.

Read: https://thehackernews.com/2023/07/cybercriminals-exploit-microsoft-word.html
πŸ‘23⚑7😁4πŸ€”3
🚨 Cyber attacks via infected USB drives have tripled in the first half of 2023. Learn more about the SOGU and SNOWYDRIVE campaigns targeting public and private sector entities worldwide.

Read: https://thehackernews.com/2023/07/malicious-usb-drives-targetinging.html
πŸ‘18🀯16⚑5πŸ”₯3
Heads up! Hackers are exploiting WebAPK technology to trick Android users into downloading fake banking apps that steal sensitive information.

Read details: https://thehackernews.com/2023/07/hackers-exploit-webapk-to-deceive.html
πŸ‘23😱21πŸ€”10🀯8😁1
JumpCloud confirms that a nation-state actor was behind the recent security incident. The breach targeted a specific group of customers.

Learn more: https://thehackernews.com/2023/07/jumpcloud-blames-sophisticated-nation.html
πŸ‘22
Beware! A critical security flaw (CVE-2023-28121) in the WooCommerce Payments #WordPress plugin is currently being actively exploited by threat actors.

In addition to this, Rapid7 has also discovered ongoing exploitation of Adobe ColdFusion flaws (including CVE-2023-29298), resulting in web shell deployments.

Read details here: https://thehackernews.com/2023/07/cybercriminals-exploiting-woocommerce.html
πŸ‘20😁4
Conor Brian Fitzpatrick, the owner of BreachForums, pleads guilty to charges related to operating a cybercrime forum and possessing child pornographyβ€”faces up to 40 years in jail and $750,000 in fines.

Read: https://thehackernews.com/2023/07/owner-of-breachforums-pleads-guilty-to.html
🀯33πŸ‘13πŸ”₯6πŸ‘1
FIN8, notorious financially motivated hacker group, has adopted a revamped version of the Sardonic backdoor to deliver the BlackCat ransomware.

Learn more: https://thehackernews.com/2023/07/fin8-group-using-modified-sardonic.html
πŸ‘13😁7
Attention VirusTotal users!

A database containing 5,600 customers' details has been exposed, including government agencies like the FBI, NSA, and more.

Learn more: https://thehackernews.com/2023/07/virustotal-data-leak-exposes-some.html
😁29🀯21πŸ”₯16πŸ‘14😱13⚑6πŸ€”3