The Hacker News
βœ”
151K subscribers
1.81K photos
9 videos
3 files
7.72K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
⚑ A fake "WalletConnect" app on Android stole over $70,000 in πŸ’Έ cryptocurrency before being pulled from Google Play, with 10,000+ downloads and 150+ victims.

Learn more: https://thehackernews.com/2024/09/crypto-scam-app-disguised-as.html

Stay alert and protect your assets from DeFi scams!
😁27🀯18πŸ‘17⚑9
Meta faces a €91 million GDPR fine for storing Facebook and Instagram user passwords in plaintext.

Meta failed to report the breach promptly and did not document these incidents correctlyβ€”a clear GDPR violation.

Read details: https://thehackernews.com/2024/09/meta-fined-91-million-for-storing.html
🀯55😁26πŸ‘8πŸ”₯5⚑3
🚨 Critical vulnerabilities in 6 ATG systems could lead to remote attacks, causing physical damage, environmental hazards, and economic losses.

Gas stations, hospitals, and military bases are at risk, with thousands of ATGs exposed online.

https://thehackernews.com/2024/09/critical-flaws-in-tank-gauge-systems.html
😁9πŸ”₯8πŸ‘6⚑2
Microsoft 365 is a prime #ransomware target, with hackers exploiting weak points to encrypt vital business data. Its widespread use across 400M+ users makes a breach devastating.

Stay protectedβ€”implement proactive defense strategies now: https://thehackernews.com/2024/09/why-microsoft-365-protection-reigns-supreme.html
😁9⚑5πŸ”₯5πŸ‘4
πŸ”‘ 🚨 Attackers are using modern session hijacking to steal credentials and access sensitive data. Even with MFA, stolen session cookies can bypass defenses and access cloud apps.

Learn what you can do to protect your cloud environments: https://thehackernews.com/2024/09/session-hijacking-20-latest-way-that.html
😁17⚑8πŸ‘7πŸ”₯3
U.K. national charged for hacking execs’ Microsoft 365 accounts, earning millions through insider trading.

Read details: https://thehackernews.com/2024/10/uk-hacker-charged-in-375-million.html
😁14⚑4πŸ‘3πŸ‘2πŸ”₯1
🚨 This week's #CybersecurityRecap is packed!

From critical CUPS vulnerabilities πŸ–₯️, to Google’s move to Rust reducing Android threats πŸ“‰, and Kia cars' security scare πŸš—πŸ”. Plus, Kaspersky’s U.S. exit and mysterious "Noise Storms" πŸ‘€.

https://thehackernews.com/2024/09/thn-cybersecurity-recap-last-weeks-top_30.html
πŸ‘7😁7πŸ”₯5⚑3🀯3
UPDATE: NSO Group responds to Apple's motion to dismiss, agreeing it should be dropped. NSO defends its Pegasus tool as essential for fighting crime in an era of end-to-end encryption (E2EE) and criticizes Apple for not cooperating with law enforcement.

https://thehackernews.com/2024/09/apple-drops-spyware-case-against-nso.html#nso-group-responds
πŸ”₯19πŸ‘9😁6⚑5πŸ‘1😱1
πŸ›‘ Researchers uncovered a cryptojacking campaign exploiting Docker API endpoints to join malicious Docker Swarms. Attackers use tools like masscan to find vulnerabilities, spreading malware across Kubernetes & SSH networks.

Details: https://thehackernews.com/2024/10/new-cryptojacking-attack-targets-docker.html
πŸ‘9⚑5πŸ”₯3😁3
Over 140,000 phishing websites connected to the Sniper Dz Phishing-as-a-Service (PhaaS) platform have surfaced, facilitating widespread credential theft.

Learn more: https://thehackernews.com/2024/10/free-sniper-dz-phishing-tools-fuel.html
πŸ”₯15πŸ‘5⚑4
⚠️ Rhadamanthys Stealer now leverages AI-powered Optical Character Recognition (OCR) to target #cryptocurrency wallets by extracting seed phrases from images.

