The Hacker News
βœ”
151K subscribers
1.85K photos
10 videos
3 files
7.77K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
πŸ”’ SolarMarker malware evolves with a multi-tiered infrastructure, making it harder for law enforcement to take down and evade detection.

Learn about the latest tactics: https://thehackernews.com/2024/05/solarmarker-malware-evolves-to-resist.html
πŸ”₯17πŸ‘5🀯1
Non-compliance with IT security rules can cause data loss, financial harm, and reputational damage.

Discover how Wazuh's open-source solution monitors files in real-time and detects unauthorized changes.

https://thehackernews.com/2024/05/streamlining-it-security-compliance.html
⚑10πŸ‘7πŸ‘3πŸ”₯2
🚨 Alert - New CLOUD#REVERSER attack campaign uses Google Drive and Dropbox to stage malware, disguising executables as Excel files with the right-to-left override Unicode trick.

Learn more: https://thehackernews.com/2024/05/malware-delivery-via-cloud-services.html
πŸ”₯20πŸ‘9
πŸ”’ Secure modern applications without compromising DevOps velocity or developer experience.

Discover the five guiding principles essential for building a highly effective DevSecOps practice in this latest article.

Read on > https://thehackernews.com/2024/05/five-core-tenets-of-highly-effective.html
πŸ‘12πŸ”₯6
⚑ Alert for GitHub Enterprise Server users.

A critical flaw (CVE-2024-4985) has been found, allowing attackers to gain admin privileges by forging SAML responses.

More details in the article > https://thehackernews.com/2024/05/critical-github-enterprise-server-flaw.html

Check if your instance is affected & update immediately.
πŸ”₯12πŸ‘8😱6
⚠️ Attention: Veeam has disclosed 4 new vulnerabilities in its Backup Enterprise Manager, including a critical security flaw (CVE-2024-29849) that could allow attackers to bypass authentication.

πŸ”— Learn more here: https://thehackernews.com/2024/05/critical-veeam-backup-enterprise.html

Don't wait - update your software now.
πŸ‘15πŸ”₯9
Zoom has announced the rollout of NIST-approved post-quantum Kyber-768 End-to-End Encryption (E2EE) for Zoom Meetings to protect users against sophisticated attacks.

Learn more: https://thehackernews.com/2024/05/zoom-adopts-nist-approved-post-quantum.html
πŸ‘20πŸ€”12
Attention QNAP users! Make sure to update your QTS and QuTS hero to the latest versions to address recently discovered vulnerabilities.

Read the article to learn more about the researchers' findings and QNAP's response: https://thehackernews.com/2024/05/qnap-patches-new-flaws-in-qts-and-quts.html
πŸ”₯13πŸ‘9
⚠️ An unknown threat actor is exploiting Microsoft Exchange Server flaws to deploy stealthy keylogger malware in targeted attacks aimed at government agencies, banks, and educational institutions.

Details here - https://thehackernews.com/2024/05/ms-exchange-server-flaws-exploited-to.html
πŸ”₯15πŸ‘10😱5😁2
🚨 New cryptojacking malware campaign HIDDEN SHOVEL uses GHOSTENGINE payload to exploit vulnerable drivers, disable EDRs, and install XMRig miner in a BYOVD attack.

Find details here: https://thehackernews.com/2024/05/ghostengine-exploits-vulnerable-drivers.html
πŸ‘10πŸ”₯6
🚨 CISA Urgent Advisory:

Rockwell Automation urges disconnecting all industrial control systems (ICS) not meant for the public internet to prevent cyber threats amid heightened geopolitical tensions.

Learn more: https://thehackernews.com/2024/05/rockwell-advises-disconnecting-internet.html
😁15πŸ‘8⚑1
🌐 Researchers uncover a stealthy threat group, dubbed "Unfading Sea Haze," targeting high-level organizations in the South China Sea. Poor credential hygiene and outdated patches enable these attacks to succeed.

Read: https://thehackernews.com/2024/05/researchers-warn-of-chinese-aligned.html
πŸ”₯13πŸ‘3πŸ‘3🀯3
The number of SaaS apps in enterprises is skyrocketing, creating complex security challenges.

Discover how SaaS Security Posture Management (SSPM) can help protect your organization against evolving threats.

Get 2025 Ultimate SaaS Security Checklist: https://thehackernews.com/2024/05/the-ultimate-saas-security-posture.html
πŸ‘19⚑4🀯1
Microsoft to deprecate VBScript in favor of JavaScript and PowerShell. The tech giant plans to phase out the scripting language starting in the second half of 2024.

Learn more: https://thehackernews.com/2024/05/the-end-of-era-microsoft-phases-out.html
πŸ”₯41πŸ‘8πŸ€”7😱5⚑2
πŸ”₯ Ivanti released patches for multiple critical security flaws (CVE-2024-29822 through CVE-2024-29827) in Endpoint Manager (EPM) β€” 6 of these are SQL injection vulnerabilities that allow RCE without authentication.

Learn more: https://thehackernews.com/2024/05/ivanti-patches-critical-remote-code.html
πŸ‘11πŸ”₯6πŸ‘3
What are the 5️⃣ core components of any robust SaaS Security Posture Management (SSPM) solution?

Learn how to choose the right SSPM vendor for your organization and get a list of 25 questions to ask in your security assessment.

Download the guide: https://thn.news/sspm-guide-ln
πŸ‘14πŸ”₯5😁2
🚨 Chinese APT group targets government entities in the Middle East, Africa, and Asia in a large-scale cyber espionage campaign dubbed Operation "Diplomatic Specter."

Learn more about the tactics and techniques used by the attackers: https://thehackernews.com/2024/05/inside-operation-diplomatic-specter.html
😁12πŸ‘8πŸ”₯4⚑2πŸ€”1😱1
🌐 Sharp Dragon, a China-linked threat actor, extends its cyber espionage reach to Africa and the Caribbean, targeting governmental organizations.

Learn more about their tactics: https://thehackernews.com/2024/05/new-frontiers-old-tactics-chinese-cyber.html
πŸ”₯10πŸ‘5⚑1😁1
Did you know the average company uses over 400 SaaS applications? Yet, 56% of IT pros aren’t aware of their data backup responsibilities.

Discover the hidden secrets in your backup data and how to keep them safe: https://thehackernews.com/2024/05/are-your-saas-backups-as-secure-as-your.html
πŸ‘12πŸ”₯7🀯2⚑1
πŸ” Attention: CISA has added a critical security flaw (CVE-2020-17519) in Apache Flink to its Known Exploited Vulnerabilities catalog. Attackers are exploiting this flaw to gain unauthorized access to sensitive information.

Learn more: https://thehackernews.com/2024/05/cisa-warns-of-actively-exploited-apache.html
πŸ‘11⚑7
🚨 Ransomware attacks on VMware ESXi follow a similar pattern, exploiting misconfigurations and vulnerabilities.

Learn the key steps and how to protect your organization: https://thehackernews.com/2024/05/ransomware-attacks-exploit-vmware-esxi.html
⚑17πŸ‘14πŸ”₯8🀯4