The Hacker News
โœ”
151K subscribers
1.78K photos
9 videos
3 files
7.7K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: admin@thehackernews.com

๐ŸŒ Website: https://thehackernews.com
Download Telegram
๐Ÿ”‘ Discover how AI-powered identity systems, like One Identityโ€™s Vigilance AIโ„ข Threat Engine, are transforming #cybersecurity by detecting behavioral anomalies and preventing credential-based attacks.

Find details here: https://thehackernews.com/2024/10/the-value-of-ai-powered-identity.html
๐Ÿ˜6๐Ÿ‘5โšก3๐Ÿ˜ฑ2
A recent case study shows how a malicious redirect led shoppers to a fake "evil twin" checkout page, stealing their financial info. Learn how quick action saved a retailer from costly damage.

Read: https://thehackernews.com/2024/10/new-case-study-evil-twin-checkout-page.html
๐Ÿ‘13๐Ÿ˜3๐Ÿคฏ1
๐ŸŽฎ Alert: Hackers are tricking GAMERS searching for cheats into downloading Lua-based malware, which stays hidden and delivers payloads like RedLine Stealer.

Learn how it works and how to stay safe: https://thehackernews.com/2024/10/gamers-tricked-into-downloading-lua.html
๐Ÿ˜ฑ9๐Ÿ‘8๐Ÿ˜8๐Ÿ‘4๐Ÿค”2โšก1
โš ๏ธ WARNING: Ivantiโ€™s CSA is under attack! Three new zero-day vulnerabilities are being actively exploited in the wild.

These flaws, CVE-2024-9379, CVE-2024-9380, and CVE-2024-9381, allow attackers to bypass restrictions, execute arbitrary SQL, and gain remote code executionโ€”all with admin privileges.

Find details here: https://thehackernews.com/2024/10/zero-day-alert-three-critical-ivanti.html
๐Ÿ˜12๐Ÿ‘6๐Ÿค”5
โš ๏ธ Microsoft warns of cyberattacks abusing OneDrive, SharePoint & Dropbox.

Hackers use โ€œliving-off-trusted-sitesโ€ (LOTS) to bypass defenses. View-only files trick users into sharing 2FA tokens, leading to BEC & financial fraud.

Learn more: https://thehackernews.com/2024/10/microsoft-detects-growing-use-of-file.html
๐Ÿ˜ฑ13๐Ÿ‘10โšก1๐Ÿ˜1
๐Ÿ‘‰ Microsoft has released patches for 118 vulnerabilities, two of which (CVE-2024-43572 and CVE-2024-43573) are being actively exploited in the wild.

Find details here: https://thehackernews.com/2024/10/microsoft-issues-security-update-fixing.html

Ensure your systems are protectedโ€”apply these patches ASAP!
๐Ÿค”8๐Ÿ”ฅ6๐Ÿ‘5๐Ÿ˜5๐Ÿ‘4
New IoT regulations may force small manufacturers out of business, despite improving security. With 100+ new vulnerabilities daily, compliance costs are rising fast.

How will this impact cybersecurity? Read: https://thehackernews.com/expert-insights/2024/10/will-small-iot-device-oem-survive.html
๐Ÿ˜10๐Ÿ‘4
Social media security is crucial for protecting your brand and finances. Poor governance can lead to unauthorized access and costly mistakes.

Learn how SSPM tools can help safeguard against unauthorized access and financial risks.

Read: https://thehackernews.com/2024/10/social-media-accounts-weak-link-in.html
๐Ÿค”8๐Ÿ‘5๐Ÿ˜2
๐Ÿšจ Developers Under Attack!

A North Korean campaign, "Contagious Interview," is tricking job seekers with fake offers, leading to malware disguised as coding tasks.

Hackers use fake video conferencing apps to target both Windows & macOS.

Read: https://thehackernews.com/2024/10/n-korean-hackers-use-fake-interviews-to.html
๐Ÿ‘14๐Ÿ”ฅ4๐Ÿค”4
โš ๏ธ Multiple MMS protocol vulnerabilities pose a severe threat to industrial devices, potentially leading to crashes or remote code execution that could disrupt critical infrastructure.

Learn more: https://thehackernews.com/2024/10/researchers-uncover-major-security.html

#infosec
๐Ÿ”ฅ9๐Ÿ‘4๐Ÿค”2
Google partners with GASA and DNS RF to launch the Global Signal Exchange (GSE), providing real-time insights into scam patterns to protect businesses from cybercrime.

Read: https://thehackernews.com/2024/10/google-joins-forces-with-gasa-and-dns.html
๐Ÿค”10๐Ÿ‘5๐Ÿ‘1
๐Ÿšจ Warning: A critical #vulnerability (CVE-2024-9680) in Firefox is being actively exploited.