Learn how this malware is evolving: https://thehackernews.com/2024/10/ai-powered-rhadamanthys-stealer-targets.html
🀯15πŸ‘6😁4
Balancing #GenerativeAI productivity with security is a major challenge.

50% of heavy R&D users risk exposing source code & proprietary info, with unrestricted use leading to data leaks and costly breaches.

Explore LayerX’s guide to secure GenAI tools: https://thehackernews.com/2024/10/5-actionable-steps-to-prevent-genai.html
πŸ‘14⚑4😁4🀯2πŸ€”1
Fake PyPI packages posed as #cryptocurrency wallet recovery tools, stealing sensitive info. Attackers used dynamic dead drop resolvers, showing evolving tactics to evade detection.

Learn more: https://thehackernews.com/2024/10/pypi-repository-found-hosting-fake.html
🀯11😁7πŸ‘1
⚠️ Zimbra Collaboration is under attack via a critical vulnerability (CVE-2024-45519) enabling remote command execution.

Even without Zimbra’s postjournal enabled, attackers can exploit this flaw with crafted SMTP messages.

Learn more: https://thehackernews.com/2024/10/researchers-sound-alarm-on-active.html
😁14πŸ‘9πŸ”₯4🀯2😱2
πŸ’£ Andariel, a sub-group of Lazarus, is now targeting U.S. orgs with financially motivated attacks using Dtrack & new Nukebot malware.

Learn more: https://thehackernews.com/2024/10/andariel-hacker-group-shifts-focus-to.html

They're exploiting known vulnerabilitiesβ€”stay alert!
πŸ”₯9πŸ‘7🀯6πŸ‘3😁2πŸ€”1
Non-Human Identities (NHIs) outnumber human ones by 92:1 in enterprises, making them a key target for cyber-attacks.

Ghost NHIsβ€”leftover identities after employees leaveβ€”often go unprotected, creating serious vulnerabilities.

Don’t let your organization fall behind. Learn how to secure them: Read: https://thehackernews.com/expert-insights/2024/09/security-operations-for-non-human.html
πŸ”₯10πŸ‘6🀯4⚑1
πŸ” Discover how dynamic malware analysis & real-time interactivity reveal hidden behaviors!

Tools like #AnyRun let #cybersecurity pros monitor DNS/HTTP traffic & export data for deeper analysis with Wireshark.

Learn more: https://thehackernews.com/2024/10/5-must-have-tools-for-effective-dynamic.html
πŸ‘9🀯3😁2
🚨 A critical vulnerability, CosmicSting (CVE-2024-34102), has hit 5% of Adobe Commerce & Magento stores.

7 hacker groups are injecting malicious scripts.

Details here: https://thehackernews.com/2024/10/alert-adobe-commerce-and-magento-stores.html

Patching isn’t enoughβ€”rotate your encryption keys now!
🀯8πŸ‘5πŸ€”4πŸ‘3
🚨 14 vulnerabilities found in DrayTek routers, including 2 critical (CVSS 10.0). These flaws allow attackers to take full control and infiltrate networks.

Read: https://thehackernews.com/2024/10/alert-over-700000-draytek-routers.html

With 704,000+ routers exposed online, the risk is massive. Patch now!
😁9πŸ‘4πŸ”₯3πŸ€”1
⚠️ πŸ” The Hidden Threat in Your Inbox!

A spear-phishing campaign is tricking recruiters into downloading a JavaScript backdoor called More_Eggs through fake resumes.

Learn how to protect your team and avoid costly breaches: https://thehackernews.com/2024/10/fake-job-applications-deliver-dangerous.html
😁11πŸ”₯4⚑2🀯2πŸ‘1
⚠️ New threat alert: CeranaKeeper is targeting Southeast Asia with massive data exfiltration!

Using tools like TONESHELL & PUBLOAD, it evades detection by abusing Dropbox & OneDrive.

Learn more: https://thehackernews.com/2024/10/china-linked-ceranakeeper-targeting.html
😁13πŸ”₯6⚑4πŸ‘1