The Hacker News
151K subscribers
1.84K photos
9 videos
3 files
7.75K links
Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

📨 Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
Attention VirusTotal users!

A database containing 5,600 customers' details has been exposed, including government agencies like the FBI, NSA, and more.

Learn more: https://thehackernews.com/2023/07/virustotal-data-leak-exposes-some.html
😁29🤯21🔥16👍14😱136🤔3
A sophisticated threat actor is targeting Pakistan government entities through a trojanized version of the E-Office application.

Read details: https://thehackernews.com/2023/07/pakistani-entities-targeted-in.html
🔥23👍12😁10👏2
ALERT: Critical security flaw in Citrix NetScaler ADC and Gateway being actively exploited! CVE-2023-3519 allows unauthenticated remote code execution.

Read: https://thehackernews.com/2023/07/zero-day-attacks-exploited-critical.html
24👍9😁6🤔4
🚨 U.S. government puts Cytrox and Intellexa, foreign commercial spyware vendors, on an economic blocklist for their potential misuse of surveillance tools.

Read details here: https://thehackernews.com/2023/07/us-government-blacklists-cytrox-and.html
🔥12👍9👏32
🔒 Cybersecurity researchers have discovered a privilege escalation vulnerability, dubbed Bad Build, in Google Cloud. Attackers could tamper with app images and infect users, leading to supply chain attacks.

Read: https://thehackernews.com/2023/07/badbuild-flaw-in-google-cloud-build.html
👍208🔥5
APT41, a China-linked nation-state actor, has been linked to two newAndroid spyware strains, WyrmSpy and DragonEgg.

Read: https://thehackernews.com/2023/07/chinese-apt41-hackers-target-mobile.html
🤯15👍8🤔42
Dark web investigations rely on techniques like OSINT to uncover identities and track down cybercriminals.

Explore the various techniques used to identify the individuals behind these sites and personas.

Read: https://thehackernews.com/2023/07/exploring-dark-side-osint-tools-and.html
🔥19👍10🤔52🤯2👏1
U.S. cybersecurity agencies issue recommendations to strengthen security in 5G network slicing. Find out how to ensure confidentiality, integrity, and availability of network services.

Read details: https://thehackernews.com/2023/07/cisa-and-nsa-issue-new-guidance-to.html
👍30🔥4😁21
ColdFusion users, beware! Adobe has released new updates to fix a critical security flaw (CVE-2023-38205) that's actively being exploited in the wild.

Read: https://thehackernews.com/2023/07/adobe-rolls-out-new-patches-for.html

Make sure to update your installations to stay protected.
👏17👍9🔥43
To address evolving nation-state cyber threats, Microsoft announces the inclusion of detailed logs of email access and more log data types for customers at no additional cost.

Read details: https://thehackernews.com/2023/07/microsoft-expands-cloud-logging-to.html
👍18🔥2👏21
Cybersecurity researchers are warning about a new cloud-targeting, peer-to-peer worm called P2PInfect. It exploits vulnerable Redis instances running on Linux and Windows OS, making it highly scalable.

Read more: https://thehackernews.com/2023/07/new-p2pinfect-worm-targeting-redis.html
👍18🤯7😱5🔥21👏1
North Korean state-sponsored groups suspected in the recent supply chain attack on JumpCloud! They used the breach to target cryptocurrency firms, aiming to generate illegal revenues.

Learn more: https://thehackernews.com/2023/07/north-korean-state-sponsored-hackers.html
🔥19👍5😁5
Multiple critical flaws in Apache OpenMeetings, a web conferencing solution, exposed admin accounts to control and malicious code execution.

CVE-2023-28936
CVE-2023-29032
CVE-2023-29246

Read details: https://thehackernews.com/2023/07/apache-openmeetings-web-conferencing.html
13👍7🔥6🤯3
Mallox ransomware surges 174% in 2023, employing double extortion tactics by stealing data before encryption.

Read: https://thehackernews.com/2023/07/mallox-ransomware-exploits-weak-ms-sql.html

Targeting manufacturing, legal services, and retail sectors, they exploit vulnerable MS-SQL servers as a primary penetration vector.
😱13👍4🤔2🤯2🔥1😁1
⚠️ Alert! New security flaws in AMI MegaRAC BMC software have been disclosed, putting vulnerable servers at risk. Attackers could remotely take control and deploy malware.

Details here: https://thehackernews.com/2023/07/critical-flaws-in-ami-megarac-bmc.html
😱13👍6🤯4🤔3
U.S. cybersecurity agency warns of a critical flaw (CVE-2023-3519) in Citrix NetScaler ADC and Gateway devices being exploited by hackers to drop web shells on vulnerable systems.

Learn more: https://thehackernews.com/2023/07/citrix-netscaler-adc-and-gateway.html
👍17😁3
DDoS botnets are exploiting the CVE-2023-28771 vulnerability in Zyxel devices to gain remote control and launch devastating attacks.

Learn more: https://thehackernews.com/2023/07/ddos-botnets-hijacking-zyxel-devices-to.html
🔥12👍94
DDoS botnets are exploiting the CVE-2023-28771 vulnerability in Zyxel devices to gain remote control and launch devastating attacks.

Learn more: https://thehackernews.com/2023/07/ddos-botnets-hijacking-zyxel-devices-to.html
🔥16👍6😱5
Protecting local governments from ransomware attacks is crucial! Implementing robust password policies is a step towards enhanced security. Check out tools like Specops Password Policy to keep your organization safe!

Read: https://thehackernews.com/2023/07/local-governments-targeted-for.html
👍194🤯4
Beware of BundleBot, a stealthy malware strain that's stealing sensitive info from compromised hosts! It spreads through Facebook Ads, cleverly disguised as regular programs, AI tools, or games.

Read: https://thehackernews.com/2023/07/sophisticated-bundlebot-malware.html
🤯18👍10😱5🤔3🔥2😁1
🚨 HotRat, a dangerous variant of the AsyncRAT malware, is spreading through pirated versions of popular software and games.

Read: https://thehackernews.com/2023/07/hotrat-new-variant-of-asyncrat-malware.html
👍19🔥7🤔7😁1🤯1