Donโ€™t waitโ€”ensure your browsers are updated now to protect against potential remote code execution.

Learn more: https://thehackernews.com/2024/10/mozilla-warns-of-active-exploitation-in.html
๐Ÿ˜ฑ25๐Ÿ‘13๐Ÿคฏ6๐Ÿ”ฅ3๐Ÿ˜2๐Ÿ‘1
โš ๏ธ Cyber Alerts:

โ€”Fortinet CVE-2024-23113 actively exploited, patch by Oct 30!
โ€”Palo Alto Expedition vulnerable to SQL & OS injection.
โ€”Cisco patches critical bug in Nexus Dashboard Fabric Controller.

Read: https://thehackernews.com/2024/10/cisa-warns-of-critical-fortinet-flaw-as.html

Critical systems must be patched immediately.
๐Ÿ‘9โšก3๐Ÿ”ฅ3๐Ÿค”2
๐Ÿšจ New "Mongolian Skimmer" uses Unicode obfuscation to steal sensitive data from e-commerce sites!

It disables debugging tools & adapts to browsers, making it highly evasive.

Learn more: https://thehackernews.com/2024/10/cybercriminals-use-unicode-to-hide.html
๐Ÿ‘10๐Ÿ”ฅ4โšก3๐Ÿ˜2๐Ÿคฏ1
๐Ÿง SOC Analyst burnout is surging, with 80.8% expecting stress to worsen. AI-driven triage and response can ease the burden, allowing analysts to focus on higher-value tasks.

Discover how AI can lighten the load for your team: https://thehackernews.com/2024/10/6-simple-steps-to-eliminate-soc-analyst.html
๐Ÿ‘16๐Ÿค”8
A critical unpatched #vulnerability (CVE-2024-9441) in the Nice Linear eMerge E3 access controller has been uncovered, carrying a CVSS score of 9.8, with proof-of-concept exploits already circulating.

Learn more: https://thehackernews.com/2024/10/experts-warn-of-critical-unpatched.html
๐Ÿ‘4๐Ÿ˜4โšก1
๐Ÿ‘ฉโ€๐Ÿ’ป OpenAI disrupts 20+ global deceptive operations exploiting AI models for advanced cyber activities like phishing, influence operations, and even election interference.

Learn more: https://thehackernews.com/2024/10/openai-blocks-20-global-malicious.html
๐Ÿ”ฅ9๐Ÿ‘6๐Ÿ˜5โšก2๐Ÿค”2
The digital landscape is shifting fastโ€”are you ready to keep up with the latest threats? ๐ŸŒโšก

Join us on October 17 as we break down the key findings from the 2024 Kaseya Cybersecurity Survey! Get insights into:

๐Ÿš€ How AI is transforming cyberattacks
๐Ÿ‘ฅ The challenges of user behavior
๐Ÿ›ก๏ธ How network penetration testing secure your network
๐Ÿ“ˆ What companies are doing to prepare for 2025

๐Ÿ“… Date: October 17
โฐ Time: 1 PM EST / 10 AM PST
๐Ÿ”— Save Your Spot: https://thn.news/cyber-survey-2024

Donโ€™t miss this session to stay one step ahead in cybersecurity!
๐Ÿ‘9๐Ÿ”ฅ9โšก1
๐ŸŒ Dutch police have dismantled Bohemia and Cannabia, the largest darkweb markets for illegal goods and cybercrime. Arrests in the Netherlands and Ireland, with โ‚ฌ8M in seized cryptocurrency, prove dark web anonymity is fading.

Read: https://thehackernews.com/2024/10/bohemia-and-cannabia-dark-web-markets.html
๐Ÿ‘12๐Ÿ‘10๐Ÿ˜ฑ9๐Ÿ”ฅ3โšก2๐Ÿคฏ1
๐Ÿšฉ A critical security flaw in GitLab (CVE-2024-9164) could allow attackers to run CI/CD pipelines on unauthorized branches.

Find details here: https://thehackernews.com/2024/10/new-critical-gitlab-vulnerability-could.html

Update your instance ASAP to avoid becoming the next victim.
๐Ÿ˜17๐Ÿ‘11๐Ÿ˜ฑ8๐Ÿ”ฅ4โšก1๐Ÿค”1
๐Ÿ’ป๐Ÿ”’ Cybercriminals are leveling up! Phishing campaigns now exploit GitHub links, Telegram bots, and even QR codes to bypass security and deliver malware.

Read: https://thehackernews.com/2024/10/github-telegram-bots-and-qr-codes.html
โšก20๐Ÿ”ฅ9๐Ÿค”8๐Ÿ‘5๐Ÿ˜3